- Document
- Privacy Policy
- Version
- 2.3
- Effective from
- 18 September 2026
- Supersedes
- 2.2 (10 August 2026)
- Controller
- AgreeVia Solutions Ltd
- Registered
- Scotland, no. SC898504
- ICO register
- ZC220362
Contents — 16 sections
1Who we are
AgreeVia is an electronic signature service operated by AgreeVia Solutions Ltd, registered in Scotland (company number SC898504) and registered with the Information Commissioner's Office (registration ZC220362).
In this notice, "we" and "AgreeVia" mean AgreeVia Solutions Ltd. "You" means anyone whose personal data we hold — account holders, people invited to sign a document, and visitors to this website.
You can reach us about anything in this notice at [email protected].
2When we're the controller, and when we're not
This distinction decides who you go to with a request, so it's worth reading. It's also why deletion works differently for different kinds of data — see §10.
We are the controller of your account data — your account details, subscription, support messages, how you use the app — and of the audit and integrity records the service generates, such as the document event log described in §11. We decide why and how that data is used, and this notice covers it in full.
We are a processor for the contents of documents you create, upload, or send for signature, and for the personal data of people you invite to sign them. You decide what goes in those documents and who sees them. Deletion works differently here than in most apps: documents cannot be deleted from within AgreeVia at all. If a document has not been signed and you want it erased, email [email protected] and we will do it. Once it has been signed, the record is fixed — §9 and §10 explain for how long, and why. We only act on your instructions, and our Terms of Service and Data Processing Addendum set out those obligations.
3What we collect
| Category | What that means |
|---|---|
| Account data | Name, email address, business name, password hash, profile photo if you add one. |
| Document content | Files you upload or generate, their titles, and any text or fields you add. |
| Signature data | The drawn or typed signature you apply, and the name you sign under. |
| Evidence metadataRecorded to make a signature stand up if challenged | IP address, device and browser type, timestamps for every view, sign and download event, and a tamper-evident hash of each event. |
| Proof of acceptanceRecorded once a document you're party to is completed | A record that you had accepted the Terms of Service and this Privacy Policy — which version of each, when, and your IP address at the time — kept as proof of the basis on which you signed. |
| Messages | Chat messages and attachments you send to other users through the app. |
| Subscription data | Which plan you're on, purchase and renewal dates, and an anonymous store identifier. We never see or store your card number. |
| Usage data | Which features you use, crash reports, and diagnostic logs. |
| Support data | Anything you send us by email or in-app when you need help. |
We do not ask for special category data — health, biometrics, political or religious views — and you shouldn't put it into documents unless your own lawful basis covers it.
4Why we use it, and on what legal basis
| Purpose | Data used | Lawful basis |
|---|---|---|
| Running your account and the signing service | Account, document, signature | Performance of a contract |
| Producing evidence that a signature is valid | Evidence metadata | Legitimate interests — the service has no value without a defensible audit trail |
| Defending a completed document if it's challenged, including after you've deleted your account | Evidence metadata, proof of acceptance | Legal obligation, and legitimate interests — establishing, exercising or defending legal claims |
| Taking payment and managing subscriptions | Subscription | Performance of a contract |
| Keeping the service secure and preventing fraud | Usage, evidence metadata | Legitimate interests — protecting users and the service |
| Fixing bugs and improving the product | Usage, support | Legitimate interests — improving a service you pay for |
| Meeting tax, accounting and legal duties | Account, subscription | Legal obligation |
| Sending product or marketing email | Account | Consent, which you can withdraw at any time |
Where we rely on legitimate interests, we've weighed those interests against your rights and concluded they don't override them. Ask us and we'll share that assessment.
5AI features
AgreeVia can draft a contract from a brief and can summarise or flag terms in a document you're about to sign. To do this, we send the relevant text to Anthropic PBC, which operates the Claude API.
