Legal
← Back to homeOS Sign — Privacy Policy
Effective: 20 August 2026
If you have just received a signing link — read this first
If you are here to sign a document, this policy covers you. You do not need an account to sign, but The OS Company still processes your personal data — your name, email address, IP address, and the signature you provide — to complete the signing process and to create a legally reliable record that the document was signed. Section 3 (“If you are a signer”) explains exactly what we do with your data and why. You can also read this policy at any time via the link shown on the signing page.
1. Who we are
The OS Company (“we”, “us”, “our”) is the data controller for personal data processed through OS Sign, a document-signing service operated at sign.theoscompany.com (primary company domain: theoscompany.co.uk).
- Controller: The OS Company (UK company)
- Registered office: [Companies House registered address]
- Company number: [Companies House number]
- Contact: privacy@theoscompany.com
OS Sign is built on a fork of the open-source Documenso platform (AGPL-3.0), run entirely on infrastructure that The OS Company operates and controls. The OS Company is the operator of the service and the controller of the personal data described in this policy — not the Documenso project.
This policy is governed by UK GDPR, the Data Protection Act 2018, and, in respect of the legal effect of electronic signatures, UK eIDAS (the retained EU Regulation 910/2014 as it applies in UK law). It applies alongside our Terms of Service, which set out the legal status of the signatures OS Sign produces (see Section 11).
2. Who this policy covers
OS Sign has two kinds of users, and this policy covers both:
- Internal users (“senders”) — members of The OS Company’s team who hold an account, upload documents, and send them for signature.
- External recipients (“signers”) — people who receive an emailed link to a document and sign it. Signers do not create an account or set a password.
Where a section applies to only one group, it says so.
3. What data we collect and why
3.1 If you are a signer
Where we get your data. If you are a signer, we do not collect your name and email address from you directly — we receive them from the sender who added you as a recipient on the document. Because of this, UK GDPR Article 14 (rather than Article 13) governs our duty to inform you about that data, and we meet that duty by providing this policy at the point we first contact you — the signing email and link. All other data in this section — your signature, the actions you take, your IP address and device details — is collected directly from you, and Article 13 governs it.
| Data | Why we collect it | Lawful basis |
|---|---|---|
| Name and email address | To identify you as the intended recipient, send you the signing link, and address you correctly on the document | Legitimate interests — the sender’s and our shared interest in delivering the document to its intended recipient and completing the signing transaction they were asked to take part in. We have assessed this as proportionate: the data used is minimal, you were expecting to receive the document, and you can object at any time (Section 8) |
| IP address, browser/device details, timestamps | To create the audit trail that evidences who signed, when, and from where — this is what gives the signed document evidential weight | Legitimate interests — both the signer’s and the sender’s interest in a signed document that will stand up if the agreement is ever disputed, outweighs the limited privacy impact of logging an IP address already visible to us as part of routine web traffic |
| Signature image or typed signature | To apply your signature to the document, exactly as you provide it | Legitimate interests — enabling you to apply your signature to the document you were sent and completing the transaction you agreed to take part in when you chose to sign |
| Actions taken on the document (viewed, signed, declined, downloaded) and their timestamps | To build the completion certificate / audit trail attached to the signed document | Legitimate interests — creating and keeping a record of who viewed, signed, declined or downloaded the document, and when, is necessary to produce a reliable audit trail and to let the document’s validity be evidenced if disputed. We have weighed this against your interests and consider it proportionate: the data is limited to actions on this document and used for no other purpose |
| Document content itself | To display the document to you for review and signature | Legitimate interests — displaying the document you were sent, at the sending party’s request, is necessary to complete the transaction you were asked to take part in and is inseparable from that purpose |
Where a document is itself a contract directly between you and The OS Company (for example, an engagement letter to which you are personally a signatory), we additionally rely on performance of a contract for the data needed to form and execute that specific document. For all other documents — where The OS Company is not itself a party — the basis is legitimate interests, as above.
We do not ask signers to register, choose a password, or provide any data beyond what is needed to complete the specific document they were sent.
3.2 If you are a sender (internal user)
| Data | Why we collect it | Lawful basis |
|---|---|---|
| Name, email address, account credentials | To create and secure your account | Legitimate interests — provisioning you with an account is necessary to give you access to a business tool your role requires, and is proportionate given the limited data involved and your reasonable expectation of it |
| Documents you upload and send | To provide the core signing service | Legitimate interests — operating the business tool you use in the course of your role. We have weighed this against your interests and consider it proportionate: the documents are your own work product created for The OS Company and are used for no purpose beyond delivering the signing service |
| IP address, login timestamps, in-app actions | Security, abuse prevention, troubleshooting | Legitimate interests — protecting the service and its users against unauthorised access, weighed against the limited privacy impact of routine access logging |
We do not use any personal data collected through OS Sign — from senders or signers — for marketing, and we do not use it to make automated decisions that produce legal or similarly significant effects about anyone. See Section 8.
3.3 If a document contains special category or criminal offence data
OS Sign displays and stores whatever document content a sender uploads. Occasionally that may include special category data (e.g. health information) or criminal offence data. Senders are responsible for having their own lawful basis and Article 9/10 condition for including such data. Where we become aware such data is present, we process it only to store, display and produce the audit trail for the document, relying on Article 9(2)(f) UK GDPR (establishment, exercise or defence of legal claims) as the applicable condition.
If you don’t provide this data. For senders: providing your name, email address and account credentials is required to create your account — without it, we cannot give you access to OS Sign. For signers: your name and email address come from the sender, not from you; but if you decline to provide a signature or the other data needed to complete signing, we cannot complete your signature or issue a valid signed document.
