How Signater stores, retains and deletes the data and files processed on the Platform, including Documents, signature evidence and account data.
Last updated on August 30, 2026
This Data Retention Policy ("Policy") describes how Signater — Signater LLC and Signater Tecnologia Ltda ("Signater", "we") — stores, retains and deletes the data and files processed on the Signater platform (the "Platform"). It supplements the Privacy Policy, the Data Processing Agreement (DPA) and the Terms of Service, and should be read together with those documents.
Capitalized terms not defined in this Policy — such as Customer, User, Signer, Envelope, Document and Plan — have the meanings given to them in the Terms of Service.
1.1. We keep personal data and other information for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, and to establish, exercise or defend legal claims. Signater is a Brazilian company and retains data in accordance with the Brazilian General Data Protection Law (Lei nº 13.709/2018 — LGPD), in particular its articles 7, 11 and 16. Where Regulation (EU) 2016/679 (GDPR) applies, we observe its storage-limitation principle on the same basis.
1.2. The Customer manages its own repository. Documents and Envelopes remain stored on the Platform for as long as the Customer keeps them in its account. Signater does not currently impose an expiration period on the repository of an active account.
1.3. For the content of Documents and the personal data of Signers, Signater acts as a processor, following the instructions of the Customer, who is the controller of that data. Each party's role is described in the Privacy Policy and in the DPA.
1.4. The periods stated in this Policy are indicative. The actual retention period for a given item may vary depending on its nature, specific legal obligations, pending disputes or requests from competent authorities, and legitimate security and fraud-prevention needs. Mandatory data-protection rights available to you under the laws of your jurisdiction remain unaffected.
1.5. The lifetimes of cookies and similar technologies used on our website and Platform are described in the Cookie Policy.
2.1. Files processed on the Platform — including Documents, signed versions, signature certificates and images collected in identity-verification flows — are stored on cloud infrastructure operated by providers engaged by Signater, listed on the Subprocessors page, with encryption at rest applied by the storage provider.
2.2. All traffic between you, the Platform and our providers is encrypted in transit (TLS). Secrets and credentials — such as API tokens, authentication codes and digital-certificate passwords — receive an additional layer of application-level encryption (AES-256).
2.3. Some of our providers process data outside Brazil, including in the United States. International transfers are carried out with the safeguards described in the Privacy Policy.
2.4. The volume limits that apply to each Plan — such as the number of Documents per Envelope and the maximum file size — are set out in the current catalog on the Pricing page, which prevails over any statement to the contrary.
2.5. The Customer may download copies of its Documents at any time while it has access to the account, and is responsible for keeping outside the Platform any copies it deems necessary for its own purposes.
3.1. The table below sets out, by category, the indicative retention periods practiced by Signater, subject to specific legal obligations, evidentiary needs and the other circumstances described in Section 1.
| Data category | Indicative period | Purpose and basis |
|---|---|---|
| Account registration data (Customer and Users) | For as long as the account exists, plus applicable statutory periods after closure | Performance of the contract; compliance with legal obligations |
| Documents and Envelopes | For as long as the Customer keeps them in the account | Provision of the service; the Customer manages its own repository |
| Signature evidence, audit trails and signature certificates | May be kept for the applicable limitation period — as a rule, up to 10 years under Brazilian law — including after the Envelope is deleted or the account is closed | Preserving the evidentiary integrity of signatures; establishing, exercising or defending legal claims; fraud prevention |
| Identity-verification images (selfies, liveness records and photos of identity documents), where required by the sender | Linked to the signature evidence they relate to; subject to the same regime as the evidence above | Assuring the authenticity of the signature; fraud prevention |
| Billing, invoicing and tax records | At least 5 years | Legal obligation (applicable tax law) |
| Access records and application logs | Limited operational periods, observing the minimum periods required by applicable law | Security, diagnostics and fraud prevention; legal obligation |
| Referral click data (Affiliate program) | Automatically deleted after 12 months | Referral attribution; legitimate interests |
| Support communications | For the period necessary to handle the matter and improve the service | Customer and Signer support; legitimate interests |
3.2. Signature evidence — which includes, among other elements, IP address, device and browser data, date and time, geolocation where provided, authentication records and the images submitted in verification flows — forms the audit trail and the signature certificate of each Envelope. It exists to prove who signed, when and how. For that reason, it may be preserved even after the Envelope is deleted or the account is closed, for as long as the signature may be challenged in or out of court.
3.3. Once the applicable periods have elapsed, data is deleted or anonymized in the ordinary course of Signater's operations, without prejudice to the retention grounds permitted by law.
4.1. The Customer may delete Envelopes and Documents through the Platform. Deletion removes access to the item on the Platform for the Customer and its Users.
4.2. After deletion, residual copies may temporarily persist in backups and in Signater's internal systems before final erasure, which occurs in the ordinary course of our operational routines.
4.3. Deleting an Envelope does not erase the signature evidence, audit trails and certificates linked to it, which may be retained as described in Section 3, including the identity-verification images associated with the signature.
4.4. Deletion actions performed by an authorized User of the account constitute the Customer's instruction to Signater under the DPA.
4.5. Signers who wish to delete or correct data contained in a Document should first contact the sender of the Envelope, who is the controller of that data. Signater responds to data-subject requests to the extent of its role as processor, as described in the Privacy Policy.
5.1. Cancelling a paid subscription does not close the account: at the end of the paid period, the account moves to the Free Plan, keeping access to the Platform and to its Documents, as described in the Terms of Service.
5.2. The Customer may request the permanent closure of the account and the deletion of the data associated with it by writing to [email protected]. Signater may take reasonable steps to confirm the identity and authority of the requester before acting on the request.
5.3. Once the request is fulfilled, Signater will delete or anonymize the personal data associated with the account within a reasonable period, except for the legal and evidentiary retentions described in Section 3 — in particular tax records, records required by law, and signature evidence of completed Envelopes.
5.4. Before requesting closure, the Customer is responsible for downloading any Documents it wishes to keep. After closure, Signater does not guarantee that the repository can be recovered.
6.1. Signater maintains backup routines intended for service continuity and disaster recovery. Backup copies are stored in a region geographically separate from the primary environment, precisely for disaster protection; they are kept for limited operational periods and are not intended to serve as long-term archival storage on the Customer's behalf.
6.2. Data deleted from the active environment may remain in backups until the relevant backup cycles rotate and expire. During that interval, backups are used only for continuity and recovery purposes.
6.3. If a backup restoration reinstates data that had already been deleted from the active environment, Signater will take reasonable steps to reapply the applicable deletions.
7.1. Signater may update this Policy from time to time, including to reflect changes in the law, in the Platform or in the providers we engage. Material changes will be announced with reasonable prior notice, by e-mail or through a notice on the Platform.
7.2. The current version will always be available at signater.com/data-retention. Continued use of the Platform after a change takes effect constitutes acceptance of the updated version.
8.1. Questions about this Policy and requests relating to data retention and deletion may be addressed to Signater's Data Protection Officer (Encarregado) at [email protected]. For general support, use [email protected].
8.2. Signater LLC, 2125 Biscayne Blvd, Ste 204 #27075, Miami, Florida 33137, United States. Signater Tecnologia Ltda, CNPJ 50.348.626/0001-61, Alameda Rio Negro, 503, Suite 2020, Alphaville, Barueri/SP, 06454-000, Brazil.