Legal Documentation
Privacy Policy
This policy explains what information SignNexa collects, how we use it, who we share it with, where it is stored, and the choices you have. It applies to signnexa.com and any SignNexa-operated subdomains. SignNexa is a product of Royal Freelancing, which operates the service.
1.Who we are
SignNexa is an email-signature, public-page, and domain/email monitoring platform. SignNexa is a product and brand of Royal Freelancing, a business registered in India and the owner, operator, and data controller for the service. For personal data that customers add about other people (for example, a colleague's details in a signature), Royal Freelancing acts as a data processor under our Data Processing Addendum.
Royal Freelancing
Kolkata, West Bengal, India
For any question about this policy or your data, contact us at hello (at) signnexa.com.
2.Account information
- Email address - your login identifier and the destination for account email.
- Name - shown in your account and used as a default sender name.
- Password - stored only as an Argon2id hash. We never store or log your plaintext password. If you sign in only with a social login provider (Google, Microsoft, LinkedIn, or Facebook), no usable password is set.
- Workspace membership - the workspaces you own or were invited to, and your role in each.
- Content you create - signatures, profiles, uploaded images (headshots, logos, banners), monitored assets, reports, and any public pages you choose to publish.
3.Usage information
- Session activity- the time of each sign-in, the originating IP address, and the user-agent string, used for security and the “active sessions” view.
- Product analytics - first-party counts such as link clicks and page visits shown in your dashboards.
- Website analytics - we use Google Analytics 4 (GA4), delivered through Google Tag Manager, to understand how visitors use signnexa.com. Under Google Consent Mode the tag container loads on page load with analytics storage defaulted to denied, so no analytics cookies or identifiers are stored until you accept the Analytics category in our cookie banner (see section 5). We do not use analytics for advertising, and we do not sell or share personal data.
- Operational logs - request and delivery metadata kept for reliability and abuse prevention; we do not log message bodies or secrets.
4.How we use information (legal bases)
For users in the UK, EU/EEA, and India, we rely on the following legal bases:
- Contract - to create and operate your account and provide the features you use.
- Legitimate interests - to keep the service secure, prevent abuse and fraud, and improve reliability.
- Consent - for non-essential cookies and website analytics, and for any optional marketing you opt into. You can withdraw consent at any time.
- Legal obligation - to meet tax, accounting, and other legal requirements.
5.Cookies and sessions
SignNexa uses strictly-necessary cookies - a signed,HttpOnlysession cookie (signnexa.sid) and a CSRF token - required to keep you signed in and to protect state-changing requests. We also use Google Analytics 4 (via Google Tag Manager) for website analytics; under Google Consent Mode its cookies are set only after you consent. We manage consent through CookieYes and do not run advertising or cross-site targeting cookies. See our Cookie Policy for the full list and your choices.
6.Email communications
We send transactional email only - verification, password reset, password-changed notices, workspace invitations, monitoring alerts and scheduled reports you have configured, replies to messages you send us, and rare service notices. Transactional email is delivered through our transactional email providers (currently Brevo and Amazon SES) and Microsoft 365 (see section 7). We do not send marketing email without prior opt-in. You can stop all SignNexa email by deleting your account (see section 10).
7.Sub-processors and third-party providers
We rely on a small number of vetted providers to run the service. They process data only as needed to provide their function and are bound by their own terms and data-processing agreements:
- Social login (Google, Microsoft, LinkedIn, Facebook) - if you choose “Continue with” a provider, we redirect you to that provider to sign in, and on your return we receive your basic profile (name, email, profile picture, and provider account id) to create or sign you in. We use a standard server-side OAuth redirect and do not embed the providers' tracking scripts. We store only the provider account id and email needed to recognise you - never your social password or long-lived access tokens. Each provider processes the sign-in under its own privacy policy.
- Google Tag Manager + Google Analytics 4 (Google) - tag management and website analytics. The container loads on page load under Google Consent Mode, but sets no analytics cookies or identifiers until you accept the Analytics category.
- CookieYes - our cookie consent management platform, which records and stores your cookie-consent choices.
- Brevo (Sendinblue SAS) - transactional email delivery. Brevo processes this data in the European Union (France).
- Amazon Web Services (AWS SES) - transactional email delivery. SES currently operates in the US East (N. Virginia) region.
- Microsoft 365 (Microsoft) - may be used as an alternative transactional email transport.
