Legal
Privacy policy
How we collect, use and look after personal data when you use Signed, and the rights you have over it.
Last updated
1.Who we are
Signed is a trading name of Cube Systems Limited, part of Crushed Ice Group (opens in a new tab). Cube Systems Limited is registered in England and Wales with company number 17220899 (opens in a new tab), and our registered office is Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP.
We're registered with the Information Commissioner's Office (ICO) as a data controller. Our registration number is ZC216972 (opens in a new tab).
In this policy, "we", "us" and "our" mean Cube Systems Limited. "Signed" means our website at usesigned.co.uk, the Signed portal, the Outlook add-in, the Signed API and the services we provide through them.
If you have a question about this policy or your personal data, email hello@usesigned.co.uk or call 01234 672 617.
2.Our role: controller and processor
Data protection law treats us differently depending on whose data it is and why we hold it.
- We're the controller for account and billing data, enquiries sent to us, visits to our website and the technical and security information our systems record. We decide how and why that data is used, and this policy explains it.
- We're a processor for the directory and signature data that customers put into Signed, such as their staff's names, job titles and phone numbers. The customer organisation is the controller for that data. We only use it to provide Signed, on the customer's instructions and under our data processing terms.
If your details are in Signed because your employer uses it, your employer decides what's held about you. Contact them first with any questions or requests. If you contact us instead, we'll pass your request on and help them respond.
3.What we collect
Account details
When you sign up or are invited to an organisation: your name, work email address, password and role, and the name of your organisation. We never store your password itself, only a one-way hash of it.
Billing details
Your plan, billing contact, any billing address or VAT details you give us, and invoice and payment status. Card payments are handled by Stripe, so your card details never reach our servers.
Directory and signature data (as a processor)
Details about the people in a customer's organisation: names, job titles, departments, email addresses, phone and mobile numbers, office addresses, social profile links, photos, pronouns and booking links. Also the logos and images a customer uploads, and the signature templates (with their saved versions), assignment rules, campaign banners, brand kits and settings the customer creates.
From Microsoft 365
If a customer connects Microsoft 365, we read the enabled member accounts in its Microsoft Entra ID directory through Microsoft Graph, using read-only access (the User.Read.All permission). For each person that's their name, email address and sign-in name, job title, department, company name, office and mobile phone numbers and office address, along with the identifiers of their account and their Microsoft 365 directory. We don't read photos, mailboxes, calendars or files.
From the Outlook add-in
When someone writes an email, the add-in sends us the sender's email address, whether the email is new or a reply, and whether everyone on it is inside their organisation, so we can return the right signature. The content of the email and the recipients' addresses aren't sent to us.
If an organisation adds signatures through our API instead, it can send us the message body and recipient addresses. We use them to add the signature and tell internal emails from external ones, and we don't keep them.
API keys
If an organisation creates API keys, we store a SHA-256 hash of each key, never the key itself, with its name, scopes and when it was last used. Each request made with a key is logged, with the IP address and browser details it came from, for 90 days.
Signature link clicks (as a processor)
If an organisation leaves click tracking on, links in its signatures and banners go through Signed. When someone clicks one we record which link it was, when, the kind of device and whether it looked like an automated mail scanner. To count repeat clicks we keep a short code made from the IP address and browser details that can't be turned back into either and changes every day. We don't store the IP address or anything that identifies the person who clicked. Organisations can turn click tracking off in their settings.
Enquiries
If you contact us, your name, email address, company and whatever you tell us in your message.
When you send the contact form, the website also sends details of your visit: the page you arrived on, the site that sent you, any campaign tags or ad click IDs in that first link, the previous page, the page you sent the form from and how many pages you viewed. It adds technical details too: your IP address, browser, operating system, device type, language, time zone, screen size and, if you allowed analytics, your Google Analytics client ID.
Website visits
If you allow analytics, Google Analytics records how you use our website, such as the pages you view, how you found us and your browser and device type. Nothing is sent to Google if you don't allow it.
Technical and security information
IP addresses, browser and device details, the times of requests, sign-in sessions (with the IP address and browser each one started from) and the record of changes kept in each organisation's audit log.
Cookies
The portal uses one essential cookie to keep you signed in. The website only uses Google Analytics cookies if you allow them. Our cookie policy lists everything Signed stores in your browser.