- Text is sent only when you actively use a drafting or analysis feature. Documents sitting in your account are not sent anywhere.
- Anthropic does not use business API content to train its models.
- We don't use the output to make any decision about you that has a legal or similarly significant effect. AI output is a draft or a summary — a person always reviews and decides.
- AI output can be wrong or incomplete. It isn't legal advice, and it doesn't replace having a solicitor read something that matters.
If you'd rather no content left our systems for this purpose, don't use the AI features. Everything else in AgreeVia works without them.
6If you were sent a link to sign
You don't need an AgreeVia account to sign a document someone sends you. When you open a signing link, we collect:
- the name and email address the sender gave us for you;
- the signature you apply and the name you sign under;
- your IP address, device and browser type, and timestamps for opening, viewing, signing or declining.
We collect this because a signature without a record of who applied it, from where and when, is difficult to rely on later. The sender decides who else can see the document, and can cancel your invitation before you sign. Neither the sender nor we can delete a document once it has been signed: it is kept for the life of the record so that it stays verifiable for everyone who relied on it. §9 sets out the full schedule, and §12 explains what you can ask us for.
7Who else handles your data
We don't sell personal data and we don't share it for advertising. We use the following providers, each under a written contract that limits them to our instructions:
| Provider | What they do | Where |
|---|---|---|
| SupabaseDatabase, file storage, authentication | Stores your account, documents and audit records | AWS, London (eu-west-2) |
| Anthropic PBCClaude API | Processes text for drafting and analysis when you use those features — the contract content you submit is sent to their API to generate the response | United States |
| RevenueCatSubscription management | Tracks entitlements and renewals | United States |
| Apple, GoogleApp stores | Take payment and process refunds | United States and elsewhere |
| CloudflareDNS, CDN, website, guest-signing pages | Serves this site and the signing pages, and protects them from attack | Global network |
| ResendTransactional email | Delivers signing invitations and account emails | United States |
| ZohoSupport desk | Handles support email you send us | EU (Netherlands) |
We may also disclose data where the law requires it, to establish or defend legal claims, or to a buyer if the business is sold — in which case we'll tell you first.
We keep a current list of providers on this page. Our Data Processing Addendum applies automatically to every customer, and we give notice before adding a new sub-processor.
8Data that leaves the UK
Some of the providers above are based outside the UK, including Resend (United States). Zoho's EU (Netherlands) data centre is inside the EEA, not the UK, so it's also a transfer, just to a region UK adequacy regulations already cover rather than one needing Standard Contractual Clauses. Where personal data is transferred out, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on UK adequacy regulations where they apply, together with a transfer risk assessment.
Ask us at [email protected] and we'll tell you which safeguard applies to a particular transfer.
9How long we keep things
| Data | Retention |
|---|---|
| Account data | While your account is open, then 30 days after you close it |
| Signed documents and their audit trail | Kept for the life of the record — we don't delete completed documents or their audit trail (see note below) |
| Documents nobody has signed yet | Until the person who created it asks us to erase it, or until their account is deleted |
| Chat messages | In a chat that contains a completed document: same period as its audit trail, above — see §10.Otherwise: your own messages are removed if you delete your account (within 30 days); there's no per-message delete outside that, and the other participant's messages remain theirs. |
| Billing records | 6 years, as tax law requires |
| Proof of acceptance | Deleted with your account — unless you have a completed document, in which case a copy is kept with that document as proof of the terms you accepted when you signed. See §10. |
| Security and diagnostic logs | 90 days |
10Account deletion
You can delete your account from within the app. This section says plainly what that does — the in-app deletion screen carries the same summary, not a softer version of it. For step-by-step instructions, including what to do if you no longer have the app installed, see our Delete your account page.
Deleted
- Your login credentials.
- Your profile — name, email, phone number, and photo.
- Draft and unsent documents that only involve you.
- Your personal chat with yourself.
- The personal identifiers on your subscription record.
