Privacy Policy
Last updated: May 2026
Our Commitment to Your Privacy
This Privacy Policy explains how GenieSign collects, uses, stores, and protects your personal data. We are committed to the responsible handling of your data and to meeting or exceeding the requirements of applicable data protection laws globally. We use the GDPR as our global baseline standard.
1. Who We Are
GenieSign is a digital signature service operated by GenieSign Sdn. Bhd. (“we”, “us”, “our”), incorporated in Malaysia with its registered address at 05-17 Kenwingston Business Centre Persiaran Bestari Cyberjaya 63000 Selangor Malaysia.
We act as the data controller for the personal data you provide when using GenieSign. Where we engage third-party service providers to process data on our behalf, those providers act as data processors and are bound by data processing agreements.
For all data protection enquiries, requests, and complaints, please contact our Privacy Team at [email protected].
2. Scope of This Policy
This Privacy Policy applies to all personal data collected by GenieSign through:
- Our WhatsApp-based document signing bot
- Our web portal
- Any other interaction you have with GenieSign, including customer support
This Policy applies regardless of your country of residence. Where local laws impose additional obligations or grant additional rights beyond this Policy, those local requirements will also apply to you. We have included jurisdiction-specific supplements in Section 12.
3. Personal Data We Collect
We collect only the minimum personal data necessary to provide the GenieSign service (‘data minimisation’). The categories we collect are:
3.1 Identity and Contact Data
- Full name
- Email address
- Mobile phone number (WhatsApp number, including country code)
- Government-issued identity document number (e.g. national ID, IC number, passport number — varies by jurisdiction)
3.2 Biometric-Adjacent and Sensitive Data
- Handwritten signature image (photograph or scan of your physical signature)
- Digital signature replica generated from your handwritten signature image address
These are treated as sensitive personal data (or special category data under GDPR) and require your explicit consent before processing.
3.3 Document Data
- Documents you upload for signing (PDF or image files)
- Signed document outputs
- Document metadata: file name, file type, page count, upload and signing timestamps
3.4 Transaction and Account Data
- Subscription plan type and status
- Number of documents signed within a billing period
- Payment transaction records (processed via Stripe — we do not store card details)
- Billing history: invoice dates, amounts, payment status
3.5 Technical and Device Data
- IP address at the time of signing or login
- Device type and browser information (web portal)
- Session tokens and login timestamps
- WhatsApp message delivery status
3.6 Communications Data
- Customer support messages and correspondence
- Feedback or enquiries submitted to us
3.7 Data We Do Not Collect
- We do not collect payment card numbers, CVV codes, or bank account details. These are collected and held directly by Stripe.
- We do not collect biometric data in the strict legal sense (such as fingerprints or facial geometry). Signature images are used solely to generate a visual digital signature replica.
- We do not collect data from children under the age of 18. See Section 11.
4. How We Collect Your Personal Data
| Collection method | Data collected |
|---|---|
| WhatsApp onboarding flow | Name, email, phone number, government ID number, signature image, OTP verification records. |
| WhatsApp bot interactions | Document uploads, signing events, session timestamps, message delivery status. |
| Web portal login | Phone number, OTP verification records, session tokens, IP address, device/browser information. |
| Web portal usage | Document uploads, signer configurations, new signing requests, billing interactions. |
| Payment via Stripe | Billing events (plan type, renewal, cancellation). Card data is held by Stripe, not GenieSign. |
| Automatically during service use | IP address, signing timestamps, document metadata, audit trail entries. |
| Customer support | Name, contact details, and description of your enquiry or issue. |
5. Legal Basis and Purposes for Processing
Under the GDPR and equivalent frameworks, we are required to have a lawful basis for each purpose for which we process your personal data. The table below sets out our purposes and legal bases:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Identity verification and onboarding | Name, email, phone number, government ID, OTP records | Consent; Contract performance |
| Creating and storing your digital signature | Signature image, digital replica | Explicit consent (sensitive/special category data) |
| AI processing of uploaded documents | Document content, metadata, page count | Explicit consent |
| Applying your signature to documents | Digital signature, document data, timestamps | Contract performance; Consent |
| Generating audit trails and signature certificates | All identity data, timestamps, IP address | Legal obligation; Contract performance |
| Delivering signed documents via WhatsApp | Signed document, phone number | Contract performance |
| Account and subscription management | Phone number, email, plan status, billing records | Contract performance |
| Payment processing | Plan type, billing events (card data held by Stripe) | Contract performance |
| Sending transactional notifications | Phone number, email | Contract performance; Legitimate interest |
| Customer support | Name, contact details, support correspondence | Legitimate interest; Consent |
| Service analytics and improvement | Anonymised usage data, error logs | Legitimate interest |
| Legal compliance and fraud prevention | All data as required by applicable law | Legal obligation |
We never process your personal data for automated decision-making that produces legal or similarly significant effects without human oversight, except where you have explicitly consented or where such processing is required by law.
