DataPhem

Data-driven products that transform business

DataPhem builds intelligent software solutions — from secure digital signatures to enterprise resource planning and real-time financial intelligence.

Legal

Privacy Policy

How DataPhem collects, uses, protects, and manages personal information across its products and services.

Effective date: May 2026

1. Introduction

Welcome to DataPhem, an electronic signature and digital document management platform owned and operated by DataPhem LLC ("DataPhem," "we," "our," or "us").

At DataPhem, protecting the privacy, confidentiality, and security of the information entrusted to us is one of our highest priorities. We recognize that our customers rely on DataPhem to manage sensitive business documents, contracts, agreements, and legally binding electronic signatures. Accordingly, we are committed to handling personal information responsibly, transparently, and in accordance with applicable privacy and data protection laws.

This Privacy Policy explains how DataPhem collects, uses, stores, discloses, transfers, and safeguards personal information when individuals or organizations access or use DataPhem, our websites, applications, APIs, integrations, customer support services, and any other products or services that reference this Privacy Policy (collectively, the "Services").

This Privacy Policy also explains the choices available to you regarding your personal information, the rights you may have under applicable privacy laws, and how you may exercise those rights.

By accessing or using DataPhem, creating an account, uploading documents, signing documents, receiving documents for signature, integrating with our APIs, or otherwise interacting with the Services, you acknowledge that you have read and understood this Privacy Policy.

2. About DataPhem LLC

DataPhem LLC is a technology company and the parent organization behind its software subsidiaries and products. BothSign is a subsidiary and software product of DataPhem. DataPhem develops secure cloud-based software solutions designed to simplify business operations, automate workflows, improve collaboration, and facilitate legally recognized electronic transactions.

DataPhem is one of the software platforms developed and operated by DataPhem LLC. Throughout this Privacy Policy:

  • "DataPhem," "we," "our," and "us" refer to DataPhem LLC.
  • "DataPhem" refers to the electronic signature, document management, workflow automation, and related services provided by DataPhem.
  • "Services" means DataPhem together with any related websites, mobile applications, APIs, integrations, customer portals, and support services operated by DataPhem.

Unless otherwise specified, DataPhem acts as the provider of the Services and, depending on the circumstances, may act as a data controller or data processor under applicable privacy laws.

3. Scope of this Privacy Policy

This Privacy Policy applies to personal information collected through:

  • DataPhem's website;
  • Customer portals and dashboards;
  • Web and mobile applications;
  • Electronic signature workflows;
  • Document upload and storage services;
  • APIs and developer tools;
  • Third-party integrations;
  • Customer support interactions;
  • Sales and marketing communications;
  • Online events, webinars, surveys, and demonstrations;
  • Any other products or services that link to this Privacy Policy.

This Privacy Policy applies whether you are:

  • An account owner;
  • An organization administrator;
  • An employee using DataPhem through your employer;
  • A document sender;
  • A document recipient;
  • A signer;
  • A witness;
  • An approver;
  • An API developer;
  • A website visitor; or
  • Any individual whose personal information is processed through DataPhem.

This Privacy Policy does not apply to third-party websites, applications, or services that may be linked from DataPhem or integrated with the Services. Those services are governed by their own privacy policies, and DataPhem is not responsible for their privacy practices.

4. Our Privacy Principles

DataPhem is committed to building and operating DataPhem according to the following principles:

  • Transparency - We clearly explain what information we collect and how we use it.
  • Security by Design - Security and privacy considerations are incorporated into the design and operation of our Services.
  • Data Minimization - We collect only the information reasonably necessary to provide and improve the Services.
  • Purpose Limitation - Personal information is processed only for legitimate and disclosed purposes.
  • Customer Control - We provide customers with tools to access, manage, and delete information where appropriate.
  • Confidentiality - We implement administrative, technical, and organizational safeguards designed to protect personal information.
  • Compliance - We strive to comply with applicable privacy, security, and electronic signature laws in the jurisdictions where we operate.

5. Information We Collect

The information DataPhem collects depends on how you interact with DataPhem, the features you use, your organization’s configuration, and applicable legal requirements. We collect information directly from you, automatically through your use of the Services, from other users of the Services, and, where permitted by law, from trusted third-party sources.

5.1 Information You Provide Directly

When you create an account, use DataPhem, contact us, or otherwise interact with the Services, you may voluntarily provide information including, but not limited to:

Personal Identification Information

  • Full name
  • Business or organization name
  • Job title
  • Email address
  • Telephone number
  • Mailing or billing address
  • Username
  • Profile photograph (optional)
  • Preferred language
  • Time zone
  • Country or region

Account Credentials

To provide secure access to the Services, DataPhem collects account authentication information such as:

  • Username
  • Password (stored using industry-standard hashing and encryption techniques)
  • Multi-factor authentication settings
  • Authentication tokens
  • Password recovery information
  • Security questions (where applicable)

DataPhem does not store passwords in plain text.

Organization Information

If you create or administer an organization within DataPhem, we may collect:

  • Organization name
  • Business address
  • Industry classification
  • Company size
  • Tax identification number (where applicable)
  • Workspace settings
  • User roles and permissions
  • Administrative preferences
  • Subscription information

5.2 Document Information

Because DataPhem is a document management and electronic signature platform, DataPhem processes documents that users upload or create through the Services.

