Skip to content
Request access

Privacy policy

Draft prepared for review by data-protection counsel in each jurisdiction where the service is offered. Items in [BRACKETS] must be completed before publication.

Last updated: 2026-10-01. This policy explains what personal data Verdana eSign processes, why, on what legal basis, who we share it with, how long we keep it and how you can exercise your rights. Country-specific annexes are at the end.

Who we are

Verdana eSign is an electronic-signature service operated by A Software Company LLC, located at [COMPLETAR: domicilio legal]. Privacy questions: [COMPLETAR: privacidad@dominio]. [COMPLETAR: delegado de protección de datos (DPO), si se designa]

Our role: controller or processor

We process data in two different capacities:

SituationOur roleWho decides about your data
You sign a document sent by a company or person (the sender)Processor on behalf of the senderThe sender. We handle your requests together with them
You have a customer account with us, or you visit this siteControllerVerdana eSign
You use the public document-verification portalControllerVerdana eSign

When we act as processor, we follow the sender's instructions and the data processing agreement we sign with them.

What data we process

CategoryExamplesFrom whomPurpose
IdentificationName, national ID number, date of birthSigners (provided by the sender, confirmed by the signer)Verify identity before signing
ContactEmailSigners, customersSend the signing link, the one-time code (OTP) and the final copy
Technical evidenceIP address, browser, session identifier, time of each step, SHA-256 fingerprintsSigners, customers, AI agentsProve who did what and when; detect fraud
DeviceDevice fingerprint (SHA-256 summary of browser attributes: screen, graphics chip, language, time zone), whether it is a phone, accelerometer readings during the liveness checkSignersFraud detection: device changed mid-signature, one device used with documents of different people, emulators
DocumentThe PDF being signed and its fingerprintsSenderProvide the signing service
Biometric (optional)Photo of the ID document, liveness video and the frames we extract from itSigners who expressly authorize itVerify that the right person signs
Customer accountName, company, email, billing data, API keysCustomersManage the contract and access
API and AI-agent usageKey name, operation, request affected, result, IPCustomers and their agentsSecurity and access log
WebsiteServer logs (IP, time, page)VisitorsSecurity and site operation

We use no advertising cookies or third-party tracking on this site. Fonts and libraries are served from our own servers.

Biometric data

The image of your face, the liveness video and the photo of your ID document are sensitive data in every jurisdiction where we operate. Therefore:

  • They are optional. We ask for a separate authorization that you may refuse. If you refuse and the sender requires biometric verification, you can request an alternative verification without biometrics; we notify the sender so they can arrange it with you. We never make signing conditional on providing sensitive data.
  • Your face is only compared with the photo on your own ID. In enhanced verification, a model running on our servers computes a similarity score between your ID photo and your selfie. We do not store the face template, only the score. We never search for your face among other people's, build profiles, train artificial-intelligence models with your data or sell it.
  • A person reviews your identity. Unless the score exceeds the threshold set by the sender, a person on the sender's side reviews the photos and video before you can sign. No verification is rejected automatically: if something does not match, a person decides, and you can ask for an explanation of the decision.
  • Where it is analyzed. In your browser, a model downloaded from our own server only guides you. Our server performs the verification on the video: it checks that you completed the actions, that you are the same person throughout, and your resemblance to your ID photo. We do not send your images to third parties. The video and extracted frames are stored as evidence with their SHA-256 fingerprints.
  • You can withdraw the authorization before signing, without consequences. After signing, the data is part of the document's evidence and is kept for the period required by law or contract, unless a local rule requires earlier deletion (see annexes).
PurposeLegal basis (depending on jurisdiction)
Provide the signing service and verify identityPerformance of the contract with the sender; legitimate interest in preventing impersonation
Process biometric dataExpress, separate and revocable consent of the signer
Keep the signature evidenceLegal retention obligations and establishment or defense of legal claims
Timestamp and anchor evidenceLegitimate interest in evidence integrity. Only cryptographic fingerprints are sent, never personal data
Respond to authoritiesLegal obligation
Service security and access logLegitimate interest
Billing and customer relationshipPerformance of the contract; accounting obligations

Who we share data with

  • The document's sender, who is the controller of their signers' data.
  • Service providers working for us (processors), under contract and security obligations: hosting ([COMPLETE]), email delivery ([COMPLETE]) and write-once custody storage ([COMPLETE]).
  • Timestamping authorities and OpenTimestamps calendars: they receive only SHA-256 fingerprints, from which no personal data can be reconstructed.
  • Judicial or administrative authorities, when required by law, through formal channels and with a record of the disclosure.

We do not sell or rent personal data.

International transfers

Our servers are located in [COMPLETE: country or region]. When data leaves the country where it was collected, we use the mechanisms each law requires (standard contractual clauses, adequacy decisions or others listed in the annexes).