6. Sensitive Personal Data
The following data you provide to GenieSign is treated as sensitive personal data (referred to as ‘special category data’ under the GDPR):
- Your government-issued identity document number
- Your handwritten signature image and the digital signature replica derived from it
We process this data only with your explicit consent, obtained at the point of onboarding. You may withdraw this consent at any time. Withdrawal means we can no longer provide the signing service to you, but it does not affect the lawfulness of processing carried out before withdrawal.
7. How We Share Your Personal Data
We do not sell, rent, or trade your personal data. We share your data only in the following limited and controlled circumstances:
7.1 With Other Signers
When you send a document for multi-party signing, your name (as the sender) and the completed signed document are shared with invited co-signers upon completion. We do not share your government ID number, signature image, or other identity details with other signers.
7.2 With Our Service Providers (Data Processors)
We work with trusted third-party service providers who process data on our behalf under binding data processing agreements:
| Service provide | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Billing events and plan information. Stripe handles card data directly and does not receive other personal data from GenieSign. |
| Cloud hosting provider | Platform hosting, document storage, database | All data stored on the platform. Provider is bound by a DPA and security obligations. |
| WhatsApp / Meta (Business API) | Message delivery: OTPs, signing invitations, signed documents, bot messages | Message content and recipient phone numbers. |
| AI processing service | Document analysis: signature field detection, document summarisation, page count verification | Uploaded document content. Not retained by the AI provider after the request is complete. |
| Analytics provider (if applicable) | Anonymised product analytics | Anonymised, aggregated usage data only. No personally identifiable information. |
7.3 Legal Disclosure
We may disclose your personal data to courts, regulators, law enforcement agencies, or other public authorities where required by applicable law, a court order, or to protect the rights, property, or safety of GenieSign, our users, or others.
7.4 Business Transfer
In the event of a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the successor entity. We will notify you before any such transfer occurs if it materially affects how your data is used, and you will retain your right to request deletion.
8. International Data Transfers
GenieSign operates globally and your data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction.
Where we transfer personal data outside your home jurisdiction, we ensure that appropriate safeguards are in place to protect your data, including one or more of the following:
- Standard Contractual Clauses (SCCs) approved by the European Commission, for transfers from the EU/EEA
- UK International Data Transfer Agreements (IDTAs) or addenda, for transfers from the United Kingdom
- Adequacy decisions, where the destination country has been recognised as providing an equivalent level of data protection
- Binding Corporate Rules or other approved transfer mechanisms where applicable
- Contractual safeguards equivalent to those above, for transfers involving data from other jurisdictions
You may request further information about the specific safeguards applied to data transfers involving your personal data by contacting us at [email protected].
9. Signature Replication and Storage - Point is Old, Will be added once the ticket is updated
You consent to GenieSign processing the image of your handwritten signature to generate a digital replica for use within your account. By submitting your signature image, you confirm that:
- The signature is your own
- You have the right to use it as your legal signature
- You authorise GenieSign to store and apply it to documents you submit through the service
Your digital signature is stored securely and used exclusively within your GenieSign account. It will not be shared with or made accessible to other users. You may request deletion of your stored signature at any time by contacting our support team. Deletion of your signature means we will no longer be able to sign documents on your behalf.
10. Plans, Pricing and Document Quotas. Point is Old, Will be added once the ticket is updated
| Plan | Price | Document Quota | Key Features |
|---|---|---|---|
| Free | No charge | 3 documents (lifetime, not per month) | Documents up to 10 pages; up to 3 signatures per document; no document storage. |
| Personal | USD 20 / month | 25 documents per billing month | 30-day signed document storage. |
| Business | USD 40 / month | 1000 signatures | Unlimited user accounts; audit trails; user dashboard, customer support. |
| Enterprise | USD 65 / month | 3000 signatures | Unlimited user accounts; audit trails; user dashboard, priority customer support. |
Prices are shown in local currencies and are exclusive of any applicable taxes. Taxes will be applied at checkout where required by law in your jurisdiction. We reserve the right to change pricing with at least 30 days’ prior notice to existing subscribers. Price changes will not affect your current billing period.
- You may cancel your subscription at any time by sending “Cancel” in your WhatsApp conversation with the GenieSign bot, or by contacting our support team.
- Cancellation takes effect at the end of your current billing period. You retain access to Personal Plan features until that date.
- We do not issue refunds for partially used billing periods unless required by applicable law in your jurisdiction (see Section 15 for EU/UK consumer rights).
