What we hold, and for how long
Version 1.0 · 23.08.2026Controller: FreeSign ApS, København, Denmark. Written for the GDPR; plain language on purpose.
privacy@freesign.onlineWhat we collect
The PDF you upload; the name, email address and optional message you type for each signer; and, when a document is signed, the signer's IP address, browser user-agent and timestamp. That last set exists so the signature can be proven later — it is the audit trail. We do not ask for an account, a phone number or a payment method.
Why we are allowed to
Performing the contract you asked for (Art. 6(1)(b)) covers the document and the signer details — without them there is nothing to send. The audit trail rests on our legitimate interest in evidential integrity (Art. 6(1)(f)); personalised advertising rests on your consent (Art. 6(1)(a)), which you give or refuse in the cookie banner and can change at any time.
How long we keep it
Documents and their audit trails are deleted automatically 5 days after the signing request is created, signed or not. You can delete sooner from the link in your confirmation email. Server logs holding IP addresses are kept 30 days for abuse prevention, then discarded. We keep nothing else — there is no archive, because there is no account.
Who else touches it
Three processors, all under data processing agreements: our hosting provider (EU region, Frankfurt and Copenhagen), our transactional email provider, and Google for advertising. Documents are never sent to the ad provider, and ads are selected by page, not by document content. No processor outside the EU/EEA receives document data.
Your rights
Access, rectification, erasure, restriction, portability and objection — write to privacy@freesign.online and we answer within 30 days. Because we hold no account, identifying your data means giving us the document link or the email address it was sent to. You may also complain to Datatilsynet, the Danish Data Protection Agency.
Security
TLS 1.3 in transit, AES-256 at rest, signing links carry a 128-bit random token and no directory listing exists. Staff cannot open your documents; access is limited to automated processing. If a breach affects you we notify you and Datatilsynet within 72 hours.