← All policies

Privacy Policy

What personal information VaseSign collects, why, who else sees it, and the rights you have over it under POPIA.

Effective 4 September 2026 · Version 2026-09-04

Who we are

Vase Digital Trust (PTY) Ltd is the responsible party for personal information processed through VaseSign, except where we act as an operator for a customer organisation (see "When we act for our customers").

  • Vase Digital Trust (PTY) Ltd (trading as VaseSign)
  • Registration 2026/644797/07 · VAT 9126847301
  • 4 Belvedere Road, Glen Austin AH, Midrand, 1685, Gauteng, South Africa
  • billing@vasedigital.com

When we act for our customers

Most documents on VaseSign belong to a customer organisation, not to us. Where an organisation uploads a document and sends it for signature, that organisation is the responsible party and we are its operator: we process the document on their instruction and do not decide what it is for.

If you signed a document and want it corrected or deleted, the organisation that sent it decides. We will pass your request to them and tell you who they are.

We are the responsible party for our own account, billing and security records.

What we collect

The categories below reflect what the platform actually records, not everything conceivably possible.

  • Account information — name, email address, organisation, role, and authentication data including multi-factor secrets.
  • Documents and their content — files you upload, text extracted from them, and the fields you place.
  • Signature evidence — your drawn or typed signature image, the date and time, your IP address, browser user agent, device fingerprint, and approximate location where available.
  • Identity verification data — where an organisation enables KYC, identity document images and verification results processed by our verification provider.
  • Communications — email and SMS delivery status, and the content of notifications we send about your documents.
  • Billing information — subscription and usage records, invoices, payment references. We do not store card numbers; payments are handled by our payment providers.
  • Technical and security records — audit logs of actions taken in the platform, and virus scan results on uploaded files.

Why we collect it, and on what basis

Signature evidence is the core of the service. The IP address, timestamp, device fingerprint and audit trail exist so that a signature can be proven later — that is the product, and a signature without them is materially weaker as evidence. We process this to perform the contract with you or your organisation, and because it is necessary for the legitimate interest of establishing the authenticity of signed records.

Identity verification is processed with consent and on the instruction of the organisation requiring it.

Security and audit records are processed to comply with legal obligations and to protect the platform.

We do not sell personal information, and we do not use your document content to train AI models.

AI processing

Where AI features are enabled, document text is sent to our AI provider for classification, review or drafting assistance. The provider processes it to return a result and under our contract may not use it to train their models.

AI output is assistance, not advice. Legal and operational judgement remains with you, and we say so in the product where the feature is used.

An organisation can disable AI features, in which case no document text is sent to the AI provider.

Who else processes your information

We use the operators below. Each processes personal information only on our instruction and under a written contract as POPIA requires.

  • Moonshot AI (Kimi) — Document classification, review and drafting assistance. Data: Document text submitted for analysis. Processed: Outside South Africa.
  • Didit — Identity verification (KYC) where enabled. Data: Identity document images, selfie, verification result. Processed: Outside South Africa.
  • Resend — Transactional email delivery. Data: Recipient name, email address, message content. Processed: Outside South Africa.
  • Stitch / PayFast — Payment processing and wallet top-ups. Data: Payment identifiers, amounts, reference. Processed: South Africa.
  • Twilio / WhatsApp Business — SMS one-time PINs and WhatsApp notifications. Data: Mobile number, message content. Processed: Outside South Africa.
  • Contabo — Server hosting and infrastructure. Data: All platform data at rest. Processed: European Union (Germany).

Cross-border transfer

Our servers are located in the European Union. Some operators listed above process information outside South Africa.

POPIA section 72 permits transfer where the recipient is subject to a law or binding agreement providing comparable protection. We rely on contractual protections with each operator.

If your organisation requires data residency in South Africa, that is not currently something the platform provides, and you should not assume otherwise.

How long we keep it

Signed documents and their evidence are retained for as long as the customer organisation requires them, because the entire purpose of an evidence pack is to remain available if a signature is later challenged. Deleting evidence on request would defeat the service.

Account and billing records are retained for at least five years, as tax and company law require.

Audit logs are retained for the period configured by the organisation, and never less than twelve months.

Where you close an account, we delete or anonymise what we are not required to keep.

Your rights

Under POPIA you may:

  • Ask what personal information we hold about you and receive a copy.
  • Ask us to correct or delete information that is inaccurate, irrelevant, excessive, misleading or unlawfully obtained.
  • Object to processing based on legitimate interest.
  • Complain to the Information Regulator (South Africa) — inforeg@justice.gov.za.
  • Withdraw consent where processing is based on consent, without affecting processing already carried out.

Security

Documents are encrypted at rest and in transit. Signing credentials and multi-factor secrets are encrypted with keys held separately from the database.

Uploaded files are scanned for malware before they are accepted, and a file that cannot be scanned is rejected rather than accepted unchecked.

Access to production systems is restricted and audited.

No system is perfectly secure. If a breach affects your personal information we will notify you and the Information Regulator as section 22 requires.

Contact

Information Officer: contact billing@vasedigital.com and mark your request for the attention of the Information Officer.

We will respond to a request about your personal information within 30 days.

Questions about this policy? Contact us and mark your message for the attention of the Information Officer. If you are asking about a document someone else sent you, the organisation that sent it decides what happens to it — we will tell you who they are.