Privacy notice
This notice explains how SignWorkspace collects, uses, discloses and protects personal information, and how it supports customers' obligations under the Protection of Personal Information Act 4 of 2013 ("POPIA").
Last updated: 10 July 2026
1. Who this notice covers
This notice applies to: (a) Customer organisations and their Authorised Users who hold a SignWorkspace account; (b) Signers and other recipients who receive an envelope for viewing, approval or signature; and (c) visitors to our marketing website. It should be read together with the Terms of Service, Cookie Policy and, for customers, the Data Processing Addendum.
2. Two roles: responsible party and operator
Under POPIA, SignWorkspace acts in two capacities:
- Responsible party — for account registration, billing, marketing communications and website analytics, SignWorkspace decides the purpose and means of processing and is the responsible party.
- Operator — for the content of envelopes Customer sends (recipient names, contact details, document content, form field values and signatures), SignWorkspace processes personal information on Customer's instructions and behalf. Customer is the responsible party for that data, and the Data Processing Addendum governs that processing.
3. Information Officer
Our Information Officer, appointed in line with POPIA section 55, can be contacted at sales@signworkspace.com. [Information Officer name and Information Regulator registration reference to be inserted once confirmed.]
4. Information we collect
| Category | Examples |
|---|---|
| Account and identity data | Name, work email, phone number, organisation name, role, password hash |
| Billing data | Billing contact details, plan, invoices, payment status (card details are handled directly by our payment processor and are not stored by SignWorkspace) |
| Envelope and signer data | Recipient name, email, phone number, role, form field values, typed or drawn signature image, verification status |
| Verification data | One-time passcodes and verification outcome (email link, SMS or WhatsApp), sent to a phone number or email address the sender supplies |
| Audit and security data | IP address, device and browser identifiers, timestamps, document hash values, event logs |
| Support data | Correspondence and attachments submitted through the contact form or support channels |
| Website usage data | Pages visited and technical metadata, described further in the Cookie Policy |
Where Customer uploads special personal information (as defined in POPIA section 26, for example health information, biometric data or information about criminal behaviour) within Content, Customer is responsible for ensuring a lawful basis exists for doing so; SignWorkspace processes it only as an operator on Customer's instructions.
5. Why we process personal information
- To provide, operate and secure the Service, including sending envelopes, verifying signer identity and generating audit evidence;
- To create and administer accounts, and to bill Subscriptions;
- To provide customer support and respond to enquiries submitted through the contact form;
- To send service notifications (for example, envelope invitations, reminders and OTP codes) by email, SMS or WhatsApp;
- To send product updates and marketing communications, where permitted and subject to opt-out;
- To detect, investigate and prevent fraud, abuse and security incidents; and
- To comply with legal, regulatory, accounting and tax obligations.
6. Lawful basis for processing
We rely on one or more of the justifications recognised under POPIA section 11: performance of a contract with Customer or preparation to enter one; compliance with a legal obligation; protection of a legitimate interest of SignWorkspace or a third party (such as fraud prevention and service security), balanced against the data subject's interests; and consent, where required (for example, for optional marketing communications).
7. Sharing and subprocessors
We share personal information with service providers who process it on our behalf to deliver the Service, under written agreements that require appropriate security and confidentiality safeguards, consistent with POPIA section 20 and 21. Categories of provider currently used include:
- Cloud application hosting and document storage;
- Transactional email delivery (for envelope invitations, reminders and account notifications);
- SMS and WhatsApp messaging delivery (for one-time passcodes and notifications, where a customer enables those verification methods);
- Payment processing (for Subscription billing).
A named, up-to-date subprocessor list is available on request and will be published once finalised and contractually confirmed. We do not sell personal information, and we do not share it for third-party advertising purposes.
We may also disclose personal information where required by law, to protect rights, safety or property, or in connection with a merger, acquisition or asset sale, subject to continued protection under this notice.
8. Cross-border transfers
Some service providers may process personal information outside South Africa. Where this occurs, we take steps required by POPIA section 72 to ensure the recipient is subject to a law, binding corporate rules or contractual terms that provide an adequate level of protection substantially similar to POPIA, before transferring personal information to that jurisdiction.
9. Retention
We retain personal information for as long as needed to provide the Service, meet the purposes described above, and satisfy legal, accounting, tax and evidentiary requirements (for example, retaining signed envelope audit trails as proof of execution). Retention periods are configurable by Customer within the Service and are described further in our data retention documentation. When information is no longer required, it is deleted or de-identified, subject to any applicable legal hold.
10. Your rights
Subject to POPIA, you may have the right to: request confirmation of whether we hold personal information about you; request access to it; request correction or deletion of inaccurate, irrelevant, excessive, out of date, incomplete or unlawfully obtained personal information; object to processing based on legitimate interest or for direct marketing; withdraw consent where processing is based on consent; and lodge a complaint with the Information Regulator.
Where a Signer's information was submitted by a Customer that sent them an envelope, requests about that data are usually directed to the relevant Customer as responsible party first, and we will assist that Customer in responding as required under the Data Processing Addendum. You may also contact us directly and we will route the request appropriately.
To exercise these rights, contact sales@signworkspace.com. We will acknowledge requests promptly and respond within the time limits required by law.
11. Security measures
We use technical and organisational measures designed to protect personal information against loss, unauthorised access, alteration and disclosure, consistent with POPIA section 19, including encryption of data in transit and at rest, role-based access controls, tenant data isolation, audit logging, and hashing of documents and verification codes. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Security incidents
If we become aware of a security compromise that has led to unauthorised access to or acquisition of personal information, we will investigate and, where required by POPIA section 22, notify the Information Regulator and affected data subjects (or the relevant Customer, where SignWorkspace acted as operator) as soon as reasonably possible.
13. Children's information
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children as defined in POPIA without the consent of a competent person (such as a parent or legal guardian), except where a Customer lawfully includes a minor as a Signer on a document with appropriate consent, for which the Customer is responsible.
14. Cookies and similar technologies
Our use of cookies and similar technologies is described in the Cookie Policy.
15. Marketing communications
Where we send marketing communications, we do so with consent or another lawful basis available to us, and every marketing email includes an unsubscribe or opt-out mechanism. Service and security notifications necessary to operate your Account are not marketing and cannot be opted out of while the Account remains active.
16. Changes to this notice
We may update this notice from time to time. Material changes will be notified by email to Account administrators or by notice within the Service at least 14 days before taking effect, except where a change is required sooner by law.
17. Information Regulator
The Information Regulator (South Africa) supervises compliance with POPIA. You can lodge a complaint or obtain guidance from the Information Regulator:
- Physical address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
- Postal address: P.O. Box 31533, Braamfontein, Johannesburg, 2017
- General enquiries: enquiries@inforegulator.org.za (010 023 5200)
- POPIA complaints: POPIAComplaints@inforegulator.org.za
- Website: inforegulator.org.za
We encourage you to contact us first at sales@signworkspace.com so we can try to resolve your concern directly.
18. Contact
Questions about this notice, or requests relating to personal information, can be sent to sales@signworkspace.com.
About this document
SignWorkspace provides privacy and security controls designed to support customers' POPIA obligations; use of SignWorkspace does not by itself make a customer POPIA compliant. This notice is a comprehensive draft and has not been certified by a South African admitted attorney or the Information Officer named above. Obtain legal sign-off before relying on it as final, and complete the bracketed details above.