Privacy Policy
This Privacy Policy describes how Nehrrett Group LLC (“Company,” “we,” “our,” or “us”), operator of the Signrrett platform (“Service”), collects, uses, and safeguards information.
Signrrett is a document workflow and AI-enabled analysis platform available globally.
1. Our Role
We determine how information is used for account administration, billing, security and customer support. For customer-controlled documents and workspaces, the customer generally determines the purposes of processing and we process information on its behalf under the applicable agreement. This notice covers signing, document review, vendor workspaces and procurement as well as our website and accounts.
2. Information We Collect
- Account and contact details, including names, email addresses, phone numbers and organization information.
- Subscription details, payment status and transaction references from supported payment providers.
- Documents, attachments, vendor profiles, procurement submissions and review comments.
- Signature images or typed marks, field values, consent records, invitations, decisions and signing timestamps.
- Support messages, contact lists, workspace membership and access information.
- Network IP address, browser user-agent information (including reported browser and operating-system versions), inferred device type, request and activity timestamps, and usage logs. See device and signing evidence below for collection contexts and purposes.
3. Document Processing
Documents are processed automatically by system infrastructure. Company personnel do not access or read document content except where strictly necessary to:
- Investigate critical technical issues,
- Respond to verified support requests, or
- Comply with legal obligations.
4. AI Processing (OpenAI)
AI-powered analysis is provided through secure API integrations with OpenAI. Submitted documents are transmitted solely for the purpose of generating AI output within the Service.
Documents are not used by the Company to train AI models and are not authorized for model training by OpenAI under API usage terms.
AI output may not be fully accurate and is provided for informational purposes only.
5. Legal Basis for Processing (Where Applicable)
We process personal data based on contractual necessity, legitimate interests, legal obligations, and user consent, depending on the context.
6. Data Retention
Documents are retained for up to five (5) years from upload unless deleted earlier by the user.
Account and billing records may be retained longer where required for legal or tax compliance.
7. Security Measures
We implement industry-standard safeguards including encryption in transit and at rest, role-based access controls, and infrastructure monitoring.
SOC 2 and ISO 27001 are security roadmap certifications for the platform and should not be treated as completed certifications unless Signrrett publishes a current certification report or attestation. Current controls focus on access control, audit history, encryption, and responsible data handling.
However, no system can guarantee absolute security.
8. Subprocessors
We engage third-party service providers to operate the Service, including:
- OpenAI (AI processing)
- Stripe (payment processing)
- Supabase and Vercel (database, storage, authentication and hosting infrastructure)
- Resend (email delivery)
- Twilio for SMS or WhatsApp where those channels are enabled
- Orange Money when that payment method is used
- Cloudflare Turnstile for automated-abuse checks; Google Analytics, Microsoft Clarity where enabled, and Vercel Speed Insights for usage or performance measurement
These providers are contractually obligated to safeguard data.
9. International Data Transfers
Because we operate globally, data may be transferred to and processed in the United States or other jurisdictions.
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data. You may also have rights to portability, to object, to withdraw consent or to complain to the relevant privacy authority, subject to applicable law and exceptions. Submit requests through our Support page and identify them as privacy requests. We may need to verify identity or authority. For customer-controlled records, we may refer the request to that organization and assist as required. You can use the same channel to ask about review of a decision or any applicable appeal rights.
11. Children’s Privacy
The Service is not intended for individuals under 18 years of age.
12. Changes to This Policy
The revision date identifies when this notice last changed. We will provide notice of material changes as required by law and obtain consent where required before applying a new use of information. Updating this notice does not itself authorize uses inconsistent with commitments applicable when information was collected.
13. Sources, Purposes and Workspace Sharing
Information may come from you, an organization inviting you, other authorized participants, providers or use of the Service. Documents may contain information about people without accounts. We use information to provide requested workflows, process payments, deliver invitations and reminders, record signing evidence, support customers and protect the Service against misuse.
Senders, recipients and authorized workspace members can access information relevant to their workflow and permissions. Completion records may include names, email addresses, timestamps and IP or device metadata where collected. Check recipients and permissions before sharing. Deleting an account does not necessarily remove customer-controlled records or copies downloaded by other participants. Contact Support about deletion and any applicable legal retention obligations; keep copies of records you need to preserve.
14. Cookies and Similar Technologies
Cookies and browser storage support authentication, security and saved preferences. Website analytics, session replay and performance measurement are currently disabled. If enabled, Google Analytics measures website usage using page views, interactions, browser and device information and cookie identifiers. Depending on settings, this includes operating system, screen resolution, language and approximate location derived from IP address. Google states that GA4 discards the IP address after deriving location information.
