Legal

Privacy policy

What personal data DropTheDoc collects, why, who we share it with, how long we keep it, and the rights you have wherever you live.

Effective
26 July 2026
Version
2.0

[your registered company name], [your entity type, for example a private limited company], operating as DropTheDoc ("we", "us"), provides an electronic signature service at dropthedoc.xyz. This policy explains what we do with personal data. It is written to satisfy the notice requirements of the Digital Personal Data Protection Act, 2023 (India), Articles 13 and 14 of the UK and EU General Data Protection Regulation, and the notice-at-collection requirement of the California Consumer Privacy Act.

The short version

We collect what we need to deliver your documents, prove who signed them, keep your account secure and bill you. We do not sell personal data, we do not share it for advertising, we run no advertising or analytics trackers, and we do not use the contents of your documents to train any model. The audit trail is the one thing we cannot delete on request, because it is the evidence that makes a signature hold up.

1.Who this policy is for

This policy covers three groups of people, who are in different positions and should read different parts of it:

Account holders.
You created a DropTheDoc account and send documents. Everything here applies to you.
Recipients and signers.
Someone sent you a document. You may not have an account and you do not need one. Clause 2 explains who is responsible for your data, and clause 11 explains how to exercise your rights.
Visitors.
You are reading our website. We collect very little from you. See the cookie policy.

2.Who is responsible for your personal data

This is the most important clause in the policy, because it determines who you go to about what.

Data

Account and billing data of account holders

Our role

Data Fiduciary under the DPDP Act; controller under GDPR

What it means for you

We decide why and how this is processed. Bring requests about it to us.

Data

Documents, fields and the personal data inside them

Our role

Data Processor under the DPDP Act; processor under GDPR

What it means for you

The account holder who uploaded the document decides what it contains and how long to keep it. We act on their instructions. Bring access and deletion requests to them, and we will support them in answering you.

Data

Recipient names and email addresses supplied by a sender

Our role

Processor, on behalf of the sender

What it means for you

The sender chose to send you a document. If you did not expect it, contact them. We will pass on a request if you cannot reach them.

Data

The audit trail and evidence records

Our role

Independent controller

What it means for you

We keep this to meet our own legal and evidentiary obligations. Neither you nor the sender can instruct us to alter or selectively delete it, because a log that can be edited on request is not evidence.

Data

Security, fraud prevention, abuse and rate limiting

Our role

Independent controller

What it means for you

We process this to keep the service safe for everyone, on our own responsibility.

Where we act as a processor, our obligations to the account holder are set out in the data processing addendum, which forms part of our contract with them.

3.What we collect, why, and on what legal basis

Legal bases are cited under GDPR Articles 6 and 9. Under the DPDP Act the corresponding basis is consent under section 6, or a legitimate use under section 7 where you voluntarily provide data for a purpose and have not objected.

Category

Identity and account

What it includes

Name, email address, hashed password, and optionally job title, company name and profile image.

Why we process it

To create and secure your account, identify you, and contact you about the service.

Legal basis

Performance of a contract. Consent for optional fields.

Category

Authentication

What it includes

Session tokens stored only as hashes, sign-in timestamps, and, if you use single sign-on, the account identifier and email returned by Google, GitHub or Microsoft.

Why we process it

To keep you signed in and to let you revoke sessions.

Legal basis

Performance of a contract. Legitimate interests in account security.

Category

Workspace

What it includes

Workspace name, branding, membership, roles and invitations.

Why we process it

To let teams share documents with the right permissions.

Legal basis

Performance of a contract.

Category

Document content

What it includes

The files you upload, the fields you place, values recipients enter, and signature images.

Why we process it

To deliver, display and complete your documents. We process this on the account holder's instructions.

Legal basis

Processor acting for the controller. The controller's own basis applies.

Category

Recipient details

What it includes

Recipient names, email addresses, assigned roles and signing order, supplied by the sender.

Why we process it

To deliver the right document to the right person in the right order.

Legal basis

Processor acting for the sender.

Category

Evidence and audit

What it includes

IP address, browser user-agent, and UTC timestamps for every send, open, view, consent, signature, decline, reminder, cancellation and expiry, plus document hashes and a hash of each signature image.

Why we process it

To prove who signed what, when and from where. This is what makes an electronic signature defensible and it cannot be disabled for a document in progress.

Legal basis

Legal obligation and legitimate interests in providing legally reliable evidence, and in establishing, exercising or defending legal claims.

Category

Contacts

What it includes

Names and email addresses you save to reuse when addressing documents.

Why we process it

To save you retyping them.

Legal basis

Performance of a contract.

