Privacy

Deutsch

Last updated: 30 July 2026

signeee is GDPR / DSGVO compliant by construction because your PDF is processed entirely inside your browser. No document data is transmitted to signeee servers, verifiable in your browser DevTools Network tab. signeee is operated by Die Quadratur UG in Hamburg, Germany, under EU jurisdiction.

Controller

Die Quadratur UG (haftungsbeschränkt)
Sierichstraße 120, 22299 Hamburg, Deutschland
Managing Director: Christian Durlej
Email: privacy@signeee.com

The short version

Your PDF never leaves your browser. signeee processes everything client-side. There is no upload.

What crosses the boundary

For the free flow: nothing. No PDF data, no filenames, no field positions. Open DevTools, Network, during a sign and you will see zero document payload.

For Pro accounts: only your email and login token, your encrypted signature library blobs and Stripe billing identifiers.

Server log files

When you load a page, our hosting provider processes technical connection data such as the requested URL, timestamp, browser type and IP address. This is required to deliver the site securely and reliably. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a secure, functioning website.

Usage statistics

We use the cookieless usage statistics provided by our hosting platform (Lovable Analytics). No cookies are set, no cross-site profiles are created and the data is aggregated. It tells us how many people visit which page, nothing about you personally and nothing about your documents. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in understanding basic site usage. Because no information is stored on or read from your device, no consent under § 25 TDDDG is required.

Fonts

All web fonts are served locally from our own infrastructure. No connection to Google Fonts or any other third-party font CDN is established, so no IP address of yours is transmitted to a font provider.

Accounts and payments

If you create a Pro account, we process your email address, authentication tokens and your encrypted signature library in order to provide the service. Legal basis: Art. 6(1)(b) GDPR, performance of a contract. Payment processing runs through Stripe, which receives the billing data required for the transaction. Legal basis: Art. 6(1)(b) GDPR, plus Art. 6(1)(c) GDPR for statutory retention of invoicing records.

Retention

Server log data is deleted or anonymised after a short period, normally within 30 days. Account data is stored for as long as your account exists and is deleted after closure, except where statutory retention periods under commercial and tax law apply, typically 6 to 10 years for invoicing records. Documents are never stored, because they never reach us.

Sub-processors

  • Cloudflare: static hosting and CDN
  • Supabase: authentication and database (Pro only)
  • Stripe: payments (Pro only)

Your rights (GDPR)

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) regarding processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time with effect for the future. Email privacy@signeee.com.

Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Hamburg, Germany.