Where enabled, Microsoft Clarity collects page and interaction data, such as clicks, scrolling and session replays, together with browser, device, screen and approximate location information, to help us understand usability problems. Vercel Speed Insights measures page loading and responsiveness with page, browser, operating-system, device and network information to help improve performance. These measurements are separate from signing evidence and are not added to a completion certificate.
Browser settings can manage cookies; blocking necessary storage may prevent sign-in or other features. Browser controls do not replace consent or opt-out rights required by applicable law. Contact Support about the technologies used and choices available in your location. Provider details are available in Google’s data collection information, Microsoft’s Clarity information and Vercel’s Speed Insights privacy information.
15. Sensitive Information, Providers and Contact
Upload only information you are authorized to provide and avoid unnecessary sensitive information. Use of Signrrett does not itself establish suitability for regulated health, financial or other special categories of data. The providers involved depend on features and channels used; payment and communication providers may also process information for their own legal, security and account purposes under their notices. Information may be disclosed when required by law or binding legal process.
For privacy questions, provider information, security concerns or reports of information submitted by a child, contact us through Support. Describe the account or document concerned without including passwords or unnecessary sensitive attachments.
16. Communication Language and Translation Tools
English is the standard language for Signrrett-generated emails, in-app notifications, system messages and support correspondence, subject to the exceptions described in our Terms of Service. An interface language setting does not automatically translate these communications or content provided by other users. You may use your own translation tool, but you are not required to install a particular tool to read our notices or exercise your privacy rights.
Depending on the tool and its settings, browser, email, device or app translation features may process text on your device or send text, documents and related information to an external provider. Review the provider’s privacy notice, permissions, retention practices and settings before using it. Do not assume that translation takes place only on your device.
Avoid sharing passwords, verification codes, signing links, confidential documents or unnecessary personal information with a translation service. Check that you are authorized to share information belonging to others. A translation tool you independently choose is not, merely by that choice, a service provider engaged by Signrrett. Its processing is governed by its own applicable terms and privacy notice. This does not limit Signrrett’s obligations for information we process.
This policy does not waive any legally required language or accessibility assistance or your privacy rights. If you need help understanding this notice or submitting a privacy request, use our Support page.
17. Device, Network and Electronic Signing Evidence
When you sign or decline through a signing link, we record the network IP address available from the request and the browser’s user-agent string, where provided. That string can report browser name and version, operating system and version, and device information. We use it to derive a browser, operating-system and mobile/desktop device summary. These records are associated with the document, recipient name and email, action and timestamp. Signing evidence also records the access method, account identity where applicable, and electronic-signature consent time, version and language.
We collect this information to document the circumstances of consent, signing or refusal; maintain an audit trail; help investigate suspected misuse, technical problems and disputed activity; and support verification of the signing record. IP and device details provide context, not proof of a person’s identity or precise physical location. A shared network, proxy or VPN may supply the address, and browser information may be incomplete or inaccurate. Document hashes separately support checks of document integrity.
The completion certificate can show the signer’s IP address, browser, operating-system and device summary, consent timestamp and invitation delivery evidence, alongside other transaction details. Raw user-agent information is stored in signing and audit records. Senders, recipients and authorized workspace users may receive evidence according to their document access. Anyone given a downloaded document or certificate may also see its contents, so share copies carefully. The public certificate verification response reports a match and issuance time; it does not return signer IP addresses or device details.
We also record available IP address and user-agent information with Terms and Privacy acceptance records to document which notices were accepted, by whom and when. Logo-permission responses record IP address and response time as evidence of the decision. Enterprise API logs associate request IP and user-agent with request details and results for access auditing and troubleshooting. Certificate verification uses IP-based request limits to reduce abuse.
For protected forms, we send an available IP address and challenge token to Cloudflare Turnstile to validate the security check. Turnstile also processes browser and connection signals, including IP address, user-agent, TLS fingerprint (characteristics of the secure connection), and the site identifier and origin, to distinguish automated abuse from legitimate visits. Cloudflare also uses these signals to improve its bot detection. See Cloudflare’s Turnstile privacy notice. Hosting and authentication providers process network and request information to deliver and secure the Service. Website measurement is described separately in section 14.
The legal bases, retention, provider processing and privacy rights described elsewhere in this policy apply to these records. Customer-held audit records and downloaded certificates may remain with their holders after an account is deleted. Contact Support about a particular record, its retention or a privacy request.
Last updated:
