Privacy Policy
Last updated: 2 July 2026
This policy explains what personal data SignFlowX (“we”, operated by Mushroom Solutions) collects, why, how long we keep it, and the choices you have. It applies to account holders and to people who sign documents through the service.
1. Information we collect
- Account data — name, work email, password (stored hashed), organization details.
- Document data — the documents you upload, their contents, and any fields.
- Signature data — typed or drawn signatures, initials, the name/date entered, and consent records.
- Identity attachments — files a signer uploads (e.g. ID documents), stored encrypted at rest.
- Technical & audit data — IP address, browser/device information, and a timestamped audit trail of actions (opening, signing, downloading), captured to make signatures legally verifiable and tamper-evident.
2. Why we process it (legal bases)
- To perform our contract with you — providing signing, storage, and delivery.
- Legitimate interests — security, fraud prevention, and tamper-evident audit trails (including capturing IP and device details on signing).
- Consent — where you agree to electronic signing, or to receive messages by email/SMS/WhatsApp.
- Legal obligations — retaining signed records where the law requires.
3. AI processing
When you use AI features (draft, summarize, suggest fields), the relevant document text is processed by SignFlowX’s built-in, managed AI to produce the output. AI output may be incomplete or wrong and is not legal advice — always review the full document. We do not sell your data or use your documents to train third-party models.
4. Retention
We keep account and document data for as long as your organization maintains an account, and signed records for the retention period required for legal validity (typically several years), after which they are deleted or anonymized. Identity attachments are kept only as long as needed for the related document.
5. Who can access your data
Within your organization, access follows role-based permissions; identity attachments are downloadable only by organization managers and the document’s creator. We do not share personal data with third parties except service providers strictly necessary to run the service (e.g. email delivery), under confidentiality obligations.
6. Security
Data is transmitted over HTTPS. Passwords are hashed, and sensitive secrets and uploaded identity attachments are encrypted at rest. Login is protected by email one-time-code verification.
7. Your rights & deletion
Depending on your location (e.g. GDPR), you may have rights to access, correct, export, or delete your personal data, and to withdraw consent. To exercise these, or to request deletion of an account and its data, contact us at privacy@mushroom-solutions.com.
8. Contact
Questions about this policy: privacy@mushroom-solutions.com.
This document is a general template and does not constitute legal advice. Have it reviewed by qualified counsel for the jurisdictions you operate in before relying on it.