Category

Billing

What it includes

Plan, billing cycle, invoice history, GST registration number where you supply one, and the country and tax status we need to invoice correctly. Card details are handled by our payment processor and never reach our servers.

Why we process it

To charge you, to issue compliant tax invoices, and to meet accounting and tax law.

Legal basis

Performance of a contract. Legal obligation.

Category

Operational and security

What it includes

Rate limiting counters, error logs, and server logs containing IP address, request path and timestamp.

Why we process it

To keep the service running, to detect and stop abuse, and to investigate incidents.

Legal basis

Legitimate interests in security and service integrity.

Category

Communications

What it includes

Messages you send us through the contact form or by email, and our replies.

Why we process it

To answer you and to keep a record of what was agreed.

Legal basis

Legitimate interests in responding to enquiries. Consent where you initiated it.

We do not collect personal data from third-party data brokers, we do not enrich your profile from external sources, and we run no advertising, analytics or behavioural tracking on any part of the service.

4.Sensitive and special category data

We do not ask for special category data under GDPR Article 9, or sensitive personal data under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, except that passwords are treated as sensitive personal data under those Rules and are stored only as bcrypt hashes.

Documents are a different matter

You control what you upload. A contract can easily contain health information, biometric data, financial account details, government identifiers such as Aadhaar or PAN, or data about criminal matters. We do not inspect documents, so we cannot warn you. If you upload special category or sensitive data, you are the controller of it, you need your own lawful basis and, under GDPR Article 9, an applicable exception. Under the SPDI Rules you need the data subject's written consent before collecting sensitive personal data.

For the avoidance of doubt: we do not sell sensitive personal data, we do not use or disclose it beyond providing the service you asked for, and there is therefore nothing for a Californian consumer to limit under the CCPA right to limit the use of sensitive personal information.

5.Children

DropTheDoc is a business tool and is not directed at children. You must be at least 18 to hold an account.

Section 9 of the DPDP Act treats everyone under 18 as a child and requires verifiable consent from a parent or lawful guardian before their personal data is processed. It also prohibits tracking, behavioural monitoring and targeted advertising directed at children. We do none of those things for any user, and we do not knowingly process a child's personal data.

In the EU and UK the digital-consent age is 16, or lower where a member state has set it lower, and in the United States COPPA applies below 13. Whichever threshold applies, if you believe a child's personal data has reached us, write to privacy@dropthedoc.xyz and we will delete it, other than any audit entries we are required to retain, which we will anonymise.

6.Who we share personal data with

We share personal data only in the situations listed here.

  • Other parties to a document. Recipients of a document can see the sender's name and email, the document, and the names and signing status of the other recipients. That is inherent to signing something together.
  • Members of your workspace. Depending on their role, colleagues in your workspace can see documents, recipients and activity in that workspace.
  • Subprocessors. Vendors that run infrastructure and send email on our behalf, listed in full at subprocessors. Each is bound by a written contract that limits them to our instructions.
  • Payment processor. For paid plans, to take payment and issue invoices. Card details go to them directly and are never stored by us.
  • Professional advisers. Lawyers, auditors and accountants, under a duty of confidentiality, where they need it to advise us.
  • Authorities and legal process. As described in clause 8.
  • A buyer or successor. If we are involved in a merger, acquisition, financing or sale of assets, personal data may transfer as part of it. We will tell you before your data becomes subject to a materially different privacy policy, and the recipient stays bound by commitments at least as protective.

We do not sell your data

We do not sell personal data and we do not share it for cross-context behavioural advertising, as those terms are defined in the CCPA. We have not done so in the preceding twelve months, including for anyone under 16. There is therefore no "Do Not Sell or Share My Personal Information" mechanism to offer, because there is nothing to opt out of. We also do not use document contents to train machine learning models, ours or anyone else's.

7.Requests from law enforcement and government

We disclose personal data to a public authority only where we are legally required to, and only to the extent required.

  • We require valid legal process. In India that means an order or written request under the Code of Criminal Procedure or its successor, section 91 of the Bharatiya Nagarik Suraksha Sanhita, 2023, section 69 of the Information Technology Act, 2000, or another lawful basis. From outside India we generally require a request routed through a mutual legal assistance treaty or a letter rogatory, or an order enforceable against us.
  • We check that the request is properly issued, is within the issuing authority's jurisdiction, and is not overbroad. We push back on requests that are not.
  • We produce the narrowest data that answers the request. We do not give bulk or standing access to any authority.
  • Where we act as a processor, we redirect the request to the account holder wherever we lawfully can, because the data is theirs.
  • We notify the affected account holder before disclosing, unless we are legally prohibited from doing so or there is an emergency involving a risk of death or serious physical harm.

