Legal

Privacy notice

Last updated: 28 September 2026

This is a courtesy translation: in the event of any conflict, the Italian text prevails. Read the Italian version

This notice is provided, pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter "GDPR"), to anyone who interacts with the website https://docujet.it or with the DOCUJET service (hereinafter also the "Service"). It explains which personal data we process, why, with what tools and for how long. If you have any questions, you can write to [email protected].

1. Data controller

The data controller is Grem S.r.l., with registered office at Via Matteo La Fragola, 4, Salerno (SA), VAT no. / tax code IT06136730659 (hereinafter "DOCUJET" or "we"). Dedicated email address for privacy requests: [email protected].

Grem S.r.l. is not required to appoint a Data Protection Officer (Art. 37 GDPR); data subjects' requests are handled at the privacy address given above.

2. Who this notice is for

This notice applies to two categories of data subjects, whose data are collected through different flows:

2.1. Registered user (holder of a DOCUJET account)

Anyone who opens a DOCUJET account to send documents for signature. The data are collected directly from the data subject at the time of registration, pursuant to Art. 13 GDPR.

2.2. Invited signer

Anyone who is invited to sign a document through a DOCUJET link, without being registered. Their contact details (name, email, telephone number) are collected indirectly: they come from the registered user who started the signing flow (the "sender"). This notice is provided pursuant to Art. 14 GDPR when the signing link is first accessed. The sender is an independent controller of the signer's data collected for its own purposes (e.g. manual entry into a CRM); DOCUJET acts as a processor solely for the management of the signing flow on behalf of the sender.

3. Categories of personal data processed

  • Account data (registered user): first name, surname, company name, email, password (stored in encrypted form by hashing), telephone number.
  • Signer data: first name, surname, email, mobile number (for sending OTPs).
  • Signature data: uploaded document, fields completed by the signer, values of the graphical signature (where applicable), date and time of acceptance of consents, date and time of signature, IP address, device user agent.
  • Identity verification (KYC) data, only when the sender has enabled the feature: image of the identity document (identity card or passport), selfie of the signer, data extracted from the document (first name, surname, date of birth, expiry date), biometric comparison score between the selfie and the photo on the document. These are special categories of personal data within the meaning of Art. 9 GDPR (biometric data for the purpose of uniquely identifying a person). The processing takes place exclusively on the basis of the explicit consent of the data subject, given at the start of the KYC flow, in accordance with Art. 9(2)(a) GDPR.
  • Billing and payment data (registered user): company name, address, VAT no. / tax code, payment transaction ID. Full credit card details are handled by our payment provider (Stripe); DOCUJET neither receives nor stores them.
  • Technical logs and usage data: access logs, IP address, browser and device type, pages visited, session identifiers, anonymous telemetry data.
  • Cookies and similar technologies: see the Cookie Policy.

4. Purposes and legal bases

PurposeCategories of dataLegal basis
Provision of the Service (creating, sending and signing documents)Account, signature, technical logsArt. 6(1)(b): performance of the contract
Verification of the signer's identity (KYC) when enabled by the senderIdentity document, selfie, biometric scoreArt. 6(1)(b) + Art. 9(2)(a): explicit consent of the signer
Retention of the signed document and of the audit trailDocument, audit trail, IP, user agentArt. 6(1)(c): legal obligation (eIDAS, CAD, sector-specific regulations)
Billing and tax complianceBilling dataArt. 6(1)(c): legal obligation
Security, fraud prevention, misuse of the ServiceTechnical logs, IP, OTP attemptsArt. 6(1)(f): legitimate interest of the Controller
Responding to support requestsEmail, content of the messageArt. 6(1)(b) or 6(1)(f), depending on the request
Measuring advertising campaigns on Facebook and Instagram: when you create an account, ask us to contact you or activate and pay for a subscription, we tell Meta that this has happened (Conversions API)Email and mobile number in hashed form (SHA-256), never in clear text; account identifier in hashed form; IP address; browser type; ad click identifiers, if any; for payments, plan, amount and currency Art. 6(1)(f): legitimate interest of the Controller in measuring the effectiveness of its campaigns. You may object at any time (Art. 21) by writing to [email protected]
Marketing communications (newsletter, product news)EmailArt. 6(1)(a): consent, which may be withdrawn at any time

5. Automated decision-making

Some stages of the Service involve automated decisions within the meaning of Art. 22 GDPR:

  • Temporary block after incorrect OTPs: after several incorrect OTP attempts in a row, the system automatically suspends the signing session to prevent brute-force attacks. The logic is described in the Security section.
  • Automatic outcome of the KYC check: when the feature is enabled, the comparison between the selfie and the photo on the document produces a similarity score. A minimum threshold automatically determines whether the check has "passed" or "failed". The outcome does not in itself affect the legal validity of the advanced electronic signature (AES), but the sender of the document may decide whether to accept the signature anyway or to request a manual check.

In both cases the data subject may request human intervention, express their point of view and contest the decision by writing to [email protected].

