ESIG — PRIVACY POLICY
Effective Date: August 12, 2026
Last Updated: August 12, 2026
This Privacy Policy explains how Esig ("Esig", "we", "us", or "our") collects, uses, discloses, stores, protects, and otherwise processes personal information when you use our website, applications, electronic-signature platform, APIs, document-management services, and related services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
If you do not agree with this Privacy Policy, please do not use the Service.
---
1. ABOUT ESIG
Esig provides electronic-signature, document-management, workflow, and related technology services.
For privacy purposes, Esig may act as:
1. an organization responsible for personal information that Esig collects directly from its users and customers; and
2. a service provider or processor acting on behalf of an organization that uses Esig to process documents and personal information.
The organization that sends you a document for signature may be responsible for determining why your personal information is collected and how it is used. In those circumstances, Esig may process your information according to that organization's instructions.
---
2. PERSONAL INFORMATION
"Personal information" generally means information about an identifiable individual.
Depending on how you use Esig, we may collect:
Account Information
- Full name
- Email address
- Telephone number
- Company or organization name
- Job title
- Username
- Password or authentication information
- Account preferences
- Profile information
Signature and Transaction Information
When you send or sign documents through Esig, we may collect:
- Electronic signatures
- Signature timestamps
- Signing status
- Document identifiers
- Transaction identifiers
- IP addresses
- Device information
- Browser information
- Authentication information
- Email addresses
- Recipient information
- Signing events
- Document access events
- Audit-trail information
- Refusal or cancellation events
- Other transaction metadata
Documents and Content
We may process documents and other content that you upload, create, send, receive, sign, or store through the Service.
This information may include personal information belonging to you or other individuals.
Billing Information
If you purchase a paid Service, we may collect:
- Billing name
- Billing address
- Company information
- Transaction information
- Subscription information
- Payment status
- Invoice information
Payment card information may be processed directly by our third-party payment providers. We generally do not need to store complete payment-card numbers.
Technical Information
When you access the Service, we may automatically collect:
- IP address
- Browser type
- Operating system
- Device type
- Device identifiers
- Language preferences
- Time zone
- Referring website
- Pages viewed
- Features used
- Login activity
- Session information
- Error logs
- Performance information
- Security information
Communications
If you contact us, we may retain:
- Emails
- Support requests
- Chat communications
- Feedback
- Attachments
- Other communications with Esig
---
3. HOW WE COLLECT INFORMATION
We may collect personal information:
1. directly from you;
2. when you create an account;
3. when you use the Service;
4. when you send or sign documents;
5. when another user sends you a document;
6. from your organization or employer;
7. from payment providers;
8. from identity or authentication providers;
9. through cookies and similar technologies;
10. through integrations you authorize;
11. from service providers;
12. from publicly available sources where permitted by law.
---
4. HOW WE USE PERSONAL INFORMATION
We may use personal information for the following purposes:
Providing the Service
We use information to:
- create and manage accounts;
- authenticate users;
- send and receive documents;
- facilitate electronic signatures;
- maintain audit trails;
- store documents;
- process transactions;
- provide workflow functionality;
- provide API functionality;
- provide customer support;
- manage subscriptions.
Security
We may use information to:
- detect fraud;
- prevent unauthorized access;
- investigate security incidents;
- protect users;
- monitor suspicious activity;
- enforce our security policies;
- protect the Service.
Service Improvement
We may use information to:
- maintain the Service;
- troubleshoot problems;
- analyze performance;
- improve functionality;
- develop new features;
- understand usage patterns;
- test system reliability.
Where appropriate, we may use aggregated or de-identified information for analytics and service improvement.
Communications
We may use contact information to send:
- account notifications;
- security notifications;
- transaction notifications;
- billing notifications;
- service announcements;
- support communications;
- legal notices.
Where permitted by law, we may also send promotional communications.
You can unsubscribe from marketing communications at any time.
Legal and Compliance Purposes
We may process personal information to:
- comply with applicable laws;
- respond to lawful requests;
- comply with court orders;
- protect our legal rights;
- investigate fraud;
- enforce agreements;
- resolve disputes;
- meet regulatory requirements.
---
5. ELECTRONIC SIGNATURE INFORMATION
Esig processes information necessary to facilitate electronic-signature transactions.
This may include:
- identity information;
- email addresses;
- IP addresses;
- timestamps;
- signing events;
- authentication information;
- document identifiers;
- audit-trail events;
- device and browser information.
