Cursiv

Privacy policy

How Cursiv handles personal information — what is collected, why, who else sees it, how long it is kept, and what you can require us to do about it.

Last updated . Material changes are announced to workspace owners by email before they take effect.

1Who is responsible

The responsible party, in the language of the Protection of Personal Information Act 4 of 2013 (“POPIA”), is I-Sixty Group, registration number 2005/033769/07, trading as Cursiv.

Our Information Officer is [ to be supplied: Information Officer's name ], reachable at support@isixty.co.za.

Where we handle documents on behalf of a customer, that customer is the responsible party for what is inside their documents and we are the operator — we act on their instructions. Where we handle a customer’s own account, we are the responsible party. Both relationships are described below because the distinction changes who you should ask about what.

2What we collect

Three separate things, kept for different reasons.

Your account

  • Your name, email address and password (stored only as a hash we cannot reverse).
  • Your workspace, its name, branding and the people you invite.
  • Sign-in history and security events — when, from what address, and whether a second factor was used.
  • Payments: the amount, the reference and the outcome. Card numbers are entered on Paystack and never reach this system.
  • If you arrived by clicking an advert we paid for, the click identifier that the advertising platform put in the link — so we can tell them their advert produced a customer.

Documents you send

  • The files themselves and everything placed on them.
  • Each recipient’s name and email address, and any information they fill into a field.
  • The signature or initials they adopt, and whether they typed, drew or uploaded it.

The record that makes a signature worth something

  • When each recipient opened, viewed and signed, and which pages they saw.
  • The IP address and browser user-agent at the moment of signing.
  • How they were authenticated, and the exact wording of the electronic-signature disclosure they accepted.
  • A hash chain over all of the above, and a keyed seal over the finished document.

The third category exists to answer a challenge to a signature. It is why the product is worth using and it is the reason some of it cannot be deleted on request — see clause 7.

3Why we are allowed to hold it

  • To perform a contract. Delivering a document to the person you asked us to send it to, and taking payment.
  • Legitimate interest. Keeping the audit trail and the seal. A signing service that could not evidence its own signatures would be of no use to either party to an agreement, and the counterparty relies on that record as much as our customer does.
  • Legal obligation. Tax and accounting records.
  • Consent. Optional things, each asked for separately — remembering an adopted signature, and sending a document’s text for analysis.

4Who else sees it

Five processors, and no others. Each is named with what actually leaves this system, because “trusted partners” is not a disclosure.

WhoWhat leavesWhere
Twilio SendGridDelivers invitations, reminders, receipts and account email.Recipient name and email address, the subject line of the envelope, and the signing link.United States
Cloudflare R2Stores uploaded documents, signature images and sealed records.The documents themselves and everything placed on them.Configurable at the bucket. Confirm the jurisdiction of your bucket before relying on this line.
PaystackTakes card payments for credits.Billing name, email and the amount. Card details are entered on Paystack and never reach this system.South Africa and Nigeria
Google Ads, Meta and Microsoft AdvertisingTold that an advert they showed produced a customer, so we know which advertising to keep paying for.The click identifier that platform itself placed in the link, and the fact that the person who clicked it opened an account. Sent once, by our server, at that moment. No name, email or document.Only ever applies to someone who arrived by clicking one of our adverts. No advertising script runs on the site, so nothing is sent when a page is merely read.United States, and for Google also Ireland
OpenRouter, and the model provider it routes toReads a document to propose who signs where, when a workspace asks it to.Extracted text only — never the document file. Names and other personal information appearing in that text are included.Off unless an API key is configured, and the screen says so before it runs.United States
IntelliDeskThe help widget: lets a person open a support request from inside the product.What Cursiv sends it: when you are signed in, your name, email address and workspace plan; on every page, the name of the screen you are on with any link token or record id replaced (for example /sign/[token]) — never the query string or the full address. Whatever you type into a help request goes to it, and so does a screenshot if you attach one; a screenshot shows whatever is on your screen at that moment, which can include a document. Because the widget loads from IntelliDesk, your browser also contacts it directly, so it sees your IP address and browser details.Loads on every page, including the signing page. It is not given the documents themselves, and its diagnostics are switched off.Widget served from intellidesk.co; help requests and screenshots are held in a Convex deployment in AWS eu-west-1 (Ireland).

Advertising is the one addition, and it is a narrow one. If you arrive by clicking an advert and go on to open an account, we report that conversion to the platform that showed it — the click identifier it issued, and the fact that it worked. That is the whole transmission, it happens once, and it is sent by our server rather than by a script on your browser. Our lawful basis is legitimate interest: knowing which of our own adverts produce customers. Nothing is sent when you merely read a page, and if you did not arrive from an advert nothing is sent at all.

We do not sell personal information, and there is no advertising network, analytics service or tracking pixel anywhere on this site or in the product. See the cookie notice, which is short for that reason.

5Information that leaves South Africa

It does, and you should know where. Section 72 of POPIA restricts transferring personal information outside the Republic. Of the processors above, SendGrid and OpenRouter are in the United States, IntelliDesk holds help requests in Ireland, Paystack operates in South Africa and Nigeria, and the storage bucket’s region is a deployment setting.

We rely on section 72(1)(a) — the recipient is subject to an agreement that upholds principles for lawful processing substantially similar to POPIA — and, for documents sent to signers abroad, on section 72(1)(b), because sending the document to the person you asked us to send it to is the performance of the contract you asked for.

6How long we keep it

  • Documents and their evidence: for as long as the workspace exists, unless the workspace sets a retention period, in which case working copies are purged after it and the sealed record is kept.
  • Email bodies: redacted after 90 days. The fact of delivery — that a message was sent, and whether it arrived — is kept, because it answers a signer who says they were never notified.
  • Webhook deliveries: 30 days.
  • The transparency log: permanently. It is append-only by construction and cannot be edited by us or by anyone. It contains no document, no name and no email address — only a blinded hash — but it is public and it is forever.

7Your rights, and the one limit on them

You may ask what we hold about you, have it corrected, object to processing, and ask for it to be deleted. Workspace owners can do the first and last themselves under Settings → Privacy requests; anyone else can write to support@isixty.co.za.

What erasure does not reach. If you were a recipient on an envelope that was never sent, you are deleted. If you signed something, or were sent something that was signed, your name, address and the record of what you did remain — because that record is evidence of a transaction that another person relies on, and erasing it on the request of one party would destroy the other party’s proof. This is the limit in section 24 of POPIA and it is the honest answer rather than a convenient one.

What is always removed on request: address-book entries, saved signatures, sign-in history, and the contents of email we sent you. The report you receive states what was removed and what was kept, item by item.

If you are unhappy with how we have handled a request you may complain to the Information Regulator of South Africa, at inforegulator.org.za.

8Security

Passwords are hashed, documents are stored encrypted at rest by the storage provider, signing links carry 256 bits of entropy and are stored only as a keyed hash, and every completed document is sealed so that a change to a single byte is detectable. The security page describes the whole arrangement, including what it does not protect against.

If we suffer a breach affecting personal information we will notify the Information Regulator and affected data subjects as section 22 of POPIA requires, in writing and without unreasonable delay. Report a vulnerability under our disclosure policy.

9Children

The service is for business use and not directed at children. We do not knowingly collect the personal information of a child as defined in POPIA. If you believe we have, write to us and we will delete it.

Privacy policy · Cursiv