ClosedInk

Privacy Policy

Last updated: June 2026

1. Information We Collect

ClosedInk processes e-signature data on behalf of partner applications ("Partners"). When a Partner integrates ClosedInk, we receive the following data to provide e-signature services:

  • Signer information: Names, email addresses, IP addresses, browser user agents, and timestamps
  • Document data: PDF documents, signature images, field placements, and completed signed documents
  • Partner user context: The email address of the Partner user who initiates a signature request (passed via the user_email parameter)
  • Audit data: Full signing audit trails including consent records, signature timestamps, and document hashes

2. How We Use Your Data

  • Facilitating legally-binding electronic signatures (ESIGN, UETA, eIDAS compliant)
  • Generating tamper-evident audit certificates for completed documents
  • Displaying signature status and envelope dashboards within Partner applications
  • Maintaining the integrity and security of the signing process
  • Complying with legal obligations and enforcing our Terms of Service

3. Data Sharing & Third Parties

ClosedInk does not sell personal data. Data is shared only:

  • With the Partner application that initiated the signature request
  • With signers (recipients of signature requests) to complete the signing process
  • As required by law or to protect our legal rights

ClosedInk is built on the Base44 platform. Base44 acts as a data processor and maintains SOC 2 compliance for infrastructure security.

4. Data Retention

Completed signed documents and their audit trails are retained indefinitely for legal validity, unless the Partner or signer requests deletion in accordance with applicable law. Uncompleted envelopes (drafts, expired, voided) may be purged after 90 days of inactivity.

5. User Consent & Revocation

Partner users must provide explicit consent before using ClosedInk for e-signatures. If a user revokes consent, their data will not be used for new signature requests. Previously completed signed documents remain legally valid and are retained per our retention policy. Users may request data deletion by contacting their Partner application administrator or ClosedInk support.

6. Security

All documents are encrypted in transit (TLS 1.3) and at rest (AES-256). Signing sessions are authenticated via unique, time-limited tokens. Audit certificates include SHA-256 hashes for tamper detection. API access is restricted to Partner-authorized API keys.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction or deletion of your data
  • Withdraw consent for future processing
  • Receive a copy of your data in a portable format

To exercise these rights, contact your Partner application administrator or email privacy@closedink.com.

8. Contact

For privacy-related inquiries: privacy@closedink.com