Legal

Privacy Policy

How FaydaSign collects, uses, protects, and manages your personal information when you use our digital signature services.

Last updated:

1. Introduction

FaydaSign ("we", "our", or "the platform") is a digital signature platform that enables individuals and organisations in Ethiopia to sign, send, and manage legally binding electronic documents. Every signature on FaydaSign is tied to a verified Fayda national identity, providing a trusted and auditable chain of custody.

This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and how we protect it. By using FaydaSign you agree to the practices described here. If you do not agree, please do not use the platform.

2. Information We Collect

We collect the following categories of information:

  • Account information — your full name, email address, phone number, and preferred language when you register.
  • Fayda identity verification information — your legal full name, date of birth, gender, and a pseudonymous Fayda subject identifier returned by the Fayda eSignet identity provider after you complete verification. We do not store your national ID number or biometrics.
  • Document metadata — file names, SHA-256 hashes, page counts, signing mode, timestamps, and recipient email addresses for documents you upload or receive.
  • Signature activity — field positions, drawn or typed signature images (stored as PNG data), IP address, user agent, and timestamps recorded at each signing event.
  • Payment information — plan selection, billing cycle, transaction references, and invoice records. Card numbers and sensitive payment credentials are handled exclusively by Chapa; FaydaSign never stores them.
  • Device and security information — IP address, browser type, and session tokens used to authenticate your account and generate audit trails.

3. Identity Verification

FaydaSign uses the Fayda eSignet OIDC service to verify your identity before you can send documents for signing. During this flow you are redirected to the Fayda eSignet portal, where you authenticate with your national credentials. Fayda returns an ID token containing your verified claims (name, date of birth, gender, and a pseudonymous subject identifier). We store these claims in your account and use them to embed verified identity information into every signed document.

Your Fayda credentials never pass through FaydaSign servers. All communication with the eSignet endpoint is performed via the OAuth 2.0 Authorization Code flow with PKCE and RS256 client assertions.

4. Document Data Protection

All documents uploaded to FaydaSign are stored in private Vercel Blob storage and are never publicly accessible. Documents are served only to authenticated users who own or have been invited to sign them, and only through time-limited, authentication-gated API routes.

Every document is assigned a SHA-256 hash at upload. Completed documents are sealed with a platform-issued PAdES digital signature, given a unique public document ID, and stored separately from the original. The sealed PDF includes a certificate page and an embedded QR code pointing to the public verification portal.

Document field values (signatures, initials, dates) are stored in the database as encrypted-at-rest records. Audit events recording who viewed, signed, or declined — together with IP address and device information — are retained for the lifetime of the document.

5. Payment Information

Subscription payments are processed by Chapa, an authorised Ethiopian payment service provider. FaydaSign stores only the transaction reference, plan ID, billing cycle, amount, and invoice records necessary to manage your subscription. We do not store card numbers, bank account details, or CVV codes. Chapa's own privacy policy governs the handling of your payment credentials.

6. Data Security

We protect your information using the following measures:

  • Encryption in transit — all communication between your browser and our servers uses TLS 1.2 or higher.
  • Encryption at rest — the database and blob storage are encrypted at rest by the underlying cloud infrastructure.
  • Access control — role-based access control ensures that platform administrators can access only the data required for their role. Every privileged admin action is logged to an immutable audit table.
  • Audit logging — all document events (created, sent, viewed, signed, declined, completed) and all admin mutations are recorded with actor identity, IP address, and timestamp.
  • Cryptographic integrity — completed documents are signed with a platform-issued PAdES certificate so any post-signing tampering is detectable.

7. Data Retention

We retain your data for as long as your account is active or as required to provide the service. Specifically:

  • Account information — retained until you request account deletion.
  • Documents and audit trails — retained for a minimum of seven years to satisfy legal and regulatory requirements applicable to electronic signatures in Ethiopia.
  • Payment records — retained for seven years for accounting and tax purposes.
  • Session tokens — expire after 30 days of inactivity and are deleted on explicit sign-out.

8. Your Rights

You have the right to:

  • Access — request a copy of the personal information we hold about you.
  • Correction — update your account information at any time from your profile page. Note that your legal full name becomes immutable once Fayda verification is complete, as it is embedded in signed documents.
  • Account closure — request deletion of your account. Documents you have already sent or signed will be retained to satisfy retention obligations and to protect the rights of other signatories.

To exercise any of these rights, email us at privacy@faydasign.com.

9. Contact Us

For privacy-related questions or requests, contact our Data Protection Officer at privacy@faydasign.com. Our registered address is in Addis Ababa, Ethiopia.

Questions about this document?

Contact us at legal@faydasign.com or visit our Security Center.