We may also disclose where necessary to establish, exercise or defend legal claims, or to prevent fraud, abuse or an imminent threat to someone's safety.

8.Where your data goes

DropTheDoc is operated from India, and our infrastructure providers are established in the United States and operate globally. Personal data is therefore processed in India, in the United States, and in whichever region hosts the database and storage for your workspace. The full list of providers and their locations is at subprocessors.

From India.
Section 16 of the DPDP Act permits transfer outside India except to countries the Central Government restricts by notification. We monitor that list and will stop transfers to any restricted country.
From the EEA.
India has no adequacy decision under GDPR Article 45. We therefore rely on the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, incorporated into our data processing addendum, together with a transfer impact assessment and the supplementary measures described in clause 10 and in our security page. Encryption at rest and in transit, and our policy on government requests, are part of those measures.
From the United Kingdom.
The International Data Transfer Addendum to the EU SCCs, issued under section 119A of the Data Protection Act 2018.
From Switzerland.
The SCCs as amended for Swiss law, with the Federal Data Protection and Information Commissioner as the competent authority.

You can request a copy of the safeguards we rely on by writing to privacy@dropthedoc.xyz. We may redact commercial terms.

9.How long we keep things

We keep personal data only while there is a reason to, and then delete or anonymise it. Section 8(7) of the DPDP Act requires erasure once the purpose is no longer served, and GDPR Article 5(1)(e) says the same thing differently.

Data

Account and profile

Retention

While your account is open, and 30 days after you close it.

Then what

Deleted.

Data

Documents and their contents

Retention

While your workspace holds them. You can delete any document at any time.

Then what

Deleted from the database and from encrypted object storage. Backups age out on their own cycle.

Data

Completed documents and certificates

Retention

While your workspace exists, unless you delete them, because the evidence is the point of the product.

Then what

Deleted with the workspace, subject to the audit trail row below.

Data

Audit trail

Retention

Retained even after the related document is deleted.

Then what

Personal identifiers are anonymised on document deletion. The hash chain itself is kept, because removing entries would break the chain and destroy the integrity guarantee for every other document.

Data

Sessions

Retention

Up to 30 days, or until you sign out or change your password.

Then what

Purged automatically by the daily maintenance job.

Data

Signing links and one-time tokens

Retention

Until used, cancelled or expired, whichever is first.

Then what

Revoked immediately and purged.

Data

Server and security logs

Retention

Up to 90 days.

Then what

Deleted, unless an entry is part of an active security investigation.

Data

Billing records and tax invoices

Retention

Eight years from the end of the relevant financial year.

Then what

Retained. This is a legal obligation under the Companies Act, 2013 and Indian tax law, and we cannot delete it on request.

Data

Support correspondence

Retention

Three years from the last message.

Then what

Deleted.

If you close your workspace, export what you need first. After the 30-day window, deletion is irreversible, and because documents are encrypted at rest we cannot reconstruct them.

10.How we protect it

Documents are encrypted at rest with AES-256-GCM and in transit with TLS. Passwords are hashed with bcrypt. Session tokens are stored only as SHA-256 hashes. Access is scoped to your workspace and checked on every request, not just in the interface. Uploads are size-limited, type-checked and virus-scanned. The audit trail is append-only and hash-chained.

Rule 8 of the SPDI Rules, 2011 requires reasonable security practices proportionate to the data held. The controls we operate are described in detail on the security page, and the contractual version of them is Annex II of the data processing addendum.

No system is perfectly secure. If something happens, clause 12 explains what we do about it.

11.Your rights

Your rights depend on where you live. We apply the strongest applicable standard rather than the minimum, and we do not charge for exercising a right unless a request is manifestly unfounded or excessive, in which case we will tell you before doing anything.

Where you are

India (DPDP Act, 2023)

What you can do

Obtain a summary of the personal data we process and who we have shared it with (section 11). Correct, complete, update or erase your data (section 12). Have a grievance addressed by us before approaching the Data Protection Board (section 13). Nominate someone to exercise your rights if you die or become incapacitated (section 14). Withdraw consent at any time, as easily as you gave it (section 6(6)).

Where you are

EEA and UK (GDPR)

What you can do

Access your data and receive a copy (Article 15). Rectification (16). Erasure (17). Restriction (18). Portability in a structured, machine-readable format (20). Object to processing based on legitimate interests (21). Withdraw consent at any time without affecting prior processing (7(3)). Complain to your supervisory authority (77), and in the UK to the Information Commissioner's Office.

Where you are

California (CCPA/CPRA)

What you can do

Know what we collect, use, disclose and sell. Delete. Correct. Portability. Opt out of sale or sharing, which does not arise because we do neither. Limit the use of sensitive personal information, which also does not arise. Non-discrimination for exercising any right. Use an authorised agent.