How long we keep data

DataPeriod
Signature evidence (document, event chain, timestamps)The legal or contractual retention period of the document; 10 years from signing by default
Biometric dataWhile part of the document's evidence, unless shorter periods are required by local law (see annexes)
Unsigned or cancelled requests[COMPLETE: e.g., 1 year]
Customer account and billingFor the contract term plus the applicable accounting and tax period
Website server logs[COMPLETE: e.g., 30 days]

Custody copies use write-once storage locked for the retention period. This protects the evidence against tampering and also prevents early deletion. A deletion request may therefore be limited by the obligation to preserve evidence.

How we protect data

  • Hash-chained event log; records the database does not allow to be modified or deleted.
  • PAdES signatures and RFC 3161 timestamps on documents and evidence certificates.
  • OTP codes stored only as HMACs, never in clear text.
  • Least-privilege API keys and a log of every access, including failed attempts.
  • Copies in write-once storage (S3 Object Lock in compliance mode).
  • Encryption in transit (TLS) and at rest [COMPLETE according to infrastructure].

If a security breach affects your data, we will notify the authority and affected people within the deadlines each law sets.

Your rights

You may request access, rectification, erasure, objection, restriction and portability, and withdraw consent, as provided by the law that applies to you (see annexes). Write to [COMPLETAR: privacidad@dominio]. If you signed a document from a sender, you may also contact them; we will coordinate the response.

We answer within the deadline set by your local law. You may also complain to the data-protection authority of your country, listed in the annexes.

Automated decisions and artificial intelligence

The liveness check uses a face-detection model that runs in your browser to guide you through the challenge. That detection does not decide on its own whether you may sign: the video remains as evidence reviewable by people, and you can always request the alternative verification. We do not make decisions with legal effects based solely on automated processing.

Customers can operate the service with AI agents (for example, to create requests or download documents). Those agents act on the customer's behalf, with limited and logged permissions. No agent can sign on behalf of a person.

Minors

The service is not directed at minors. If a sender needs a minor's signature, it must be given through their legal representative under applicable law.

Changes to this policy

We will publish any change on this page with its date. For significant changes we will notify customers by email in advance.

Annexes by jurisdiction

What changes by country. If an annex and the body of this policy differ, the annex prevails for people in that jurisdiction.

Colombia

  • Law: Ley 1581 de 2012 y Decreto 1377 de 2013 (compilado en el Decreto 1074 de 2015).
  • Authority: Superintendencia de Industria y Comercio (SIC)
  • Biometric data: Datos sensibles (Ley 1581, art. 5). Requieren autorización explícita y facultativa, y ninguna actividad puede condicionarse a entregarlos (Decreto 1377, art. 6).
  • Rights: Consultas: 10 días hábiles. Reclamos: 15 días hábiles (Ley 1581, arts. 14 y 15).
  • Breaches: Reporte a la SIC a través del RNBD dentro de los 15 días hábiles siguientes a la detección.
  • Transfers: A países con nivel adecuado según la SIC (la Circular 005 de 2017 incluye a Estados Unidos), o con autorización expresa u otra excepción (Ley 1581, art. 26).
  • Also: Inscripción en el Registro Nacional de Bases de Datos (RNBD) para sociedades con activos superiores a 100.000 UVT. Hay un proyecto de reforma (brechas en 72 h, DPO, evaluación de impacto) aún no aprobado.

México

  • Law: Ley Federal de Protección de Datos Personales en Posesión de los Particulares (DOF 20-mar-2025). El reglamento sigue pendiente.
  • Authority: Secretaría Anticorrupción y Buen Gobierno (sustituyó al INAI)
  • Biometric data: Se interpretan como datos sensibles. Requieren consentimiento expreso y por escrito, que puede darse con firma electrónica.
  • Rights: Derechos ARCO: respuesta en 20 días y ejecución en 15 días más, prorrogable una vez.
  • Breaches: Informar de inmediato al titular cuando se afecten de forma significativa sus derechos patrimoniales o morales.
  • Transfers: Requieren consentimiento salvo excepciones legales. La remisión a un encargado (como nosotros) no lo requiere.

Brasil

  • Law: Lei Geral de Proteção de Dados Pessoais (Lei 13.709/2018).
  • Authority: Autoridade Nacional de Proteção de Dados (ANPD)
  • Biometric data: Dado sensível (art. 5, II). Bases: consentimento específico e destacado (art. 11, I) ou prevenção à fraude e segurança do titular na autenticação (art. 11, II, g).
  • Rights: Acesso completo em 15 dias (art. 19, II).
  • Breaches: Comunicar à ANPD e aos titulares em 3 dias úteis quando houver risco ou dano relevante, presumido com dados sensíveis (Res. CD/ANPD 15/2024).
  • Transfers: Cláusulas-padrão da ANPD obrigatórias desde 23-ago-2025 quando não houver outro mecanismo (Res. CD/ANPD 19/2024).
  • Also: Indicação de encarregado (DPO) conforme a Res. 18/2024. A ANPD pode exigir relatório de impacto (art. 38).

