1. Introduction
Quantidia (“Quantidia”, “we”, “us” or “our”) provides electronic signature, digital certificate and related trust services to organisations operating in multiple jurisdictions. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the choices and rights you have regarding your information when you use our websites, platform and related services (together, the “Services”).2. Data We Collect
Account and contact data
When you or your organisation create an account, request a demo, or contact our sales or support teams, we collect information such as your name, business email address, phone number, job title, company name and country. This information is used to set up your account, respond to your enquiries and provide the Services.3. Documents and Signature Data
When you use Quantidia to send, sign or manage a document, we process the content of that document, the identity and contact details of the signatories, and evidentiary data generated during the signing process, such as timestamps, IP addresses, device information and the audit trail associated with each signature. This information is essential to guarantee the legal validity and integrity of every signed document.4. Cookies
Our websites use cookies and similar technologies to keep you signed in, remember your preferences, and understand how our Services are used. For full details on the categories of cookies we use, their purpose and how to manage your preferences, please see our Cookie Policy.5. Who Has Access to Your Data
Access to your personal data is limited to Quantidia staff and contractors who need it to operate and support the Services, such as our systems administrators and customer support team, and to the organisation that sent you a document for signature, where applicable. We do not sell your personal data, and we do not share it with third parties for their own marketing purposes.6. Sub-processors and Service Providers
We work with a limited number of carefully selected service providers to operate our Services, for example cloud hosting and infrastructure providers, customer support ticketing tools, email delivery services and analytics providers. These providers only receive the data necessary to perform their function on our behalf, are bound by data processing agreements, and are never permitted to use your data for their own purposes.7. How Long We Retain Your Data
We retain account and contact data for as long as your account remains active, and for a reasonable period afterwards to comply with legal, accounting and regulatory obligations. Signed documents and their audit trails are retained for the period required by applicable electronic signature and record-keeping regulations, which can extend to several years depending on the jurisdiction and type of document. You can request deletion of data we are not legally required to keep at any time.8. Security Measures
We protect personal data and document content using industry-standard safeguards, including TLS 1.3 encryption in transit, AES-256 encryption at rest, qualified timestamps, and strict access controls for our staff. In the event of a data breach affecting your personal data, we will take immediate steps to contain and remediate the incident and will notify affected customers and the relevant authorities in accordance with applicable law.9. Your Data Rights
Depending on where you are located, you may have the right to access, correct, export or request deletion of your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. If you are located in the European Union, these rights are granted under the General Data Protection Regulation (GDPR); similar rights may apply under other local data protection laws. To exercise any of these rights, please contact us using the details in Section 11 below. Please note that we may need to retain certain data, such as signed documents and their audit trails, where required by law to preserve their legal and evidentiary value.10. Third-Party Websites and Links
Our websites may contain links to third-party websites, including partners, integrations and social media platforms. These third-party sites are not covered by this Privacy Policy, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policy of any third-party website you visit.11. Legal Disclosures and Contact Us
We may disclose personal data where required to do so by law, regulation, legal process or governmental request, including to comply with obligations under electronic signature, anti-fraud or anti-money-laundering regulations. Any such disclosure will be made in compliance with the laws applicable to your data.If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us through our Contact Us page. This Privacy Policy is a general description of our practices and is provided for information purposes; it may be updated from time to time to reflect changes in our Services or in applicable law.