Product transparency

Privacy notice

The personal data SignaGenius processes, split by the two very different roles it plays: as the operator of this website, and as a supplier acting on a customer's instructions inside their workspace.

Updated 31 August 2026

Two different relationships, and why the difference matters

Almost every complaint about a notice like this comes from mixing up two roles, so they are separated here.

For this website, the signup flow, the billing relationship, and the measurement described in the cookie notice, Magpie Nexus decides what is collected and why. It is the controller, and it answers to visitors and to administrators directly.

For everything inside a customer's workspace, the customer decides. The employee records, the signature content, the campaign and profile analytics, the connected directory: a customer's own organisation determines what goes in and what it is for, and Magpie Nexus processes it on that customer's documented instructions. It is the processor there, and an employee of a customer should ask their own employer first, because their employer is the controller of that data and holds the answers about it.

One consequence is worth stating plainly. Measuring a customer's employees for our own analytics is not something a processing agreement authorises by itself. Public profile pages are therefore left out of our own site measurement entirely: views of them are recorded for the customer, under the settings that customer controls. Signed-in use of the panel is measured as ours, on the consent recorded in the browser.

Who we are, and what this notice cannot yet say

SignaGenius is operated by Magpie Nexus, a company based in Spain.

A notice under Articles 13 and 14 has to identify the controller by its registered name and address, give contact details, and either give the contact details of a data protection officer or say that none has been designated. Spanish e-commerce law separately requires this site to publish the registered name, the registered address, the tax identification number, the commercial register entry, and a contact email address. None of that has been supplied for publication, so none of it appears here. Those are gaps in this draft, not exemptions, and they must be filled before it is published.

Until they are, questions about this notice can be sent through the contact page on this site, and a customer with a workspace can also raise them through the contact stated in their order or workspace agreement.

Data the product processes inside a customer workspace

SignaGenius stores administrator account details and the managed employee identity data needed to build signatures and public profiles. Depending on how the workspace is configured this can include names, work email addresses, job details, phone numbers, profile photos, aliases, entity membership, custom attributes, and delegated signature variations.

It also stores organisation branding, templates, campaigns, configuration, audit records, deployment outcomes, connector job history, billing references, and support or notification preferences.

In this data the customer is the controller and Magpie Nexus is the processor. Requests from an employee to see, correct, or delete their record are answered by their employer; we assist the employer rather than deciding for them.

  • Public profile leads are stored only after the visitor submits the form and accepts the consent text displayed to them.
  • Click, impression, profile, and link events are collected only where the workspace's own tracking setting allows them, and the workspace can choose to respect the browser Do Not Track signal.
  • Each of those events records what the request itself reveals: approximate location supplied by the network edge, the mail client or browser, device type, operating system, preferred language, and a salted one-way hash of the visitor address used to count unique readers. The address itself is not stored, and the events are deleted under the workspace's own analytics retention setting.
  • Connector and webhook credentials are held in server-side encrypted or hashed stores and are excluded from workspace exports.

Data we process as controller

The account and workspace record of the administrator who signs up: name, work email address, the sign-in method used, the workspace and its primary domain, and the plan. We need this to provide the service that was requested, so the basis is performance of a contract, and it is a contractual requirement: without it an account cannot be created.

Billing data, handled through Stripe. Card details are entered on Stripe's own pages and are not seen by us. Keeping invoices and the records behind them is a legal obligation under Spanish tax and accounting law, and those records outlive the account.

Support and service correspondence, and the operational email the product sends about deployments and account state. These rest on the contract, because they are how the service reports on itself.

The product also sends a short onboarding sequence to workspace administrators in the days after signup, encouraging them to deploy a signature, invite the rest of their team, and consider a paid plan. Every message in that sequence carries a one-click unsubscribe link that needs no login, and an unsubscribe header your mail client can offer as its own button. Using either stops the whole sequence for that address across every workspace it administers. Messages you actually need, such as sign-in links, billing receipts, and security notices, are not commercial and continue regardless.

Site and product measurement through Google Analytics, described in full in the cookie notice. Its basis is your consent, given on the banner, and it can be withdrawn.

First-touch acquisition attribution, described in the cookie notice. Its basis is your consent: the cookie is written only at the moment you accept on the banner, while the campaign parameters and referring site are still in the browser, and never before. Declining, or arriving with nothing to attribute, means no such cookie is set at all.

