Privacy Policy
What data is collected, why, who sees it, how long it is kept, and what you can demand.
Last updated: August 24, 2026 · Version 1.2
The documents that pass through this service are contracts, forms and personal papers. This policy is written accordingly — it names names, not categories.
1. Who is responsible for the data
The database controller is Kamal Agbaria, a licensed sole proprietor (עוסק מורשה), no. 034650887, of Almadina 62, Umm Al Fahem, Israel, who operates BasmaSign (Basma) at basmasign.com.
For privacy matters — access, correction and deletion: info@basmasign.com.
This policy covers the website, the customer area, and the signing page signers arrive at. The Terms of Service are a separate, complementary agreement.
2. Two kinds of people, two roles
There are two populations in this service, and our legal position differs for each:
- Account users
- The business owner and the team members who registered and use the service. For them we are the controller: they gave us their details in order to buy and use the service.
- Signers
- Our customers’ customers — the people who receive a document to sign. For them the controller is the business that sent the document; we are a holder and processor acting on its instructions. It chose the recipient, typed the number, decided which fields to require, and decided whether to ask for an ID number.
What that means in practice: if you received a document to sign and you are asking why it wants your ID number, or asking for your data to be deleted, the answer sits with the business that sent it. We pass every such request to them and help, and we handle ourselves anything that is within our control.
3. What data is collected
From account users:
- name, email address, phone number, language and role in the account;
- business name and details, and billing details;
- payment records and invoices. Card details are held by our payment provider — we store only a token, never a card number;
- sign-in events, and IP address and browser type for security and record-keeping;
- support correspondence.
From signers — on the instructions of the business that sent the document:
- name, and the phone number or email address as entered by the sender, and the language of the request;
- the document itself and every value you filled into it — including ID number, address, dates and free text, to the extent the sender asked for them;
- the signature image you drew, typed or uploaded;
- evidence data: when the link was opened, IP address, browser and device identifier, whether a verification code was requested and verified and on which channel, consent to sign electronically, timestamps, delivery and read status from WhatsApp, and a hash chain linking the events to one another.
And from the system itself: server logs, error events (scrubbed of identifying details) and technical request data.
Providing the data is not a legal obligation — but without it the service cannot be provided: with no address there is nowhere to send, and with no evidence data there is nothing to show the signature happened. A signer unwilling to provide it can sign outside the service, with the sender directly.
4. What the data is used for
- to provide the service: store and render documents, deliver them to recipients, collect signatures and seal;
- to produce the evidence pack — a purpose in its own right, and what turns a signed document into evidence;
- to verify identity with a one-time code, where the sender asked for it;
- to bill, invoice and collect;
- to support, fix faults, prevent abuse and protect the security of the service;
- to meet legal obligations — tax, bookkeeping, and requests from a competent authority.
And, expressly, what we do not do with it:
- we do not sell data and we do not trade in it;
- we do not market to our customers’ signers;
- we do not train AI models on your documents. A plugin that sends content to a third party (such as automatic field detection) is off by default and requires explicit activation;
- we do not record the screen (session replay) on the signing page. Such a recording would capture a person drawing their signature on a document they may be bound by — and scrubbing identifying details does not extend to pixels.
6. Who else touches the data
The providers below process data for us, on our instructions and under contract. This is the complete list; it is updated before a new provider starts processing, and customers are notified.
| Provider | What it does for us | Where |
|---|---|---|
| Google Cloud | Stores documents and sealed files, and runs document processing | Israel (Tel Aviv); the job queue in Germany |
| MongoDB Atlas | The database — accounts, documents and evidence logs | Belgium (European Union) |
| Vercel | Serves the website and the app | Global edge network |
| Firebase (Google) | Identity and sign-in for account users | Managed cloud |
| Meta Platforms | Delivers documents and verification codes over WhatsApp | Meta |
| Brevo | Transactional email — links, reminders and billing notices | European Union |
| Allpay | Card payments and storage of the card token | Israel |
| Sentry | Error monitoring, after identifying details are scrubbed | Managed cloud |
Beyond these, we disclose data only where the law requires it — a court order or a demand from a competent authority — or to defend a legal right. If we sell or transfer the business, data passes to the successor subject to this policy, and notice is given.
7. Transfers out of Israel
Documents and sealed files are stored in Israel (Google Cloud’s Tel Aviv region). Some of the providers listed above operate outside Israel.
Every such transfer is made under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, and on the basis of the recipient’s contractual undertaking — use limited to the purpose of the transfer, rights of access, correction and deletion, confidentiality, and information security at the level Israel requires.
