Legal

Privacy policy

Version 1.0 · Effective from September 9, 2026

This privacy policy explains how MITRA ("we") processes personal data when you use the YouSignDigital electronic-signature platform: the administration portal, the API and SDK, the embeddable signing widget and the public tracking pages. It applies to the administrators of our customer organisations, to the people invited to sign or approve documents ("signers") and to the visitors of the public tracking pages.

1. Who is responsible for your data

MITRA, pondy, operates this platform. For any privacy matter you can reach us at veeravel.pichaimuthu@it-mitra.com.

Two roles apply, depending on the data concerned:

  • For the personal data of administrators (the people who sign in to this portal) and for the security and audit logs of the platform, MITRA is the data controller.
  • For the personal data of signers and approvers and for the content of the documents sent for signature, the customer organisation that created the signature request is the data controller; MITRA acts as its data processor and processes this data only on its documented instructions (the settings and actions the organisation performs on the platform). Signers should address their requests first to that organisation; we assist it in answering them.

2. What this policy covers

This policy covers the administration portal (including the sign-in, single sign-on and password-reset pages), the REST API and the PHP SDK, the embeddable signing widget, the transactional e-mails and SMS sent for a signature, the public tracking pages reached through a tracking link, and the payment step operated with Stripe when an organisation chooses to collect a payment together with a signature.

The signature ceremony itself (identity verification, one-time codes, the signature and its evidence file) is performed by Yousign SAS, whose own privacy notice applies to the signing pages it hosts.

3. Personal data we process

  • Identity and contact data of signers and approvers: first and last name, e-mail address, mobile phone number (for one-time codes sent by SMS), preferred language and role in the signature workflow.
  • Documents: the files sent for signature, their titles, their cryptographic hashes (SHA-256), the fields placed on them and the values entered, and the signed versions.
  • Evidence and audit data: the timestamp of every step (sent, viewed, signed, declined, expired), the IP address and browser identification (user agent) recorded at each action, the sending and opening status of the notification e-mails, and the certificate and audit-trail file produced by Yousign (retrieved from Yousign when it is downloaded).
  • Administrator account data: name, e-mail address, role, hashed password, sign-in history, security events (failed sign-ins, IP allow-list and geographic-restriction decisions, organisation switches), API keys (stored encrypted), preferences and notifications.
  • Payment metadata when a payment is collected: amount and currency, payer e-mail address, the Stripe identifiers of the checkout session and of the payment, and its status. We never receive or store card numbers.
  • Technical data: server logs (request path, status, timing, correlation identifier), the webhook payloads received from Yousign and Stripe, and the outbound webhooks configured by the organisation.

4. Why we process it and on what legal basis

  • Providing the electronic-signature service to the customer organisation (creation, sending, reminders, signing, tracking, storage of the signed documents): performance of the contract with the organisation; for signers, the legal basis determined by the organisation as controller (usually its contract with the signer or its legitimate interest).
  • Producing and preserving the evidence of a signature (timestamps, IP addresses, hashes, audit trail) so that it can be proven and challenged in accordance with Regulation (EU) 910/2014 (eIDAS): legal obligation and legitimate interest in the enforceability of signed documents.
  • Securing the platform (authentication, session management, rate limiting, IP allow-lists, geographic restrictions, anomaly detection, append-only audit log): legitimate interest in preventing unauthorised access and fraud.
  • Collecting payments linked to a signature through Stripe: performance of the contract and accounting obligations.
  • Sending transactional notifications (invitations, reminders, completion notices, security alerts): performance of the contract. No marketing message is sent.
  • Answering lawful requests from competent authorities: legal obligation.

5. Who receives your data

Your data is accessible to the administrators of the customer organisation that created the signature request, within the roles they hold on the platform, and to the personnel of MITRA strictly for operating, securing and supporting the service.

We rely on a limited number of sub-processors, each bound by a data-processing agreement. On this installation they are: Yousign SAS, Stripe Payments Europe, Limited, IT-Mitra, Resend, api.country.is. This list is generated from the running configuration, so it names every processor actually engaged here — including, where they are configured, the AI provider that analyses document text and the IP-geolocation provider used for geographic access rules. The purpose, the data categories and the location of each are published on the sub-processors page.

When an organisation connects its own integrations (cloud storage, CRM, outbound webhooks, calendar feeds), the data sent to those services is transferred at the organisation's request and under its responsibility.

We disclose data to public authorities only when the law requires it.

