Home · Legal
Privacy policy
Last updated: 19 August 2026
1. Data controller
- Holder
- Sean Alessandro Mora Infante
- NIE
- Y1897312B
- Registered address
- Ronda República Argentina 39, 3.º B · 27002 Lugo · España
- Contact email
- info@sektorsign.com
2. What data is processed, and why
Only the data needed to provide the service is processed:
- Account data — name, email and password (stored as a secure hash, never in the clear). Purpose: to create and maintain your account and your workspace. Legal basis: performance of the service contract (art. 6.1.b GDPR).
- Documents and signer data — the PDFs you upload and the name, email and role of the people you name as signers. Purpose: to send the document out for signature. Legal basis: performance of the contract; as for the third-party data you enter, it is you who warrants that you may provide it.
- Evidence of the signing process — server dates and times, the IP address and user agent observed at each opening and signature, the consent text accepted, and the SHA-256 hashes of the documents. Purpose: to build the evidence record that is the very object of the service, and which the signer expressly accepts before signing (art. 6.1.a and 6.1.b GDPR, and legitimate interest in the integrity of the process, art. 6.1.f).
- Transactional email — addresses and the minimum content needed to deliver signing invitations, confirmations and access emails. These are part of the service and cannot be switched off without stopping using it.
- Marketing newsletter — only if you tick the box yourself, and it always arrives unticked. Data processed: your email address, your name if you gave one, the language you signed up in, and the date, time and IP address the consent came from. Purpose: to send you product news. Legal basis: your consent (art. 6.1.a GDPR), stored with its date and IP precisely so that it can be demonstrated. You can withdraw it at any time using the unsubscribe link in every one of those emails, with no explanation needed and with no effect on your contracts. Agreeing to a contract in order to sign it does not sign you up to anything: they are two separate, independent boxes. We do not share or sell these addresses to anyone.
- Account access log — every sign-up, sign-in, sign-out, password change and failed sign-in attempt is recorded with its server date and time, the IP address and user agent it came from, and your acceptance of these terms together with its version. Purpose: account security — so that «who signed in, and from where?» can be answered if you suspect someone else got in — and proof of the consent you gave when registering. Legal basis: legitimate interest in the security of the service (art. 6.1.f GDPR) and compliance with our obligations as controller (art. 6.1.c). This log is tamper-proof by design: it cannot be edited or rewritten, because a security history you can edit is worth nothing.
- Visit counting — to know which pages are viewed and from what kind of screen. No cookies, no identifiers and no personal data: your IP address is not stored, nor your browser, nor anything that could recognise you or follow you between pages. All that is kept is a daily counter per page, referring domain and screen type — “yesterday, 14 visits to this page from Google, on mobile”. Those figures cannot be traced back to any person, because no person was ever stored. Legal basis: legitimate interest in knowing whether the service is used (art. 6.1.f GDPR), with an impact on your privacy that is, literally, none. If your browser sends the “do not track” signal, the visit is not even counted.
No profiling is carried out and no automated decisions are taken about people.
3. Where the data is kept
Data and documents are hosted on a server contracted with Hostinger International Ltd. located in Frankfurt (Germany), within the European Union. The connection between your browser and the server travels encrypted with TLS. There are no international transfers outside the European Economic Area.
4. Who it is shared with
Nobody, save for a legal obligation. The only technical recipients are the providers strictly needed to run the service (hosting and email delivery), acting as processors.
5. How long it is kept
Account data, for as long as the account exists. Contracts and their evidence, for as long as the workspace keeps them and its plan is up to date: they are the record the service promises to hold.
If your paid subscription ends or goes unpaid, your documents are kept for 30 days from the end of the paid period. Before they are deleted you will receive an email with the exact date, and you will be able to reactivate the plan or download your documents and reports. After that, they are permanently removed from the server and cannot be recovered. The people who signed receive their copy of the document and the report by email as each contract completes, so they keep theirs regardless of this period.
You can also ask for erasure at any time by writing to info@sektorsign.com; bear in mind that deleting a contract also deletes its associated evidence.
The access log is the exception, and it is worth explaining. That history cannot be deleted: the database prevents it by design, because a security log you can edit is no log at all. What happens instead when you exercise erasure is that it is anonymised: the IP address and the browser are removed, and all that remains is the fact — that there was a sign-in or a signature, of what kind and when — with nothing left that could locate you. It is irreversible and it is recorded.
6. Your rights
You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to info@sektorsign.com from the email address linked to your account. If you believe the processing is not correct, you may complain to the Spanish Data Protection Agency (aepd.es).
7. Cookies
This site uses only strictly necessary cookies. The detail is in the Cookie policy.