Last updated 24 July 2026

This Privacy Policy explains what personal information Authent (the "Service") collects, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it. It sits alongside our Terms and Conditions.

Authent prepares documents, captures electronic signatures and maintains a tamper-evident audit trail. Much of what follows is a consequence of that purpose: a record that could be quietly altered or erased would not be evidence of anything. So some of the information described here is deliberately kept, and deliberately not editable — including by us.

1. Who this policy covers

Two kinds of people use the Service. Account holders create an account, upload documents and invite others to sign. Signing parties are invited to sign a document and need no account to do so. Where you are a signing party, the account holder who invited you decides why your information is processed; we process it on their instruction, to carry out the signing and produce its record.

2. Information we collect

Account information. Your first name, surname and email address, your role, your account number, and the dates on which you created the account and accepted the Terms.

Sign-in information. One-time codes sent to your email are stored only as a hash and expire within minutes. If you use a passkey we store its public key and the challenge used to verify it. There is no password to store, and the private half of a passkey never leaves your device.

Documents you upload. The file itself, its title, file name and type, and cryptographic hashes of it before and after signing. Files are encrypted at rest.

Signing party details. Supplied by the account holder when a party is added: full name, identity number and email address, together with the party's role and place in the signing order. These appear on the signing certificate.

Client records. If you keep client records in the Service: name, identity number, email address, telephone number, and postal and domicilium addresses.

Signing audit records. For each step of a signing, the Service records the event type, the date and time, the email address of the person acting, their IP address, their browser and device string, how they authenticated, and the document's hash at that moment. Each record is cryptographically chained to the one before it.

Purchase records. An order reference, the pack bought, the amount and currency, whether it succeeded, the email address of the person who bought it, and the relevant timestamps. Card details are never sent to us — see section 4.

Coworker records. The email address, label and role of anyone you invite to share your account, and whether the invitation has been accepted.

Notification subscriptions. If you turn on browser notifications, the endpoint and keys needed to deliver them.

3. Why we use it

To run the Service and sign you in; to deliver documents to the parties you name and collect their signatures; to produce each signing certificate and audit trail and allow it to be verified afterwards; to process purchases and keep your signings balance; to send service messages such as one-time codes, signing invitations and completion receipts; and to secure the Service, investigate misuse and meet our legal obligations.

We do not sell personal information. We do not use it for advertising or profiling, and we do not use your documents or their contents to train machine-learning models.

4. Who we share it with

Our email provider, which delivers one-time codes, signing invitations and receipts. It receives the recipient's email address and the message.

Our payment provider, which runs the checkout. Card details are entered on their systems and never reach ours; we receive an order reference, an amount and whether the payment succeeded.

A trusted timestamp authority, which receives a SHA-256 hash of the completion seal and nothing else. The document cannot be read, reconstructed or identified from that hash.

Public OpenTimestamps calendars, and through them the Bitcoin blockchain, which receive the same kind of hash and commit it to a public ledger. Once committed, that hash is public and permanent: neither we nor anyone else can withdraw it. It discloses no content and no personal information — only that a particular piece of data existed at a particular time.

Our hosting and infrastructure providers, which store the data on our behalf.

Coworkers you invite, who can see the documents in the account you share with them.

We also disclose information where the law requires it, or where it is necessary to establish, exercise or defend a legal claim — which includes producing a signing certificate and its audit trail as evidence of a signing.

5. How we protect it

Documents are encrypted at rest, and each account's data is held under its own isolated storage path. Traffic to the Service travels over HTTPS. The audit trail is a hash chain, each entry sealed with a keyed message authentication code, so an altered, removed or reordered entry can be detected. The completion seal is digitally signed and anchored both to an independent timestamp authority and to the Bitcoin blockchain. Sign-in uses a one-time email code or a passkey, so there is no password to be leaked or reused.

No system is perfectly secure and we cannot guarantee absolute security. Your email account is the key to your Authent account — please keep it secure.

6. How long we keep it

Draft documents that were never sent for signature are deleted when you delete them.

Completed signings are kept for as long as the account exists. Deleting a completed signing removes it from your board but does not destroy the record: the document, its signatures, its certificate and its audit trail survive, because their value is that they survive. Audit-trail entries are never edited or deleted individually — the chain would no longer verify if they were.

Purchase records are kept for as long as we need them for accounting and tax purposes. One-time codes and authentication challenges expire within minutes. Hashes committed to the Bitcoin blockchain are permanent and cannot be deleted by anyone.

7. Your rights

Under applicable data-protection law you may ask us to confirm whether we hold information about you and give you a copy of it; to correct information that is wrong or incomplete; to delete information; to stop or restrict a particular use, or to object to it; to withdraw consent where we rely on it; and to provide a copy in a portable form where that right applies.

Write to info@authent.io. We may need to confirm your identity first, and we will respond within the period applicable law allows. If we cannot do what you have asked — usually because the information forms part of a signing record that another party may need to rely on, or because we are required to keep it — we will tell you why. You may also complain to the data-protection authority in your country.

If you were invited to sign a document and want your information corrected or removed, the account holder who invited you controls that record. Please ask them first; if you contact us we will pass the request on and help where we can.

8. Cookies, analytics and email tracking

We set three first-party cookies. One keeps you signed in, a short-lived one carries a status message from one page to the next, and one records whether you agreed to analytics. There are no advertising cookies and no third-party analytics.

Our analytics are our own and are opt-in. If you accept when asked, we derive an identifier from your network address and browser so that repeat visits can be counted and we can see how people reach us. If you decline, or have not yet answered, nothing is derived and nothing is recorded.

Email we send carries open tracking and link tracking, applied by our email provider (see section 4). Open tracking embeds a small invisible image — a tracking pixel — so opening the message records that it was opened, when, and the device and network it was opened from. Link tracking rewrites the links in the message, so following one records that the link was followed and routes the click through that provider before it reaches us. This applies to everyone we email, including signing parties who hold no account with us. If you would rather not be tracked this way, most email clients can be set to block remote images, which prevents the open pixel from loading.

9. International transfers

The service providers named in section 4 may be located in other countries. Where personal information crosses a border we take reasonable steps to see that it remains protected to a comparable standard.

10. Children

The Service is not intended for children, and we do not knowingly collect their personal information.

11. Changes to this policy

We may update this policy. The date at the top always reflects the current version, and we will tell you about material changes through the Service or by email.

12. Contact us

Questions about this policy, or about the information we hold: info@authent.io.