Privacy Policy
Last Updated: August 11, 2026
1. Introduction
Initial and Sign ("we", "us", "our", or "Company") operates the Initial and Sign service. This Privacy Policy describes how we collect, use, and protect your personal information when you use our Service.
Privacy Act Compliance: We are subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy complies with APP 1 (transparent management), APP 11 (security), APP 12 (access), and APP 13 (correction).
2. Personal Information We Collect
We collect personal information necessary to provide our electronic signing service:
- Identity Information: Name, email address, phone number (optional)
- Company Information: Organization name, role, ACN/ABN (if signing for company)
- Authentication Data: Password hashes, 2FA tokens, backup codes
- Transaction Data: Documents uploaded, signatures captured, timestamps
- Usage Data: IP address, browser type, pages accessed
- Audit Trail Data: Who accessed what, when, what action taken
- Signature Data: Your signature image (biometric personal information)
3. How We Use Your Information
We use your personal information for:
- Providing electronic signing services
- Authenticating your identity (login, 2FA, OTP verification)
- Creating and maintaining audit trails (legal evidence)
- Preventing fraud and unauthorized access (rate limiting, security monitoring)
- Customer support and technical assistance
- Complying with legal obligations (electronic transactions laws)
- System maintenance and service improvement
4. Security of Personal Information (APP 11)
Data Protection: We take the security of your personal information seriously and use reasonable steps to protect it:
- In Transit: All data transmission uses TLS 1.2+ encryption
- At Rest: Database and file storage encrypted with AES-256
- Access Control: Limited to authorized staff only; all access logged and audited
- Authentication: Passwords hashed with Argon2id; multi-factor authentication available
- Token Security: Signing tokens hashed; never stored in plaintext
- Audit Trail: Cryptographically secured (hash-chained) to prevent tampering
- Rate Limiting: Public endpoints protected against brute-force attacks
Important: No method of transmission over the Internet is 100% secure. If you suspect unauthorized access, contact security@cloudsign.local immediately.
5. Data Retention & Lifecycle
- Signed Documents: Retained for 7 years (required for legal evidence under electronic transactions laws)
- Audit Logs: Retained for 3 years (compliance and forensics)
- Authentication Records: (2FA, OTP logs) Retained for 1 year
- User Accounts: Deleted within 30 days of closure (legal hold exceptions apply for disputes)
- User-Requested Deletion: We will process deletion requests within 30 days, subject to legal holds
6. Your Privacy Rights (APP 12 & 13)
You have rights under the Privacy Act. You may request to:
- Access Your Information: Receive a copy of your personal information (within 30 days)
- Correct Inaccurate Data: Request correction of your personal information
- Delete Your Data: Request deletion of your account and associated data (subject to legal holds)
- Opt-out: Unsubscribe from non-essential communications
- Lodge a Complaint: Contact the Privacy Commissioner if you believe we have breached your privacy
To exercise these rights, email: privacy@cloudsign.local
7. Data Breach Notification
If we detect unauthorized access to your personal information:
- We will notify affected individuals within 30 days
- Notification will be via email and phone (if available)
- We will explain: what was accessed, what we're doing about it, what steps you should take
- You have the right to contact the Privacy Commissioner regarding the breach
8. Third-Party Disclosure
We do not sell or rent your personal information. We may disclose information only:
- To document recipients (signers and originators - necessary for signing)
- To law enforcement or government agencies (when legally required)
- To our service providers under confidentiality agreements
- With your explicit consent
9. International Data Transfers
Your personal information is stored and processed in Australia. We do not transfer personal information overseas without your explicit consent (except where required by law).
10. Children's Privacy
Our Service is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete it immediately.
11. Privacy Commissioner
If you have unresolved privacy concerns, you may escalate your complaint to:
Office of the Australian Information Commissioner (OAIC)
Web: www.oaic.gov.au
Phone: 1300 363 992
12. Changes to This Privacy Policy
We may update this Privacy Policy at any time. We will notify you by posting the new policy on this page and updating the "Last Updated" date. Your continued use of our Service constitutes acceptance of the updated policy.
13. Contact Us
Privacy questions or concerns?
Email: privacy@cloudsign.local
Security issues: security@cloudsign.local