4. Where your data is stored and processed
All document content, signature data, and audit trail data are stored in a PostgreSQL database on a server we operate in London, United Kingdom (AWS Lightsail, region eu-west-2). We configure our infrastructure not to replicate this data to other AWS regions. However, AWS is a global corporate group whose data processing terms permit limited access to data outside your selected region where necessary to provide the service (for example, technical support) or to comply with a legal obligation. Where this occurs, it is a restricted international transfer and the safeguards in Section 5 apply.
5. Who we share data with
We use a small number of infrastructure providers to run OS Sign. We do not sell personal data, and we do not share it with anyone for their own marketing purposes. The providers below act as our processors — they process data on our instructions, under contract, and only to the extent needed to deliver the service:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting — the server and database that run OS Sign | All data described in Section 3 | London, UK (eu-west-2) |
| Cloudflare | Network security and TLS/encryption in front of the service | Connection metadata (IP addresses, request data) in transit; Cloudflare does not hold document content at rest | Traffic may transit Cloudflare’s global network as part of standard content-delivery/security routing |
| Google (Google Workspace) | Sends transactional email — signing invitations, reminders, and completion notices | Recipient name, email address, and the content of the notification email (which references but does not embed full document content) | Google’s global infrastructure, including outside the UK |
Cloudflare’s own use of data. In addition to acting as our processor for your connection to OS Sign, Cloudflare independently processes some connection and log data (such as IP addresses) for its own network-security and threat-detection purposes, as described in Cloudflare’s own privacy policy. For that limited purpose, Cloudflare acts as an independent controller, not as our processor.
International transfers. Two of our processors may, in limited circumstances, move or access data from outside the UK: Google (routinely, as part of delivering email through its global infrastructure) and AWS (occasionally, for technical support or where required by law — see Section 4). Cloudflare’s network is also global, and a connection may be handled at a location outside the UK as part of standard TLS routing. For each of these, the safeguard we rely on is: for Google, the UK Extension to the EU–US Data Privacy Framework, under which Google is certified for Google Workspace; for AWS, the UK Addendum to the EU Standard Contractual Clauses incorporated into the AWS GDPR Data Processing Addendum; for Cloudflare, the UK Addendum to the EU Standard Contractual Clauses in the Cloudflare Data Processing Addendum. Copies are available on request to privacy@theoscompany.com, and Google’s and AWS’s mechanisms are also published at policies.google.com/privacy/frameworks and aws.amazon.com/compliance/gdpr-center.
We do not use any analytics, advertising, or tracking vendors. No third party receives your data for their own purposes.
6. Cookies
OS Sign uses only the cookies strictly necessary to keep you signed in (senders) or to maintain your signing session (signers) securely. We do not use analytics cookies, advertising cookies, or any tracking technology beyond this. Because these cookies are strictly necessary for the service you have asked us to provide, UK law does not require separate cookie consent for them, and we do not show a cookie banner.
7. Retention
We keep signed documents and their audit trails for as long as the underlying agreement remains in force, and afterwards for the limitation period that applies to a claim on that document under the Limitation Act 1980 — six years for a document signed as a simple contract, or twelve years for a document executed as a deed.
Account data for senders is kept for as long as the account is active, and for [insert period, e.g. 90 days] afterwards to allow for account recovery. We delete it after that period unless it forms part of a document’s audit trail (retained under the rule above) or a specific legal reason requires us to keep it longer, in which case we will tell you what that reason is.
Signature requests that are not completed. If a document is sent for signature but is declined, expires, or is cancelled before signing, we keep the associated data (recipient name and email, and any partial audit trail) for [insert period, e.g. 12 months] from the date it was sent, then delete it, unless a longer period is needed for a specific legal reason.
If you ask us to delete your data before this period ends, we will do so unless we are legally required to keep it — for example, where a document forms part of a live or reasonably anticipated dispute, or where deletion would compromise the audit trail relied on by other parties to the same document. Where we cannot delete data outright, we will restrict its use instead (see Section 8).
8. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erasure (“right to be forgotten”), subject to the retention grounds in Section 7
- Restrict processing in certain circumstances
- Data portability, where processing is based on contract and carried out by automated means
- Object to processing based on our legitimate interests
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you. Every signing decision on OS Sign is a deliberate action taken by a human — the signer.
To exercise any of these rights, contact privacy@theoscompany.com. We will respond within one month, as required by UK GDPR.
If you are not satisfied with how we have handled your data, you have the right to complain to the UK’s data protection regulator:
Information Commissioner’s Office (ICO) ico.org.uk ico.org.uk/make-a-complaint
9. Security
Data in transit is encrypted via TLS, terminated at Cloudflare and re-encrypted through to our origin server. Data at rest sits in a PostgreSQL database on infrastructure we control in London. Access to the underlying server and database is restricted to authorised The OS Company personnel.
10. Children
OS Sign is a business document-signing tool. It is not directed at, and we do not knowingly collect data from, children.
11. A note on the legal effect of signatures
This policy covers how we handle your personal data. It does not describe the legal status of the signatures OS Sign produces. In short: OS Sign generates signatures with a supporting audit trail, in the manner of an advanced electronic signature under UK eIDAS — it does not produce a qualified electronic signature. Full detail is set out in our Terms of Service, not this policy.
12. Changes to this policy
We may update this policy as the service changes. We will update the effective date above when we do, and, for material changes, take reasonable steps to notify active senders.
13. Contact
Questions about this policy or how we handle your data: privacy@theoscompany.com.