Depending on how the Services are used, this information may include:

  • Contracts
  • Agreements
  • Forms
  • Invoices
  • Purchase orders
  • Human resource documents
  • Legal documents
  • Financial documents
  • Government forms
  • Templates
  • Images
  • PDF files
  • Microsoft Office documents
  • Metadata associated with uploaded files

Document metadata may include:

  • File names
  • File size
  • File type
  • Date created
  • Date modified
  • Version history
  • Folder location
  • Workflow status
  • Document ownership
  • Sharing permissions

DataPhem processes these documents solely for the purpose of providing the Services, unless otherwise authorized by the customer or required by law.

5.3 Electronic Signature Information

To facilitate legally recognized electronic signatures, DataPhem collects and maintains records associated with signing activities, including:

  • Electronic signatures
  • Initials
  • Signature images
  • Typed signatures
  • Signature placement coordinates
  • Signing order
  • Signature timestamps
  • Document completion timestamps
  • IP addresses
  • Browser information
  • Device information
  • Operating system
  • Authentication method
  • Audit trail events
  • Certificate information (where applicable)
  • Consent records

These records are used to establish the authenticity, integrity, and evidentiary value of electronically signed documents.

5.4 Identity Verification Information

Certain customers may enable identity verification features.

Where these features are used, DataPhem or its authorized service providers may process information necessary to verify the identity of document participants, including information voluntarily submitted by users or generated through supported verification methods.

Identity verification requirements vary depending on customer configuration, applicable law, and the verification services selected.

5.5 Payment and Billing Information

When purchasing subscriptions or paid services, payment transactions are processed through authorized third-party payment providers.

Depending on the transaction, DataPhem may receive:

  • Billing name
  • Billing address
  • Email address
  • Subscription plan
  • Invoice information
  • Transaction identifiers
  • Payment status
  • Tax information
  • Purchase history

For security purposes, DataPhem generally does not store complete payment card numbers or payment authentication credentials.

5.6 Customer Communications

When you communicate with DataPhem, we may retain records of those interactions, including:

  • Customer support requests
  • Live chat conversations
  • Emails
  • Telephone communications
  • Product feedback
  • Survey responses
  • Bug reports
  • Feature requests
  • Training sessions
  • Webinar participation

These communications help us provide customer support, improve our Services, and maintain quality assurance.

5.7 Information Collected Automatically

When you access DataPhem, DataPhem automatically collects certain technical and usage information to operate, secure, and improve the Services.

This information may include:

Device Information

  • Device type
  • Device manufacturer
  • Operating system
  • Browser type
  • Browser version
  • Screen resolution
  • Device identifiers
  • Language settings
  • Time zone

Network Information

  • IP address
  • Internet service provider
  • Network identifiers
  • Approximate geographic location derived from IP address

Usage Information

  • Login history
  • Session duration
  • Pages viewed
  • Features accessed
  • Documents created
  • Documents viewed
  • Documents signed
  • API requests
  • Integration activity
  • Error logs
  • Performance metrics
  • System diagnostics

Security Information

To help protect our Services and users, we may collect:

  • Authentication logs
  • Failed login attempts
  • Access timestamps
  • Session identifiers
  • Security event logs
  • Fraud detection signals
  • Abuse prevention indicators

5.8 Cookies and Similar Technologies

DataPhem uses cookies, local storage, pixels, software development kits (SDKs), and similar technologies to:

  • Authenticate users
  • Maintain secure sessions
  • Remember user preferences
  • Improve website functionality
  • Analyze platform performance
  • Measure feature adoption
  • Personalize user experiences
  • Detect fraudulent or malicious activity
  • Support security monitoring
  • Enhance platform reliability

Some cookies are essential to the operation of DataPhem, while others are optional and may be managed through your browser settings or cookie preferences, where available.

Additional information regarding our use of cookies is provided in our Cookie Policy.

5.9 Information Received from Other Sources

DataPhem may receive information about you from trusted third parties, including:

  • Identity providers
  • Enterprise single sign-on (SSO) providers
  • Payment processors
  • Customer relationship management systems
  • Cloud storage providers
  • Calendar providers
  • Integration partners
  • Fraud prevention services
  • Publicly available business information
  • Other users who invite you to use DataPhem

We use this information only for purposes consistent with this Privacy Policy and applicable law.

5.10 Sensitive Personal Information

DataPhem is designed to process business documents, some of which may contain sensitive personal information.

Depending on how customers use the Services, uploaded documents may include information such as government-issued identifiers, financial information, employment records, health-related information, or other sensitive data.

DataPhem processes such information only as necessary to provide the Services, fulfill contractual obligations, comply with applicable law, or as otherwise instructed by the customer acting as the data controller. We encourage customers to upload only the information necessary for their intended business purpose and to avoid including sensitive personal information unless required.

6. How DataPhem Uses Personal Information

DataPhem uses personal information only where necessary to provide, maintain, improve, secure, and support DataPhem and other services operated by DataPhem. We process personal information only for legitimate business purposes, contractual obligations, legal compliance, or where you have provided your consent, as required by applicable law.

Depending on your interaction with DataPhem, DataPhem may use personal information for the following purposes.

