Baltic AI SIA(“we”, “us”, “our”) operates SignSecure at https://sign.baltic-ai.xyz (“SignSecure”, “the Service”). This Privacy Policy explains what personal data we process, why, with whom we share it, how long we keep it, and what rights you have.
1. Data controller
Baltic AI SIA
Republic of Latvia
For general support, open a ticket at /support. For data-protection requests, contact kyc@baltic-ai.xyz.
Website: https://baltic-ai.xyz
2. Scope
This policy applies when you use SignSecure as a guest signer, registered user, or administrator. It covers our website, APIs, and native app wrappers that load the Service. It does not govern third-party sites you reach through links (including Didit's verification flow or Stripe Checkout).
3. Data we collect
- Account data — email address, password hash, display name, company, locale, notification preferences, plan tier, and subscription status.
- Identity verification data — when you complete KYC, our processor Didit Identity Inc. collects government ID images, biometric liveness data, and document metadata. Didit returns a verification decision (approved, declined, in review) and structured identity fields (e.g. name, document type, date of birth, nationality). We store the decision, session status, and decision payload returned to us. Raw ID images are primarily held by Didit under its own privacy policy.
- Documents and signatures — PDFs you upload, signature images you draw, placement coordinates, SHA-256 hashes, verification codes, signer name, signer email, co-signing confirmations, and timestamps of signing events.
- Security and audit data — IP address, user agent, login timestamps, identity recheck results, blocked-IP flags, admin audit logs, and verification events when someone checks a document at /verify.
- Communications — KYC appeal messages, support correspondence, and email verification codes (hashed; not stored in plain text).
- Billing data — processed by Stripe. We receive customer ID, subscription status, and plan metadata — not full card numbers.
- Technical data — cookies or similar technologies strictly necessary for authentication sessions and security (see Section 9).
4. Why we process data (legal bases)
Under the GDPR we rely on:
- Contract — to provide document upload, identity verification, electronic signing, verification-code lookup, and account features you request.
- Legal obligation — to maintain audit trails, respond to lawful requests, and meet anti-fraud or financial-regulation duties where applicable.
- Legitimate interests — to secure accounts (including login recheck from new IPs), prevent abuse, enforce our Terms, and improve reliability — balanced against your rights.
- Consent — for optional marketing emails and for biometric/ID processing where required by local law before you enter the Didit flow. You may withdraw consent for marketing at any time.
5. Who we share data with
We do not sell your personal data. We share it only with processors that help us run the Service:
- Didit — identity verification and liveness checks.
- Stripe — subscription billing.
- Hosting and database providers — secure storage of documents and application data (EU-based infrastructure where possible).
- Email delivery providers — transactional messages (e.g. verification codes) when configured.
Each processor is bound by a data-processing agreement or equivalent contractual safeguards. If data is transferred outside the EEA, we use appropriate safeguards (e.g. Standard Contractual Clauses) where required.
6. Retention
- Signed documents and audit trail — retained while your account is active and for a reasonable period afterward so verification codes remain meaningful, unless you request earlier deletion and we are not legally required to keep them.
- KYC decisions — retained for fraud prevention and to evidence who signed, typically aligned with document retention.
- Account data — deleted or anonymised within 30 days of a confirmed deletion request, except records we must keep for legal, tax, or dispute-resolution purposes.
- Security logs — typically up to 12 months unless needed for an investigation.
7. Your rights
If you are in the EEA/UK, you may request access, rectification, erasure, restriction, portability, or object to processing. You may withdraw consent where processing is consent-based. You may lodge a complaint with the Latvian Data State Inspectorate (DVI) or your local supervisory authority.
To exercise rights, open a support ticket at /support or contact kyc@baltic-ai.xyz for formal data-protection requests.
8. Security
We use encryption in transit (HTTPS), hashed passwords, capability tokens for guest document access, rate limiting, and access controls for admin functions. No system is perfectly secure; report suspected breaches via /support.
9. Cookies
We use essential session cookies to keep you logged in and to protect against cross-site attacks. We do not use advertising or third-party tracking cookies on the core Service.
10. Children
SignSecure is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a minor has used the Service, contact us and we will delete the data where appropriate.
11. Changes
We may update this policy. Material changes will be reflected in the “Last updated” date. Continued use after changes constitutes acceptance where permitted by law. For significant changes we may ask you to re-accept via the Service.