- Usage and diagnostic data, once it's past the retention window in §9.
Retained, and why
- Completed documents and their audit trail — the hash-chained event log described in §11 — kept to meet our legal obligations and so a document can still be established, exercised or defended as evidence if it's challenged.
- The record that you accepted our terms and this notice at the time a document you were party to was completed — see §3 — kept for the same reason.
- Messages in a chat that contains a completed document, as part of that document's evidence — see §9.
What happens to documents you created but nobody signed They are deleted outright, along with their event history, provided nobody else is a subject of them.
What happens to your name on documents that were signed We remove you from the ownership record — the document stays, but it is no longer linked to your account. Your name as it appears inside the document, and in its audit trail, remains, because that is what the other parties signed.
Asking us to erase something without closing your account Email [email protected]. If nobody has signed the document, we will delete it and its event history and confirm when it's done, normally well within one month. If it has been signed, we will explain why we cannot and what we can offer instead.
Retained items above are purged in full once they reach the retention period set out in §9. Everything else on this list is deleted within 30 days of your request.
11How we protect it
- Everything is encrypted in transit with TLS, and at rest on our providers' infrastructure.
- Access to your data is enforced at the database level, so one account cannot read another's records.
- Every document event is written to an append-only log and chained with a SHA-256 hash, so any alteration to the history is detectable.
- Signing links are single-purpose, time-limited, and revocable.
- Staff access to production data is limited to what's needed to run the service and is logged.
If a breach happens that's likely to risk your rights, we'll report it to the ICO within 72 hours and tell you without undue delay where the risk is high.
12Your rights
Under UK data protection law you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything inaccurate or incomplete.
- Delete your data, where we have no overriding reason to keep it.
- Restrict how we use it while a dispute is resolved.
- Port it to another service in a machine-readable format.
- Object to processing based on legitimate interests, including any direct marketing.
- Withdraw consent where consent was the basis, without affecting what came before.
Email [email protected]. We'll respond within one month, and it's free, to the extent of a reasonable and proportionate search of our records. If your request concerns a document sent to you by an AgreeVia customer, we'll pass it to them, and tell you we've done so. They decide what happens to a document nobody has signed, and can ask us to erase it. Once it's signed the retention period in §9 applies and neither of us can shorten it — we'll tell you that directly rather than leave you chasing them for something they cannot deliver.
Closing your account is described in §10: we delete what we can, but some completed records and their audit trail are kept for the period set out in §9 where the law requires it, and can't be selectively erased.
13Cookies and similar technology
AgreeVia doesn't currently use cookies — not in the mobile app, not on this website, and not on the signing pages. We don't run advertising, analytics, or cross-site tracking of any kind.
If that changes, we'll update this section first. Anything beyond what's strictly necessary to run the service would need your consent under PECR, and we'd ask for it rather than assume it.
14Children
AgreeVia is a business tool and isn't intended for anyone under 18. We don't knowingly collect data from children. If you believe a child has given us personal data, tell us and we'll delete it.
15Changes to this notice
We version this notice rather than quietly editing it. The version number and effective date are at the top of the page. Where a change materially affects how we use your data, we'll email you or show a notice in the app before it takes effect, and we'll record which version you accepted.
Earlier versions are available on request.
16Contact and complaints
If you're unhappy with how we've handled your personal data, tell us first — most things are quicker to fix directly. Email [email protected] with "Complaint" in the subject line, or use our contact form. We'll acknowledge your complaint within 30 days, investigate it without undue delay, keep you updated on progress, and tell you the outcome.
Under the Data (Use and Access) Act 2025, you also have the right to complain to the Information Commissioner's Office directly — you don't have to come to us first if you'd rather not, though we'd welcome the chance to put things right. If we decline to act on a request, we'll tell you why and remind you of these complaint rights at the same time.
AgreeVia
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
0303 123 1113
ico.org.uk/make-a-complaint