- Cloudflare - object storage (Cloudflare R2, in Western Europe) for user media and encrypted backups, content delivery (CDN), reverse proxy (which processes visitor IP addresses), and inbound email routing for the email-diagnostics tools.
- Hostinger - virtual private server hosting for the application and database, located in the United Kingdom (Manchester).
- Google PageSpeed Insights - when you run a website performance check, the URL you test is sent to Google to generate the report.
- Stripe (Stripe Payments)- our payment processor for paid subscriptions, operating under Royal Freelancing's own merchant account. When you pay, Stripe collects and processes your card and payment details directly and is certified PCI-DSS Level 1. Stripe may process this data in the United States. See section 13 for what we do and do not receive.
Email-diagnostics tools. When you use the Inbox Tester, the test message you send is received through Cloudflare email routing and processed only transiently: it is held for about 30 minutes and then deleted automatically. We show you the authentication results (such as SPF, DKIM, and DMARC) and do not store the raw message body. Our other diagnostic tools (DNS, SSL, domain and email health) query publicly available records for the domain you enter.
We do not sell your personal information and do not share it with advertisers or data brokers.
8.Where your data is stored and international transfers
The application, database, and user media are hosted in the United Kingdom (Hostinger, Manchester) and the European Union (Cloudflare R2, Western Europe), and encrypted backups are stored in the European Union (Cloudflare R2, Western Europe).
Some providers process limited data in the United States - Amazon SES (email delivery), Google (analytics and PageSpeed Insights), Stripe (payment processing), and the social-login providers you choose to use. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards such as the providers' Standard Contractual Clauses and, where applicable, their certification under the EU-US and UK-US Data Privacy Framework.
9.Data security
- HTTPS/TLS for all traffic.
- Argon2id password hashing; no plaintext passwords stored.
- Optional two-factor authentication (TOTP), with your 2FA secret encrypted at rest and never stored in the clear.
- Server-side sessions with revocation, plus CSRF protection on every state-changing request.
- Rate-limiting and account-lockout against brute-force attempts.
- Encrypted database backups on a rolling retention window.
No system is perfectly secure. To report a security concern, email hello (at) signnexa.com.
10.Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. You can:
- Access and update your account, profiles, and content from your dashboard.
- Manage cookie consent at any time through the cookie settings on our website.
- Disconnect social loginand continue with email and password (reset a password via “Forgot password” if you only used social login).
- Delete your account and data - see our Data Deletion Instructions.
- Complainto your local data-protection authority - for example the Information Commissioner's Office (UK), your EU supervisory authority, or the Data Protection Board of India - though we'd prefer you reach out to us first.
To exercise any of these rights, contact hello (at) signnexa.com. We respond within one month (or the period required by applicable law), do not charge a fee for reasonable requests, and may ask you to verify your identity before we act.
India (DPDP Act 2023). If you are in India, you also have the right to access a summary of the personal data we hold about you and how it is processed, to correct or erase it, to grievance redressal, and to nominate another person to exercise your rights in the event of death or incapacity. Our Grievance Officer is Rajesh Ravidas, reachable at hello (at) signnexa.com.
We do not use automated decision-making or profiling that produces legal or similarly significant effects about you.
11.Data retention
We keep account information while your account is active. When you request deletion, your account is deactivated immediately and enters a 30-day recovery period during which you can ask us to restore it; after that period ends, we permanently delete your user record, profiles, content, and personal workspace from our live systems. Limited data may be retained where required for legal, tax, security, or fraud-prevention reasons; encrypted backups cycle out and are overwritten automatically in line with our backup retention schedule. Where a specific retention period is not set, we keep data only as long as reasonably necessary for the purpose it was collected.
12.Children
SignNexa is intended for users aged 18 or older. We do not knowingly collect personal data from anyone under 18. Contact us if you believe a minor has signed up and we will remove the account.
13.Payments
Payments for paid subscriptions are processed by Stripeon behalf of Royal Freelancing, under Royal Freelancing's own merchant account. Your card details are entered into and processed directly by Stripe - SignNexa and Royal Freelancing never see or store your full card number; card-data security (PCI-DSS) is handled by Stripe. We store only limited billing metadata needed to run your subscription and meet our accounting obligations - for example your plan, billing country, the card brand and last four digits, and the Stripe customer and subscription identifiers. Invoices (including GST where applicable) are issued by Royal Freelancing. See our Refund & Cancellation Policy for more.
14.Changes & contact
We will post material changes at this URL and update the date above. Questions or requests: hello (at) signnexa.com.
Last updated: 1 August 2026