Privacy Policy
Effective date: 18 August 2026
Operator: VICENT SOLUCOES TI LTDA · CNPJ 53.183.462/0001-58
This Privacy Policy describes how VICENT SOLUCOES TI LTDA ("DottSign", "we", "us", or "our"), a company registered in Brazil (CNPJ 53.183.462/0001-58), collects, uses, stores, and protects your personal data when you use the DottSign platform (website, web application, mobile application, and WhatsApp signing channel). It applies to all users worldwide and is designed to comply with Brazil's Lei Geral de Proteção de Dados (LGPD — Law No. 13,709/2018) and, where applicable, the EU General Data Protection Regulation (GDPR — Regulation 2016/679).
1. Controller Identity and Contact
Data Controller: VICENT SOLUCOES TI LTDA CNPJ: 53.183.462/0001-58 Registered office: Brazil Data Protection Officer (Encarregado — LGPD Art. 41): dpo@dottsign.com General privacy enquiries: privacy@dottsign.com Legal notices: legal@dottsign.com We will respond to data-subject requests within 15 business days (LGPD Art. 18) or 30 calendar days (GDPR Art. 12(3)), whichever is stricter for your jurisdiction.
2. Personal Data We Collect
2.1 Account and Identity Data
- Full name (optional at registration; required for signing).
- E-mail address (required).
- Password (stored securely; the plaintext is never stored).
- Profile picture — uploaded voluntarily or obtained via Google OAuth.
- Google OAuth identifier and Google profile data, when you choose Google sign-in.
- Preferred language setting.
2.2 Authentication and Security Data
- Two-factor authentication (2FA) secret and backup codes, stored securely.
- Session tokens stored server-side with expiry.
- Password-reset tokens (short-lived).
- Mobile app: a flag indicating whether biometric app-lock is enabled. Biometric authentication is handled entirely on-device by the operating system. No biometric data reaches our servers.
2.3 Contract and Document Data
- PDF files you upload or import, stored encrypted on AWS S3.
- Contract title, description, tags, category, status, and expiry dates.
- Plain text extracted from PDFs, used to provide document-processing and AI features.
- A cryptographic hash of each uploaded document for integrity verification.
2.4 Signature and Audit Data
- Typed name used as electronic signature.
- IP address and browser information at the time of signing.
- Signing timestamp, verified by a timestamp authority.
- Cryptographic signature value and associated certificate.
- A cryptographic hash of the signed PDF.
- E-mail address of external (non-registered) signers.
- One-time code verification records for signing sessions.
2.5 AI Analysis Data
- Extracted document text may be sent to Groq, Inc. (USA) for AI inference, including categorisation, summarisation, clause analysis, and question-and-answer functionality, when you use DottSign's AI features.
- This processing is performed solely to provide the AI functionality requested by you. Neither DottSign nor Groq uses DottSign customer data to create, train, fine-tune, or improve generalized artificial intelligence or machine-learning models.
- AI job results, such as categories, summaries, and clause flags, are stored on our servers and linked to the relevant contract.
- Groq's applicable data-handling controls govern any temporary processing or logging associated with API inference requests. We do not authorize Groq to use DottSign customer data for generalized model training or improvement.
2.6 Billing and Subscription Data
- Stripe customer ID and subscription/price identifiers.
- Subscription status and current period end date.
- We do not store raw card numbers or full payment credentials — all payment processing is handled by Stripe, Inc.
2.7 Organisation Data
- Organisation name, URL slug, and optional logo.
- Member roles within organisations you belong to.
2.8 Technical and Usage Data
- Audit log entries (action type, resource, IP address, timestamp) for security and legal-evidence purposes.
- In-app notification content and read status.
- Usage counters (contracts created, AI questions used) for plan-limit enforcement.
- Salesforce OAuth tokens (stored encrypted) if you connect the Salesforce integration.
- Mobile app only: screen views and product usage events (e.g. which screens you open) collected via Firebase Analytics and linked to your account ID, used to understand feature usage and improve the app.
