Privacy Policy
Version 1.0 · Last updated 3 July 2026
1. Overview
This Policy explains how MauriSign collects, uses, shares and protects personal data when you use the Service. We process personal data in accordance with the Data Protection Act 2017 of Mauritius. For the data you upload to be signed, you are the controller and MauriSign acts as your processor; for your account data, MauriSign is the controller.
2. Data we collect
- Account data — your name, email, password (stored only as a secure hash) and workspace details.
- Document data — the files, signatures and signer details you upload or generate through the Service.
- Evidence data — audit-trail events, timestamps and the cryptographic seals used to verify document integrity.
- Usage data — technical logs needed to operate, secure and improve the Service.
3. How we use your data
We use personal data to:
- provide the signing, sending and verification features;
- generate and preserve tamper-evident evidence of signatures;
- authenticate you and keep your account secure;
- process plan changes and billing; and
- send service messages, and — only with your consent — marketing updates.
4. Legal bases
We rely on the performance of our contract with you (to provide the Service), our legitimate interests (to secure and improve the Service), your consent (for optional marketing), and compliance with legal obligations (including retention of signed records).
5. Sharing
We do not sell your personal data. We share it with signers and recipients you designate, and with service providers who host and operate the platform on our behalf under appropriate confidentiality and data-protection terms. We may disclose data where required by law.
6. Retention
Signed documents and their audit trails are retained for the period needed to preserve their legal value — up to ten (10) years — so that integrity can be verified long after signing. Account data is kept while your account is active and for a limited period afterwards, subject to legal retention requirements.
7. Security
We apply technical and organisational measures to protect personal data, including encryption in transit, hashed credentials, tenant isolation and cryptographic sealing of completed documents. No system is perfectly secure, but we work to protect your data against unauthorised access, loss or alteration.
8. Your rights
Subject to the Data Protection Act 2017, you may request access to, correction of, or erasure of your personal data, and may object to or restrict certain processing. You can export your account data and request deletion from your privacy settings. Some data must be retained where it forms part of a signed legal record.
9. International transfers
Where personal data is processed outside Mauritius, we take steps to ensure it receives a comparable level of protection as required by applicable law.
10. Changes and contact
We may update this Policy and will revise the version and date above when we do. For privacy questions or to exercise your rights, contact privacy@maurisign.mu.
