Privacy Policy
Last updated: September 2026
1. Introduction
This privacy policy explains which personal data CanUSign processes when you use the service, for what purposes and on what legal basis.
2. Data Controller
3. Data We Collect
We collect the following data:
- Account data: Email address for authentication
- Contract data: Contracts and documents you create
- Signature data: Digital signatures, IP addresses, timestamps
- Saved signature: If you store a signature for future contracts (in your settings or while signing), we keep the image of that signature in your account so you can insert it with one click when signing. Storing it is optional; without it you draw your signature anew for each contract. The legal basis is Art. 6(1)(b) GDPR. The image is stored with Vercel (storage location Frankfurt am Main), is not publicly accessible and is visible only to you. We do not analyse it biometrically and do not compare it with other signatures. You can change or delete it at any time in your settings; it is also deleted when you delete your account. Signatures you have already inserted into contracts remain part of those contracts and their audit trail.
- Abuse protection for the free credit: New accounts receive one free credit once. So that it cannot be claimed repeatedly by registering again, we store your email address, your IP address and the time when you register and compare them with earlier registrations. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is preventing misuse of the free offer. We keep the IP address for seven days and the email address and time for two years, even if you delete your account earlier, because otherwise the protection could be bypassed by deleting the account and signing up again. You can object to this processing under Art. 21 GDPR.
- Usage data: How you use our service
- Payment data: Processed securely via Stripe
4. Purpose of Data Processing
Your data is used to:
- Provide our contract service
- Process digital signatures
- Create audit certificates as proof
- Process payments
- Improve our service
5. Legal Basis
Processing is based on Art. 6(1)(b) GDPR (contract performance), Art. 6(1)(a) GDPR (consent), and Art. 6(1)(f) GDPR (legitimate interest).
Information about similar services
If you buy from us, we may occasionally send information about similar canusign services to the email address you gave at purchase (Section 7(3) of the German Unfair Competition Act, UWG). The legal basis is our legitimate interest in direct marketing under Art. 6(1)(f) GDPR. You can object to this use at any time (Art. 21(2) GDPR), in your settings or by replying to any email; this costs nothing beyond the transmission costs at basic rates. After an objection we no longer use the address for this purpose.
6. Data Storage & Security
Your data is encrypted and stored on secure servers in the EU. We use industry-standard security measures.
7. Deleting your account and how long we keep data
We store contracts, together with uploaded documents, signatures and the audit trail, only for as long as necessary. Drafts that were never paid for are deleted 90 days after their last change; if you have an account, we email you 30 days before and delete no earlier than 30 days after that email. All other contracts in an account stay stored for as long as the account exists, because keeping them is part of the service you use; you can delete any contract yourself at any time. Contracts without an account are deleted at the end of the third calendar year after signing, or after the last change for contracts without a signature. That is how long claims arising from a contract can usually be made (Sections 195 and 199(1) of the German Civil Code, BGB). The legal basis is Art. 6(1)(b) and (f) GDPR. Once deleted, we cannot restore anything. Contracts kept after an account is deleted follow the period in the next paragraph.
If you delete your account, we delete your account data, your saved signature, your templates, API keys and webhooks, and every document that not all parties have signed yet. Fully signed contracts that other people besides you are party to are not deleted right away. This does not apply to contracts created through our API; we delete those with the account. The signed document and the audit trail with the signers' names, email addresses, times, IP addresses and device details are kept so that the other parties can still retrieve their contract and prove it. These contracts are then linked to no account and can only be reached through the signers' links and the verification page. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest, and that of the other parties, is being able to prove, assert or defend claims arising from the contract (Art. 17(3)(e) GDPR). We delete these contracts at the end of the tenth calendar year after the last signature. After that period, contractual claims under German law are time-barred regardless of when anyone learned of them (Section 199(4) German Civil Code, BGB). You may object to this storage on grounds relating to your particular situation (Art. 21(1) GDPR). We then assess your objection individually. We keep payment data and invoices because commercial and tax law require us to (Section 257 German Commercial Code, Section 147 German Fiscal Code): accounting records for eight years, counted from the end of the calendar year of the payment. The legal basis for this is Art. 6(1)(c) GDPR.
8. Your Rights (GDPR)
Under GDPR, you have the following rights:
- Right to access your stored data
- Right to rectification of inaccurate data
- Right to deletion of your data
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right to withdraw your consent
9. Third-Party Services
We use the following third-party services: Vercel Analytics and Speed Insights (performance measurement). Transfers to the USA are based on the EU-US Data Privacy Framework (DPF) or the Standard Contractual Clauses (SCC). Further services:
- Google Cloud: PDF generation and the AI features (detecting signature fields in uploaded documents, short version of a contract for the signer). Processing takes place in Frankfurt am Main, Germany. Contractually, the content is not used to train AI models.
- Stripe: Payment processing (USA, EU-US Data Privacy Framework (DPF) or Standard Contractual Clauses (SCC))
- Resend: Email delivery (USA)
- Vercel: Hosting and infrastructure (provider based in the USA, the functions run in Frankfurt am Main, Germany)
- Neon: Database hosting (EU)
- e-Signature.eu: Qualified electronic signature, only when the sender chooses it for a signer. For this, the finished document, the role and the email address of the signer go to e-Signature.eu (VisitOnWeb, Belgium), which works on our behalf (Art. 28 GDPR); eID Easy (Estonia) is its subprocessor for the technology. The signer identifies there with itsme or Evrotrust and signs. What comes back to us is the signed document and the name confirmed in the identification.
10. Cookies
We set technically necessary cookies for authentication and session management without consent. Vercel Analytics and Speed Insights work without cookies and without storing anything on your device. No consent under § 25 TDDDG / Art. 5(3) ePrivacy Directive is required for them. For audience measurement the site also stores a random session identifier in your browser's sessionStorage. It contains no personal data, is deleted when the tab is closed, and is exempt from consent as strictly necessary storage under § 25(2) TDDDG.
11. Contact
For privacy-related questions, contact us at: contact@canusign.com