2.9 Google Drive Data (Web Only — Optional)
- What we access: When you choose to import a PDF from Google Drive, we request a short-lived OAuth 2.0 access token scoped to drive.file and open Google's own Picker window, where you browse and select a file yourself. We never see or request a list of your Drive contents — Google's Picker handles browsing and search entirely on its own side. Upon your selection, we download the binary content of only the chosen PDF file.
- Purpose: Solely to allow you to import the PDF you selected as a contract document in DottSign. If you subsequently use DottSign AI features on that contract, the extracted text may be sent to Groq solely to provide the requested AI functionality.
- Storage: The OAuth access token is held only in browser memory for the duration of the import and is never transmitted to or stored on our servers. The selected PDF is stored encrypted on AWS S3 as a DottSign contract. We do not retain other Google Drive metadata.
- Third-party AI processing: When AI features are used on a document imported from Google Drive, extracted text from that document may be transmitted to Groq, Inc. solely to provide the requested DottSign AI functionality. Neither DottSign nor Groq uses Google Workspace or Google Drive user data, including raw, aggregated, anonymized, or derived data, to create, train, fine-tune, or improve generalized artificial intelligence or machine-learning models.
- Scope used: https://www.googleapis.com/auth/drive.file (per-file access limited to files you explicitly select through Google's Picker or that DottSign itself creates; no standing access to your Drive, no write, delete, or sharing permissions beyond that).
- No background access: Drive access occurs exclusively in response to an explicit user action (clicking “Import from Google Drive”). We do not access your Drive at any other time.
- Revoking access: You may revoke this access at any time from your Google Account permissions page (myaccount.google.com/permissions) without affecting your DottSign account.
2.10 WhatsApp Communication Data (PRO and ENTERPRISE plans)
- Signer phone number: Collected when a contract owner invites a signer via WhatsApp. Stored in our database linked to the signature spot and associated WhatsApp message record.
- WhatsApp signing session state: A temporary session is created when a signer initiates the WhatsApp-native signing flow. It stores the signer's name, email address, verified identity state, and signing progress. Sessions expire automatically after 30 minutes of inactivity.
- WhatsApp message records: Each outbound WhatsApp message (signature invitation, OTP, document delivery) generates a log entry containing the signer's phone number, delivery status, and the external message ID returned by the WhatsApp provider. This log is retained with the signature spot record.
- WhatsApp identity collection via Flows: When the signer completes the in-WhatsApp identity form (email address and full name), these values are received by our server through the Meta WhatsApp Cloud API and used solely to verify the signer's identity and pre-fill the signature record.
3. Legal Basis for Processing
| Processing purpose | LGPD basis (Art. 7/11) | GDPR basis (Art. 6) |
|---|---|---|
| Providing the platform and performing your contract | Contract execution (Art. 7, V) | Contract (Art. 6(1)(b)) |
| Authentication, security, and fraud prevention | Legitimate interest / legal obligation (Art. 7, II/IX) | Legitimate interests (Art. 6(1)(f)) |
| Generating cryptographic signature records | Legal obligation / contract (Art. 7, II/V) | Legal obligation / Contract (Art. 6(1)(b/c)) |
| Sending transactional e-mails (OTP, notifications) | Contract execution (Art. 7, V) | Contract (Art. 6(1)(b)) |
| AI-powered document analysis | Legitimate interest (Art. 7, IX) | Legitimate interests (Art. 6(1)(f)) |
| Google Drive file import (optional, user-initiated) | Consent (Art. 7, I) | Consent (Art. 6(1)(a)) |
| Processing payments via Stripe | Contract execution (Art. 7, V) | Contract (Art. 6(1)(b)) |
| Retaining audit logs for legal evidence | Legal obligation (Art. 7, II) | Legal obligation (Art. 6(1)(c)) |
| Product analytics (anonymised) | Legitimate interest (Art. 7, IX) | Legitimate interests (Art. 6(1)(f)) |
| Mobile app usage analytics (Firebase, linked to account ID) | Legitimate interest (Art. 7, IX) | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications (optional) | Consent (Art. 7, I) | Consent (Art. 6(1)(a)) |
| Sending WhatsApp messages (signature invitations, OTPs, document delivery) via WhatsApp channel | Contract execution (Art. 7, V) | Contract (Art. 6(1)(b)) |
| WhatsApp identity collection (email and name via WhatsApp Flows) | Contract execution (Art. 7, V) | Contract (Art. 6(1)(b)) |
4. How We Use Your Personal Data
- Creating and managing your account and organisation memberships.
