Introduction
This Privacy Policy explains how ivory-ravine collects, uses, processes, and protects your personal data when you use our electronic signature services. We are committed to protecting your privacy and maintaining the security of your information in compliance with applicable data protection laws.
Data Controller
The data controller responsible for your personal data is ivory-ravine, with registered address at 28 Merrion Square North, Dublin 2, D02 X576, Ireland.
Information We Collect
We collect and process the following categories of personal data:
- Account Information: Name, email address, company name, job title, and billing information when you register for our services.
- Document Data: Documents you upload for signing, including content, metadata, and associated information.
- Signature Data: Electronic signatures, IP addresses, timestamps, and authentication data related to signing activities.
- Usage Information: Log data, device information, browser type, and interaction patterns with our platform.
- Communication Data: Records of correspondence with our support team and service-related communications.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contractual Necessity: Processing required to provide our electronic signature services.
- Legitimate Interests: Improving our services, preventing fraud, and ensuring security.
- Legal Obligations: Compliance with regulatory requirements and legal processes.
- Consent: Where you have provided explicit consent for specific processing activities.
How We Use Your Information
We use collected data for the following purposes:
- Providing and maintaining electronic signature services
- Processing signature requests and managing document workflows
- Generating audit trails and compliance documentation
- Communicating about service updates and account matters
- Improving platform functionality and user experience
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations and responding to lawful requests
Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service Providers: Third-party vendors who assist with hosting, analytics, and operational support under strict data processing agreements.
- Business Partners: When you explicitly authorize integration with third-party applications.
- Legal Authorities: When required by law or to protect our legal rights.
- Corporate Transactions: In connection with mergers, acquisitions, or asset sales, subject to confidentiality obligations.
Data Security
We implement comprehensive security measures including:
- Encryption of data in transit using TLS 1.3
- Encryption of data at rest using AES-256
- Regular security audits and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection practices
- Incident response procedures and breach notification protocols
Data Retention
We retain personal data for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Document data and audit trails are retained for a minimum of seven years to meet legal and regulatory requirements. Account information is retained while your account remains active and for a reasonable period thereafter.
Your Rights
Under GDPR and applicable data protection laws, you have the following rights:
- Right of Access: Request copies of your personal data.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data under certain circumstances.
- Right to Restrict Processing: Limit how we use your data.
- Right to Data Portability: Receive your data in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent for consent-based processing.
To exercise these rights, contact us at [email protected]. We will respond within one month of receiving your request.
International Data Transfers
Your data is primarily stored and processed within the European Economic Area. If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Cookies and Tracking
We use cookies and similar technologies to enhance user experience and analyze platform usage. For detailed information about our cookie practices, please review our Cookie Policy.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes through email or prominent notice on our platform. The "Last updated" date at the top of this policy indicates when it was most recently revised.
Contact Information
For questions about this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Address: 28 Merrion Square North, Dublin 2, D02 X576, Ireland
Supervisory Authority
You have the right to lodge a complaint with the Irish Data Protection Commission if you believe we have not handled your personal data in accordance with applicable law. Contact details are available at dataprotection.ie.