PII data
PII data is collected and stored but NOT distributed.
Types of PII data
EmailIP addressNameOther
Mechanisms to ensure data privacy & security
During the document signing process in LibreSign, it is necessary to identify the signer. The administrator can choose different levels of data collection, ranging from the simplest, which only identifies the signer's email and name (by accessing the link to sign via email), to more advanced options, which collect the IP address and browser user agent to associate this information with the document signature. These data are linked to the document and are not distributed. Only those who have access to the document can view this information during the signature validation process.
Encryption: All communication between clients and servers is secured using HTTPS, ensuring that data is encrypted during transmission. Additionally, documents and metadata associated with signatures are stored securely, protected by cryptographic methods. Access Control: Only authorized users with proper credentials have access to documents and associated data. The platform provides role-based access control (RBAC) to ensure that sensitive information, such as the identity of signers, IP addresses, and browser information, is only accessible to those with appropriate permissions. Data Minimization: LibreSign offers flexible data collection options. Administrators can choose the minimum necessary data, such as only requiring the signer's email and name, or opt for additional data points like IP and browser details for more robust validation. This ensures that only relevant data is collected. Secure Storage: Collected data, including documents and signer information, is stored securely within the system. No External Distribution: Data associated with the signing process is not distributed or shared with external entities. Only those with access to the document have visibility into the signing data during the document validation process. Audit Trails and Transparency: LibreSign keeps a secure audit trail of all actions taken during the document signing process. This ensures transparency and allows for verification of the integrity of signatures and the data associated with the document. Compliance with Data Protection Regulations: LibreSign complies with privacy regulations such as LGPD (Brazil) and GDPR (EU), ensuring that data is handled in accordance with legal standards. This includes providing mechanisms for data subjects to review, correct, or request deletion of their data, where applicable.