Legal
Terms of service
Version 1.0 · Effective from September 9, 2026
These terms of service (the "Terms") govern the use of the YouSignDigital platform (the "Service") provided by MITRA, pondy ("we"), by the customer organisation that holds an account (the "Customer") and by the administrators acting on its behalf. By accepting these Terms — through the acceptance button on this page or through the API — an administrator confirms that they are authorised to bind the Customer.
1. Parties and acceptance
The Service is offered to businesses and organisations only; it is not intended for consumers. The Customer is the legal entity identified in its account. Each acceptance of a version of these Terms is recorded with the identity of the accepting administrator, the version number, the date and time and the IP address, and constitutes the evidence of the agreement.
Signers and approvers invited by the Customer are not parties to these Terms; their relationship with the Customer is governed by the Customer's own agreements with them.
2. Description of the Service
The Service is a multi-organisation electronic-signature platform built on the Yousign API. It lets the Customer prepare documents and templates, place signature and form fields, define signers and approvers, send signature requests (simple, advanced or qualified electronic signature, as offered by Yousign), automate reminders, workflows and expiry actions, follow progress, collect the signed documents and their evidence files, share public tracking links, integrate through a REST API, a PHP SDK, an embeddable widget and webhooks, connect storage and CRM services, and optionally collect a payment through Stripe together with a signature.
The signature ceremony, the identity checks, the one-time codes and the evidence file are performed by Yousign SAS under its own terms; the legal effect of a signature depends on the signature level chosen by the Customer and on the applicable law.
3. Accounts, credentials and security
The Customer is responsible for every action performed with its accounts, API keys and single sign-on configuration. It shall keep credentials confidential, assign roles (viewer, operator, administrator) according to the least privilege, deactivate the accounts of people who leave, rotate API keys and notify us without delay of any suspected compromise. We may suspend an account or key that presents a security risk.
4. Acceptable use
The Customer shall use the Service only for lawful purposes and for documents it is entitled to have signed. It shall not: send documents to people whose data it is not allowed to process; impersonate another person or organisation; use the Service to sign on behalf of someone without authority; upload malicious content; attempt to circumvent access controls, rate limits or the isolation between organisations; or resell the Service without our written agreement.
5. The Customer as data controller
For the personal data of signers and approvers and for document content, the Customer is the data controller and we act as its processor under the data-processing terms described in the privacy policy. The Customer warrants that it has a lawful basis to process that data and to send documents for signature, provides accurate signer data, informs signers as required, configures retention settings appropriate to its obligations, and answers data-subject requests using the export and erasure tools provided by the Service.
6. Payments collected through the Service
When the Customer chooses to collect a payment together with a signature, the payment is processed by Stripe under Stripe's terms; the Customer must hold a valid Stripe account and defines the amount and currency requested. We are not a party to the transaction between the Customer and the payer, we never hold the funds and we do not receive card data. Refunds are initiated by the Customer's administrators and executed by Stripe.
7. Signatures and evidence
For every signature request the Service records timestamps, IP addresses, browser identification, document hashes and the status of each step, and lets the Customer download the certificate and audit-trail file issued by Yousign (that file is produced and held by Yousign and fetched from it on each download). Platform actions are written to an append-only, hash-chained audit log. The Customer is responsible for assessing whether the chosen signature level satisfies the formal requirements applicable to its documents.
8. Availability, support and changes
We make reasonable efforts to keep the Service available and to announce planned maintenance in advance. The Service depends on third-party services (Yousign, Stripe, hosting, e-mail delivery) whose incidents may affect it. We may evolve the Service provided that its essential functions are preserved; material changes to these Terms follow the procedure described below.
9. Liability
To the fullest extent permitted by law, we are not liable for indirect or consequential damages (loss of business, profits, data or reputation), and our total liability for all claims arising from the Service in any twelve-month period is limited to the amounts paid by the Customer for the Service during that period. Nothing in these Terms excludes a liability that cannot be excluded by law.
10. Suspension and termination
Either party may terminate the Service at the end of the agreed subscription period. We may suspend or terminate access with immediate effect in case of a serious breach of these Terms, of a security threat or of a legal obligation. Before termination the Customer can export its documents and data; afterwards, data is deleted or archived in accordance with its retention policies and with the legal minimum retention of audit logs described in the privacy policy.
11. Governing law and jurisdiction
These Terms are governed by the law of the country in which MITRA is established (see the address above). Any dispute that cannot be settled amicably is submitted to the competent courts of that country.
12. Changes to these Terms
Each version of these Terms carries a version number and an effective date. When we change them materially, administrators are asked to accept the new version on this page or through the API; continued use of the Service after the effective date constitutes acceptance. The acceptance status of your organisation is available to its administrators on this page and through the API.