- Processing electronic signatures and generating cryptographically sealed PDF documents.
- Sending signature-request e-mails, one-time codes, and signed-document copies to signers.
- Running AI analysis on your documents (summarisation, categorisation, clause extraction, and Q&A).
- Importing a PDF you select from Google Drive (web only, on your explicit request) and storing it as a contract document.
- When requested by you, sending extracted text from an imported document to Groq solely to provide DottSign's AI functionality.
- Sending WhatsApp signature invitations, identity-collection prompts, OTP verification codes, and signed PDF documents to signers when the WhatsApp signing channel is used (PRO and ENTERPRISE plans).
- Processing subscription payments and managing plan entitlements.
- Maintaining audit logs to provide legal evidence of signing events.
- Sending in-app notifications and, if opted in, e-mail notifications about contract events.
- Enforcing usage limits per subscription plan.
- Improving the platform through anonymised, aggregated usage analytics.
- Understanding mobile app feature usage through Firebase Analytics events linked to your account ID.
- Complying with applicable laws, court orders, and regulatory obligations.
5. Sharing and International Transfer of Data
5.1 Sub-processors and Third-Party Services
- AWS (Amazon Web Services): encrypted document storage and e-mail delivery. AWS infrastructure may be located in Brazil or the USA depending on configuration.
- Stripe, Inc. (USA): payment processing and subscription management.
- Google LLC (USA): optional OAuth-based authentication; on the web platform, optional Google Drive file import (read-only, user-initiated, access token never stored on our servers); and, on the mobile app, Firebase Analytics for product usage events linked to your account ID.
- Groq, Inc. (USA): third-party AI inference provider used to provide DottSign's contract analysis features. Extracted document text may be transmitted to Groq when AI functionality is requested by the user. DottSign does not authorize Groq to use customer data to create, train, fine-tune, or improve generalized AI or machine-learning models.
- Salesforce (optional integration): if you enable the Salesforce integration, your OAuth tokens and selected contract metadata are shared with Salesforce's servers.
- Meta Platforms, Inc. (USA) — WhatsApp Cloud API (PRO and ENTERPRISE plans): When the WhatsApp signing channel is used, signer phone numbers, contract titles, signer names, and email addresses are transmitted to Meta via the WhatsApp Cloud API to deliver signature invitation templates, interactive WhatsApp Flows (identity collection), OTP codes, and signed PDF documents. Meta processes this data as a data processor under our WhatsApp Business terms. Meta's data policy applies: business.whatsapp.com/privacy.
5.2 International Data Transfers
- We are a Brazilian company (LGPD Art. 33). Transfers of personal data to third countries, including the USA for Stripe, Groq, Google, AWS, and Meta, are made using applicable legal safeguards and transfer mechanisms required by the LGPD and, where applicable, the GDPR.
- Where transfers rely on the receiving party's adequacy decision, certification, contractual safeguards, or another legally recognized mechanism, we maintain the applicable documentation in our records.
5.3 Disclosure to Authorities
- We may disclose personal data to courts, law enforcement, or regulatory authorities (including the ANPD) when required by applicable law or valid legal process.
- We will notify affected users of such disclosures where legally permitted.