6.1 Providing the Services

DataPhem processes personal information to operate and deliver DataPhem, including to:

  • Create and manage user accounts.
  • Authenticate users and maintain secure access.
  • Deliver electronic signature services.
  • Process signature requests.
  • Store and organize documents.
  • Generate document audit trails.
  • Maintain document version history.
  • Facilitate workflow automation.
  • Route documents for approval or signature.
  • Deliver completed documents.
  • Synchronize information across authorized devices.
  • Provide customer dashboards and reporting.
  • Manage subscriptions and workspaces.
  • Support API integrations and connected applications.

6.2 Identity Verification and Authentication

Where enabled by customers, DataPhem uses personal information to:

  • Verify user identities.
  • Authenticate signers.
  • Prevent unauthorized account access.
  • Detect fraudulent activity.
  • Support multi-factor authentication.
  • Validate electronic signature events.
  • Improve trust in electronic transactions.

Identity verification requirements may vary depending on customer configuration and applicable legal requirements.

6.3 Maintaining Legally Reliable Electronic Signature Records

Because DataPhem is an electronic signature platform, DataPhem maintains certain records necessary to preserve the integrity and evidentiary value of electronic transactions.

These records may include:

  • Signature timestamps.
  • Audit trail events.
  • Signing sequence.
  • Document completion history.
  • IP addresses.
  • Device information.
  • Authentication events.
  • Document hash values.
  • Certificate information, where applicable.
  • User consent records.

These records help demonstrate the authenticity and integrity of electronically signed documents and support compliance with applicable electronic signature laws.

6.4 Customer Support

DataPhem processes personal information to provide customer support and technical assistance, including to:

  • Respond to inquiries.
  • Diagnose technical issues.
  • Resolve software defects.
  • Investigate reported incidents.
  • Provide onboarding assistance.
  • Deliver implementation support.
  • Improve customer satisfaction.
  • Monitor service quality.

Support interactions may be recorded or retained for training, quality assurance, security, and dispute resolution purposes where permitted by law.

6.5 Service Communications

DataPhem may use your contact information to send communications relating to your use of DataPhem, including:

  • Account verification emails.
  • Password reset requests.
  • Security notifications.
  • Signature requests.
  • Document completion notifications.
  • Workflow updates.
  • Billing notices.
  • Subscription renewal reminders.
  • Maintenance announcements.
  • Changes to our Services.
  • Updates to legal agreements.

These communications are considered essential to the operation of the Services and generally cannot be opted out of while maintaining an active account.

6.6 Product Improvement

DataPhem continually improves DataPhem by analyzing how the Services are used.

We may use personal information to:

  • Evaluate feature adoption.
  • Identify usability improvements.
  • Improve accessibility.
  • Enhance performance.
  • Optimize system reliability.
  • Develop new functionality.
  • Improve document workflows.
  • Enhance search capabilities.
  • Improve collaboration features.
  • Measure customer satisfaction.

Whenever possible, DataPhem uses aggregated or de-identified information for product improvement activities.

6.7 Artificial Intelligence Features

DataPhem may provide optional artificial intelligence ("AI") features designed to improve productivity and automate portions of document workflows.

Depending on the Services used, AI features may assist with:

  • Document summarization.
  • Clause extraction.
  • Metadata extraction.
  • Intelligent document classification.
  • OCR enhancement.
  • Suggested signature placement.
  • Workflow recommendations.
  • Search optimization.
  • Content organization.
  • Intelligent automation.

AI-generated outputs are intended solely to assist users and should be independently reviewed before being relied upon for legal, financial, regulatory, or business decisions.

Unless expressly stated, DataPhem does not provide legal advice through AI features.

6.8 Security and Fraud Prevention

Protecting customer information is a fundamental objective of DataPhem.

Personal information may be processed to:

  • Detect suspicious activity.
  • Identify fraudulent behavior.
  • Prevent unauthorized access.
  • Monitor account security.
  • Investigate security incidents.
  • Prevent abuse of the Services.
  • Protect customer accounts.
  • Enforce platform security policies.
  • Maintain audit records.
  • Detect malware or malicious software.
  • Protect system infrastructure.

6.9 Legal and Regulatory Compliance

DataPhem processes personal information where necessary to comply with applicable legal obligations, including to:

  • Respond to lawful governmental requests.
  • Comply with court orders.
  • Meet tax obligations.
  • Maintain financial records.
  • Fulfill contractual obligations.
  • Enforce our legal rights.
  • Protect our users.
  • Resolve disputes.
  • Comply with applicable privacy, electronic signature, consumer protection, anti-money laundering, anti-fraud, sanctions, export control, and other legal requirements.

6.10 Analytics and Business Intelligence

DataPhem may analyze information to better understand platform performance and customer needs.

This includes:

  • Usage analytics.
  • Performance monitoring.
  • Capacity planning.
  • Reliability engineering.
  • Service availability.
  • Error analysis.
  • Operational reporting.
  • Forecasting.
  • Internal business intelligence.

Whenever practical, analytics are performed using aggregated, anonymized, or de-identified information.

6.11 Research and Innovation

DataPhem may use aggregated or de-identified information to:

  • Improve our Services.
  • Develop new products.
  • Evaluate emerging technologies.
  • Conduct internal research.
  • Improve platform security.
  • Enhance accessibility.
  • Measure operational efficiency.

DataPhem does not intentionally use customer documents or electronic signatures to train general-purpose artificial intelligence models without appropriate authorization or another lawful basis.

6.12 Marketing Communications

Where permitted by applicable law, DataPhem may send:

  • Product announcements.
  • Educational content.
  • Service updates.
  • Newsletters.
  • Event invitations.
  • Promotional offers.
  • Customer success stories.
  • Product surveys.

