ArcaSign is a digital signature platform operated from San José, Costa Rica. This policy describes what personal data we collect, what we use it for, who we share it with, and what your rights are as the owner of that data.
By using ArcaSign you accept this policy. If you do not agree, do not use the service.
1. Data controller
ArcaSign is the controller of the personal data of registered users and of external signers who interact with documents sent through the platform. You can contact us at support@arcasign.com.
2. Data we collect
Account data
- Full name and email address (when you register or are invited to an organization)
- Organization name and account settings
- Role assigned within the organization (Administrator, Operator or Auditor)
Usage data
- PDF documents uploaded for signing
- Case metadata: name, dates, status, tags and folders
- Audit trail: every action on a document is recorded with a timestamp
- Signature request configuration (signers and deadlines)
External signer data
- Name and email address (provided by the operator who sends the document)
- BCCR digital certificate used to sign (validated at the time of signing)
- IP address and timestamp associated with the signing action
Technical data
- IP address and HTTP headers (processed by Cloudflare as a proxy)
- API access logs (method, endpoint, response code, latency)
Billing data
- Name, email and credit card details — processed directly by Stripe. ArcaSign does not store payment data.
3. What we use the data for
- Service delivery: authenticating users, managing cases and running signing flows with legal validity under Law 8454.
- Notifications: sending emails about signature requests and confirmations.
- Audit and integrity: maintaining the immutable audit trail required for legally valid documents.
- Security: detecting unauthorized access, preventing fraud and protecting document integrity.
- Billing: managing subscriptions and processing payments through Stripe.
- Service improvements: analyzing aggregated, anonymous usage patterns to improve the platform.
4. Legal basis
Data processing is grounded in Law 8968 (Costa Rica’s Law on the Protection of Individuals with regard to the Processing of their Personal Data) and applicable regulations:
- Contract performance: data necessary to provide the contracted service.
- Legal obligation: retention of audit trails under the minimum periods of Law 8454.
- Legitimate interest: security, fraud prevention and service improvement.
- Consent: for optional marketing communications, where applicable.
5. Subprocessors
We share data with the following third parties solely to provide the service. None receives documents in clear text or signer identity data except as noted:
- Cloudflare — CDN and network proxy. Processes traffic metadata (IP, headers). Does not access document content.
- S3-compatible storage — PDF files encrypted with AES-256. The encryption key is not shared with the provider.
- Time-Stamping Authority (TSA) — Receives the document’s SHA-256 hash. Does not receive the full document or personal data.
- Stripe — Processes payments. PCI DSS Level 1. ArcaSign does not store card data.
- BCCR — Validates digital signature certificates in accordance with Law 8454.
Full list at arcasign.com/transparencia.
6. Data retention
- Signed documents: kept while the account is active. Upon cancellation, you have 30 days to export them before permanent deletion.
- Audit trails: kept for the life of the case and for an additional 5 years after the account is closed (Law 8454).
- Account data: deleted when the account is closed, except for billing records that tax law requires us to keep (5 years).
7. Your rights
As a data owner you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Deletion: request the deletion of your data when there is no legal obligation to keep it.
- Objection: object to processing based on legitimate interest.
- Portability: receive your data in a structured format (JSON or PDF).
To exercise any of these rights, write to support@arcasign.com. We process requests within a maximum of 10 business days.
8. Security
- Documents encrypted with AES-256 at rest.
- Communications protected with TLS 1.3 in transit.
- Infrastructure on Cloudflare with active DDoS protection.
- Passwordless authentication via magic link through verified email.
- Multi-tenant with full isolation between organizations.
- Cryptographic RFC 3161 time-stamping independent of ArcaSign.
9. Cookies and tracking
ArcaSign uses strictly necessary session cookies to authenticate users. We do not use advertising tracking cookies and do not share data with ad networks.
10. Changes to this policy
We may update this policy when the service changes. If the changes are material, we will notify you by email at least 15 days in advance. The current version is always available on this page with the last-updated date.