← Back to procusign.com

Procusign Privacy Notice

Last updated: 4 August 2026

Data controller
Procuman Software OÜ
Registered office: Paju tn 2, 50603 Tartu, Estonia
Registry code: 16587438
VAT number: EE102542686
E-mail: info@procuman.com
Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — www.aki.ee

Purpose

At Procusign, privacy protection is a top priority issue. The purpose of this Notice is to set out how Procuman Software OÜ ("Procusign", "us", "our" or "we") collects, uses, stores, or otherwise processes personal information about customers and other individuals (collectively "you") who access or use our websites, products and services. By using our Services, you understand that we will collect and use your personal information as described in this Privacy Notice.

In some cases, we may process your personal information pursuant to an agreement with a third-party organization. In those cases, the terms of that agreement may govern how we process your personal information. If you believe a third-party organization has asked us to process your personal information on their behalf, please consult with them in the first instance as they will be responsible for how we process your information. This Privacy Notice ("Notice") does not apply to any third-party websites and apps that you may use, including those to which we link in our Services. You should review the terms and policies for third-party websites and apps before clicking on any links.

Procusign's core product and Services help users create, complete, and show the validity of digital or electronic transactions, such as electronically signing a Purchase Order, NDA, Contract or MOU. As part of our Services, users want us to collect and record information that helps the parties prove the validity of the transactions, such as the names of the persons who are involved in the transactions and the devices those persons use.

Procusign is built on Documenso, the open-source eSignature platform. Underlying eSignature functionality, audit trail generation, and certificate-of-completion are provided by Documenso and operated by Procuman Software OÜ.

We recommend that you read this Notice in full to ensure you are fully informed about the manner in which we collect, use, store, or otherwise process your personal information as well as your privacy rights.

1. Personal information collection and storage

Information Collection

You have choices about whether you visit our websites, install our apps, or provide personal information to us. However, if you do not provide us with certain personal information, you may not be able to use some parts of our Services. For example, if you do not adopt an electronic signature, then you will not be able to sign certain electronic documents on our Service. For choices and rights you may have, please see Sections 5 and 7 of this Notice.

Personal Information We Collect from You. You provide us with personal information about yourself when you:

  • Register or log in to your account.
  • Start, sign, or review an electronic document.
  • Create or edit your user profile.
  • Contact customer support.
  • Purchase or order Procusign products and services online.
  • Use Procusign products and related services.

You also provide us with personal information about others when you use parts of our Services, such as when you:

  • Start or participate in an electronic transaction, such as an envelope within Procusign eSignature.
  • Add others as a member to an existing account.
  • Refer colleagues or business partners.

Your main choice for this type of personal information is simply not providing it, such as by not creating a profile. For other choices you may have, please see Section 5 of this Privacy Notice.

Examples of the categories of personal information you may provide are:

  • Identifiers and contact information. This includes your name, email address, mailing address, phone number, or electronic signature.
  • Commercial information. This includes billing and payment information (e.g., credit card number, expiration date, visual cryptogram, transaction records, consumption records), products or services purchased.
  • Geolocation. This includes physical location to the extent required for the audit trail of an electronic signature (signer IP, timestamp, user-agent) — a legally-required element of an eIDAS-compliant electronic signature.

Personal Information We Collect Automatically. We may automatically collect personal information from you and your devices when you use our Services, including when you visit our websites or apps without logging in. For choices you may have on what information we automatically collect, please see Section 5 of this Privacy Notice.

The categories of personal information we may automatically collect include:

Device, Usage Information, and Transactional Data. We collect personal information about how you use our Services and the devices (e.g., computers, mobile phones, tablets) you use to access our Services. This may include, but is not limited to, the following:

  • IP address.
  • Precise geolocation information that you allow our apps to access (usually from your mobile device).
  • Unique device identifiers and device attributes, such as operating system and browser type.
  • Usage data, such as web log data, referring and exit pages and URLs, platform type, number of clicks, domain names, landing pages, pages and content viewed and the order of those pages, the amount of time spent on particular pages, the date(s) and time(s) you used our Services, the frequency of your use of our Services, error logs, and other related information.
  • Transactional data, such as names and email addresses of parties to a transaction, subject line, history of actions that individuals take in connection with a transaction (e.g., review, sign, enable features) and personal information about those individuals or their devices, such as name, email address, IP address, and authentication methods.

Cookies and Related Technologies. We use cookies, which are text files containing small amounts of information that are downloaded on your device, or related technologies, such as web beacons, local shared objects and tracking pixels, to collect and/or store information. The Procusign marketing website (procusign.com) does not currently use cookies for tracking or analytics; cookies are limited to the eSignature app (app.procusign.com) for session and authentication purposes.

