European Union

GDPR-ready data practices

Signing a document means handling personal data. BeeSign collects it for a stated purpose, never sells it, and protects it with encryption — with identity-verification data handled privacy-first.

What is the GDPR?

The General Data Protection Regulation (GDPR) is the European Union’s data-protection law. It governs how organizations collect, process, store, and protect the personal data of individuals in the EU, and applies to any company that handles that data regardless of where the company is based.

GDPR is built on principles including lawfulness and purpose limitation (data is collected for specified, legitimate purposes), data minimization, storage limitation, integrity and confidentiality (appropriate security), and accountability. It also grants individuals rights over their data — access, rectification, erasure, and more.

How BeeSign supports GDPR

Purpose limitation

Personal data is collected to complete and evidence the signing transaction — not repurposed, and never sold to third parties.

Security of processing

Data is encrypted in transit over TLS and at rest in cloud storage, and stored under owner-scoped isolation so it is only reachable by its owner.

Privacy-first identity verification

When Advanced Electronic Signatures require ID capture and a biometric check, that verification is handled privacy-first through a dedicated identity provider.

Data residency options

White-label customers on AWS can bring their own S3 bucket, keeping signer data within a cloud account and region they control.

GDPR-aligned data handling

  • Purpose-limited data collection
  • No sale of personal data
  • Encryption in transit and at rest
  • Owner-scoped access isolation
  • Privacy-first identity verification
  • Bring-your-own-cloud data residency (white label)

Frequently asked questions

Does BeeSign sell or share signer data?

No. Personal data is used only to complete and evidence the signing transaction. It is never sold, and it is not shared beyond the processors needed to deliver the service.

Where is signer data stored?

In encrypted cloud storage under an owner-scoped namespace. White-label customers on AWS can bring their own S3 bucket to keep data within a region and account they control.

How is biometric identity-verification data handled?

For Advanced Electronic Signatures, government-ID and biometric checks are processed through a dedicated identity-verification provider in a privacy-first manner, tied only to the specific signing event.

Can a signer request their data be deleted?

GDPR grants data-subject rights including erasure. If you need to action a data-subject request related to a BeeSign document, contact support and we will assist within the bounds of records you are legally required to retain.

This page explains how BeeSign supports GDPR-aligned data practices and is provided for general information — it is not legal advice. Consult your data protection officer or counsel about your obligations.

Compliant from your first document

Every BeeSign plan includes legally binding signatures, tamper-evident audit trails, and a certificate of completion. Start your free trial today.