How Signater processes personal data of visitors, Customers, Signers, and Affiliates: purposes, legal bases, sharing, and your rights under the LGPD and GDPR.
Last updated on August 30, 2026
Signater — Signater LLC, a limited liability company organized under the laws of the State of Florida, United States, with its principal place of business at 2125 Biscayne Blvd, Ste 204 #27075, Miami, Florida 33137, USA, and Signater Tecnologia Ltda, a Brazilian company enrolled with the National Register of Legal Entities (CNPJ) under No. 50.348.626/0001-61, with its registered office at Alameda Rio Negro, 503, Suite 2020, Alphaville, Barueri/SP, 06454-000, Brazil (together, "Signater", "we", "us") — processes personal data to operate the Signater electronic signature platform (the "Platform"). The entity acting as controller of your data is the entity you contract with, as set out in Section 2 of the Terms of Service; the two entities operate the Platform together. This Privacy Policy (the "Policy") explains what personal data we process, for which purposes, on which legal bases, with whom we share it, and how you can exercise your rights.
This Policy is drafted in accordance with the Brazilian General Data Protection Law — Law No. 13,709/2018 (the "LGPD") — and, where applicable, Regulation (EU) 2016/679 (the "GDPR") and other applicable data protection laws. Please read it carefully and in full.
This Policy applies to personal data processed by Signater through:
This Policy covers every natural person whose personal data Signater processes: website visitors, Customers and Users, Signers, and Affiliates, as defined below.
Capitalized terms have the meaning given to them in the Terms of Service. In short: "Customer" is the holder of an account on the Platform; "User" is a person who uses the Platform under a Customer's account; "Signer" is a person invited to sign, view, or fill in a Document; "Envelope" is the unit of sending, which may contain one or more Documents; "Document" is the digital content submitted for signature or generated by the Platform; and "Sender" is the Customer (or a User of its account) who creates and sends an Envelope.
This Policy should be read together with the following documents, which supplement it:
Under the LGPD and the GDPR, Signater acts either as a controller (when it decides the purposes and means of the processing) or as a processor (when it processes personal data on behalf of, and under the instructions of, a Customer). The table below summarizes the roles:
| Processing context | Signater's role | Who the controller is |
|---|---|---|
| Data of website visitors and of people creating an account | Controller | Signater |
| Data of Customers and Users (registration, authentication, billing, support, account usage) | Controller | Signater |
| Data of Affiliates | Controller | Signater |
| Data of Signers and the content of Documents and Envelopes sent by Customers | Processor | The Customer (Sender) |
When you sign, view, or fill in a Document as a Signer, it was the Sender who decided to collect your data, defined the verification methods required, and manages the Document. Requests from Signers regarding the content of Documents and the data entered into them must therefore be addressed first to the Sender, who is the controller of that data. Signater, as processor, will provide reasonable support in handling such requests, in accordance with the Data Processing Agreement and applicable law.
In specific situations, Signater processes certain Signer data as a controller, to the extent necessary to: (i) keep the Platform secure and prevent fraud; (ii) comply with its own legal obligations; (iii) produce and preserve evidence of the electronic signature; and (iv) measure and improve the operation of the Platform, subject to the Cookie Policy.
The data we process depends on your relationship with Signater. We process only the data necessary for the purposes described in this Policy.
Facial comparison and liveness detection (verifying that a real person is in front of the camera) take place only when the Sender requires those verification steps for the signing of a Document. Signater does not carry out biometric processing on its own initiative, nor does it apply it generally across the Platform.
Selfies, liveness audit frames, and identity document photos are used for a one-time verification at the moment of signing and are then kept solely as evidence of that signature, linked to the corresponding Envelope. Signater does not build a persistent biometric profile or database, does not use these images to identify you in other contexts, and does not use them for any purpose other than verification and signature evidence.
Biometric processing is carried out by a specialized provider engaged by Signater and located abroad, and the automated analysis of identity documents uses artificial intelligence providers, all listed on the Subprocessors page. International transfers are subject to the safeguards described in section 8.
The processing of biometric data relies on the consent you express by voluntarily proceeding with the biometric step of the signing flow (LGPD, art. 11, I; GDPR, art. 9(2)(a), where applicable) and, additionally, on fraud prevention and the protection of the data subject in identification processes (LGPD, art. 11, II, "g"). You have the right not to proceed with the biometric step and to arrange an alternative form of execution directly with the Sender, as described in the Terms for Signers.