Recipients may opt out of marketing communications at any time by following the unsubscribe instructions included in the communication or by adjusting communication preferences within their account.

Opting out of marketing communications does not affect essential service-related communications.

6.13 Corporate Transactions

If DataPhem is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or other corporate transaction, personal information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality obligations.

Where required by law, affected individuals will be notified of any material changes relating to the processing of their personal information.

6.14 Other Compatible Purposes

DataPhem may process personal information for additional purposes that are compatible with the original purpose for which the information was collected, provided such processing is permitted by applicable law and consistent with this Privacy Policy.

Where required, DataPhem will obtain your consent before processing personal information for a materially different purpose.

7. Legal Bases for Processing Personal Information

Where DataPhem processes personal information that is subject to the General Data Protection Regulation ("GDPR"), the United Kingdom GDPR, or similar privacy laws, we process personal information only where a valid legal basis exists.

Depending on the circumstances, DataPhem may rely on one or more of the following legal bases.

7.1 Performance of a Contract

DataPhem processes personal information where necessary to fulfill our contractual obligations, including to:

  • Create and manage user accounts.
  • Deliver DataPhem Services.
  • Process electronic signatures.
  • Store documents.
  • Manage workflows.
  • Authenticate users.
  • Process subscriptions.
  • Provide customer support.
  • Maintain audit records.

Without processing this information, we may be unable to provide the Services.

7.2 Legitimate Interests

DataPhem may process personal information where necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms.

Examples include:

  • Improving the Services.
  • Preventing fraud.
  • Maintaining platform security.
  • Monitoring system performance.
  • Detecting abuse.
  • Developing new functionality.
  • Conducting internal analytics.
  • Supporting customers.
  • Protecting our legal rights.
  • Maintaining business continuity.

7.3 Legal Obligations

We may process personal information to comply with applicable legal obligations, including:

  • Tax laws.
  • Accounting requirements.
  • Court orders.
  • Regulatory investigations.
  • Electronic signature regulations.
  • Anti-fraud obligations.
  • Anti-money laundering laws where applicable.
  • Export control and sanctions requirements.
  • Consumer protection laws.

7.4 Consent

Certain processing activities are performed only with your consent where required by law.

These may include:

  • Optional marketing communications.
  • Certain cookies and analytics technologies.
  • Optional AI-powered productivity features.
  • Participation in surveys or research.
  • Other activities where consent is legally required.

You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.

7.5 Protection of Vital Interests

In limited circumstances, DataPhem may process personal information where necessary to protect the vital interests of an individual or another person, such as responding to serious security incidents or preventing imminent harm.

8. How DataPhem Shares Personal Information

DataPhem does not sell your personal information. We disclose personal information only where necessary to operate DataPhem, fulfill contractual obligations, comply with applicable law, protect our rights, or with your authorization.

Depending on the circumstances, we may share personal information with the following categories of recipients.

8.1 Within DataPhem

Authorized employees, contractors, and personnel may access personal information only when necessary to perform their assigned responsibilities and only subject to appropriate confidentiality obligations and access controls.

Access is limited based on business need and the principle of least privilege.

8.2 Service Providers and Subprocessors

DataPhem engages trusted third-party service providers ("Subprocessors") to perform services on our behalf.

Depending on the Services used, these providers may assist with:

  • Cloud infrastructure hosting.
  • Secure document storage.
  • Payment processing.
  • Email delivery.
  • Customer support.
  • Identity verification.
  • Authentication services.
  • Monitoring and logging.
  • Error reporting.
  • Analytics.
  • Customer communications.
  • Backup and disaster recovery.
  • Security monitoring.
  • Fraud prevention.

Each subprocessor is contractually required to:

  • Process information only on DataPhem's documented instructions.
  • Maintain appropriate security safeguards.
  • Protect confidentiality.
  • Comply with applicable privacy laws.
  • Notify DataPhem of security incidents where required.

DataPhem remains responsible for managing its subprocessors in accordance with applicable law.

8.3 Organization Administrators

If you use DataPhem through an organization, your organization's authorized administrators may have access to certain information associated with your account, documents, workflows, and usage, in accordance with your organization's policies and permissions.

8.4 Other Users

Information may be shared with other authorized users when necessary to facilitate document workflows, including:

  • Document senders.
  • Signers.
  • Approvers.
  • Witnesses.
  • Delegates.
  • Organization administrators.
  • Team members with appropriate permissions.

Only information necessary to complete the workflow is shared.

8.5 Third-Party Integrations

If you choose to connect DataPhem with third-party applications or services, DataPhem may share information necessary to enable those integrations.

Examples include:

  • Cloud storage providers.
  • Customer relationship management systems.
  • Productivity platforms.
  • Identity providers.
  • Workflow automation tools.
  • Business management applications.

Your use of third-party integrations is subject to the privacy policies and terms of those providers.

8.6 Professional Advisors

DataPhem may disclose information to professional advisors where reasonably necessary, including:

  • Attorneys.
  • Auditors.
  • Accountants.
  • Insurance providers.
  • Financial advisors.
  • Compliance consultants.

Such disclosures are subject to appropriate confidentiality obligations.

