Skip to content
inSigner

Workflow

overview Product overview From PDF preparation to final proof arrow_forward route Prepare & route Fields, recipients, roles, and signing order arrow_forward timeline Track every step Opens, signatures, reminders, and completion arrow_forward

Scale

content_copy Templates & campaigns Reuse repeatable signing workflows arrow_forward groups Teams & RBAC Organizations, permissions, folders, and tags arrow_forward workspaces Use cases HR, legal, sales, real estate, and vendors arrow_forward

Extend

api Developer platform REST API v1, keys, scopes, and webhooks arrow_forward hub Integrations Connect signing to the systems around it arrow_forward qr_code_2 Public verification Check the completed agreement record arrow_forward

Essentials

verified_user Trust Center Security, privacy, providers, and review material arrow_forward shield Evidence & controls Review signing evidence and security controls arrow_forward workspace_premium PAdES lifecycle B-B, B-T, and the path to B-LTA arrow_forward verified Public verification Validate the sealed record without an account arrow_forward

Regional context

🇺🇸 United States ESIGN Act · UETA arrow_forward 🇪🇺 European Union eIDAS · eIDAS 2.0 arrow_forward 🇬🇧 United Kingdom UK eIDAS context arrow_forward

Regional context

🇧🇷 Brazil MP 2.200-2 · ICP-Brasil context arrow_forward 🇲🇽 Mexico Commercial Code · NOM-151 context arrow_forward 🇨🇴 Colombia Law 527 context arrow_forward

Country guidance is educational, not legal advice.

Developers Pricing

Learn

edit_document Product See the complete signing workflow arrow_forward security Security Evidence, controls, and regional context arrow_forward sell Pricing Unlimited, Developer, and Enterprise arrow_forward

Build & operate

terminal Developers API building blocks and webhook events arrow_forward menu_book API documentation Guides, endpoints, and examples arrow_forward monitor_heart Service status Live platform availability arrow_forward

Company & access

info About inSigner Why evidence belongs in the product arrow_forward contact_support Contact sales Contracts, SLA, deployment, and review arrow_forward verified_user Verify a document Open the public verification service arrow_forward
Log in Get started
  • EN English
  • ES Español Soon
  • PT Português Soon
  • FR Français Soon
  • DE Deutsch Soon
  • IT Italiano Soon
Log in Get started
Home / Legal / Privacy Policy

Legal center

Privacy Policy

How Nubesti LLC handles personal data across the inSigner website, accounts, electronic signature workflows, identity checks, billing, APIs, and support.

calendar_today Last updated August 18, 2026 business Nubesti LLC

Company

Nubesti LLC United States hi@insigner.co

On this page

  1. 1. Scope and roles
  2. 2. Data we collect
  3. 3. Documents and evidence
  4. 4. Identity and communications
  5. 5. Purposes and legal bases
  6. 6. How data is shared
  7. 7. Retention
  8. 8. Security
  9. 9. International transfers
  10. 10. Your rights
  11. 11. U.S. privacy notices
  12. 12. Children
  13. 13. Changes and contact
On this page expand_more
  1. 1. Scope and roles
  2. 2. Data we collect
  3. 3. Documents and evidence
  4. 4. Identity and communications
  5. 5. Purposes and legal bases
  6. 6. How data is shared
  7. 7. Retention
  8. 8. Security
  9. 9. International transfers
  10. 10. Your rights
  11. 11. U.S. privacy notices
  12. 12. Children
  13. 13. Changes and contact

All policies

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Billing & Cancellation
  • Electronic Signature Notice
  • Subprocessors
  • Security Overview
  • Data Processing Addendum
  • Legal Notice

This Privacy Policy explains how Nubesti LLC, operator of inSigner, collects, uses, discloses, and protects personal data. It also explains the different roles played by inSigner and the customer that sends a document for signature.

We do not sell personal data. The public marketing site is designed to operate without non-essential advertising or analytics cookies at launch.

1. Scope and roles

This Policy applies to insigner.co, app.insigner.co, our APIs, and related support services.

