Privacy Policy

Last updated: August 14, 2026

AKMSign is operated and provided by AKM Digital Solutions.

This Privacy Policy explains what personal data AKMSign processes when you use the platform, why we process it, who we share it with, and how long we keep it. AKMSign is operated and provided by AKM Digital Solutions, which is the party responsible for the processing described here.

1. Who this applies to

This policy covers account holders and workspace members, external recipients who open or sign a document through an AKMSign link, and visitors who contact us through the website.

When a customer uses AKMSign to send documents, that customer decides what documents to upload and who to send them to. AKMSign processes that content on the customer's behalf in order to provide the service.

2. Data we process

· Account information: name, email address, job title and profile details, including a saved signature, initials or stamp image if you create one.

· Workspace information: company name, legal name, timezone, logo, roles, invitations and membership records.

· Recipient information: the name, email address, role and signing order of each recipient a sender adds to a document.

· Uploaded documents and supporting files, and the field values entered into them.

· Electronic signature records: signature images or typed signatures, timestamps, recipient verification steps and document integrity hashes.

· Audit and activity events: sending, opening, viewing, signing, declining, revoking, reminders, revisions and downloads.

· Technical and security metadata associated with those events, such as the time of the action and the signing link used.

· Email delivery metadata: the delivery outcome for messages we send, such as delivered, bounced, complained or unsubscribed.

· Subscription and billing identifiers, such as the plan, billing cycle, subscription state and the customer and subscription identifiers returned by our payment provider.

· Storage and usage information, such as the number of documents and the storage consumed by a workspace.

· Support and contact requests: the name, work email, company name, category and message you submit through the contact form.

Our hosting and infrastructure providers also process standard technical logs, which can include IP address and browser or device information, for security, abuse prevention and reliability purposes.

3. Why we process it

· to provide, operate and maintain AKMSign;

· to authenticate users and control access to workspaces and documents;

· to deliver signing workflows, including sending signing links, notifications and reminders;

· to maintain audit, evidence and security records associated with signed documents;

· to detect, prevent and investigate abuse, fraud and security incidents;

· to process subscriptions, plan changes and billing state;

· to send transactional communications relating to your account, documents and subscription;

· to respond to support, sales and privacy requests;

· to improve the reliability, performance and security of the service.

AKMSign does not sell personal data, and does not use the content of customer documents for advertising.

4. Service providers

We use a small number of processors to run the service. Each receives only the data needed for its function:

· Paddle — subscription checkout, payment processing and, where applicable, merchant of record.

· Lovable Cloud (built on Supabase) — application hosting, authentication, database and document storage.

· Lovable's managed email service — delivery of transactional email such as signing requests, reminders, verification codes and password resets, sent from our verified sender domain.

· Google — only where a user chooses Google to sign in; Google then processes the sign-in and returns basic profile information.

Content of your documents is shared with the recipients you designate, and with workspace members according to the roles and permissions your administrators configure.

We may disclose information where required by law or valid legal process, or to protect the rights, safety and security of users and of the service.

5. Payment data

Payment card details are entered into and handled by Paddle's checkout and payment infrastructure. AKMSign does not need, receive or store full payment card numbers.

AKMSign stores only the subscription state and the identifiers required to link a workspace to its subscription and to display billing information to workspace administrators.

6. Retention

Documents, signing records and audit events remain available to the workspace while the workspace is active.

When a paid subscription ends, the workspace enters a read-only retention window of 90 days. When an unpaid trial expires, the read-only retention window is 30 days.

Reactivating a subscription during the retention window restores normal access without data loss.

After the applicable retention window ends, the workspace becomes eligible for deletion under AKMSign's data-retention policy.

Some records may be retained for longer where required for legal, financial, tax, security, fraud-prevention, dispute-resolution or regulatory purposes.

Where data is deleted from the live service, residual copies may persist for a limited period in routine infrastructure backups until those backups expire on their normal cycle.

7. Your rights

Depending on where you live, you may have rights to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, or a copy of the data you provided to us.

You can update most of your account information directly in AKMSign, and can send other requests through the contact form using the "Privacy / data request" category.

If your data was uploaded to AKMSign by a customer — for example because you were sent a document to sign — we will normally direct your request to that customer, who decides what happens to their documents.

We will respond to requests as required by applicable law. Some data may be retained where a legitimate legal, security or record-keeping requirement applies.

8. Security

AKMSign applies technical and organisational measures appropriate to the service, including authenticated access, role-based permissions, database-level access rules that isolate each workspace, private document storage, hashed and expiring signing links, and audit logging of document actions. Data is transmitted over encrypted connections.

No online service can be guaranteed to be completely secure. AKMSign does not claim any security certification or regulatory compliance attestation that it has not obtained.

9. International processing

Our infrastructure and service providers may store or process data in more than one country. Where data is transferred across borders, we rely on the safeguards offered by those providers and on the protections required by applicable law.

10. Cookies and local storage

AKMSign uses only the storage needed to run the service: a session token that keeps you signed in, a cookie that remembers your language preference, and local browser storage used to speed up document rendering. We do not use advertising cookies.

11. Changes to this policy

This policy may be updated as the service evolves. The date of the latest version is shown at the top of this page, and material changes will be communicated where appropriate.

12. Contact

Privacy questions and requests can be sent through the AKMSign contact form or by email to support@akmsign.com.