Skip to content

Legal

Privacy policy

How we collect, use and look after personal data when you use Signed, and the rights you have over it.

Last updated

1.Who we are

Signed is a trading name of Cube Systems Limited, part of Crushed Ice Group (opens in a new tab). Cube Systems Limited is registered in England and Wales with company number 17220899 (opens in a new tab), and our registered office is Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP.

We're registered with the Information Commissioner's Office (ICO) as a data controller. Our registration number is ZC216972 (opens in a new tab).

In this policy, "we", "us" and "our" mean Cube Systems Limited. "Signed" means our website at usesigned.co.uk, the Signed portal, the Outlook add-in, the Signed API and the services we provide through them.

If you have a question about this policy or your personal data, email hello@usesigned.co.uk or call 01234 672 617.

2.Our role: controller and processor

Data protection law treats us differently depending on whose data it is and why we hold it.

  • We're the controller for account and billing data, enquiries sent to us, visits to our website and the technical and security information our systems record. We decide how and why that data is used, and this policy explains it.
  • We're a processor for the directory and signature data that customers put into Signed, such as their staff's names, job titles and phone numbers. The customer organisation is the controller for that data. We only use it to provide Signed, on the customer's instructions and under our data processing terms.

If your details are in Signed because your employer uses it, your employer decides what's held about you. Contact them first with any questions or requests. If you contact us instead, we'll pass your request on and help them respond.

3.What we collect

Account details

When you sign up or are invited to an organisation: your name, work email address, password and role, and the name of your organisation. We never store your password itself, only a one-way hash of it.

Billing details

Your plan, billing contact, any billing address or VAT details you give us, and invoice and payment status. Card payments are handled by Stripe, so your card details never reach our servers.

Directory and signature data (as a processor)

Details about the people in a customer's organisation: names, job titles, departments, email addresses, phone and mobile numbers, office addresses, social profile links, photos, pronouns and booking links. Also the logos and images a customer uploads, and the signature templates (with their saved versions), assignment rules, campaign banners, brand kits and settings the customer creates.

From Microsoft 365

If a customer connects Microsoft 365, we read the enabled member accounts in its Microsoft Entra ID directory through Microsoft Graph, using read-only access (the User.Read.All permission). For each person that's their name, email address and sign-in name, job title, department, company name, office and mobile phone numbers and office address, along with the identifiers of their account and their Microsoft 365 directory. We don't read photos, mailboxes, calendars or files.

From the Outlook add-in

When someone writes an email, the add-in sends us the sender's email address, whether the email is new or a reply, and whether everyone on it is inside their organisation, so we can return the right signature. The content of the email and the recipients' addresses aren't sent to us.

If an organisation adds signatures through our API instead, it can send us the message body and recipient addresses. We use them to add the signature and tell internal emails from external ones, and we don't keep them.

API keys

If an organisation creates API keys, we store a SHA-256 hash of each key, never the key itself, with its name, scopes and when it was last used. Each request made with a key is logged, with the IP address and browser details it came from, for 90 days.

Signature link clicks (as a processor)

If an organisation leaves click tracking on, links in its signatures and banners go through Signed. When someone clicks one we record which link it was, when, the kind of device and whether it looked like an automated mail scanner. To count repeat clicks we keep a short code made from the IP address and browser details that can't be turned back into either and changes every day. We don't store the IP address or anything that identifies the person who clicked. Organisations can turn click tracking off in their settings.

Enquiries

If you contact us, your name, email address, company and whatever you tell us in your message.

When you send the contact form, the website also sends details of your visit: the page you arrived on, the site that sent you, any campaign tags or ad click IDs in that first link, the previous page, the page you sent the form from and how many pages you viewed. It adds technical details too: your IP address, browser, operating system, device type, language, time zone, screen size and, if you allowed analytics, your Google Analytics client ID.

Website visits

If you allow analytics, Google Analytics records how you use our website, such as the pages you view, how you found us and your browser and device type. Nothing is sent to Google if you don't allow it.

Technical and security information

IP addresses, browser and device details, the times of requests, sign-in sessions (with the IP address and browser each one started from) and the record of changes kept in each organisation's audit log.

Cookies

The portal uses one essential cookie to keep you signed in. The website only uses Google Analytics cookies if you allow them. Our cookie policy lists everything Signed stores in your browser.

4.How we use it and our lawful bases

UK data protection law (the UK GDPR and the Data Protection Act 2018) says we need a lawful basis for each way we use personal data. These are ours.

