Last updated June 2026.
This policy explains what data QuillSign processes and why.
To provide the signing service, authenticate you, build the audit trail and certificate of completion, and operate organization features. Webhook payloads you configure are sent to endpoints you control.
Data is encrypted in transit and at rest; sensitive secrets are additionally encrypted with a customer-managed key. See our security page for details.
Documents and audit records are retained for the life of your workspace, and as needed to evidence completed transactions, comply with legal obligations, and resolve disputes. You may request deletion of your data as described below, subject to records we are required or permitted to retain.
Organization administrators can deactivate members, which revokes access. For data access or deletion requests in a production deployment, contact the operator.
The Service runs on Amazon Web Services. We do not sell personal data.
Questions about this policy may be directed to the contact address published by the operator of the Service.