Identity document verification and facial comparison use automated analysis with confidence thresholds and may occasionally reject legitimate captures or require new attempts. You may request the review of decisions made solely on the basis of automated processing that affect your interests (LGPD, art. 20; see also section 13 for the GDPR), by contacting the Sender or Signater at legal@signater.com.
Verification images form part of the signature evidence and may be accessed by the Sender, as controller of the Envelope data, to prove the signature and defend against any challenge to it.
We process personal data for the purposes, and on the legal bases, indicated below:
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the Platform and performing the contract | Creating and maintaining accounts; processing Envelopes and signatures; notifying Signers by e-mail, SMS, or WhatsApp; providing support; billing and invoicing | Performance of a contract or pre-contractual steps (LGPD, art. 7, V; GDPR, art. 6(1)(b)) |
| Complying with legal and regulatory obligations | Issuing tax documents; keeping records required by law; responding to requests from competent authorities | Legal obligation (LGPD, art. 7, II; GDPR, art. 6(1)(c)) |
| Security and fraud prevention | Authentication and access control; session records; audit trail; signature evidence; anti-fraud and anti-bot mechanisms | Legitimate interest (LGPD, art. 7, IX; GDPR, art. 6(1)(f)); for sensitive data, fraud prevention and the data subject's protection (LGPD, art. 11, II, "g") |
| Measuring and improving the Platform | Usage metrics; performance analysis; error diagnosis and correction | Legitimate interest (LGPD, art. 7, IX; GDPR, art. 6(1)(f)) |
| Communications and marketing | Product news and offers to Customers; non-essential cookies; campaign measurement | Consent (LGPD, art. 7, I; GDPR, art. 6(1)(a)) or legitimate interest with a right to object, as the case may be |
| Biometric verification required by the Sender | Liveness detection; facial comparison; identity document verification | Consent within the signing flow (LGPD, art. 11, I; GDPR, art. 9(2)(a)); fraud prevention (LGPD, art. 11, II, "g") |
| Regular exercise of rights | Establishing evidence and defending claims in judicial, administrative, or arbitration proceedings | Regular exercise of rights (LGPD, art. 7, VI; GDPR, arts. 6(1)(f) and 9(2)(f)) |
The Platform offers artificial intelligence features, such as AI chat about the Documents in an Envelope, text extraction from Documents for search and AI, automated identity document verification, and facial comparison. These features run when the Customer chooses to use them or when the Sender requires them in the signing flow — never by default across the entire Document library.
When an AI feature is used, the relevant content (text excerpts or images) is processed by specialized providers listed on the Subprocessors page, engaged solely to deliver the feature. Signater does not use the content of your Documents to train its own artificial intelligence models. The full terms are set out in the AI Terms.
We share personal data with engaged service providers who act on our behalf, under contracts containing data protection obligations and only to the extent necessary for the purposes of this Policy. The categories are:
The named list of providers, with their function and processing location, is available on the Subprocessors page.
Signer data — including the audit trail, the evidence certificate, and, where required, the verification images — is made available to the Sender and, as applicable, to the other parties to the Envelope, as an essential part of the electronic signature service.
We may share personal data where necessary to comply with a legal or regulatory obligation, a court order, or a request from a competent authority, and to protect rights, prevent fraud, and pursue or defend claims in judicial, administrative, or arbitration proceedings.
Signater LLC and Signater Tecnologia Ltda belong to the same corporate group and share between them the data necessary to operate the Platform together, under this same Policy. In the event of a corporate transaction — such as a merger, acquisition, or reorganization — personal data may be transferred to the successor, which will remain bound by this Policy or by an equivalent policy.
Signater does not sell personal data. Signer data is not used for advertising.
Some of the service providers we use are located outside Brazil, notably in the United States and in other countries indicated on the Subprocessors page. In those cases, the international transfer is subject to the safeguards of art. 33 of the LGPD, in particular contractual clauses that ensure a level of data protection abroad compatible with Brazilian law. Where the GDPR applies, we rely on the European Union's Standard Contractual Clauses (SCCs) or an equivalent transfer mechanism, as described in section 13.