Why we use personal data and the lawful basis for each use
What we doLawful basis
Provide Signed and manage accounts, organisations and team membersContract
Send service emails, such as email verification, password resets, invitations and billing noticesContract
Take payments and keep financial recordsContract and legal obligation
Keep Signed secure, prevent abuse and fix problemsLegitimate interests
Reply to enquiries and support requestsLegitimate interests
Send the visit details with an enquiry, so we can route and answer it and see which pages lead to enquiriesLegitimate interests
Measure how our website is used with Google AnalyticsConsent
Tell customers about important changes to SignedLegitimate interests
Improve Signed based on feedback and support requestsLegitimate interests
Meet our legal obligations and respond to lawful requestsLegal obligation
Process directory and signature dataOn the customer's instructions, as their processor

Where we rely on consent, you can withdraw it at any time. For analytics, use Cookie settings in the footer of any page.

Where we rely on legitimate interests, we've weighed our interests against yours and only go ahead where they aren't outweighed. You can object at any time (see your rights).

We don't sell personal data, and we don't use it for advertising.

5.Who we share it with

We use a small number of providers to run Signed. They only get the data they need to do their job. Our sub-processors page lists the ones that handle customer data.

  • Amazon Web Services hosts Signed, including its servers and database, in its London region (eu-west-2). It also sends our service emails, such as verification, password reset and invitation emails, through Amazon SES in the same region.
  • Stripe processes payments. Card details go straight to Stripe and are covered by Stripe's own privacy policy.
  • Google provides Google Analytics on our website, only if you allow it.
  • Microsoft provides the directory data when a customer connects Microsoft 365. The customer's use of Microsoft 365 is covered by its own agreement with Microsoft.
  • Professional advisers, such as lawyers and accountants, when we need their help and under a duty of confidentiality.
  • Authorities, such as the police or HMRC, where the law requires us to.
  • A buyer or successor, if our business or its assets are sold. This policy would continue to apply to your data.

6.International transfers

Signed is hosted on Amazon Web Services in its London region (eu-west-2), so our servers and database are in the UK. Our service emails are sent from the same region.

Stripe and Google may process data outside the UK, including in the United States. Google Analytics transfers are covered by the UK Extension to the EU-US Data Privacy Framework. For any other transfer we make sure a lawful safeguard is in place, such as UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses.

You can ask us for more information about the safeguards we use.

7.How long we keep it

We keep personal data for as long as we need it for the purposes above, then delete or anonymise it.

  • Account data: while the account is open, then deleted or anonymised within 90 days of the account closing, unless we need to keep something for a legal reason.
  • Directory and signature data: while the customer's organisation uses Signed, then deleted within 90 days of the organisation being closed.
  • Billing records: six years after the end of the financial year they relate to, as UK tax law requires.
  • Sign-in sessions: until you sign out, or 14 days after you last used Signed.
  • Technical and security logs: normally no more than 12 months.
  • API key request logs: 90 days.
  • Signature link clicks: 400 days, so a year can be compared with the one before.
  • Website analytics: up to 14 months, then deleted by Google.
  • Enquiries: up to two years after we last hear from you.

8.Keeping it secure

We use technical and organisational measures to protect personal data. Passwords are hashed with bcrypt, session tokens and API keys are only stored as hashes, sessions use httpOnly cookies, each organisation's data is kept separate and the service runs over HTTPS. Our security page explains more.

No system is perfectly secure. If we become aware of a personal data breach that affects you, we'll tell you and the Information Commissioner's Office where the law requires it.

9.Your rights

You have rights over your personal data. You can ask us to:

  • give you a copy of the data we hold about you
  • correct data that's wrong or incomplete
  • delete your data
  • restrict how we use your data
  • give you your data in a format you can take elsewhere
  • stop using your data where we rely on legitimate interests
  • stop using your data for any marketing

Where we rely on your consent, such as for website analytics, you can withdraw it at any time with the Cookie settings link in the footer.

Some rights only apply in certain situations. To use any of them, email hello@usesigned.co.uk. We may need to confirm who you are first. We'll reply within one month, and there's normally no charge.

If your data is in Signed because your employer uses it, please contact your employer, who controls that data. We'll help them deal with your request.

10.Complaints

If you're unhappy with how we've handled your data, please tell us first so we can try to put it right.

You also have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. You can make a complaint online (opens in a new tab), call 0303 123 1113 or write to the ICO at Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Our ICO registration number is ZC216972.

11.Children

Signed is a service for businesses. It isn't meant for children, and we don't knowingly collect data about them.

12.Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed. If we make a significant change, we'll tell account owners by email or in the portal before it takes effect.

13.Contact us

Email hello@usesigned.co.uk, call 01234 672 617, or write to Cube Systems Limited, Unit 11, Olney Business Park, Osier Way, Olney, Buckinghamshire, MK46 5FP.