Privacy Policy
Last updated: September 26, 2026
Company Information
This Privacy Policy is provided by Ideateq, Inc. / Ideateq Digital Private Limited (also referred to as "we", "us", or "our"). Ideateq, Inc. / Ideateq Digital Private Limited is the data controller responsible for the collection, use, and protection of your personal information as described in this Privacy Policy.
Introduction
Welcome to eSignLabs. We are committed to protecting your privacy and ensuring you have a positive experience on our website and in using our products and services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website and use our services.
Information We Collect
We collect information that you provide directly to us, including when you create an account, use our services, contact us for support, or otherwise communicate with us.
Personal Information
This may include your name, email address, phone number, mailing address, and any other information you choose to provide.
Usage Information
We automatically collect certain information about your device and how you interact with our services, including your IP address, browser type, operating system, and access times.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send technical notices, updates, security alerts, and support messages
- Respond to your comments, questions, and requests
- Monitor and analyze trends, usage, and activities
- Detect, investigate, and prevent fraudulent transactions and other illegal activities
Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:
- With your consent
- To comply with legal obligations
- To protect our rights and safety
- With service providers who assist us in operating our services
Data Security
We implement enterprise-grade technical and organizational security measures to protect your personal information and documents. Our security infrastructure includes:
- Encryption: All data is encrypted at rest using AES-256 encryption, and all data in transit is protected with TLS 1.3 encryption.
- Digital Signatures: We use industry-standard document signing certificates from a trusted Certificate Authority to provide cryptographically secure digital signatures for all documents. These certificates ensure document integrity, authenticate signer identity, and provide non-repudiation, meeting requirements for FDA 21 CFR Part 11, HIPAA, GDPR, and other regulatory frameworks.
- Access Controls: We implement granular access controls and user authentication to ensure only authorized users can access your data.
- Audit Trails: All actions on documents are logged with immutable timestamps, providing comprehensive audit trails for compliance and security purposes. Certificate metadata, including issuer information and validation status, is included in audit logs.
- Secure Infrastructure: Our infrastructure is hosted on secure cloud platforms with regular security assessments and monitoring.
While we implement industry-leading security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to maintain the highest standards of data protection.
Data Storage and Management
eSignLabs stores and manages your data in accordance with industry best practices and regulatory requirements:
- Data Location: Your data is stored in secure data centers located in regions that comply with applicable data protection laws. We may transfer data internationally in accordance with applicable laws and with appropriate safeguards.
- Data Retention: We retain your data for as long as necessary to provide our services and comply with legal obligations. You can request deletion of your data at any time, subject to legal retention requirements. For signed documents, we maintain records as required by applicable regulations (e.g., FDA 21 CFR Part 11, HIPAA).
- Data Backup: We maintain regular backups of your data to ensure availability and recovery in case of system failures.
- Data Deletion: When you request deletion of your data, we will securely delete it from our active systems. However, some data may remain in backups for a limited period as part of our disaster recovery procedures.
- Document Integrity: All signed documents are cryptographically sealed to prevent tampering and ensure their integrity and legal validity.
Compliance and Regulatory Frameworks
eSignLabs is designed to comply with various international and industry-specific regulations:
- GDPR (General Data Protection Regulation): We comply with GDPR requirements for processing personal data of EU residents, including data subject rights, data processing agreements, and international transfer safeguards.
- CCPA (California Consumer Privacy Act): We respect the privacy rights of California residents, including the right to know, delete, and opt-out of the sale of personal information (we do not sell personal information).
- HIPAA (Health Insurance Portability and Accountability Act): For healthcare customers, we offer HIPAA-compliant solutions using industry-standard document signing certificates. These certificates provide strong identity authentication, data integrity, and non-repudiation required by HIPAA technical safeguards. We are prepared to enter into Business Associate Agreements (BAAs) as required.
- FDA 21 CFR Part 11: Our platform meets FDA requirements for electronic records and signatures using document signing certificates designed for 21 CFR Part 11 compliance. This includes validation, audit trails, access controls, and cryptographic proof of identity and document integrity (available for Enterprise licenses).
- eIDAS (EU): For European Union customers, we offer eIDAS-compliant certificates issued by a Qualified Trust Service Provider (QTSP). These certificates provide Advanced and Qualified Electronic Signatures with the same legal effect as handwritten signatures in the EU.
- PCI DSS (Payment Card Industry Data Security Standard): We maintain PCI DSS compliance for secure handling of payment card information through our payment processors.
- SOC 2 Type II: We maintain SOC 2 Type II certification, demonstrating our commitment to security, availability, processing integrity, confidentiality, and privacy.
Data Processing Agreements and Sub-processors
We may use third-party service providers (sub-processors) to assist in operating our services. All sub-processors undergo due diligence and are required to maintain appropriate security measures. We enter into Data Processing Agreements (DPAs) with sub-processors to ensure they meet our data protection standards.
Certificate Authority: We use Sectigo as our Certificate Authority for document signing certificates. Sectigo issues digital certificates that enable secure document signing. Sectigo does not process your document content or personal information beyond what is necessary for certificate issuance and validation. According to Sectigo's terms, certificate issuance does not create HIPAA obligations unless otherwise agreed in writing. For more information about Sectigo, please visit sectigo.com.
For enterprise customers requiring specific compliance certifications (such as HIPAA or FDA 21 CFR Part 11), we can provide additional documentation and agreements as needed. Please contact us for more information about our compliance capabilities.
International Data Transfers
As a global service, your data may be transferred to and stored in countries outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- EU-U.S. Data Privacy Framework compliance (where applicable)
- Other legally recognized transfer mechanisms
By using our services, you consent to the transfer of your data to countries that may have different data protection laws than your country of residence.
Your Rights
Depending on your location, you may have certain rights regarding your personal information, including:
- The right to access your personal information and receive a copy of your data
- The right to rectify inaccurate or incomplete information
- The right to erase your personal information ("right to be forgotten"), subject to legal retention requirements
- The right to restrict processing of your information in certain circumstances
- The right to data portability - receive your data in a structured, commonly used format
- The right to object to processing of your personal information
- The right to withdraw consent where processing is based on consent
- The right to lodge a complaint with a supervisory authority (for EU residents)
To exercise any of these rights, please contact us through our website or support channels. We will respond to your request within the timeframes required by applicable law (typically 30 days).
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our service and hold certain information. You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent.
Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
Contact Us
If you have any questions about this Privacy Policy, please contact Ideateq, Inc. / Ideateq Digital Private Limited through our website or support channels.