Privacy Policy
This Privacy Policy is provided in English. If you do not understand English, please contact us at contact@prosignature.io before using the Service. In case of any discrepancy, the English version shall prevail.
Protecting the privacy of our Users is especially important to us. Therefore, Users of the ProSignature application are guaranteed high standards of privacy protection.
The data controller is:
Damian Kamiński
ul. Akacjowa 5 78-630 Człopa
VAT ID (NIP): 765-170-11-21
📧 contact@prosignature.io
1. Legal basis for data processing
Personal data of Users is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”).
We process data based on:
- Art. 6(1)(b) GDPR – necessity to perform a contract (provision of the Service),
- Art. 6(1)(f) GDPR – legitimate interests of the controller (e.g., customer support, preventing abuse, service development),
- Art. 6(1)(c) GDPR – legal obligations (e.g., tax and accounting obligations).
2. Scope of collected data
We may process the following User data:
- name and surname,
- email address,
- login credentials (username, password – passwords are always encrypted),
- payment details processed by a third-party provider (Stripe) – we do not store card numbers,
- technical data: IP address, server logs, browser type, device information.
3. Purposes of data processing
Personal data is processed for the following purposes:
- registration and management of a User account,
- enabling the use of the email signature generator,
- processing payments and subscriptions,
- ensuring system security and preventing abuse,
- communication with the User (e.g., support, handling inquiries),
- fulfilling legal obligations (accounting, tax).
4. Data recipients
Personal data may be shared with:
- Hosting and database providers (e.g., Vercel, Supabase),
- GDPR-compliant analytics providers (e.g., Simple Analytics, Google Analytics 4),
- SEO and marketing analysis tools (e.g., Ahrefs),
- Advertising and conversion tracking providers (e.g., Google Ads, via Consent Mode v2).
- Error monitoring and performance analytics provider (Sentry.io) — to detect application errors, measure performance, and improve service stability. Processed data may include error details, stack traces, browser and device information, IP address, performance/session data, and — for logged-in users — user ID and email address. Data is processed in the European Union (Germany). We do not use Session Replay.
- AI service provider (OpenAI) — to power the AI Quick Start feature. We may send a website URL and publicly available content extracted from that website for analysis. We do not send your account password or payment data to OpenAI.
- Email delivery provider (Mailgun) — to deliver messages sent via the contact form (email address and message content).
- Spam protection provider (Google reCAPTCHA) — to protect the contact form from abuse. Subject to Google's Privacy Policy.
Data is processed only for the purposes described in this Privacy Policy and is never sold or transferred to unauthorized parties.
5. Cookies
The Service uses cookies necessary for its proper functioning (e.g., login, session maintenance).
With the user’s consent, we may also use optional cookies for analytics and marketing purposes, including:
- Google Analytics 4 – to measure traffic and user interactions in a privacy-compliant manner (with IP anonymization and Consent Mode v2),
- Google Ads Conversion Tracking – to measure campaign performance.
Users can manage their cookie preferences via the cookie consent banner (powered by CookieYes) and may withdraw consent at any time.
Alternatively, cookies can be managed in the browser settings; however, disabling necessary cookies may prevent the Service from functioning properly.
6. Data retention
- Account data is stored for the duration of the Service, and after termination – for the period necessary to handle potential claims (up to 6 years).
- Data required by law (e.g., tax/accounting records) is stored as required (5 years).
- Technical logs are stored for up to 12 months.
- Error and performance data collected by Sentry is retained for up to 90 days, unless a longer period is required for security or legal purposes.
7. User rights
Under GDPR, Users have the right to:
- access their data,
- correct or delete data,
- restrict processing,
- data portability,
- object to processing,
- withdraw consent (if processing is based on consent),
- file a complaint with a Data Protection Authority.
8. Data security
We apply appropriate technical and organizational measures to protect data against unauthorized access, loss, or destruction. Data is stored in secured systems using encryption and access controls.
9. Changes to the Policy
This Privacy Policy may be updated. The current version is always available on our website. Changes take effect on the date they are published.
10. Contact
For questions regarding data protection, please contact us:
📧 contact@prosignature.io