Skip to main content
Privacy & Trust

Institutional
Privacy.

Last updated: May 11, 2026

1. Our Commitment

At Plannorium Sign, privacy is not a feature—it's our foundation. We provide e-signature infrastructure for high-stakes agreements, which means we handle your most sensitive documents with bank-grade security and absolute transparency. This policy details how we protect your data across our entire ecosystem.

2. Data We Collect

We minimize data collection to the essentials required to provide a legally binding signing service. This includes:

Identity Data

Name, verified email address, and IP-based identity markers for audit trails.

Metadata

Document timestamps, device signatures, and signing location telemetry.

3. Document Security & Encryption

Encryption Standards

Every document uploaded to Plannorium is encrypted using **AES-256** at rest. In transit, we enforce **TLS 1.3** to ensure your agreements are never exposed. We utilize hardware security modules (HSMs) to manage cryptographic keys, ensuring that even Plannorium employees cannot access your document content.

4. Third-Party Infrastructure

To provide institutional-grade services, we partner with industry leaders who share our commitment to privacy:

  • Polar: Processes all financial transactions under PCI-DSS Level 1 compliance. We never store your credit card details.
  • Resend: Powers our secure email notifications, ensuring signing links are delivered reliably and privately.
  • Vercel: Hosts our distributed infrastructure with global edge security.

5. Compliance & Residency

Plannorium Sign complies with global privacy and security standards, including SOC II (US), HIPAA (US), and eIDAS (EU). We provide option-based regional data storage configurations so that your documents, audit logs, and keys remain stored strictly inside your chosen geographic jurisdiction.

6. EU & UK Residents (GDPR Compliance)

If you reside in the European Economic Area (EEA) or the United Kingdom (UK), your personal data is protected under the General Data Protection Regulation (GDPR) and UK GDPR.

Data Controller vs. Processor: When you register an account with us, Plannorium acts as the Data Controller. When you upload agreements or waiver forms to send to signers, your organization is the Data Controller, and Plannorium acts as the Data Processor.

Legal Basis for Processing: We process your data under the following legal bases: (a) Performance of a contract (to execute e-signatures), (b) Consent (for opting into specific tools), and (c) Legitimate interests (to compile audit trails, verify signer identity, and prevent service abuse).

Your Rights: You hold the right to access, rectify, export, or request deletion (the 'right to be forgotten') of your personal data. You may also object to or restrict specific processing operations.

7. Data Rights

All users maintain total ownership of their files. You can export complete audit logs, request permanent deletion of your account, and manage data consent settings at any time through our Console.

8. Contact & DPO

For questions about our privacy practices, GDPR compliance details, or to contact our Data Protection Officer, please message us at support@plannorium.com.