Information We Collect from Other Sources. Subject to applicable law, we may collect personal information about you from others, such as:

  • Third-Party Sources. Examples of third-party sources include marketers, partners, researchers, affiliates (companies under common ownership or control of Procuman Software OÜ), service providers, and others where they are legally allowed to share your personal information with us. For example, if you register for our Services on another website, the website may provide your personal information to us.
  • Other Customers. Other customers may give us your personal information. For example, if a customer wants you to sign an electronic document in our Services, he or she will give us your email address and name.
  • Combining Personal Information from Different Sources. We may combine the personal information we receive from other sources with personal information we collect from you (or your device) and use it as described in this Notice.

Personal Information We Collect & Process on Behalf of Customers. When our business customers use certain Services, we generally process and store limited personal information on their behalf as a data processor. For example, in the context of Procusign eSignature, when a customer uploads contracts or other documents for review or signature, we act as a data processor and process the documents on the customer's behalf and in accordance with their instructions. In those instances, the customer is the data controller and is responsible for most aspects of the processing of the personal information. If you have any questions or concerns about how personal information is processed in these cases, including how to exercise your rights as a data subject, you should contact the customer (either your employer or the individual or entity requesting your signature). If we receive any rights requests concerning instances where we act as data processor, we will forward your query on to the relevant customer.

Information Storage

Your personal information collected and generated during your use of Procusign products and services is stored in the European Union. The Procusign marketing site (procusign.com) is hosted on a Hetzner server in Frankfurt, Germany. The Procusign eSignature service (app.procusign.com) is operated from Frankfurt, Germany. All eSignature data, audit trail, and certificate of completion remain within the European Union at all times. Cross-border data transfers outside the European Economic Area are not performed as part of the ordinary course of the Procusign Services.

Where data must transit across borders (e.g., a signatory accessing the eSignature service from outside the EEA), we ensure appropriate safeguards are in place in accordance with Chapter V GDPR (such as Standard Contractual Clauses, or reliance on adequacy decisions).

In compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Estonian Personal Data Protection Act (Isikuandmete kaitse seadus), and other applicable regulations, we will only retain your personal information for the duration necessary to fulfill Procusign's service objectives. Once the retention period expires, we will either delete or anonymize your data unless otherwise required by law or agreed upon with you. We will no longer use or disclose your personal information under this account.

We may change the retention period of personal information for the following reasons, as required by law:

  • To comply with applicable laws, regulations and other relevant provisions;
  • To comply with the requirements of court judgments, rulings or other effective legal documents;
  • To comply with the requirements of relevant government agencies or organizations authorized by law.

2. Use of Personal Information

In general, and subject to applicable law, including consent (as required), we may use your personal information to provide, fix, and improve our Services, develop new Services, and market our companies and their products and Services. Examples of how we use the personal information we process include, but are not limited to, the following:

  • Provide you with and collect payment for the products and Services you request.
  • Create your account and manage our relationship with you (e.g., communicating with you, providing you with requested information).
  • Send you records of our relationship, including for purchases or other events.
  • Market features, products, or special events using email or phone or send you marketing communications about third-party products and services we think may be of interest to you (you may opt out at any time).
  • Record details about transactions involving electronic documents (e.g., who initiated, viewed, or signed the documents; signers' IP addresses; timestamps) — this is required to satisfy the audit-trail obligations of the eIDAS Regulation (Regulation (EU) No 910/2014).
  • Create and review data about our users and how they use our Services.
  • Fix problems you may have with our Services, including answering support questions, customer education and training, and resolving disputes.
  • Manage the Services platform, including support systems and security.
  • Prevent, investigate and respond to fraud, unauthorized access to or use of our Services, breaches of terms and policies, or other wrongful behavior.
  • Comply with legal obligations.
  • Meet legal retention periods.
  • Establish, exercise, or defend our rights in legal claims.

Other Uses. We may combine the personal information we collect ("aggregate") or remove pieces of personal information ("de-identify") to limit or prevent identification of any particular user or device to help with goals like research and marketing. Once such information has been aggregated and anonymized so that it is no longer considered personal information under applicable data protection law, this Notice does not apply.

Lawful Basis for Processing Your Personal Information. Where the GDPR applies and where Procusign acts as a data controller, our lawful basis for collecting and using the personal information described in this Notice will depend on the type of personal information concerned and the specific context in which we collect or use it.

