Privacy Policy
Effective September 24, 2026
This Privacy Policy describes how iCommuneTech ("we," "us," or "our") collects, uses, and protects information in connection with the AISignFlow platform ("the Service"). It applies to account holders, their organization members, and the recipients of documents sent through the Service. By using AISignFlow, you agree to the practices described here, as they may be updated from time to time.
Data We Collect
Account and organization data. Name, email address, organization name, billing information, and role/permission assignments provided when creating or managing an account.
Document content and metadata. The documents uploaded as templates or sent as envelopes, the field values entered by recipients (including signature images or typed/drawn signature representations), and metadata such as timestamps, IP address, and device/browser information captured for each signing event as part of the audit trail.
Usage data. Log data generated through ordinary use of the Service — pages visited, features used, and API/webhook activity — collected to maintain platform reliability and improve the product.
Communications. Correspondence with support, sales, or through demo/booking requests, including information submitted via contact or "request a plan" forms.
How We Use Data
We use collected data to: operate the core signing workflow, including generating and delivering envelopes, recording audit trail events, and producing Certificates of Completion; authenticate users and enforce organization-level access controls; send transactional communications, including signing invitations, reminders, and status notifications; provide customer support and respond to inquiries; process billing through our payment providers; and monitor, secure, and improve the Service, including detecting fraud or abuse.
We do not use the content of customer documents to train third-party or foundation AI models. Where the Service includes AI-assisted features, such as suggested field placement on a template, those features operate on your document data solely to power that in-product functionality.
Third-Party Sharing
We do not sell personal information or document content. We share data only in the following circumstances:
- With subprocessors that provide infrastructure we rely on to operate the Service, such as cloud object storage, transactional email delivery, and payment processing.
- With your organization's administrators, who by design can access envelopes and audit trails created within that organization.
- When required by law, such as in response to a valid legal request.
- In connection with a business transfer, such as a merger or acquisition, subject to continued protection under a policy at least as protective as this one.
Recipients who are not account holders (i.e., people asked to sign a document) have their name, email, and signing activity processed solely to facilitate that specific signing request and its audit trail — not for independent marketing use. Organizations on the Self-Hosted plan run the Service on their own infrastructure, so document data in that deployment model does not pass through our hosted subprocessors.
Document Security
Documents and signature data are protected in transit using TLS encryption and at rest using industry-standard encryption. Access to documents within an organization is governed by role-based permissions, and every meaningful action — view, field completion, signature — is recorded in an immutable audit trail. Completed documents are additionally protected by a signed Certificate of Completion with a public hash-verification mechanism, allowing tampering to be independently detected after signing.
Data Retention
We retain account data for as long as your account remains active. Document and audit trail data is retained for as long as necessary to fulfill the purpose for which it was collected — including the evidentiary and legal purpose of an audit trail and Certificate of Completion — after which it is deleted or anonymized in accordance with applicable law. You may request deletion of your account data at any time, subject to these retention obligations.
Your Rights
Subject to applicable law (including, where relevant, GDPR and equivalent regional frameworks), you may have the right to access the personal data we hold about you, request correction of inaccurate data, request deletion of your data subject to our legal and audit-trail retention obligations, export your data in a portable format, and object to or restrict certain processing. Requests can be submitted to the contact below.
International Transfers
Where data is transferred internationally in the course of operating the Service, we rely on appropriate safeguards intended to ensure it receives a comparable level of protection, consistent with applicable transfer mechanisms.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to account holders via email or in-app notice prior to taking effect.
Contact
Questions about this policy or requests regarding your data can be directed to:
Email: enquiry@icommunetech.com
Website: www.icommunetech.com