Skip to content

Privacy Policy

This policy explains how DDSign collects, uses, stores, and protects your information across our web platform and integrations.

1. Information We Collect

  • Personal Data: Name, email address, phone number, organization details, login credentials, digital signature data, and document-related metadata.
  • Technical Data: IP address, browser type, device identifiers, operating system, and usage logs.

2. How We Use Information

  • Provide and operate electronic signature services
  • Authenticate users and prevent fraud
  • Improve platform performance and reliability
  • Comply with legal and regulatory obligations

3. Data Protection & Security

We apply appropriate administrative, technical, and organizational safeguards including encryption, access controls, and secure storage mechanisms.

4. Private Key Protection

DDSign does not generate, store, or have access to Subscriber private keys at any point. Private keys are generated on the Subscriber's own device during the certificate enrollment process using the Web Crypto API or a locally installed cryptographic module. The key material never leaves the device in unencrypted form.

Where a Subscriber opts to use a hardware security module (HSM) or a FIPS 140-2 Level 2 (or higher) compliant token, the private key is generated and stored entirely within that hardware device and cannot be exported.

For software-based key storage, the private key is encrypted at rest using AES-256 and protected by a passphrase that only the Subscriber knows. DDSign does not hold, escrow, or back up this passphrase. If the Subscriber loses the passphrase, DDSign cannot recover the private key, and the associated certificate must be revoked and reissued.

During signing operations, the private key is loaded into memory only for the duration of the cryptographic operation and is zeroed from memory immediately after use. Signing is performed locally on the Subscriber's device; DDSign receives only the resulting digital signature, not the key.

DDSign recommends that Subscribers take the following steps to protect their private keys:

  • Store private keys on hardware tokens or HSMs where possible.
  • Use strong, unique passphrases for software-based key stores.
  • Do not copy, email, or transfer private key files between devices.
  • Report suspected key compromise to DDSign immediately so the certificate can be revoked.
  • Keep the operating system and browser used for signing operations up to date with security patches.

If a Subscriber suspects that their private key has been compromised, they must notify DDSign within 24 hours. DDSign will revoke the affected certificate, publish it to the Certificate Revocation List (CRL), and update the OCSP responder. The Subscriber may then apply for a new certificate following the standard enrollment process.

5. Cookies & Tracking Technologies

DDSign uses cookies and similar technologies to enhance functionality and analyze usage. You can manage cookies through your browser settings.

6. Third-Party Services

We rely on trusted third-party providers for hosting, analytics, document processing, and infrastructure. These providers process data only as required to deliver services.

7. Data Retention

Documents and related metadata are retained only for as long as necessary to provide the service or meet legal requirements. Users may delete documents or accounts in accordance with platform functionality.

8. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict processing, or request portability of your personal data.

9. International Data Transfers

Your data may be processed in countries outside your place of residence. We implement safeguards to ensure adequate data protection.

10. Word Add-in & Integrations

When using DDSign through integrations such as the Microsoft Word Add-in, documents are transmitted securely to DDSign servers solely for the purpose of enabling electronic signing.

11. Policy Updates

We may update this Privacy Policy periodically. Continued use of the platform constitutes acceptance of the updated policy.