We normally collect or use personal information only where we have your consent to do so, where we need the personal information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may have a legal obligation to collect or retain personal information or may need the personal information to protect your vital interests or those of another person. For example, when we:

  • Use personal information to create and manage an account, we do so in order to provide you with relevant Services and perform our contract with you (Article 6(1)(b) GDPR).
  • Gather and record data associated with use of a digital certificate or electronic signature, we do so to comply with legal obligations under the eIDAS Regulation and the Estonian Personal Data Protection Act (Article 6(1)(c) GDPR).
  • Use names and email addresses for email marketing purposes, we do so with your consent (which you can withdraw at any time) or, where permitted under applicable law, on the basis of our legitimate interests (Article 6(1)(a) and (f) GDPR).
  • Gather usage data and analyze it to improve our Services or ensure the security of our websites, we do so based on our legitimate interest in safeguarding and improving our Services (Article 6(1)(f) GDPR).

If you have questions about or need further information concerning the lawful basis on which we collect and use your personal information, please contact us using the contact details provided in Section 10 of this Notice. Note that in situations where Procusign acts as a processor, it is our customer who determines the appropriate legal basis associated with processing activities, and queries about the applicable lawful basis should be directed to them.

3. Personal Information Sharing

Subject to applicable law, including consent (as required), we may share personal information as follows:

Service Providers / Sub-processors. We share your personal information with service providers we use to support our Services. These companies provide services like hosting (Frankfurt, Germany), eSignature platform (Documenso, open-source, operated by Procuman Software OÜ as a hosted instance), payment processing, transactional email delivery, and customer support. We have contracts with our service providers that address the safeguarding and proper use of your personal information, in accordance with Article 28 GDPR.

Affiliates. We may share your personal information with other companies under common ownership or control with Procuman Software OÜ. These companies use your personal information as described in this Notice.

Public or Government Authorities. We may share your personal information to comply with our legal obligations, regulations, or contracts, or to respond to a court order, administrative, or judicial process, such as a subpoena, government audit, or search warrant where we are legally compelled to do so. We also may share your information when there are threats to the physical safety of any person, violations of Procusign policies or other agreements, or to protect the legal rights of third parties, including our employees, users, or the public.

Corporate Transactions. Your personal information may be disclosed or transferred to relevant third parties in the event of, or as part of the due diligence for, any proposed or actual reorganization, sale, merger, consolidation, joint venture, assignment, transfer, or other disposition of all or part of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding). If a corporate transaction occurs, we will provide notification of any changes to the control of your information, as well as choices you may have.

Consent. We may share your personal information in other ways if you have asked us to do so or have given consent.

Your personal information may also be shared as described below:

  • Other Procusign users. When you allow others to access, use, or edit content in your account, we share that content with them. For example, if you send an envelope to others for review or signature, we make the contents of the envelope available to them.
  • Third Parties. When you make a payment to another user within our Services, we share your payment method details with the third-party payment processor selected by you.

Transfers to the U.S. and Third Countries. Subject to applicable law, we may transfer your personal information outside of your jurisdiction, including for further processing. As a matter of standard practice, Procusign does not transfer personal data to the United States or to any third country outside the European Economic Area. Where a transfer outside the EEA is unavoidable (e.g., where a sub-processor is established outside the EEA), we ensure appropriate safeguards in accordance with Chapter V GDPR, such as Standard Contractual Clauses adopted by the European Commission, or reliance on an adequacy decision.

4. Retention of Personal Information

We keep your personal information for no longer than necessary for the purposes for which it is processed. The length of time for which we retain personal information depends on the purposes for which we collected and use it and/or as required to comply with applicable laws as set out in our data retention policy and information handling standards. Generally, this means we retain your personal information to comply with any retention or statutory limitations (including the Estonian Accounting Act / Raamatupidamise seadus, which sets a 7-year retention period for accounting records) or for purposes of performing a contract with you. Where there are technical limitations that prevent deletion or anonymization, we safeguard personal information and limit active use of it.

5. Your Choices

This section describes many of the actions you can take to change or limit the collection, use, storage, or other processing of your personal information.

  • Profile. You are not required to fill out a profile. If you do, you can access and review this personal information. If any personal information is inaccurate or incomplete, you can make changes in your account settings.
  • Cookies and Other Related Technology. You can decline cookies through your browser settings.
  • Device and Usage Information. If you do not want us to see your device location, you can turn off location sharing on your device, change your device privacy settings, or decline to share location on your browser.
  • Closing Your Account. If you wish to close your account, please log in to your account and edit your plan, or contact us at info@procuman.com.
  • Complaints. We are committed to resolving valid complaints about your privacy and our collection, use, storage, or other processing of your personal information. For questions or complaints regarding our data use practices or this Notice, please contact us using the contact details provided in Section 10 of this Notice.