6. Blockchain anchoring

To ensure the integrity of signed documents over time, DOCUJET periodically anchors their cryptographic hash (SHA-256) on the public Bitcoin blockchain, using the OpenTimestamps protocol. Only the hash is recorded on the blockchain: a string of 64 hexadecimal characters. The content of the document, the identities of the signer and any personal data are never published. The hash is irreversible: it cannot be used to trace back to the original content.

7. Recipients and external processors

Data may be disclosed to third parties acting as processors (Art. 28 GDPR), appointed in writing, solely for the purposes set out above. Current list:

ProviderRoleCountry
Namirial S.p.A.Qualified electronic seal and qualified time stamp (eIDAS)Italy
Hosting Solutions S.r.l. (Archivia.online)Reseller of Namirial servicesItaly
Stripe Payments Europe Ltd.Payment processingIreland
Amazon Web Services EMEA SARLSigner identity verification (Rekognition + Textract)Luxembourg / AWS regions in the EU
HetznerApplication and database hostingEU
CloudflareSending transactional emails (signature notifications, confirmations)EU
Bulk GateSending OTPs by SMSEU

This list may be updated. Material changes are communicated by email or by a notice on the website. We do not sell personal data to third parties.

For measuring advertising campaigns (section 4), the data indicated are disclosed to Meta Platforms Ireland Ltd., which processes them in accordance with its own Business Tools Terms and may transfer them to the United States on the basis of the EU-US Data Privacy Framework.

8. Transfers of data outside the EU

By default, data are processed and hosted within the European Economic Area. For some ancillary features (e.g. AWS regions), a one-off transfer to third countries may occur: in that case the transfer is covered by standard contractual clauses adopted by the European Commission (Commission Implementing Decision (EU) 2021/914) or, where applicable, by an adequacy decision. A copy of the clauses is available on request from [email protected].

9. Retention periods

We keep each category of data for as long as strictly necessary for the purposes for which it was collected. When a document is signed, the data relating to the audit trail and to the document itself remain stored even after any closure of the registered user's account, for the period required by the legislation on the evidential value of the document.

Category of dataDurationBasis
Signed document + audit trail + blockchain hash10 years from signature (or longer, if required by the legislation applicable to the content of the document)Legal obligation + evidential value of the electronic signature
Registered user account data (name, email, company)For the entire life of the account; deletion within 30 days of closure, except for data linked to signed documents, which remain subject to the retention period of those documentsPerformance of the contract
Billing data10 years from the date of issueLegal obligation (Art. 2220 of the Italian Civil Code, tax legislation)
Technical access and security logs12 monthsLegitimate interest (IT security)
Identity verification (KYC) data: document + selfie + match score5 years from verification, unless early deletion is requested where the data are not linked to active signed documentsPerformance of the contract + anti-money laundering obligations where applicable
Conversations with the AI assistant (messages and generated drafts)90 days from the last message in the conversationPerformance of the contract
Cookies and site preferencesUp to 12 months (details in the Cookie Policy)Consent or legitimate interest, depending on the purpose

Blockchain anchoring: the cryptographic hash of the document (SHA-256) anchored on the Bitcoin blockchain is, by the nature of the technology, permanent. It contains no personal data and is not reversible (see section 6).

10. Security

We adopt technical and organisational measures appropriate to the sensitivity of the data processed, including:

  • encryption of data in transit (TLS 1.2+) and at rest (AES-256);
  • access control based on least privilege and multi-factor authentication (2FA available);
  • audit log with a SHA-256 hash chain (tamper-evident audit trail);
  • rate limiting on the APIs and automatic blocking after repeated incorrect OTP attempts;
  • encrypted operational backups stored separately.

11. Rights of the data subject

You may at any time exercise the rights granted by Articles 15-22 GDPR. In particular, you have the right to:

  • obtain confirmation as to whether processing is taking place and access your data (Art. 15);
  • request their rectification (Art. 16);
  • request their erasure, within the limits of the law (Art. 17);
  • request restriction of processing (Art. 18);
  • receive your data in a structured format and transmit them to another controller (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • not be subject to automated decisions, by requesting human intervention (Art. 22);
  • withdraw at any time the consents you have given (e.g. KYC, marketing), without affecting the lawfulness of processing carried out before the withdrawal.

Requests should be sent to [email protected]. We will reply within 30 days, unless the period is extended for justified reasons.

Limits on erasure: requests for erasure concerning data linked to a document that has already been signed (e.g. audit trail, signer data contained in the document) are subject to the mandatory retention requirements of section 9. In that case we may restrict the processing to the sole evidential purposes provided for by law.

12. Complaint to the supervisory authority

If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Italian data protection authority, the Garante per la protezione dei dati personali (Piazza Venezia, 11, 00187 Roma, website: https://www.garanteprivacy.it), without prejudice to any other administrative or judicial remedy.

13. Cookies

For details on cookies and similar technologies, please see the Cookie Policy.

14. Changes to this notice

We may update this notice to reflect regulatory, technical or organisational changes. Material changes are communicated by email or by a notice on the website. The date at the top indicates the latest revision.

15. Contact

For any questions about the processing of your personal data or to exercise your rights, write to us at [email protected]. For support requests not related to privacy: [email protected].