This information may be used to create and maintain an audit trail associated with a transaction.
The existence of an audit trail does not guarantee that a particular document or electronic signature will be legally enforceable in every jurisdiction or circumstance.
---
6. DOCUMENT CONTENT
Documents uploaded or processed through Esig may contain personal information belonging to multiple individuals.
Esig generally processes document content to provide the Service and according to the instructions of the account holder or organization using the Service.
If you upload or process personal information belonging to another person, you are responsible for ensuring that you have the appropriate legal authority to do so.
You should not upload information to Esig unless you have the right or authorization to process that information through the Service.
---
7. ORGANIZATIONAL ACCOUNTS
If you use Esig through an employer, law firm, business, government organization, educational institution, or other organization, that organization may control your account.
Depending on the configuration of the account, administrators may be able to:
- manage users;
- access documents;
- view transaction information;
- view audit trails;
- manage permissions;
- manage billing;
- deactivate accounts.
In these circumstances, your organization's privacy policies may also apply.
Questions concerning your organization's use of your personal information should generally be directed to that organization.
---
8. COOKIES AND SIMILAR TECHNOLOGIES
Esig may use cookies, local storage, pixels, logs, SDKs, and similar technologies.
These technologies may be used to:
- keep you signed in;
- maintain sessions;
- remember preferences;
- provide security;
- understand website usage;
- measure performance;
- improve the Service;
- detect fraud;
- provide analytics.
Cookies may be:
- essential;
- functional;
- analytics-related;
- performance-related;
- marketing-related.
You may be able to control cookies through your browser settings.
Disabling certain cookies may affect the functionality of the Service.
---
9. ANALYTICS
We may use analytics services to understand how users interact with our website and Service.
Analytics information may include:
- pages visited;
- session duration;
- browser information;
- device information;
- approximate geographic information;
- referral information;
- feature usage.
Where appropriate, we may configure analytics services to reduce the collection of personal information.
---
10. DISCLOSURE OF PERSONAL INFORMATION
We do not sell personal information for monetary consideration.
We may disclose personal information to:
Service Providers
We may use third-party service providers for:
- hosting;
- cloud infrastructure;
- storage;
- email delivery;
- payment processing;
- analytics;
- security;
- customer support;
- authentication;
- communications;
- database management;
- monitoring;
- backup and disaster recovery.
Service providers may only receive information reasonably necessary to perform their services.
Organizations Using Esig
If you receive or sign a document through an organization using Esig, information related to the transaction may be provided to that organization.
Legal Requirements
We may disclose information when reasonably necessary to:
- comply with applicable law;
- comply with a court order;
- respond to government requests;
- protect our rights;
- protect the safety of users;
- investigate fraud or abuse.
Business Transactions
If Esig is involved in a merger, acquisition, financing, restructuring, sale of assets, bankruptcy, or similar transaction, personal information may be transferred as part of that transaction, subject to applicable privacy laws.
---
11. INTERNATIONAL AND CROSS-BORDER PROCESSING
Esig and its service providers may process or store information in Canada and other jurisdictions.
As a result, personal information may be subject to the laws of jurisdictions outside Canada.
Where required by applicable law, Esig will take reasonable contractual, technical, and organizational measures to protect personal information transferred to another jurisdiction.
---
12. RETENTION OF PERSONAL INFORMATION
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention periods may depend on:
- the type of information;
- the nature of the Service;
- the customer's instructions;
- contractual obligations;
- legal requirements;
- dispute-resolution requirements;
- security and fraud-prevention requirements.
Documents may remain available according to the account's retention settings and applicable subscription.
When information is no longer required, we may delete, anonymize, or securely dispose of it.
Backup systems may retain information for a limited additional period.
---
13. SECURITY
Esig uses reasonable administrative, technical, and organizational safeguards designed to protect personal information.
Security measures may include:
- access controls;
- authentication;
- encryption;
- network security;
- logging;
- monitoring;
- backups;
- vulnerability management;
- security testing;
- employee access controls;
- incident-response procedures.
However, no Internet-based service can be guaranteed to be completely secure.
You are responsible for maintaining the security of your account credentials and devices.
---
14. DATA BREACHES AND SECURITY INCIDENTS
If Esig determines that a security incident has occurred involving personal information, we will assess the incident and take steps required by applicable law.
Where legally required, we may:
- investigate the incident;
- contain the incident;
- notify affected individuals;
- notify customers;
- notify regulators;
- take corrective measures.