Security and abuse records: rate limits, audit events, and hashed addresses used to detect abuse. The basis is our legitimate interest in keeping the service available and not defrauded, balanced against the limited data each record holds.

The free signature generator

The generator at the tools page runs entirely in your browser. What you type into it is never sent to us or to anyone else, it is not stored on a server, and there is no account, no upload, and no submission. The signature is assembled in the page and copied to your clipboard from there.

If you accepted measurement, four things about the visit are reported: that the generator was opened, which template was chosen, which field you edited first, and that a signature was copied together with how many fields had been filled. The names of the fields, never their contents.

Who else receives data

A deployment can use Supabase for database, authentication, and storage; Railway for hosting; Stripe for billing; Resend for email delivery; Google Workspace or Microsoft 365 for the directory and signature operations a customer authorises; OpenRouter for AI features where a customer enables them; and Google for the site measurement described in the cookie notice.

Each of these is engaged as a processor and needs a written contract that meets Article 28 before it starts processing, and every customer whose data we process needs the same kind of contract with us, on every plan and not only on the largest one. Which of those contracts are signed, and where each provider processes the data, has not been confirmed for publication. The final notice must name the processors actually in use, their locations, and their role, and a current list must be available to customers.

For its part in the site measurement Google acts as a processor on our instructions. It receives no name, email address, company name, or customer domain in any event value, and a workspace reaches it only as a one-way salted value that is pseudonymous rather than anonymous and remains personal data. Page addresses are handled separately: where the address of a page is itself sensitive, such as a public profile addressed by a person's name or a self-service page carrying an access token, no measurement runs on that page at all.

Transfers outside the European Economic Area

Several of the providers above are established in the United States or process data there. Where a transfer is not covered by a European Commission adequacy decision, the safeguard relied on is the standard contractual clauses contained in the relevant provider's data processing terms, supplemented where necessary by additional measures.

This notice does not name a specific adequacy decision or claim a specific certification for a specific provider, because that has not been verified for this deployment. The operator must complete a transfer record and a transfer impact assessment for each provider, then state the mechanism precisely here and make a copy of the safeguards available on request.

How long data is kept

Inside a workspace, the customer controls users, templates, campaigns, public profiles, tracking settings, and the retention of analytics events. Operational and security records can be kept separately where that is needed for integrity, fraud prevention, recovery, or a legal obligation.

Account and workspace records are kept for the life of the account. Invoices and the accounting records behind them are kept for the period Spanish tax and commercial law requires, which is longer than the account itself. Measurement data in Google Analytics is kept for the period configured on the property.

Two things currently have no schedule at all: the first-touch attribution values copied onto a workspace record, and the Google client and session identifiers captured when a workspace is created. Both are kept for as long as the workspace exists. A defined retention period for each is one of the items outstanding, and a complete retention schedule has to appear here before this notice is published.

Your rights

You can ask for access to your data, for it to be corrected or erased, for processing to be restricted, for a copy in a portable form, and you can object to processing that rests on legitimate interest. Where processing rests on consent you can withdraw it at any time, and withdrawing it does not affect what was done before you did.

Route the request to whoever controls the data. For an account on this site, for billing, or for the site measurement, that is us. For an employee record inside a workspace, that is the employer who runs the workspace; we help them answer it rather than answering over their head. A request will normally be answered within one month.

You can complain to a supervisory authority. For a company established in Spain that is the Agencia Española de Protección de Datos, at www.aepd.es, and you may also complain to the authority where you live or work. A complaint to an authority is available to you whether or not you have raised the matter with us first.

No decision producing legal effects or similarly significant effects is taken about anyone solely by automated means. The AI features are for drafting campaign and template content, and they are switched on per workspace by its administrator; they do not decide anything about an individual.

Security, and what not to send us

The controls implemented include tenant-scoped authorisation, row-level database security, granular permissions, audit events, multi-factor and single sign-on policy gates, encrypted connector credentials, hashed API keys, signed webhooks, rate limits, and revocable agent access. The versioned workspace export deliberately omits secrets, sessions, event history, and anything the product can rebuild.

Do not send passwords, recovery codes, private keys, API tokens, signing certificates, or service-account credentials in a privacy or support request. Nobody here needs them to answer one.

Changes to this notice

This notice changes when the processing changes, and the date at the top of the page is the date of the version you are reading. Where a change materially affects what is done with personal data, workspace administrators are told before it takes effect. Where a change affects what the banner asked you to agree to, the disclosure version behind the banner is raised and you are asked again.