# Privacy Policy

Last updated: May 2026

## 1. Information We Collect

We collect the information provided when using SecurySign: account details such as name and email, WebAuthn credential identifiers, digital-signature metadata and documents submitted for signing. Identity verification also involves document images and face captures.

## 2. How We Use Your Information

We use this information to operate the service, authenticate accounts through WebAuthn, create and verify digital signatures, and communicate about the service. Document images and face captures are processed to produce identity-verification results.

## 3. Data Security

Server-side signing keys and account RSA encryption keys are generated and used in a hardware security module (HSM). Stored identity-verification evidence is encrypted. Passkey private keys are managed by the user’s authenticator.

## 4. Data Retention

We retain data for as long as needed to provide the service or meet legal requirements. Signature records are retained for legal-compliance purposes.

## 5. Your Rights

You can request access to personal data, correction of inaccurate data, deletion subject to legal obligations, or export in a portable format. Send requests to the privacy contact below.

## 6. Third-Party Services

Authentication and cryptographic operations use identity-management and hardware-security services. Their handling of data is also subject to their own privacy policies.

## 7. Cookies

Essential cookies maintain sessions and protect requests. SecurySign does not use advertising-tracking cookies. See the [Cookie Policy](#/docs/cookies) for cookie use and browser settings.

## 8. Changes to This Policy

We will notify you of significant policy changes by email or through the service. The current policy is published on this page.

## 9. Contact

For privacy questions and data requests, contact [privacy@tenda.world](mailto:privacy@tenda.world).