We use cookies and similar technologies on the website and in the application for essential operation, preferences, analytics, and marketing. Non-essential cookies run only after you accept them in the cookie notice shown on your first visit, and you can change your preferences at any time through the "Cookie preferences" link in the footer. Declining non-essential cookies does not prevent you from browsing. The details — including the list of cookies, their purposes, and durations — are in the Cookie Policy.
We keep personal data for as long as necessary to fulfill the purposes of this Policy, to comply with applicable legal and regulatory obligations, and for the regular exercise of rights. Documents and Envelopes are managed by the Customer within its account, and signature evidence — including the audit trail, the certificate, and verification images — may be kept for the applicable limitation period, even after the Envelope is deleted or the account is closed, to preserve its evidentiary integrity. The criteria and indicative periods per data category are set out in the Data Retention Policy.
We adopt technical and organizational measures designed to protect the personal data we process, including:
No system is entirely immune to incidents. If a security incident occurs that may create relevant risk or harm to data subjects, Signater will notify the affected data subjects and the competent authorities — including the Brazilian National Data Protection Authority (ANPD) — as required by applicable law.
Under art. 18 of the LGPD, you may request from Signater:
Send your request to legal@signater.com. For your protection, we may ask for information or documents confirming the identity of the requester before acting on the request. We will respond within a reasonable time, subject to the deadlines of applicable law. Nothing in this Policy limits any mandatory data protection or consumer rights you hold under the laws of your own jurisdiction.
If your request concerns the content of a Document or the data entered into an Envelope, it must be addressed first to the Sender, the controller of that data, as explained in section 2. Signater will assist with such requests to the extent of its role as processor.
You also have the right to lodge a petition concerning your data with the Brazilian National Data Protection Authority (ANPD).
This section applies where Signater offers services to individuals located in the European Economic Area (EEA) or the United Kingdom, in which case the GDPR or the UK GDPR applies in addition to this Policy. The controller and processor roles described in section 2 correspond to the equivalent concepts under the GDPR: for Signer data and Document content, the Customer (Sender) is the controller and Signater is the processor; for the other categories, Signater is the controller.
Where Signater acts as controller, it relies on the following legal bases under art. 6(1) of the GDPR: performance of a contract (point (b)); compliance with a legal obligation (point (c)); legitimate interests (point (f)), notably platform security, fraud prevention, service improvement, and the establishment, exercise, or defense of legal claims; and consent (point (a)) for non-essential cookies and marketing communications. For biometric data, Signater relies on your explicit consent (art. 9(2)(a)), expressed by voluntarily proceeding with the biometric step of the signing flow, and, where applicable, on the establishment, exercise, or defense of legal claims (art. 9(2)(f)).
If you are located in the EEA or the UK, you have the rights of access, rectification, erasure, restriction of processing, data portability, and objection — including objection to processing based on legitimate interests — as well as the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal. You also have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you, and to obtain human intervention in respect of such decisions (art. 22). To exercise these rights, contact legal@signater.com; where the Customer (Sender) is the controller, we will refer your request to it and assist as processor.
The Signater group is established in Brazil and in the United States, and its service providers process data in the countries indicated on the Subprocessors page. Where personal data subject to the GDPR is transferred to countries without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (or the UK equivalent) or another valid transfer mechanism.
You have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement — in the UK, the Information Commissioner's Office (ICO).
The Platform is not directed at persons under 18 as account holders, and Signater does not knowingly collect personal data from minors for that purpose. A minor's participation as a Signer in a Document occurs by decision, and under the responsibility, of the Sender, subject to the legal representation or assistance requirements of applicable law. If we become aware of processing of minors' data in breach of this Policy, we will take appropriate measures.
Signater has designated Gabriel Hildebrandt as its Data Protection Officer (in Brazil, the "Encarregado pelo Tratamento de Dados Pessoais"), who can be reached at gabriel@signater.com or legal@signater.com, or by mail at the addresses stated in the preamble of this Policy. For general questions about the Platform, use contact@signater.com.
Signater may update this Policy at any time to reflect changes to the Platform, to its providers, or to the law. Material changes will be announced with reasonable prior notice, by e-mail or through a notice on the Platform. Continued use of the Platform after the changes take effect constitutes acceptance of the updated version. The current version will always be available at signater.com/privacy-policy. The other documents governing the use of the Platform are available in the Legal Center.