6. Where your data is stored and transferred

The platform and its database are hosted by IT-Mitra in the France (EU) region. Yousign SAS processes signature data in the European Union. Stripe Payments Europe, Limited is established in Ireland; some payment data may be transferred to Stripe, Inc. in the United States under the safeguards of Stripe's data-processing agreement (EU Standard Contractual Clauses).

Because no local geolocation database is installed here, the IP address of anyone connecting to an organisation that uses geographic access rules — administrators and signers alike — is sent to api.country.is to resolve its country.

Where a transfer outside the European Economic Area occurs, it relies on an adequacy decision or on Standard Contractual Clauses. Processing takes place in the same locations for every organisation on this installation: the platform offers no per-organisation residency or cross-border transfer control, so the locations stated above are the ones that apply to you.

7. How long we keep your data

Each customer organisation configures retention policies for its signature requests, documents, webhook events and analytics, and the platform enforces them automatically after the number of days it chooses: deletion is available for all four, anonymisation for signature requests, documents and webhook events, and archiving (a snapshot kept after the original is removed) for signature requests only. Signed documents and their evidence are kept as long as the organisation needs them to prove the signature, then archived or deleted according to its policy.

Security and audit logs are kept for the period the organisation configures (7 years by default) and never less than the platform minimum of 7 years, because they are the legal evidence of who did what and when. The audit log is append-only and hash-chained: entries cannot be modified or removed before that period ends.

Administrator accounts are kept for the duration of the organisation's subscription; after termination, data is exported on request and deleted in accordance with the retention policies. Erasure requests are honoured by pseudonymising personal data while preserving the evidence elements the law requires (document hashes, timestamps, signature status).

8. How we protect your data

  • Encryption in transit (TLS) for every connection to the portal, the API, the widget and the sub-processors.
  • Encryption at rest of API keys and integration credentials; passwords are stored as salted hashes.
  • Role-based access (viewer, operator, administrator), optional single sign-on (SAML), IP allow-lists and geographic restrictions per organisation, rate limiting and lock-out of sensitive flows.
  • Signed webhooks (HMAC) in both directions and protection against server-side request forgery on every outbound call.
  • Append-only, hash-chained audit log with periodic integrity verification; regular backups.
  • Signer identification by one-time code (SMS or e-mail) and, at higher signature levels, identity verification performed by Yousign.

9. Your rights

You have the right to access the personal data we hold about you, to have it rectified or erased, to restrict or object to its processing, and to receive it in a portable format, within the limits set by the law (the evidence of a signature may have to be kept even after an erasure request).

If you are a signer, please address your request to the organisation that invited you: as the data controller it can, from its privacy settings on this platform, export every record about you and pseudonymise your personal data across the platform, and it keeps a log of the erasures it performs. If you are an administrator, the administrators of your organisation manage your account; you can also contact us directly.

For any request, or if you believe your data is not handled correctly, write to veeravel.pichaimuthu@it-mitra.com. You also have the right to lodge a complaint with your data-protection authority (in France, the CNIL).

10. Public tracking pages

A tracking link lets anyone who holds it follow the progress of a signature request without signing in. These pages only show the request title, its status, the progress, the initials of the signers and the dates of the status changes; they never display e-mail addresses, documents or internal identifiers, and they set no cookie. The visit itself is recorded, however: each time a tracking link or the open-tracking image in a notification e-mail is fetched, we log the event with the date and time, your IP address and your browser identification, attributed to the invited signer when the link identifies one. This is how the sending organisation sees that its message was opened and its link followed. Treat a tracking link as confidential: do not forward it to people who should not see this information.

11. Technical third parties contacted by your browser

Apart from our sub-processors, your browser loads a small number of resources directly from third-party servers when displaying our pages. Those servers receive your IP address and standard browser headers as a technical necessity of serving the file; they receive no data about your signature requests. The current list is:

  • fonts.googleapis.com, fonts.gstatic.com — Inter web font delivered by Google Fonts (Google LLC) — loaded by every page that uses the application stylesheet: the administration interface, the sign-in page and these legal pages

12. Changes to this policy

Each version of this policy carries a version number and an effective date. When we change it materially, the administrators of customer organisations are asked to accept the new version, and the acceptance (version, date, time, IP address) is recorded. Earlier versions remain available on request.

13. Contact

MITRA, pondy. Privacy contact: veeravel.pichaimuthu@it-mitra.com.

MITRA — pondy — veeravel.pichaimuthu@it-mitra.com

Version 1.0 · Effective from September 9, 2026