---
15. YOUR PRIVACY RIGHTS
Depending on your jurisdiction and applicable law, you may have rights regarding your personal information.
These may include the right to:
- request access to personal information;
- request correction of inaccurate information;
- request information about how personal information is used;
- request information about disclosures;
- withdraw consent where applicable;
- request deletion where legally available;
- request information about retention;
- make a privacy complaint.
Some rights may be subject to legal limitations.
---
16. ACCESSING OR CORRECTING YOUR INFORMATION
You may contact us to request access to or correction of personal information that Esig holds about you.
We may need to verify your identity before processing a request.
Where permitted by law, we may decline or limit a request in certain circumstances.
If your personal information is controlled by an organization using Esig, you may need to direct your request to that organization.
---
17. WITHDRAWING CONSENT
Where processing is based on consent, you may withdraw your consent subject to legal or contractual restrictions.
Withdrawal of consent may affect our ability to provide certain Services.
We may continue to process information where permitted or required by law.
---
18. MARKETING COMMUNICATIONS
You may receive promotional communications from Esig where permitted by applicable law.
You can unsubscribe by:
- clicking the unsubscribe link in a promotional email;
- changing your account preferences; or
- contacting us.
Even after opting out of marketing communications, we may continue sending essential service, transaction, security, billing, and legal communications.
---
19. CHILDREN'S PRIVACY
The Service is not intended to be used by children where such use is prohibited by applicable law.
We do not knowingly collect personal information from children in circumstances where parental consent is legally required without obtaining the required consent.
If you believe a child has provided personal information to us improperly, please contact us.
---
20. THIRD-PARTY SERVICES
The Service may integrate with or link to third-party services.
Third parties may have their own privacy policies and terms.
Esig is not responsible for the privacy practices of third-party services that are not controlled by Esig.
You should review the privacy policies of third-party services before using them.
---
21. PAYMENT PROCESSING
Payments may be processed through third-party payment processors.
Esig may receive information such as:
- payment status;
- transaction identifiers;
- billing information;
- subscription information.
Payment processors may collect and process payment-card information according to their own privacy policies.
---
22. API DATA
If you use the Esig API, information transmitted through the API may include documents, personal information, transaction information, and authentication information.
You are responsible for:
- securing API credentials;
- limiting access;
- implementing appropriate security controls;
- ensuring your API use complies with applicable privacy laws.
Esig may log API requests and technical information for security, debugging, performance, and operational purposes.
---
23. DE-IDENTIFIED AND AGGREGATED INFORMATION
Where permitted by law, Esig may create aggregated, statistical, or de-identified information from information collected through the Service.
Such information may be used to:
- analyze usage;
- improve the Service;
- monitor performance;
- develop products;
- conduct research;
- understand trends.
We will not intentionally use de-identified information to re-identify individuals except where permitted or required by law.
---
24. DO-NOT-TRACK SIGNALS
Some browsers provide "Do Not Track" signals.
Because there is currently no universally accepted technical standard for responding to such signals, Esig may not respond to all browser-based Do Not Track settings.
---
25. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time.
When we make material changes, we may provide notice through:
- the website;
- the Service;
- email;
- account notifications; or
- another reasonable method.
The "Last Updated" date at the top of this Privacy Policy indicates when it was most recently updated.
---
26. PRIVACY COMPLAINTS
If you have a concern regarding our handling of personal information, please contact us first so that we can investigate and attempt to resolve the issue.
You may also have the right to contact the privacy regulator applicable to your jurisdiction.
For individuals in Canada, applicable privacy oversight may depend on the nature of the organization, activity, and jurisdiction involved.
---
27. CONTACT US
For privacy questions, requests, or complaints, contact:
Esig
Website: https://esig.ca
Email: support@esig.ca
Telephone: +1 (343) 700-0633
Subject line:
Privacy Request
---
28. GOVERNING LAW
This Privacy Policy is intended to operate in accordance with applicable Canadian federal and provincial privacy laws.
Where applicable, the privacy laws of the jurisdiction in which an individual resides may provide additional rights and protections.
Nothing in this Privacy Policy is intended to remove or restrict rights that cannot legally be waived.
---
29. ACKNOWLEDGEMENT
By using Esig, you acknowledge that you have read and understood this Privacy Policy.
© 2026 Esig. All rights reserved.
Esig · support@esig.ca · +1 (343) 700-0633 · 536 Oldenburg Ave, Richmond, ON, K0A 2Z0, Canada