5.4 Google API Limited Use Disclosure
- DottSign's use of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
- Google Account information obtained through Google Sign-In, such as name, email address, profile picture, and Google account identifiers, is used solely to create and authenticate your DottSign account and provide the requested sign-in functionality. We do not use this information for advertising, sell it, or transfer it to third parties for purposes unrelated to providing the DottSign service.
- Google Drive data obtained through the optional drive.file integration is used solely to allow you to select and import a PDF into DottSign. Access occurs only after your explicit request and only for the file you select through Google's own Picker.
- When you use DottSign AI features on a document imported from Google Drive, the extracted text from that document may be transferred to Groq, Inc. solely to provide the AI functionality requested by you. This transfer is necessary to provide a user-facing DottSign feature and is not performed for an unrelated purpose.
- Neither DottSign nor its third-party AI provider, Groq, uses Google Workspace or Google Drive user data, including raw, aggregated, anonymized, or derived data, to create, train, fine-tune, or improve generalized artificial intelligence or machine-learning models.
- Google Workspace or Google Drive user data is not used for advertising, creditworthiness determination, lending purposes, or sale to data brokers or other third parties.
- Firebase Analytics events described in Section 2.8 are collected independently of Google Sign-In and Google Drive. They relate solely to use of the DottSign mobile application and are not combined with Google Sign-In or Google Drive data.
6. Data Retention
| Data category | Retention period | Justification |
|---|---|---|
| Account profile data | Anonymised in place when you delete your account; see the deleted-account identity record below | Service delivery; LGPD legitimate interest |
| Contract documents and signature records | Retained after account deletion; deleted on request except where an audit trail must be kept for at least 5 years | Legal evidence obligation |
| Deleted-account identity record (email, name, phone, sign-in identifiers) | Kept encrypted and separated for 5 years after account deletion, then permanently erased | Verifying a former user's identity if they later contact us about a contract they signed, and defending signed-contract audit trails (MP 2.200-2/2001, Lei 9.492/1997) |
| Audit logs | 5 years from event date | Legal and regulatory compliance |
| Billing records | 5 years from transaction | Brazilian tax and accounting requirements |
| AI job results | Deleted with associated contract | Derived data; no independent retention needed |
| Session and refresh tokens | Short-lived; revoked on logout or expiry | Authentication security |
| Password-reset tokens | Short-lived from generation | Security |
| One-time signing codes | Short-lived from generation | Security |
| WhatsApp signing sessions (temporary state) | 30 minutes (automatic expiry) | Security — no longer needed after session completes or times out |
| WhatsApp message records (phone, delivery status, external message ID) | Retained with the signature spot; deleted with contract data | Audit trail for signing event |
7. Security Measures
We implement the following technical and organisational security controls (LGPD Art. 46; GDPR Art. 32):
- Encryption at rest for all documents stored in cloud storage; encryption keys are managed separately.
- Secure hashing for passwords and tokens.
- Encryption in transit for all API and web traffic.
- Cryptographic signatures and timestamp verification for legally verifiable signing records.
- Role-based access controls (administrator, manager, signer, viewer).
- Two-factor authentication (2FA) available for all accounts.
- Biometric app-lock on mobile (on-device only; no biometric data transmitted).
- Short-lived session tokens with server-side rotation.
- Comprehensive audit logging of all sensitive actions.
- Secure token storage on mobile devices using platform-provided secure storage.
- WhatsApp signing sessions: identity verified via email OTP before any signature is applied; sessions expire automatically after 30 minutes of inactivity and are deleted from our database on expiry. No signing credentials are stored on WhatsApp's or Meta's servers.
8. Cookies and Local Storage
- Product web application — strictly necessary cookies: We set one secure, server-side cookie containing the session token. This cookie is required to maintain your authenticated session and cannot be disabled without preventing login.
- Product web application — no third-party analytics or advertising cookies: We do not use Google Analytics, Meta Pixel, or any advertising cookies within the authenticated product.
- Marketing website (our public site) — cookie consent: On your first visit, a cookie banner lets you Accept all, Reject non-essential, or Manage preferences by category (Analytics, Marketing). Strictly necessary cookies are always active; analytics and marketing cookies are only set after you opt in. You can change your choice at any time via the “Cookie Preferences” link in the site footer.
