Legal
Privacy policy
Last updated 2026-01-01. This document is a working template provided with the platform; have qualified counsel review and adapt it to your jurisdiction and business before relying on it.
Global Consortium for Technology & Economic Innovations (“we”) operates Accordify at accordify.io.
What we collect
- Account data: name, email, organization, verification status. Identity documents and selfies for KYC are handled by our identity provider; we keep only the outcome.
- Envelope data: documents you upload, recipients, field values, signatures.
- Evidence data: IP address, user agent, timestamps and authentication method for each signing action. This is collected because it is required to prove who signed and when.
- Billing data: handled by Stripe; we store the customer ID and plan.
Why we process it (GDPR Art. 6)
- Performance of the contract with the sender and signers (delivering and sealing envelopes).
- Legitimate interests (fraud prevention, security logging, product reliability).
- Legal obligation (record retention, KYC/KYB).
- Consent where we ask for it.
Your rights
- Access & portability: Settings → Notifications & privacy → “Download my data”.
- Erasure: Settings → “Delete my account”. We erase personal data and drafts. Signed and in-flight envelopes and their audit trails are retained under legal hold for the statutory period (GDPR Art. 17(3)(b),(e)); access to them is removed from your account.
- Objection, restriction, correction, complaint: contact privacy@accordify.io or your supervisory authority.
Processors and transfers
Cloudflare (storage, queues, email), Supabase (database), Clerk (authentication), Stripe (billing and identity), Upstash/Redis (caching), Sectigo (timestamping). International transfers rely on Standard Contractual Clauses where applicable; see our data processing agreement.
Retention
Completed documents: the retention period set by the organization (default 7 years), stored write-once. Audit logs: same. Drafts: until deleted. Account data: until erasure, subject to legal hold.
Security
Encryption in transit and at rest, tenant isolation with row-level security, hashed API keys, tamper-evident audit logs, and cryptographic sealing of completed documents.