8.7 Business Transactions

If DataPhem undergoes:

  • A merger.
  • Acquisition.
  • Corporate restructuring.
  • Financing transaction.
  • Sale of assets.
  • Bankruptcy.
  • Change in ownership.

Personal information may be transferred as part of that transaction, subject to appropriate safeguards and applicable law.

Where legally required, affected individuals will receive notice of the transaction and any resulting changes to this Privacy Policy.

8.8 Legal Compliance and Government Requests

DataPhem may disclose personal information where we believe in good faith that disclosure is necessary to:

  • Comply with applicable law.
  • Respond to lawful governmental requests.
  • Enforce our agreements.
  • Protect our legal rights.
  • Investigate fraud.
  • Prevent illegal activities.
  • Protect the safety of users or the public.
  • Defend against legal claims.

Where permitted by law, DataPhem will seek to limit disclosures to only the information reasonably necessary to satisfy the applicable legal requirement.

8.9 With Your Consent

DataPhem may disclose personal information for other purposes when you direct us to do so or where you have otherwise provided your consent.

9. International Data Transfers

DataPhem is a cloud-based platform that may be accessed globally.

As a result, personal information may be transferred to, processed in, or stored in countries other than the country in which it was originally collected.

Where DataPhem transfers personal information internationally, we implement appropriate safeguards designed to protect such information, which may include:

  • Standard Contractual Clauses (SCCs).
  • Adequacy decisions recognized by applicable authorities.
  • Contractual data protection commitments.
  • Technical and organizational security measures.
  • Encryption during transmission and storage.
  • Access controls.
  • Data minimization practices.

DataPhem takes reasonable measures to ensure that international transfers comply with applicable privacy and data protection laws.

10. Law Enforcement and Government Requests

DataPhem carefully reviews requests from law enforcement agencies, courts, and governmental authorities before disclosing customer information.

Unless prohibited by law, we may:

  • Review the legal validity of requests.
  • Challenge requests that appear overly broad or unlawful.
  • Limit disclosures to the minimum information reasonably required.
  • Notify affected customers before disclosure where legally permitted.

Nothing in this Privacy Policy prevents DataPhem from complying with valid legal obligations or lawful judicial processes.

11. Security of Personal Information

DataPhem is committed to protecting the confidentiality, integrity, and availability of the information entrusted to us. Because DataPhem is designed to facilitate legally binding electronic signatures, document management, and business workflows, we implement administrative, technical, and organizational safeguards intended to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

No method of transmitting or storing information electronically is completely secure. While DataPhem strives to implement commercially reasonable safeguards aligned with industry best practices, we cannot guarantee absolute security.

11.1 Security Program

DataPhem maintains a comprehensive information security program designed to protect customer information throughout its lifecycle.

Our security program includes, where appropriate:

  • Information security governance.
  • Risk management processes.
  • Secure software development practices.
  • Security awareness and employee training.
  • Access management controls.
  • Encryption standards.
  • Network security protections.
  • Vulnerability management.
  • Security monitoring.
  • Incident response procedures.
  • Business continuity planning.
  • Disaster recovery capabilities.
  • Vendor security assessments.
  • Periodic security reviews.

Security measures are regularly reviewed and updated to address evolving threats and changes in technology.

11.2 Encryption

DataPhem employs encryption technologies designed to protect customer information.

Depending on the Services used, encryption may include:

  • Encryption of data in transit using industry-standard Transport Layer Security (TLS).
  • Encryption of stored data using strong cryptographic standards.
  • Secure key management practices.
  • Cryptographic hashing for passwords.
  • Secure transmission of authentication credentials.

Sensitive authentication credentials are never intentionally stored in plain text.

11.3 Access Controls

Access to personal information is restricted to authorized personnel who require access to perform their assigned responsibilities.

DataPhem implements access control measures including, where appropriate:

  • Role-based access control (RBAC).
  • Least privilege principles.
  • Multi-factor authentication for administrative access where supported.
  • Session management controls.
  • Password complexity requirements.
  • Access logging.
  • Periodic access reviews.
  • Account provisioning and de-provisioning procedures.

11.4 Infrastructure Security

To support the secure operation of DataPhem, DataPhem maintains technical safeguards designed to protect the underlying infrastructure, including:

  • Network segmentation.
  • Firewalls.
  • Intrusion detection and prevention measures.
  • Malware protection.
  • Security monitoring.
  • Logging and alerting.
  • Infrastructure hardening.
  • Secure configuration management.
  • Availability monitoring.
  • Backup systems.

11.5 Application Security

DataPhem integrates security into the design, development, and maintenance of DataPhem.

Our application security practices may include:

  • Secure development lifecycle practices.
  • Source code reviews.
  • Dependency management.
  • Vulnerability remediation.
  • Security testing.
  • Authentication controls.
  • Authorization enforcement.
  • Input validation.
  • Session security.
  • Audit logging.

11.6 Employee Confidentiality

Employees, contractors, and authorized personnel with access to customer information are subject to confidentiality obligations and receive appropriate training regarding privacy, information security, and acceptable handling of confidential information.

Access is limited to individuals with a legitimate business need.

12. Data Retention

DataPhem retains personal information only for as long as necessary to:

  • Provide the Services.
  • Fulfill contractual obligations.
  • Maintain audit records.
  • Comply with applicable legal requirements.
  • Resolve disputes.
  • Enforce agreements.
  • Protect our legal rights.
  • Improve platform reliability and security.