- Marketing website — analytics cookies (opt-in): With your consent, we load Google Tag Manager / Google Analytics to understand aggregated site traffic and improve the website. Google Consent Mode keeps these tags from writing analytics cookies until you consent.
- Marketing website — marketing cookies (opt-in): With your consent, we load the Meta (Facebook) Pixel to measure advertising performance. It is not loaded at all until you opt in to the Marketing category.
- Marketing website — third-party review widget (opt-in): We embed a Trustpilot widget to display customer reviews on the site. Since we cannot fully verify Trustpilot's own cookie behavior, we treat it like any other non-essential embed: the script only loads once you consent to the Analytics category, and it is never loaded before that choice is made.
- Mobile application — secure storage: Access tokens and session tokens are stored in the device's secure storage provided by the operating system.
- Mobile application — local storage: Offline contract metadata cache and locale preference are stored in local device storage.
9. Your Rights
Under LGPD (Art. 18) and GDPR (Arts. 15–22), you have the following rights. To exercise any of them, e-mail privacy@dottsign.com with your account e-mail address. We will respond within the applicable legal deadline.
Rights applicable under LGPD (all users) and GDPR (EU/EEA users)
- Right of Access (Art. 18, I / GDPR Art. 15): obtain confirmation whether we process your data and receive a copy.
- Right to Rectification (Art. 18, III / GDPR Art. 16): correct inaccurate or incomplete data.
- Right to Deletion/Erasure (Art. 18, VI / GDPR Art. 17): request deletion of your data, subject to legal retention obligations.
- Right to Data Portability (Art. 18, V / GDPR Art. 20): receive your personal data in a structured, commonly used, machine-readable format.
- Right to Information about Sharing (Art. 18, VII): know which entities we have shared your data with.
- Right to Object / Opt-out (Art. 18, II / GDPR Art. 21): object to processing based on legitimate interest; opt out of marketing communications at any time.
- Right to Withdraw Consent (Art. 8, §5 / GDPR Art. 7(3)): withdraw consent for consent-based processing without affecting the lawfulness of prior processing.
- Right to Review Automated Decisions (Art. 20 / GDPR Art. 22): request human review of decisions taken solely by automated means that significantly affect you.
- Right to Petition the ANPD (Art. 18, VIII): lodge a complaint with Brazil's Autoridade Nacional de Proteção de Dados (www.gov.br/anpd).
- GDPR only — Right to Restriction of Processing (Art. 18 GDPR): request that we restrict processing in certain circumstances.
- GDPR only — Lodge a complaint with a supervisory authority: EU/EEA residents may lodge a complaint with their local data protection authority.
10. Children's Privacy
DottSign is not directed at children under 18 years of age. We do not knowingly collect personal data from minors. If we learn we have collected data from a minor without verified parental consent, we will delete it promptly. Contact privacy@dottsign.com if you believe a minor's data has been collected.
11. Data Breach Notification
In the event of a personal data breach, we will assess the incident and make any notifications to the ANPD, other competent authorities, and affected data subjects that are required by applicable law, within the applicable legal deadlines. Notifications will include the information required by applicable law, including, where applicable, the nature of the breach, categories of data affected, likely consequences, and remediation measures taken.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you by e-mail and/or prominent in-app notice at least 15 days before material changes take effect. The updated policy will display a new effective date. Continued use of the platform after the effective date constitutes acknowledgment of the updated policy. For material changes affecting consent-based processing, we will request fresh consent where required.
13. Contact and Complaints
Data Protection Officer (Encarregado): dpo@dottsign.com Privacy enquiries: privacy@dottsign.com Legal notices: legal@dottsign.com ANPD (Autoridade Nacional de Proteção de Dados): www.gov.br/anpd EU/EEA supervisory authorities: edpb.europa.eu/about-edpb/board/members