When Nubesti LLC is the controller

We generally decide why and how account registration, subscription, website, security, service-usage, sales, and support data is processed. For that data, Nubesti LLC acts as a controller, business, or similar responsible party under applicable privacy law.

When the customer is the controller

A customer decides which documents to upload, who should receive them, which fields and authentication methods to require, and how long records should be kept. For Customer Content, recipient data, and signing instructions, the customer generally acts as controller and Nubesti LLC acts as processor or service provider on the customer’s behalf.

If you received a document from an inSigner customer, contact that sender first for questions about the document or to exercise rights relating to the customer’s workflow. We will assist customers as required by contract and law.

2. Data we collect

Category Examples Source
Account and profile Name, email, phone, language, time zone, organization, role, profile settings You, an organization administrator, or Google OAuth when selected
Subscription and transaction Plan, subscription status, PayPal customer or subscription reference, payment status You and PayPal; full payment credentials remain with the payment provider
Documents and workflow PDFs, templates, attachments, field values, recipients, routing, messages, status The customer, account users, signers, approvers, and integrations
Signature and evidence Signature marks, consent events, dates, IP address, user agent, approximate location, hashes, timestamps, audit events Your browser, the signing process, Cloudflare request context, and trust providers
Identity and authentication Email or phone OTP status, access-code checks, KYC session reference, result, and selected verified attributes You, the sender, communications providers, and Didit when KYC is required
API and security API-key metadata, webhook delivery, request logs, rate-limit events, device and access information Applications, integrations, and service infrastructure
Support and communications Messages, email address, troubleshooting details, security reports, and feedback You and people communicating with us

We ask customers not to upload data that is unnecessary for a signing workflow. Some documents may contain sensitive data chosen by the customer; the customer is responsible for determining whether that processing is lawful and appropriate.

3. Documents and signing evidence

inSigner processes documents and recipient information to prepare, route, render, sign, seal, store, and verify agreements. The service may create a durable evidence record containing document hashes, event timestamps, delivery events, authentication results, signature actions, IP and browser information, and certificate or timestamp references.

Evidence records help customers and recipients explain what occurred during a signing process. They may also be used to detect fraud, troubleshoot delivery, verify integrity, resolve disputes, and comply with legal obligations. A public verification page may confirm limited record or integrity information without exposing the underlying document.

Customers control the documents they send. Recipients should direct requests about document content, parties, purpose, or deletion to the sender, unless the request concerns data for which Nubesti LLC independently acts as controller.

4. Identity checks and communications

Optional KYC

A sender may require identity verification through Didit. In that case, Didit may process identity documents, images, biometric or liveness information, and verification signals under its own privacy notice and our service arrangement. inSigner may retain a session reference, result, report, and selected identity attributes needed for the workflow and audit record.

Email, SMS, and WhatsApp

A sender may provide a recipient’s email address or phone number for invitations, reminders, one-time passcodes, status messages, or completed-document notices. These communications may be delivered through ZeptoMail, Kapso and Meta’s WhatsApp platform, or Infobip, depending on the method selected and provider availability.

Communications can include the sender’s name, recipient name, document title, signing link, status, or verification code. Customers should avoid placing sensitive document content in a message or title.

5. Purposes and legal bases

We use personal data to:

  • Provide accounts, document workflows, signatures, APIs, verification, and support.
  • Authenticate users and recipients and protect the service from fraud, abuse, and intrusion.
  • Deliver invitations, one-time codes, reminders, webhooks, and service communications.
  • Manage plans, subscriptions, payment status, taxes, and financial records.
  • Maintain auditability, integrity, availability, backups, and disaster recovery.
  • Diagnose errors, measure service reliability, and improve features and usability.
  • Comply with law, respond to lawful requests, and establish or defend legal claims.

Where the GDPR or UK GDPR applies, legal bases may include performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where required. For Customer Content, we primarily process data under the customer’s documented instructions and the customer determines the applicable legal basis.