Argentina

  • Law: Ley 25.326 de Protección de Datos Personales (2000).
  • Authority: Agencia de Acceso a la Información Pública (AAIP)
  • Biometric data: Son sensibles solo si pueden revelar datos potencialmente discriminatorios (Res. AAIP 4/2019). En todo caso, nadie puede ser obligado a darlos (art. 7).
  • Rights: Acceso: 10 días corridos. Rectificación y supresión: 5 días hábiles.
  • Breaches: No hay obligación legal general de notificar; la AAIP publica guías.
  • Transfers: Prohibidas hacia países sin protección adecuada salvo cláusulas modelo (Disp. 60-E/2016 y Res. AAIP 198/2023). Estados Unidos no figura en la lista de países adecuados.
  • Also: Las bases de datos se inscriben en el Registro Nacional de Bases de Datos de la AAIP.

Chile

  • Law: Ley 21.719 (en vigor desde el 1-dic-2026), que reemplaza el régimen de la Ley 19.628.
  • Authority: Agencia de Protección de Datos Personales
  • Biometric data: Dato sensible (art. 2, letra g). Requiere consentimiento expreso, por escrito, verbal o por un medio tecnológico equivalente (art. 16).
  • Rights: 30 días corridos, prorrogables por 30 más (art. 11).
  • Breaches: Reportar a la Agencia por los medios más expeditos posibles y sin dilaciones indebidas (art. 14 sexies).
  • Transfers: A países adecuados según la Agencia o con garantías: cláusulas tipo, normas corporativas vinculantes o certificación.

Perú

  • Law: Ley 29733 (2011) y su nuevo Reglamento, DS 016-2024-JUS (vigente desde el 30-mar-2025).
  • Authority: Autoridad Nacional de Protección de Datos Personales (ANPD, MINJUSDH)
  • Biometric data: Dato sensible. El consentimiento debe constar por escrito (Ley 29733, art. 13.6).
  • Rights: Plazos del reglamento anterior: información en 8 días hábiles, acceso en 20 y rectificación, cancelación u oposición en 10. Verificar si el nuevo reglamento los modificó.
  • Breaches: Comunicar a la ANPD en 48 horas cuando hay gran volumen, datos sensibles o daño evidente.
  • Transfers: A países con nivel adecuado, o si el emisor garantiza un tratamiento conforme (cláusulas). Los flujos transfronterizos se comunican a la ANPD.
  • Also: Inscripción obligatoria de bancos de datos. Oficial de datos obligatorio por tramos desde el 30-nov-2025 (grandes empresas).

Ecuador

  • Law: Ley Orgánica de Protección de Datos Personales (2021) y su Reglamento (Decreto Ejecutivo 904, 2023).
  • Authority: Superintendencia de Protección de Datos Personales (SPDP)
  • Biometric data: Datos sensibles con consentimiento explícito (art. 26). La Res. SPDP-SPD-2026-0039-R exige evaluación de impacto previa y prueba documentada de que las alternativas no biométricas son insuficientes, con 12 meses de adecuación.
  • Rights: 15 días.
  • Breaches: Notificar a la SPDP en 5 días y, en ciertos supuestos, a los titulares.
  • Transfers: Arts. 55 a 60 de la LOPDP y norma general de transferencias (Res. SPDP-SPD-2026-0004-R).

United States

  • Law: No general federal privacy law. State laws: CCPA/CPRA (California) and about twenty comprehensive state laws; biometric laws in Illinois (BIPA), Texas (CUBI) and Washington.
  • Authority: Federal Trade Commission (FTC) and state attorneys general; California Privacy Protection Agency
  • Biometric data: BIPA: written release, public retention and destruction schedule, no sale, private right of action ($1,000 to $5,000 per violation). CCPA: sensitive personal information with the right to limit its use.
  • Rights: CCPA: respond within 45 days, extendable by 45 more.
  • Breaches: State breach-notification laws in all 50 states; deadlines vary (often "without unreasonable delay", 30 to 60 days in many states).
  • Transfers: No general restriction on transfers abroad. The DOJ bulk sensitive data rule (28 CFR Part 202) restricts transfers of bulk biometric data to countries of concern.

European Union

  • Law: General Data Protection Regulation (EU) 2016/679, plus national implementing laws.
  • Authority: National data protection authorities, coordinated by the European Data Protection Board (EDPB)
  • Biometric data: Special category when processed to uniquely identify a person (art. 9). Explicit consent as legal basis; a DPIA is likely required.
  • Rights: One month, extendable by two more for complex requests (art. 12.3).
  • Breaches: Notify the supervisory authority within 72 hours (art. 33) and data subjects without undue delay when the risk is high (art. 34).
  • Transfers: Adequacy decision (including the EU–US Data Privacy Framework for certified companies) or Standard Contractual Clauses with a transfer impact assessment.
  • Also: Controllers established outside the EU must appoint a representative in the Union (art. 27).