Legal

Privacy Policy

How MEGITS Intelligent SL collects, uses and protects personal data when you use CloudSignLab, and how to exercise your data protection rights.

Last updated: 25 September 2026. This policy is also available in Spanish; where the two versions differ, the Spanish version prevails.

CloudSignLab is a service of MEGITS Intelligent SL. This policy explains what personal data we process when you use the CloudSignLab website and application, why we process it, how long we keep it and what rights you have. CloudSignLab is a business service intended for organizations and professionals aged 18 or over.

Who is responsible for your data

Data controllerMEGITS Intelligent SL
Tax ID (CIF)B93978385
AddressCalle Alejandro Dumas 17, 29004 Málaga, Spain
Privacy contactprivacy@cloudsignlab.com

We have not appointed a Data Protection Officer because our processing does not require one under Article 37 GDPR. You can contact us about any privacy matter at the address above.

What data we process and why

Your account

  • Data: name, email address, password (stored only as a one-way cryptographic hash, never readable by anyone), optional profile photo, language, and your two-factor and passkey settings.
  • Purpose: to create and run your account, let you sign in and provide the service.
  • Legal basis: performance of our contract with you or your organization (Art. 6(1)(b) GDPR).
  • Retention: while your account exists. When you delete your account, it is removed from our active systems (see "Security logs" for the exception).

Organizations and team members

  • Data: organization name and logo, members and their roles, and invitations (the invited person's email address and role).
  • Purpose: to let organizations work together and manage who has access.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Invited people are processed on the basis of the inviting organization's legitimate interest (Art. 6(1)(f) GDPR).
  • Retention: while the organization exists; invitations expire if they are not accepted.

Security logs

To protect your account and our service, we record security-relevant events:

  • sign-ins (including the sign-in method), failed sign-in attempts on existing accounts, and sign-outs;
  • security changes such as password changes and resets, two-factor authentication and passkey changes, email changes and account deletion;
  • team management actions (for example inviting or removing members) and actions performed by our administrators.

Each entry stores the date and time, the account's email address, the IP address and the browser/device used. Passwords, codes and access tokens are never recorded.

  • Purpose: to detect and investigate unauthorized access, abuse and fraud, and to show you your own recent security activity in your account settings.
  • Legal basis: our legitimate interest in keeping the service and its users secure (Art. 6(1)(f) GDPR).
  • Retention: up to 365 days, after which entries are deleted automatically. Entries are kept for this period also after an account is deleted, so that abuse can still be investigated.

We also use these events to warn you: you see security notifications in your account (for example a sign-in from a new device, several failed sign-in attempts or a changed password), and we email you when your account is used from a device we have not seen recently. Notifications store the type of event, the device and the IP address, and are deleted automatically after 90 days.

Emails we send you

  • Data: your email address and the content of the message (for example verification links, sign-in codes, password resets and invitations).
  • Purpose: to operate your account securely.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

Mailing list (news and updates)

  • Data: email address, language, where you signed up, and the dates you subscribed, confirmed or unsubscribed.
  • Purpose: to send you news about CloudSignLab.
  • Legal basis: your consent (Art. 6(1)(a) GDPR). We use double opt-in: you are only added after confirming through the link we email you.
  • Retention: until you unsubscribe. Every email includes an unsubscribe link. After you unsubscribe we keep a record of it, so that we do not contact you again.
  • Sending records: for each newsletter we keep who it was sent to and whether it was delivered, so that nobody receives the same newsletter twice. Every newsletter can be unsubscribed from with one click.

Contact form

  • Data: name, email address and your message.
  • Purpose: to answer your enquiry. Messages are sent to our team by email and are not stored in the application.
  • Legal basis: our legitimate interest in responding to enquiries, or steps prior to a contract (Art. 6(1)(f) and (b) GDPR).
  • Retention: up to two years after the enquiry is closed.

Analytics and error monitoring

  • Data: pages visited, interactions, technical errors, browser and device information, and a pseudonymous user identifier. We do not send your name or email address to our analytics provider.
  • Purpose: to understand how the product is used and to fix problems.
  • Legal basis: your consent (Art. 6(1)(a) GDPR). Nothing is collected until you accept analytics cookies, and you can withdraw your consent at any time using "Cookie settings" in the footer.
  • Retention: up to 14 months.

Payments

  • Data: billing details and payment information. Card data is entered directly with our payment provider, Stripe; we never see or store full card numbers.
  • Purpose: to process subscriptions and payments.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
  • Retention: invoices and accounting records are kept for six years, as required by Spanish commercial law.

Server and backup data

Our servers keep technical request logs (IP address, time, requested address) for a short rolling period to operate and secure the service. Database backups are kept on a rolling basis for disaster recovery and are overwritten automatically.

Who we share data with

We do not sell your personal data. We share it only with service providers that process it on our behalf under data processing agreements:

ProviderPurposeLocation
Amazon Web Services (AWS)Hosting, database, file storage and email deliveryEuropean Union
PostHogAnalytics and error monitoring (only with your consent)European Union
StripePayment processingEuropean Union / see below

We may also disclose data where required by law or by a competent authority.

Where your data is stored

All our servers, our database and file storage are hosted by Amazon Web Services in the European Union. Some providers (for example Stripe, or support staff of our providers) may process data outside the European Economic Area; when that happens, the transfer is protected by the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework.

How we protect your data

We use encrypted connections (HTTPS), store passwords only as secure hashes, offer two-factor authentication and passkeys, restrict internal access to what each role needs, keep uploaded files private except profile photos, and record administrative actions in an audit log.

Your rights

You can ask us to:

  • give you a copy of your personal data (access);
  • correct inaccurate data (rectification);
  • delete your data (erasure);
  • restrict or object to certain processing;
  • provide your data in a portable format (portability);
  • withdraw any consent you have given, at any time, without affecting earlier processing.

Write to privacy@cloudsignlab.com. We will reply within one month. We may ask you to confirm your identity before acting on a request.

If you believe we have not handled your data correctly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

Automated decisions

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Changes to this policy

We may update this policy when our service or the law changes. We will publish the new version on this page with a new date and, for significant changes, notify account holders by email.