6. How data is shared

We disclose personal data only as reasonably necessary:

  • To recipients, senders, organization members, and integrations involved in a workflow.
  • To infrastructure, storage, database, communications, billing, identity, and trust providers.
  • To professional advisers and potential transaction parties under confidentiality obligations.
  • To comply with law or valid legal process, or protect rights, safety, and service integrity.
  • During a merger, financing, reorganization, acquisition, or sale of all or part of the business.

We do not sell personal data or share it for cross-context behavioral advertising. Current provider categories and optional services are listed on our Subprocessors page.

7. Retention

We retain data for as long as needed to provide the service, follow customer instructions, preserve legitimate evidence, maintain security and financial records, resolve disputes, and comply with law. Retention varies by data type, account status, plan, customer configuration, backup lifecycle, and legal requirements.

Our current operational process is designed to purge soft-deleted account and organization data after approximately 30 days, including related objects in document storage, subject to technical completion, backups, legal holds, fraud prevention, financial records, and other lawful exceptions. A customer may retain completed records outside inSigner after deletion.

Payment providers, identity providers, timestamp authorities, and communications providers apply their own retention schedules to data they process independently.

8. Security

We use technical and organizational measures designed to protect personal data, including access controls, transport encryption, credential protection, audit logging, rate limits, document-integrity checks, backups, and encryption mechanisms described in our Security Overview.

No security measure can eliminate all risk. Customers and users must protect their credentials, API keys, devices, downloaded documents, connected systems, and recipient lists. Please report a suspected vulnerability or unauthorized access to hi@insigner.co.

9. International transfers

Nubesti LLC and its providers may process data in the United States and other countries. Provider locations depend on the service selected, deployment, recipient, and communications route. Those countries may have privacy laws different from your country.

Where required for transfers from the EEA, United Kingdom, or Switzerland, we use appropriate safeguards such as Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism. Customers may request relevant contractual information through our sales process.

10. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or object to processing; receive portable data; withdraw consent; opt out of certain disclosures; and complain to a data-protection authority.

For data controlled by an inSigner customer, contact that customer. For account, website, billing, or other data controlled by Nubesti LLC, email hi@insigner.co. We may verify your identity and ask for information needed to locate the relevant data. Authorized agents may submit requests where permitted by law.

We will respond within the timeframe required by applicable law. Some rights are subject to exceptions, including records needed for security, legal claims, transaction compliance, or the rights of other people.

11. U.S. privacy notices

Residents of California and other U.S. states with comprehensive privacy laws may have rights to know, access, correct, delete, or obtain a copy of personal data, and to opt out of sale, targeted advertising, or certain profiling.

Nubesti LLC does not sell personal data and does not use personal data for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right.

Because our current practices do not constitute sale or targeted-advertising sharing, we do not provide a separate “Do Not Sell or Share” link. If those practices change, we will update this Policy and provide required controls.

12. Children

inSigner is not directed to children. Account holders must be at least 18 or the age of legal majority in their jurisdiction. Customers must not use the service to collect a child’s data without the authority, notices, consents, and safeguards required by law.

If you believe a child’s data was submitted improperly, contact us and identify the sender or document workflow if possible.

13. Changes and contact

We may update this Policy to reflect changes in the service, providers, law, or data practices. We will change the “Last updated” date and provide additional notice when a change is material and notice is required.

Privacy questions and requests may be sent to hi@insigner.co. The responsible entity is Nubesti LLC, United States.

arrow_back Back to legal center
inSigner

Sign Smarter. Not Harder.

Compliance-first electronic signatures for Europe and LATAM.

Product OverviewSecurityTrust CenterDevelopersPricingUse cases
Access Log inCreate accountVerify a documentContact sales
Legal Legal centerPrivacyTermsCookiesAcceptable use

© 2026 Nubesti LLC. Securely Architected.

Open source — coming very soon

cookie

Privacy by default

Cookies, kept simple.

This website only stores your dismissal choice. The inSigner app uses essential cookies for secure sessions and preferences. No advertising or analytics cookies.

Read the Cookie Policy