Retention periods vary depending on the type of information, customer configuration, legal obligations, and operational requirements.

12.1 Customer Documents

Documents uploaded to DataPhem are retained according to:

  • Customer account settings.
  • Subscription features.
  • Customer instructions.
  • Applicable legal or regulatory requirements.

Customers remain responsible for determining appropriate document retention periods based on their own legal and business obligations.

12.2 Audit Trails

Electronic signature audit trails may be retained for longer periods where necessary to preserve evidence of electronic transactions, satisfy legal obligations, support dispute resolution, or maintain the integrity of completed workflows.

12.3 Account Information

Account information may be retained while an account remains active and for a reasonable period thereafter where necessary to:

  • Comply with legal obligations.
  • Resolve disputes.
  • Prevent fraud.
  • Enforce agreements.
  • Maintain financial records.
  • Protect platform security.

12.4 Backups

Information contained in secure system backups may remain available for a limited period following deletion from production systems until backup media are overwritten or securely destroyed in accordance with DataPhem's backup retention procedures.

13. Business Continuity and Disaster Recovery

DataPhem maintains business continuity and disaster recovery procedures designed to support the ongoing availability and resilience of DataPhem.

These procedures may include:

  • Secure backups.
  • Redundant infrastructure.
  • Disaster recovery planning.
  • Service restoration procedures.
  • Operational resilience testing.
  • Availability monitoring.
  • Incident escalation procedures.

Business continuity capabilities are periodically reviewed and updated to support operational resilience.

14. Security Incidents

DataPhem maintains documented procedures for identifying, investigating, responding to, and mitigating security incidents.

Where appropriate, our incident response activities may include:

  • Incident identification.
  • Containment.
  • Investigation.
  • Risk assessment.
  • Recovery.
  • Corrective actions.
  • Root cause analysis.
  • Continuous improvement.

Where required by applicable law or contractual obligations, DataPhem will notify affected customers or regulatory authorities of qualifying security incidents within legally required timeframes.

15. Customer Responsibilities

Security is a shared responsibility.

Customers are responsible for helping protect their accounts and information by:

  • Maintaining the confidentiality of account credentials.
  • Using strong passwords.
  • Enabling multi-factor authentication where available.
  • Managing user permissions appropriately.
  • Protecting endpoint devices.
  • Reviewing document recipients before sending.
  • Complying with applicable laws.
  • Maintaining appropriate backups where desired.
  • Promptly notifying DataPhem of suspected unauthorized access or security incidents.

Customers remain responsible for the information they upload, transmit, or process through DataPhem.

16. Deletion of Personal Information

Subject to applicable law, contractual obligations, and legitimate business requirements, individuals may request deletion of certain personal information processed by DataPhem.

Upon receiving a valid request, DataPhem will evaluate whether the requested information:

  • May be deleted immediately;
  • Must be retained to comply with legal obligations;
  • Must be retained for dispute resolution, fraud prevention, or security purposes; or
  • Must be retained to fulfill contractual commitments.

Where deletion is approved, DataPhem will use commercially reasonable efforts to delete or anonymize the applicable information within a reasonable period, except where retention is required or permitted by law.

Deletion requests do not automatically remove information contained within secure backup systems until those backups are overwritten or expire in accordance with our retention procedures.

17. Your Privacy Rights

Depending on your location and applicable law, you may have certain rights regarding your personal information. DataPhem is committed to honoring these rights where required by law and providing transparent processes for exercising them.

Nothing in this section limits any rights you may have under applicable privacy legislation.

17.1 Right to Access

You may request confirmation of whether DataPhem processes your personal information and, where applicable, request access to that information.

Subject to applicable law, you may also request information regarding:

  • The categories of personal information processed.
  • The purposes for which information is processed.
  • The categories of recipients with whom information has been shared.
  • The source of the information, where not collected directly from you.
  • The anticipated retention period for the information.

17.2 Right to Correct

If your personal information is inaccurate, incomplete, or outdated, you may request that it be corrected or updated.

Where possible, users may update certain account information directly through their DataPhem account settings.

17.3 Right to Delete

Subject to legal, contractual, security, and operational requirements, you may request deletion of your personal information.

Deletion requests may be limited where retention is necessary to:

  • Comply with legal obligations.
  • Complete ongoing transactions.
  • Resolve disputes.
  • Detect fraud.
  • Protect platform security.
  • Enforce agreements.
  • Preserve electronic signature records where legally required.

17.4 Right to Restrict Processing

Where permitted by law, you may request that DataPhem temporarily restrict the processing of your personal information while certain issues are reviewed.

17.5 Right to Object

You may object to certain processing activities where DataPhem relies on legitimate interests as the legal basis for processing.

DataPhem will evaluate such requests in accordance with applicable law.

17.6 Right to Data Portability

Where applicable, you may request a copy of certain personal information in a structured, commonly used, and machine-readable format.

Where technically feasible and legally permitted, you may also request that such information be transmitted to another service provider.

17.7 Right to Withdraw Consent

Where DataPhem relies on your consent for processing, you may withdraw that consent at any time.

Withdrawal of consent does not affect processing that occurred before consent was withdrawn.

17.8 Right to Lodge a Complaint

If you believe DataPhem has processed your personal information in violation of applicable privacy laws, you may contact us using the information provided in this Privacy Policy.

Where applicable, you may also lodge a complaint with your local supervisory authority or privacy regulator.

18. California Privacy Rights

If you are a resident of California, you may have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), subject to applicable exceptions.

Depending on applicable law, California residents may have the right to:

  • Know what categories of personal information we collect.
  • Know the purposes for which personal information is used.
  • Request access to personal information.
  • Request deletion of certain personal information.
  • Request correction of inaccurate personal information.
  • Request information regarding disclosures of personal information.
  • Limit the use of certain sensitive personal information where applicable.
  • Be free from unlawful discrimination for exercising privacy rights.

DataPhem does not sell personal information as that term is defined under the CCPA/CPRA.

DataPhem does not knowingly share personal information for cross-context behavioral advertising unless expressly disclosed and permitted by applicable law.

19. European Privacy Rights

Individuals located within the European Economic Area (EEA), the United Kingdom, or Switzerland may have additional rights under applicable data protection laws.

These rights may include:

  • Access.
  • Rectification.
  • Erasure.
  • Restriction of processing.
  • Data portability.
  • Objection to processing.
  • Withdrawal of consent.
  • The right not to be subject solely to automated decision-making where prohibited by law.

DataPhem will respond to verified requests within the timeframes required by applicable law.

20. Cookies and Similar Technologies

DataPhem uses cookies and similar technologies to provide secure, reliable, and personalized Services.

Cookies may be categorized as follows:

Essential Cookies

These cookies are necessary for the operation of DataPhem and cannot generally be disabled.

Examples include:

  • Authentication.
  • Session management.
  • Security.
  • Fraud prevention.
  • Load balancing.

Functional Cookies

Functional cookies help remember user preferences such as:

  • Language.
  • Time zone.
  • Display preferences.
  • Accessibility settings.

Analytics Cookies

Analytics technologies help DataPhem understand how users interact with DataPhem by collecting aggregated information regarding:

  • Page views.
  • Feature usage.
  • Navigation patterns.
  • Performance metrics.
  • Error reporting.

Performance Cookies

Performance technologies assist in monitoring system reliability, service availability, and infrastructure performance.

Marketing Cookies

Where permitted by law, DataPhem may use marketing technologies to communicate information about our products and services.

Marketing cookies are used only where required consent has been obtained.

Users may manage cookie preferences through browser settings or available cookie preference tools.

For additional information, please refer to our Cookie Policy.

21. Children's Privacy

DataPhem is intended for business and professional use and is not directed to children.

DataPhem does not knowingly collect personal information from individuals under the age required by applicable law to provide valid consent without appropriate authorization.

If DataPhem becomes aware that personal information has been collected from a child in violation of applicable law, we will take reasonable steps to delete such information.

Parents or legal guardians who believe a child has provided personal information to DataPhem should contact us promptly.

22. Changes to this Privacy Policy

DataPhem may update this Privacy Policy from time to time to reflect:

  • Changes in applicable laws.
  • New products or services.
  • Changes to platform functionality.
  • Security improvements.
  • Business operations.
  • Regulatory guidance.

When material changes are made, DataPhem will provide notice through appropriate means, which may include:

  • Email notifications.
  • Website announcements.
  • In-application notices.
  • Updated publication dates.

Your continued use of DataPhem after the effective date of an updated Privacy Policy constitutes acknowledgment of the revised Privacy Policy to the extent permitted by applicable law.

23. Contact DataPhem

If you have questions, requests, or concerns regarding this Privacy Policy or DataPhem's privacy practices, you may contact us using the information below.

DataPhem LLC

Privacy Office

Website: https://bothsign.com

Email: [privacy@bothsign.com](mailto:privacy@bothsign.com)

Support Email: [support@bothsign.com](mailto:support@bothsign.com)

If required by applicable law, DataPhem will respond to verified privacy requests within the applicable statutory timeframe.

24. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws applicable to DataPhem LLC, without regard to conflict of law principles, except where mandatory privacy or consumer protection laws require otherwise.

Nothing in this Privacy Policy limits any rights that individuals may have under applicable data protection or consumer protection laws.

25. Data Controller and Data Processor Roles

Depending on the circumstances in which DataPhem is used, DataPhem may act as either a Data Controller or a Data Processor (or similar role under applicable law).

25.1 When DataPhem Acts as a Data Controller

DataPhem acts as a Data Controller for personal information processed to:

  • Create and manage customer accounts.
  • Process subscription and billing information.
  • Provide customer support.
  • Improve the Services.
  • Maintain platform security.
  • Prevent fraud and abuse.
  • Manage our website and business operations.
  • Comply with legal obligations.

When acting as a Data Controller, DataPhem determines the purposes and means of processing personal information.

25.2 When DataPhem Acts as a Data Processor

For documents, electronic signatures, workflows, and personal information uploaded or managed by customers through DataPhem, DataPhem generally acts as a Data Processor (or "Service Provider" where applicable).

In these circumstances:

  • Customers determine the purposes for which personal information is processed.
  • Customers determine what information is uploaded.
  • Customers determine document retention periods.
  • Customers determine who may access documents.
  • Customers are responsible for obtaining any necessary consents and complying with applicable privacy laws.

DataPhem processes such information only on documented instructions from the customer, except where otherwise required by applicable law.

26. Electronic Signature Compliance

DataPhem is designed to facilitate electronic signatures and digital document workflows.