Where you are

Other US states

What you can do

Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes: access, correction, deletion, portability, opt-out of targeted advertising, sale and certain profiling, and appeal a refusal.

Where you are

Canada, Australia, Brazil, elsewhere

What you can do

Access, correction and complaint rights under PIPEDA, the Privacy Act 1988 and the Australian Privacy Principles, the LGPD, and comparable laws. Tell us where you are and we will apply the right framework.

If someone sent you a document, we hold your data as a processor for them. Send access, correction or deletion requests to that sender. If you cannot identify or reach them, write to us and we will either forward the request or tell you who to ask.

One limit on erasure

We cannot delete audit entries for a document that has been signed. That record is what makes the signature provable, other parties to the document have a legal interest in it, and a hash chain with entries removed no longer proves anything for anyone else either. We anonymise the personal identifiers in it instead. This is permitted by GDPR Article 17(3)(b) and (e), and by the corresponding exemptions in section 17 of the DPDP Act.

12.How to exercise a right

Email privacy@dropthedoc.xyz from the address on your account, or write to the Grievance Officer named in clause 14. Tell us what you want and which jurisdiction you are in.

We verify identity before acting, because handing someone's contract history to the wrong person is worse than being slow. For most requests, control of the account email is enough. For deletion or a large export we may ask for more. An authorised agent must supply written permission signed by you.

Request type

Grievance under the DPDP Act or the SPDI Rules

We acknowledge

Within 24 hours

We complete

Within 15 days, and in any case within the period the applicable rules require

Request type

GDPR or UK GDPR rights request

We acknowledge

Promptly

We complete

Within one month, extendable by two further months for complex requests, which we will tell you about within the first month

Request type

CCPA request

We acknowledge

Within 10 business days

We complete

Within 45 days, extendable once by a further 45 days with notice

Request type

Anything else

We acknowledge

Within 3 business days

We complete

Within 30 days

You can export your own documents and certificates from the dashboard at any time without asking us.

13.If there is a data breach

If personal data is breached, we will investigate immediately, contain it, and notify as follows:

  • India. The Data Protection Board of India and every affected Data Principal, as required by section 8(6) of the DPDP Act and the rules made under it, without the delay those rules prohibit. We will also report to CERT-In within 6 hours of becoming aware where the incident falls within the categories in its directions of 28 April 2022.
  • EEA and UK. The lead supervisory authority within 72 hours of becoming aware, under GDPR Article 33, and affected individuals without undue delay where the risk to their rights and freedoms is high, under Article 34.
  • United States. Affected individuals and regulators within the deadlines set by the applicable state breach notification statutes.
  • Our customers. Where we act as a processor, we notify the affected account holder without undue delay so that they can meet their own notification obligations, and we give them the information they need to do it.

Notifications will describe what happened, what data was involved, what we have done, and what you should do.

14.Automated decisions and profiling

We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not profile you. Rate limiting and abuse detection are automated, but they throttle or block a request rather than decide anything about you as a person, and you can reach a human at support@dropthedoc.xyz if you are affected.

15.Who to contact

Grievance Officer (India)

Appointed under section 13 of the DPDP Act, 2023, Rule 5(9) of the SPDI Rules, 2011 and Rule 3(2) of the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

[the name of your Grievance Officer]

[your registered company name], [your full registered office address]

Email: grievance@dropthedoc.xyz

See the grievance redressal policy for how complaints are handled and escalated.

Privacy and data protection

[the name of your Data Protection Officer]

Email: privacy@dropthedoc.xyz

Representatives in the EU and UK

EU representative under GDPR Article 27: [your Article 27 representative in the EU]

UK representative under UK GDPR Article 27: [your UK representative]

You always have the right to complain to your own regulator. In India that is the Data Protection Board of India, in the EEA your national supervisory authority, and in the UK the Information Commissioner's Office. We would rather you came to us first, but nothing here requires it.

16.Changes to this policy

We will update this policy when the service or the law changes. The version number and effective date at the top always tell you which version you are reading, and clause history is listed at the foot of the page.

For material changes that reduce your rights or expand how we use personal data, we will give account holders at least 30 days' notice by email before they take effect. For clarifications and corrections we will update the page and bump the version.

Version history

  • Version 2.0 · 26 July 2026

    Rewritten for the DPDP Act, 2023, the SPDI Rules, 2011, GDPR Articles 13 and 14, and the CCPA as amended. Added the controller and processor split, the retention schedule, transfer mechanisms, response deadlines, breach notification timelines, and the Grievance Officer contact.

  • Version 1.0 · 1 July 2026

    First publication.