Legal
Privacy Policy
How PDFService handles account, document, and signer data on the hosted electronic-signature platform (web, agents, and API).
Last updated 20 August 2026 · Draft · Counsel review required
1. Who we are
PDFService is a hosted SaaS product operated by the Granis team (“we,” “us”). This policy covers pdfservice.ai, the workspace web app, agent/MCP interfaces, and the REST API.
2. Data we process
We process the categories below as needed to run the service:
- Account data — email, name (if provided), authentication events
- Billing references — credit purchases and transaction ids via the payment provider when checkout is enabled
- Document content — PDFs you upload and signature-field positions
- Placement-ceremony participants — email, placed signature images, and the date and text values they place
- Signer data — email, optional name, signing-session metadata (including IP and user agent for audit)
- Usage data — API/agent calls, credit consumption, request status
- Support data — messages you send us through contact channels
3. How we use data
We use personal data only as needed to operate the product:
- Provide signing and document features
- Authenticate users and signers (including email one-time codes)
- Maintain audit trails and security logs
- Meter credits and prevent abuse
- Send service notices related to your account or signing requests
- Comply with law
- We do not sell personal data
- We do not use your document contents to train foundation models as a product feature
4. Legal bases (where applicable)
Depending on jurisdiction: performance of a contract, legitimate interests (security, reliability, and aggregate product improvement), consent where required, and legal obligation.
5. Sharing
We share data only as needed to operate the service:
- Sub-processors for hosting, storage, email delivery, and payments
- Signers and counterparties you invite, as required to complete the signature
- Authorities when required by law
- Professional advisors under confidentiality
6. International transfers
We may process data in the United States and other regions where we or our sub-processors operate. We will use appropriate transfer mechanisms where required by law.
7. Retention
- Account data — for the life of the account plus a reasonable wind-down
- Documents and audit trails — product defaults or enterprise agreements; defaults will be published as the product hardens
- Security logs — as needed for security and abuse prevention
8. Security
See our Security page for organizational and technical measures at a high level. No method of transmission or storage is perfectly secure.
9. Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Contact us via the site contact channels. You may also lodge a complaint with a supervisory authority where applicable.
10. Children
The service is not directed to children under 16 (or a higher age where required). Do not use the service to collect children’s data.
11. Changes and contact
We may update this policy with notice for material changes. Contact: privacy channels on pdfservice.ai (draft addresses will be finalized with counsel).