4.How we use it and our lawful bases
UK data protection law (the UK GDPR and the Data Protection Act 2018) says we need a lawful basis for each way we use personal data. These are ours.
| What we do | Lawful basis |
|---|---|
| Provide Signed and manage accounts, organisations and team members | Contract |
| Send service emails, such as email verification, password resets, invitations and billing notices | Contract |
| Take payments and keep financial records | Contract and legal obligation |
| Keep Signed secure, prevent abuse and fix problems | Legitimate interests |
| Reply to enquiries and support requests | Legitimate interests |
| Send the visit details with an enquiry, so we can route and answer it and see which pages lead to enquiries | Legitimate interests |
| Measure how our website is used with Google Analytics | Consent |
| Tell customers about important changes to Signed | Legitimate interests |
| Improve Signed based on feedback and support requests | Legitimate interests |
| Meet our legal obligations and respond to lawful requests | Legal obligation |
| Process directory and signature data | On the customer's instructions, as their processor |
Where we rely on consent, you can withdraw it at any time. For analytics, use Cookie settings in the footer of any page.
Where we rely on legitimate interests, we've weighed our interests against yours and only go ahead where they aren't outweighed. You can object at any time (see your rights).
We don't sell personal data, and we don't use it for advertising.
5.Who we share it with
We use a small number of providers to run Signed. They only get the data they need to do their job. Our sub-processors page lists the ones that handle customer data.
- Amazon Web Services hosts Signed, including its servers and database, in its London region (eu-west-2). It also sends our service emails, such as verification, password reset and invitation emails, through Amazon SES in the same region.
- Stripe processes payments. Card details go straight to Stripe and are covered by Stripe's own privacy policy.
- Google provides Google Analytics on our website, only if you allow it.
- Microsoft provides the directory data when a customer connects Microsoft 365. The customer's use of Microsoft 365 is covered by its own agreement with Microsoft.
- Professional advisers, such as lawyers and accountants, when we need their help and under a duty of confidentiality.
- Authorities, such as the police or HMRC, where the law requires us to.
- A buyer or successor, if our business or its assets are sold. This policy would continue to apply to your data.
6.International transfers
Signed is hosted on Amazon Web Services in its London region (eu-west-2), so our servers and database are in the UK. Our service emails are sent from the same region.
Stripe and Google may process data outside the UK, including in the United States. Google Analytics transfers are covered by the UK Extension to the EU-US Data Privacy Framework. For any other transfer we make sure a lawful safeguard is in place, such as UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.
You can ask us for more information about the safeguards we use.
7.How long we keep it
We keep personal data for as long as we need it for the purposes above, then delete or anonymise it.
- Account data: while the account is open, then deleted or anonymised within 90 days of the account closing, unless we need to keep something for a legal reason.
- Directory and signature data: while the customer's organisation uses Signed, then deleted within 90 days of the organisation being closed.
- Billing records: six years after the end of the financial year they relate to, as UK tax law requires.
- Sign-in sessions: until you sign out, or 14 days after you last used Signed.
- Technical and security logs: normally no more than 12 months.
- API key request logs: 90 days.
- Signature link clicks: 400 days, so a year can be compared with the one before.
- Website analytics: up to 14 months, then deleted by Google.
- Enquiries: up to two years after we last hear from you.
8.Keeping it secure
We use technical and organisational measures to protect personal data. Passwords are hashed with bcrypt, session tokens and API keys are only stored as hashes, sessions use httpOnly cookies, each organisation's data is kept separate and the service runs over HTTPS. Our security page explains more.
No system is perfectly secure. If we become aware of a personal data breach that affects you, we'll tell you and the Information Commissioner's Office where the law requires it.
9.Your rights
You have rights over your personal data. You can ask us to:
- give you a copy of the data we hold about you
- correct data that's wrong or incomplete
- delete your data
- restrict how we use your data
- give you your data in a format you can take elsewhere
- stop using your data where we rely on legitimate interests
- stop using your data for any marketing
Where we rely on your consent, such as for website analytics, you can withdraw it at any time with the Cookie settings link in the footer.
Some rights only apply in certain situations. To use any of them, email hello@usesigned.co.uk. We may need to confirm who you are first. We'll reply within one month, and there's normally no charge.
If your data is in Signed because your employer uses it, please contact your employer, who controls that data. We'll help them deal with your request.
10.Complaints
If you're unhappy with how we've handled your data, please tell us first so we can try to put it right.
You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. You can make a complaint online (opens in a new tab), call 0303 123 1113 or write to the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Our ICO registration number is ZC216972.
11.Children
Signed is a service for businesses. It isn't meant for children, and we don't knowingly collect data about them.
12.Changes to this policy
We may update this policy from time to time. The date at the top shows when it last changed. If we make a significant change, we'll tell account owners by email or in the portal before it takes effect.
13.Contact us
Email hello@usesigned.co.uk, call 01234 672 617, or write to Cube Systems Limited, Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP.