Legal
Privacy notice
Last updated: 28 September 2026
This is a courtesy translation: in the event of any conflict, the Italian text prevails. Read the Italian version
This notice is provided, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter "GDPR"), to anyone who interacts with the website https://docujet.it or with the DOCUJET service (hereinafter also the "Service"). It explains which personal data we process, why, with what tools and for how long. If you have any questions, you can write to [email protected].
1. Data controller
The data controller is Grem S.r.l., with registered office at Via Matteo La Fragola, 4, Salerno (SA), VAT no. / tax code IT06136730659 (hereinafter "DOCUJET" or "we"). Dedicated email address for privacy requests: [email protected].
Grem S.r.l. is not required to appoint a Data Protection Officer (Art. 37 GDPR); data subjects' requests are handled at the privacy address given above.
2. Who this notice is for
This notice applies to two categories of data subjects, whose data are collected through different flows:
2.1. Registered user (holder of a DOCUJET account)
Anyone who opens a DOCUJET account to send documents for signature. The data are collected directly from the data subject at the time of registration, pursuant to Art. 13 GDPR.
2.2. Invited signer
Anyone who is invited to sign a document through a DOCUJET link, without being registered. Their contact details (name, email, telephone number) are collected indirectly: they come from the registered user who started the signing flow (the "sender"). This notice is provided pursuant to Art. 14 GDPR when the signing link is first accessed. The sender is an independent controller of the signer's data collected for its own purposes (e.g. manual entry into a CRM); DOCUJET acts as a processor solely for the management of the signing flow on behalf of the sender.
3. Categories of personal data processed
- Account data (registered user): first name, surname, company name, email, password (stored in encrypted form by hashing), telephone number.
- Signer data: first name, surname, email, mobile number (for sending OTPs).
- Signature data: uploaded document, fields completed by the signer, values of the graphical signature (where applicable), date and time of acceptance of consents, date and time of signature, IP address, device user agent.
- Identity verification (KYC) data, only when the sender has enabled the feature: image of the identity document (identity card or passport), selfie of the signer, data extracted from the document (first name, surname, date of birth, expiry date), biometric comparison score between the selfie and the photo on the document. These are special categories of personal data within the meaning of Art. 9 GDPR (biometric data for the purpose of uniquely identifying a person). The processing takes place exclusively on the basis of the explicit consent of the data subject, given at the start of the KYC flow, in accordance with Art. 9(2)(a) GDPR.
- Billing and payment data (registered user): company name, address, VAT no. / tax code, payment transaction ID. Full credit card details are handled by our payment provider (Stripe); DOCUJET neither receives nor stores them.
- Technical logs and usage data: access logs, IP address, browser and device type, pages visited, session identifiers, anonymous telemetry data.
- Cookies and similar technologies: see the Cookie Policy.
4. Purposes and legal bases
| Purpose | Categories of data | Legal basis |
|---|---|---|
| Provision of the Service (creating, sending and signing documents) | Account, signature, technical logs | Art. 6(1)(b): performance of the contract |
| Verification of the signer's identity (KYC) when enabled by the sender | Identity document, selfie, biometric score | Art. 6(1)(b) + Art. 9(2)(a): explicit consent of the signer |
| Retention of the signed document and of the audit trail | Document, audit trail, IP, user agent | Art. 6(1)(c): legal obligation (eIDAS, CAD, sector-specific regulations) |
| Billing and tax compliance | Billing data | Art. 6(1)(c): legal obligation |
| Security, fraud prevention, misuse of the Service | Technical logs, IP, OTP attempts | Art. 6(1)(f): legitimate interest of the Controller |
| Responding to support requests | Email, content of the message | Art. 6(1)(b) or 6(1)(f), depending on the request |
| Measuring advertising campaigns on Facebook and Instagram: when you create an account, ask us to contact you or activate and pay for a subscription, we tell Meta that this has happened (Conversions API) | Email and mobile number in hashed form (SHA-256), never in clear text; account identifier in hashed form; IP address; browser type; ad click identifiers, if any; for payments, plan, amount and currency | Art. 6(1)(f): legitimate interest of the Controller in measuring the effectiveness of its campaigns. You may object at any time (Art. 21) by writing to [email protected] |
| Marketing communications (newsletter, product news) | Art. 6(1)(a): consent, which may be withdrawn at any time |
5. Automated decision-making
Some stages of the Service involve automated decisions within the meaning of Art. 22 GDPR:
- Temporary block after incorrect OTPs: after several incorrect OTP attempts in a row, the system automatically suspends the signing session to prevent brute-force attacks. The logic is described in the Security section.
- Automatic outcome of the KYC check: when the feature is enabled, the comparison between the selfie and the photo on the document produces a similarity score. A minimum threshold automatically determines whether the check has "passed" or "failed". The outcome does not in itself affect the legal validity of the advanced electronic signature (AES), but the sender of the document may decide whether to accept the signature anyway or to request a manual check.
In both cases the data subject may request human intervention, express their point of view and contest the decision by writing to [email protected].
6. Blockchain anchoring
To ensure the integrity of signed documents over time, DOCUJET periodically anchors their cryptographic hash (SHA-256) on the public Bitcoin blockchain, using the OpenTimestamps protocol. Only the hash is recorded on the blockchain: a string of 64 hexadecimal characters. The content of the document, the identities of the signer and any personal data are never published. The hash is irreversible: it cannot be used to trace back to the original content.
7. Recipients and external processors
Data may be disclosed to third parties acting as processors (Art. 28 GDPR), appointed in writing, solely for the purposes set out above. Current list:
| Provider | Role | Country |
|---|---|---|
| Namirial S.p.A. | Qualified electronic seal and qualified time stamp (eIDAS) | Italy |
| Hosting Solutions S.r.l. (Archivia.online) | Reseller of Namirial services | Italy |
| Stripe Payments Europe Ltd. | Payment processing | Ireland |
| Amazon Web Services EMEA SARL | Signer identity verification (Rekognition + Textract) | Luxembourg / AWS regions in the EU |
| Hetzner | Application and database hosting | EU |
| Cloudflare | Sending transactional emails (signature notifications, confirmations) | EU |
| Bulk Gate | Sending OTPs by SMS | EU |
This list may be updated. Material changes are communicated by email or by a notice on the website. We do not sell personal data to third parties.
For measuring advertising campaigns (section 4), the data indicated are disclosed to Meta Platforms Ireland Ltd., which processes them in accordance with its own Business Tools Terms and may transfer them to the United States on the basis of the EU-US Data Privacy Framework.
8. Transfers of data outside the EU
By default, data are processed and hosted within the European Economic Area. For some ancillary features (e.g. AWS regions), a one-off transfer to third countries may occur: in that case the transfer is covered by standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) or, where applicable, by an adequacy decision. A copy of the clauses is available on request from [email protected].
9. Retention periods
We keep each category of data for as long as strictly necessary for the purposes for which it was collected. When a document is signed, the data relating to the audit trail and to the document itself remain stored even after any closure of the registered user's account, for the period required by the legislation on the evidential value of the document.
| Category of data | Duration | Basis |
|---|---|---|
| Signed document + audit trail + blockchain hash | 10 years from signature (or longer, if required by the legislation applicable to the content of the document) | Legal obligation + evidential value of the electronic signature |
| Registered user account data (name, email, company) | For the entire life of the account; deletion within 30 days of closure, except for data linked to signed documents, which remain subject to the retention period of those documents | Performance of the contract |
| Billing data | 10 years from the date of issue | Legal obligation (Art. 2220 of the Italian Civil Code, tax legislation) |
| Technical access and security logs | 12 months | Legitimate interest (IT security) |
| Identity verification (KYC) data: document + selfie + match score | 5 years from verification, unless early deletion is requested where the data are not linked to active signed documents | Performance of the contract + anti-money laundering obligations where applicable |
| Conversations with the AI assistant (messages and generated drafts) | 90 days from the last message in the conversation | Performance of the contract |
| Cookies and site preferences | Up to 12 months (details in the Cookie Policy) | Consent or legitimate interest, depending on the purpose |
Blockchain anchoring: the cryptographic hash of the document (SHA-256) anchored on the Bitcoin blockchain is, by the nature of the technology, permanent. It contains no personal data and is not reversible (see section 6).
10. Security
We adopt technical and organisational measures appropriate to the sensitivity of the data processed, including:
- encryption of data in transit (TLS 1.2+) and at rest (AES-256);
- access control based on least privilege and multi-factor authentication (2FA available);
- audit log with a SHA-256 hash chain (tamper-evident audit trail);
- rate limiting on the APIs and automatic blocking after repeated incorrect OTP attempts;
- encrypted operational backups stored separately.
11. Rights of the data subject
You may at any time exercise the rights granted by Articles 15-22 GDPR. In particular, you have the right to:
- obtain confirmation as to whether processing is taking place and access your data (Art. 15);
- request their rectification (Art. 16);
- request their erasure, within the limits of the law (Art. 17);
- request restriction of processing (Art. 18);
- receive your data in a structured format and transmit them to another controller (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- not be subject to automated decisions, by requesting human intervention (Art. 22);
- withdraw at any time the consents you have given (e.g. KYC, marketing), without affecting the lawfulness of processing carried out before the withdrawal.
Requests should be sent to [email protected]. We will reply within 30 days, unless the period is extended for justified reasons.
Limits on erasure: requests for erasure concerning data linked to a document that has already been signed (e.g. audit trail, signer data contained in the document) are subject to the mandatory retention requirements of section 9. In that case we may restrict the processing to the sole evidential purposes provided for by law.
12. Complaint to the supervisory authority
If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia, 11, 00187 Roma, website: https://www.garanteprivacy.it), without prejudice to any other administrative or judicial remedy.
13. Cookies
For details on cookies and similar technologies, please see the Cookie Policy.
14. Changes to this notice
We may update this notice to reflect regulatory, technical or organisational changes. Material changes are communicated by email or by a notice on the website. The date at the top indicates the latest revision.
15. Contact
For any questions about the processing of your personal data or to exercise your rights, write to us at [email protected]. For support requests not related to privacy: [email protected].