DataPhem designs and operates DataPhem to support compliance with applicable electronic signature laws, including, where applicable:

  • United States Electronic Signatures in Global and National Commerce Act (ESIGN Act).
  • Uniform Electronic Transactions Act (UETA).
  • Regulation (EU) No. 910/2014 on electronic identification and trust services (eIDAS), where applicable.
  • Other electronic transaction laws applicable to the jurisdictions in which our customers operate.

Nothing in this Privacy Policy constitutes legal advice regarding the enforceability or legal effect of any electronic signature.

Customers remain responsible for determining whether DataPhem is appropriate for their intended legal, regulatory, or contractual requirements.

27. Artificial Intelligence Governance

DataPhem may provide optional artificial intelligence ("AI") capabilities within DataPhem to assist customers with document workflows and productivity.

Examples may include:

  • Document summarization.
  • Clause extraction.
  • Optical Character Recognition (OCR).
  • Metadata extraction.
  • Workflow recommendations.
  • Intelligent search.
  • Document classification.
  • Smart document routing.

AI features are intended to assist users and should not replace independent review or professional judgment.

Unless expressly stated otherwise:

  • AI outputs are not legal advice.
  • AI outputs are not guaranteed to be complete or error-free.
  • Users remain responsible for reviewing all AI-generated content before relying upon it.

DataPhem implements governance measures designed to support the responsible development and use of AI capabilities, including ongoing evaluation of accuracy, security, and privacy considerations.

28. Data Processing Agreements

Where required by applicable law or customer contract, DataPhem may enter into a Data Processing Agreement ("DPA") with customers.

A DPA may address matters including:

  • Processing instructions.
  • Confidentiality.
  • Security obligations.
  • International data transfers.
  • Audit rights.
  • Assistance with data subject requests.
  • Incident notification.
  • Return or deletion of customer data upon termination.

Where applicable, the DPA forms part of the contractual relationship between DataPhem and the customer.

29. Subprocessors

To provide DataPhem, DataPhem may engage carefully selected subprocessors to perform services on our behalf.

Subprocessors may provide services such as:

  • Cloud infrastructure.
  • Secure document storage.
  • Content delivery.
  • Email delivery.
  • Payment processing.
  • Identity verification.
  • Authentication.
  • Customer support.
  • Analytics.
  • Monitoring.
  • Logging.
  • Security.
  • Backup and disaster recovery.

DataPhem requires subprocessors to:

  • Maintain appropriate technical and organizational safeguards.
  • Process personal information only on documented instructions.
  • Protect confidentiality.
  • Comply with applicable privacy obligations.
  • Notify DataPhem of relevant security incidents where required.

DataPhem remains responsible for the management of its subprocessors in accordance with applicable law and contractual commitments.

30. Security Certifications and Compliance

DataPhem continually evaluates and enhances its security program.

Depending on our operational maturity, customer requirements, and regulatory obligations, DataPhem may pursue or maintain security frameworks and certifications such as:

  • SOC 2.
  • ISO/IEC 27001.
  • ISO/IEC 27701.
  • CSA STAR.
  • NIST Cybersecurity Framework alignment.
  • Regional privacy and security certifications as appropriate.

Where certifications have been achieved, additional information may be made available through our Trust Center or upon request, subject to applicable confidentiality obligations.

31. Availability of Security Documentation

Subject to appropriate confidentiality protections, DataPhem may make available certain security and compliance documentation to customers, prospective customers, or auditors, including where appropriate:

  • Security whitepapers.
  • Compliance reports.
  • Data Processing Agreements.
  • Subprocessor information.
  • Security questionnaires.
  • Penetration testing summaries.
  • Business continuity information.
  • Disaster recovery summaries.

Requests may be subject to reasonable verification and confidentiality requirements.

32. Privacy by Design and by Default

DataPhem is committed to integrating privacy considerations throughout the lifecycle of DataPhem.

When designing, developing, and operating our Services, we strive to:

  • Minimize unnecessary collection of personal information.
  • Limit access based on legitimate business need.
  • Apply appropriate security controls.
  • Support customer privacy choices.
  • Reduce privacy risks during system design.
  • Evaluate new features for privacy impacts.
  • Continuously improve our privacy and security practices.

Privacy and security considerations are incorporated into our software development, operational processes, and organizational governance.

33. Contacting DataPhem's Privacy Office

Questions regarding this Privacy Policy, DataPhem's privacy practices, or requests relating to personal information may be directed to our Privacy Office.

DataPhem LLC

Privacy Office

Website: https://bothsign.com

Privacy Email: [privacy@bothsign.com](mailto:privacy@bothsign.com)

Support Email: [support@bothsign.com](mailto:support@bothsign.com)

General Inquiries: [info@bothsign.com](mailto:info@bothsign.com)

Mailing Address:

DataPhem LLC

*[Insert Registered Business Address]*

Where required by applicable law, DataPhem will respond to verified privacy requests within the applicable statutory timeframes.

34. Entire Privacy Policy

This Privacy Policy constitutes the complete statement of DataPhem's privacy practices relating to DataPhem unless supplemented by:

  • A separate Data Processing Agreement.
  • Enterprise customer agreements.
  • Regional privacy notices.
  • Product-specific privacy notices.
  • Additional legal terms expressly incorporated by reference.

If a conflict exists between this Privacy Policy and a separately executed customer agreement, the customer agreement shall govern to the extent of that conflict with respect to the applicable customer relationship.