Privacy Policy

Version 2026-09-24 · Effective 2026-09-24

Codeless Pty Ltd (ABN 81 669 880 773), trading as Signadoc, is bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth). This policy explains what personal information we collect through Signadoc, why we collect it, and how you can access or correct it.

1. Two roles we play

As the provider of Signadoc, we collect information about the people who hold accounts — their name, email address, timezone, signature images and sign-in activity. This policy covers that information.

As a processor for our customers, we host the documents our customers upload and the details of the recipients they invite. That information belongs to the customer’s organisation: we handle it on their instructions and do not use it for our own purposes. If you received a signing request and want your details corrected or removed, contact the organisation that sent it; we will help them action it.

2. What we collect

  • Account information — name, email address, hashed password, timezone, organisation membership and role, saved signature images.
  • Document information — the PDFs you upload, the fields placed on them, recipient names and email addresses, and the signature images recipients apply.
  • Signing evidence — for each recipient, the IP address, browser user agent, timezone and timestamps of opening, signing or declining. This is recorded to make an electronic signature reliable and is reproduced in the certificate of completion attached to every sealed document.
  • Technical logs — request logs, error reports and background job records, used to operate and secure the service.

We do not collect sensitive information (as defined in the Privacy Act) about account holders, and we ask that you do not upload it unless it is necessary for your document.

3. Why we collect it

  • to create and secure your account, including two-factor codes sent to your email;
  • to deliver the service — rendering documents, emailing signing requests and reminders, sealing completed documents;
  • to produce the audit trail and certificate that evidence a signature;
  • to apply plan limits, invoice you and support you;
  • to detect abuse and meet our legal obligations.

We do not sell personal information, we do not use it for advertising, and we do not use customer documents to train machine learning models.

4. Who we share it with

We disclose personal information only to:

  • the parties to a document — recipients can see the document, the sender’s name and email, and, after completion, the certificate listing every participant’s signing evidence;
  • service providers who host or transmit data for us — Amazon Web Services provides our hosting, document storage and email delivery, all in the Sydney region. They act on our instructions and may not use the data for their own purposes;
  • authorities where we are required or authorised by law.

We do not currently transfer personal information overseas. If that changes we will update this policy and take reasonable steps to ensure any overseas recipient handles the information consistently with the Australian Privacy Principles.

5. Cookies

Signadoc uses only the cookies it needs to work: a session cookie that keeps you signed in, a cookie recording which organisation you last used, and — if you choose “trust this device” — a cookie that lets you skip the two-factor code on that browser for 30 days. We do not use advertising or cross-site tracking cookies.

6. Security

Data is encrypted in transit (TLS) and at rest with our storage provider. Passwords are hashed with Argon2id and never stored in readable form. Every sign-in requires a code sent to your email address. Access to documents is scoped to the owning organisation, and administrative actions on our side are recorded in an append-only log.

No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

7. Retention

We keep account information while your account is open and for 30 days after it closes so you can export your data. Documents and their audit trails are kept while the owning organisation keeps them; completed documents and certificates may be retained longer where a party needs them as evidence of a transaction. Redacting a document permanently destroys the redacted content and the original file.

8. Access, correction and complaints

You can view and correct most of your information in Settings. To request access to, or correction of, information we hold about you, email contact@signadoc.com.au. We will respond within 30 days and will not charge you for making a request.

If you are unhappy with how we handled your personal information, contact us first at contact@signadoc.com.au. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

9. Changes

We may update this policy. The version and effective date are shown at the top of this page; material changes will be notified by email or in the application.

10. Contact

Privacy Officer, Codeless Pty Ltd, 2/60A Lambert Rd, Royston Park, South Australia, Australia. Email: contact@signadoc.com.au.