Legal
Effective 19 June 2026

Privacy Policy

How OwnSigner collects, uses, and protects information when you visit ownsigner.com or use the OwnSigner platform.

هذا المستند القانوني متاح حاليًا باللغة الإنجليزية. النسخة الإنجليزية هي المرجع الرسمي. سيتم نشر ترجمة عربية معتمدة قانونيًا قريبًا.

Last updated: 19 June 2026 · Version 1.0

OwnSigner is sovereignty-first. When you deploy OwnSigner in your own cloud or on-premise, document contents, signatures, and audit logs stay on infrastructure you control. We never see them.

1. Who we are

"OwnSigner", "we", "us", or "our" refers to the OwnSigner product operated by Hany Elmaghrabi. We can be reached at [email protected].

2. What this policy covers

This Privacy Policy describes how we handle personal data in three contexts:

3. Marketing website

3.1 What we collect

3.2 Why we use it

3.3 Legal basis (GDPR)

Legitimate interest (operating and securing the site) and, where required, your consent (e.g. demo requests).

4. OwnSigner Cloud (managed SaaS)

4.1 Roles

When you use OwnSigner Cloud, you are the Data Controller of the documents, signatures, and signer details you upload. OwnSigner is the Data Processor acting on your documented instructions.

4.2 Categories of data processed

CategoryExamplesRetention
Account dataEmail, name, hashed password, roleUntil you delete the account
Document contentUploaded PDFs / Office docsPer your retention settings (default: indefinite until deleted)
Signer identitySigner email, name, phone (if OTP), IP, user agentFor audit-trail purposes — at least 6 years for legal evidence
Signature artifactsDrawn signature images, captured timestampsBundled with the signed document
Audit logsEvery view, signature, decline event with IP + timestampSame as document retention

4.3 Where data is stored

You choose your region during onboarding. We offer hosting in EU (Frankfurt), US (us-east-1), and KSA (Jeddah). Documents do not leave your selected region.

4.4 Sub-processors

For OwnSigner Cloud we use:

A current list of sub-processors is provided in the Data Processing Addendum at /dpa.html. We notify customers of any change 30 days in advance.

5. Self-hosted OwnSigner

If your organization runs OwnSigner on your own infrastructure (private cloud, on-prem, or air-gapped), OwnSigner Inc. processes no document, signer, or signature data on your behalf. We do not have access to your data, and this Privacy Policy does not apply to that data — your own privacy policy does.

We may receive optional, anonymous telemetry (version number, error counts) only if you enable it. Telemetry never includes document content, signer details, or any personal data.

6. Your rights

Subject to applicable law (GDPR, KSA PDPL, UAE PDPL, CCPA, etc.), you have the right to:

For OwnSigner Cloud customers, document-level rights of signers (data subjects) should be exercised through the controlling customer organization in the first instance.

Submit a request: [email protected]. We respond within 30 days.

7. Security

We use industry-standard safeguards including:

8. International transfers

For OwnSigner Cloud, we host all data in the region you select. We do not transfer personal data outside that region. For incidental support transfers (e.g. support email exchanges), we rely on Standard Contractual Clauses where required by law.

9. Children

OwnSigner is not directed at children under 16. If we learn we have collected personal data of a child without parental consent, we will delete it.

10. Changes to this policy

We will notify registered customers by email at least 30 days before material changes. The current version is always available at this URL.

11. Contact

OwnSigner — Privacy Officer
Email: [email protected]
Website: ownsigner.com

Template notice. This Privacy Policy is a working template provided in good faith. Have it reviewed by qualified counsel in your jurisdiction before final publication, especially for regulated industries (healthcare, financial services) or specific regulatory frameworks (GDPR, HIPAA, KSA NDMO, UAE PDPL).