6. Children's Privacy

Our Services are not designed for and are not marketed to people under the age of 13, the age of consent for information-society services under the Estonian Personal Data Protection Act and Article 8 GDPR. We do not knowingly collect or ask for personal information from children under 13. We do not knowingly allow children under 13 to use our Services. If you are under 13, please do not use our Services or send us your personal information. We delete personal information that we learn is collected from a child under 13 without verified parental consent. Please contact us using the contact details provided in Section 10 of this Notice if you believe we might have personal information from or about a child under 13 that should be removed from our system.

7. Your Privacy Rights

You may have certain rights related to your personal information, subject to local data protection laws, as described in more detail below. To exercise any of these rights, please contact us using the contact details provided in Section 10 of this Notice.

You can access and review personal information associated with your account at any time by signing in to your Procusign account at app.procusign.com.

Subject to the GDPR and the Estonian Personal Data Protection Act, you also have the right to request the following from us:

  • How we collect and use your personal information and why; the categories of personal information involved; the categories of recipients of your personal information; how we received your personal information and its source; our business purpose for using your personal information; and how long we use or store your personal information or the manner in which we determine relevant retention periods (Article 15 GDPR — right of access).
  • To correct inaccurate personal information about you, and you should notify us immediately if you believe the personal information we hold about you is inaccurate, incomplete, or out-of-date (Article 16 GDPR — right to rectification).
  • In certain situations, to erase or stop using your personal information (Article 17 GDPR — right to erasure / "right to be forgotten"), to object to or restrict the use of your personal information (Articles 18, 21 GDPR), or to export your personal information to another controller (Article 20 GDPR — right to data portability).
  • Where we rely on your consent to process your personal information, you have the right to decline consent and/or, if provided, to withdraw consent at any time. This will not affect the lawfulness of processing prior to the withdrawal of your consent. At any time, you can request that we stop using your personal information for direct marketing purposes (Article 7(3) GDPR).
  • Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you (Article 22 GDPR).

If you are unsatisfied with our response to your complaint, you have a right to raise questions or complaints with your local data protection authority at any time. For residents of Estonia, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) — www.aki.ee. For residents of other EEA Member States, the relevant supervisory authority is the one established in your country of residence; a list is available on the European Data Protection Board's website at edpb.europa.eu.

If you make a request to exercise the rights referenced above, we will require you to provide certain information for identity verification purposes. If you have an account with us, we may verify you through your login of your account. If you do not have an account with us, we may require you to provide additional information from which we can confirm your identity. You may authorize an agent to make a request to us on your behalf and we will verify the identity of your agent or authorized legal representative by either seeking confirmation from you or documents that establish the agent's authorization to act on your behalf.

Certain personal information may be exempt from such requests under applicable law. We need certain types of personal information so that we can provide the product and Services to you. If you ask us to delete it, you may no longer be able to access or use our product and Services.

If you wish to exercise these rights, please contact us using the contact details provided in Section 10 of this Notice.

8. How We Protect Your Personal Information

We have implemented appropriate technical, physical and organizational measures to protect your personal information from misuse or accidental, unlawful, or unauthorized destruction, loss, alteration, disclosure, acquisition, or access as well as all other forms of unlawful processing. To achieve this, we have developed and implemented an Information Security Management System and other sub-policies and guidelines relating to the protection of your personal information. For example, our staff is permitted to access customer personal information only to the extent necessary to fulfill the applicable business purpose(s) and to perform their job, subject to confidentiality obligations.

The Procusign Services are built on Documenso, the open-source eSignature platform. The signing cryptography, audit trail format, and certificate generation are all open source and publicly auditable (see documenso.com). Audit trails generated for each eSignature event satisfy the requirements of Article 25 of the eIDAS Regulation.

9. Changes to This Privacy Notice

We may amend this Notice to reflect changes in the law, our companies, our Services, our data processing practices, or advances in technology. Our use of the personal information we collect is subject to the Privacy Notice in effect at the time such personal information is used. Depending on the type of change, we may notify you of the change by posting on this page, by email (if you have an account), or by other reasonable means. The "Last updated" date at the top of this Notice will reflect the date of the most recent change.

10. How to Contact Us

For questions or complaints regarding our use of your personal information or this Notice, please contact us at info@procuman.com.

By post:

Procuman Software OÜ
Paju tn 2
50603 Tartu
Estonia

If you are unsatisfied with our response to your complaint, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at www.aki.ee, or with the data protection authority of your habitual residence.