For data subjects in the European Union: Israel is recognised by the European Commission as providing an adequate level of protection, a status reaffirmed in the Commission’s review published in January 2024.
8. How long data is kept
- account and business details — while the account exists, plus 30 days after termination so you can export;
- documents and their content — until you delete them, or until the account is deleted;
- sealed documents — in a versioned bucket with a 365-day retention policy; a copy cannot be removed before that period ends;
- evidence logs — for the life of the document, because they are its evidence, and they cannot be edited;
- a photograph of an identity document, where the sender asked a signer for one — 90 days from capture, then deleted automatically. Its fingerprint, the document type and the time of capture stay in the evidence log and on the signature certificate, so that the presentation can still be proved after the photograph is gone;
- billing records and invoices — seven years, as Israeli bookkeeping rules require;
- WhatsApp delivery data — with the document’s evidence;
- server logs and error events — up to 90 days;
- support correspondence — up to 24 months.
The full account of what is deleted, what remains and why is on the Data & Account Deletion page.
9. Your rights, and how to exercise them
- to see the data held about you (section 13 of the Privacy Protection Law);
- to ask for correction of data that is incorrect, incomplete, unclear or out of date (section 14);
- to ask for deletion, to the extent the law provides and subject to what we are required to keep;
- to ask to be removed from a direct-marketing list;
- to receive a copy of the data in a readable format.
How: a message to info@basmasign.com from the account’s email address, or with details that let us identify you. We acknowledge within 5 business days and answer the substance within 30 days.
If our answer does not satisfy you, you may approach the Privacy Protection Authority at the Ministry of Justice. Your right to go to court remains in any event.
10. If you received a document to sign
The business that sent the document is the controller of your data: it chose to contact you, decided which fields to require, and decides what to do with the signed document. Requests about the data inside the document go to them.
You can also write to us at info@basmasign.com. We will pass the request to the sending business, confirm to you that we did, and handle ourselves anything within our control — for example stopping messages to you.
If the sender asked for it, you may be asked to photograph an identity document before the document opens. That is their request, not ours, and you may refuse — talk to them if you want to. If you did photograph one: the image is kept for 90 days and then deleted automatically, we do not read it and derive no ID number or biometric template from it, and the record that a document was presented remains after the image is gone.
A code is printed on the last page of the signed document. Whoever holds that page — a party who received a printed copy, for instance — can use it to open a page showing the document’s name, the signers’ names, their roles and when they signed, and re-checking the evidence log. The code is the only way to reach that page, and the document’s reference number opens nothing. Contact details, IP addresses and devices are not shown there.
Note: a document that has been signed and sealed cannot be altered, and the evidence log cannot be edited. That is a property of evidence, not a technical limitation.
11. Security
- encryption in transit, and encryption at rest with our cloud providers;
- separation between customers enforced on every query — not as a convention, but as part of the access mechanism;
- role-based permissions, and staff access to a customer’s data written to an audit log;
- unguessable signing links; only hashes are stored, so a link that was sent cannot be recovered from inside the system;
- error monitoring with identifying details scrubbed, and no screen recording;
- an append-only evidence log, and sealed documents in a versioned bucket with a retention policy.
We apply measures appropriate to the risk and consistent with Israel’s Privacy Protection (Data Security) Regulations, 5777-2017. No system is impregnable, and we do not promise absolute security.
12. Security incidents
A serious security incident is reported to the Privacy Protection Authority as the Regulations require. A customer whose data is affected is notified without delay, so they can meet their own obligations to their signers, and we notify individuals directly as well where the law or the circumstances require it.
13. Minors
The service is not intended for minors and we do not knowingly collect their data. A business that sends a document to a minor is responsible for the lawful basis for doing so. If you learn that a minor’s data has reached us without a proper basis, write to us and it will be deleted.
14. Marketing messages
Documents sent for signature, verification codes and billing notices are operational messages, not advertising. Marketing from us is sent only with consent, as section 30A of the Communications (Telecommunications and Broadcasting) Law, 5742-1982 requires, and every such message carries a simple way to unsubscribe.
We will not use a customer’s signer list to market anything to them.
15. Changes to this policy
We update this policy when the service changes or the law changes. For a material change, customers are given advance notice. The update date and version are at the top of this page.
16. Contact
Kamal Agbaria — licensed sole proprietor (עוסק מורשה), no. 034650887. Almadina 62, Umm Al Fahem, Israel. Email: info@basmasign.com.
Write in Hebrew, Arabic or English — we answer in the same language.