11. Your Privacy Rights
Depending on your location, you have various rights in relation to your personal data. The table below sets out the rights available under the major frameworks we adhere to:
| Right | Description | How to exercise |
|---|---|---|
| Right to Access | Request a copy of the personal data we hold about you. | Contact us at [email protected]. We will respond within 30 days (GDPR) or as required by local law. |
| Right to Rectification / Correction | Request correction of inaccurate or incomplete personal data. | Contact us or update your account details directly in the web portal. |
| Right to Erasure (‘Right to be Forgotten’) | Request deletion of your personal data where we no longer have a lawful basis to retain it. Note: audit trails and billing records retained under legal obligations cannot be deleted early. | Contact us at [email protected]. |
| Right to Restrict Processing | Request that we limit how we use your data in certain circumstances (e.g. while a dispute is resolved). | Contact us at [email protected]. |
| Right to Data Portability | Receive your personal data in a structured, machine-readable format and transfer it to another provider, where technically feasible. | Contact us at [email protected]. |
| Right to Object | Object to processing based on legitimate interest, or to direct marketing. We will stop processing unless we have compelling legitimate grounds. | Contact us at [email protected] or use the unsubscribe link in any marketing communications. |
| Right to Withdraw Consent | Withdraw consent to any processing based on consent at any time. Withdrawal does not affect prior lawful processing. Withdrawing core consents will prevent us from providing the service. | Contact us or follow the instructions in the onboarding flow. |
| Right Not to Be Subject to Automated Decision-Making | We do not use your data for purely automated decisions that significantly affect you without human review. | Contact us if you have concerns. |
We will respond to all rights requests within 30 days. In complex cases we may extend this by a further 60 days and will notify you. We do not charge a fee for rights requests unless they are manifestly unfounded or excessive.
12. Jurisdiction-Specific Supplements
The following additional provisions apply to users in specific jurisdictions. These supplements apply in addition to the rest of this Policy, not instead of it.
12.1 European Union and European Economic Area (GDPR)
If you are located in the EU or EEA, the EU General Data Protection Regulation (GDPR) applies to the processing of your personal data by GenieSign.
- Legal basis: We process your data on the bases of consent, contract performance, legal obligation, and legitimate interest as described in Section 5.
- Special category data: Your signature image and government ID number are processed only with your explicit consent under Article 9 GDPR.
- Supervisory authority: You have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu.
- Data transfers: Transfers of your data outside the EU/EEA are made under Standard Contractual Clauses or adequacy decisions as described in Section 8.
- DPO: Where required by GDPR Article 37 (based on our processing volume and nature), we will appoint a Data Protection Officer. Contact details will be provided when applicable.
12.2 United Kingdom (UK GDPR)
If you are located in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply. Your rights and our obligations are materially the same as under the EU GDPR above. You may lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
12.3 California, United States (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following additional rights:
- Right to Know: You may request details about the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the third parties with whom it has been shared.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing: GenieSign does not sell or share your personal information with third parties for cross-context behavioural advertising. No opt-out is required, but you may contact us to confirm.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit the use of sensitive personal information to that which is necessary to provide the service.
- Right to Non-Discrimination: Exercising your CCPA rights will not result in discrimination against you.
To submit a CCPA rights request, contact us at [email protected] or [toll-free number if applicable]. We will verify your identity before processing your request and will respond within 45 days.
12.4 Other Jurisdictions
GenieSign is committed to respecting applicable privacy laws in all markets where we operate. If you are located in a jurisdiction not listed above and have questions about your rights or our compliance with local laws, please contact us at [email protected]. We will do our best to respond to your enquiry in accordance with applicable local law.
13. Artificial Intelligence and Automated Processing
GenieSign uses artificial intelligence to deliver its core service. Specifically, AI is used to:
- Analyse documents you upload to detect signature fields and suggest placement locations
- Generate a plain-language summary of the document type
- Process your handwritten signature image to generate a digital replica
- Assess documents for compliance with plan-based limits (page count, signature count)
This AI processing involves automated analysis of your documents and signature image. It does not produce legally binding decisions about you as an individual — it assists in the technical process of signature placement and document categorisation only.
We do not use your documents, signature, or personal data to train AI models. Documents are processed solely for the purpose of delivering the signing service and are not retained by our AI service providers after the request is completed.
You consented to this AI processing during onboarding. You may withdraw this consent at any time by contacting us, though this will prevent us from processing your documents through GenieSign.
14. Limitation of Liability. Point is Old, Will be added once the ticket is updated
To the maximum extent permitted by applicable law, GenieSign provides the service on an “as is” and “as available” basis without warranties of any kind, express or implied, including without limitation any warranty of merchantability, fitness for a particular purpose, or non-infringement.
To the maximum extent permitted by applicable law, GenieSign’s total liability to you for any claim arising from or related to your use of the service shall not exceed the total fees paid by you to GenieSign in the 12 months preceding the event giving rise to the claim, or USD 100, whichever is greater.
In no event shall GenieSign be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, loss of data, or loss of goodwill, arising from your use of or inability to use the service.
GenieSign is not liable for:
- The legal validity or enforceability of any document signed through the service
- Any dispute between you and another party to a document you signed via GenieSign
- Any loss arising from your failure to download or retain signed documents within the applicable storage period
- Any interruption, delay, or failure of the WhatsApp platform or any third-party service provider
15. Children’s Privacy
GenieSign is not intended for use by individuals under the age of 18 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us immediately at [email protected] and we will delete that data as soon as reasonably practicable.
16. Third-Party Services and Links
GenieSign integrates with and may contain links to third-party services, including WhatsApp (Meta), Stripe, and our cloud infrastructure providers. This Privacy Policy applies only to GenieSign. We are not responsible for the privacy practices of third-party services. We encourage you to read the privacy policies of any third-party services you use in connection with GenieSign before sharing your personal data with them.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable laws. Where changes are material, we will notify you via WhatsApp message or your registered email address at least 14 days before the changes take effect. The updated ‘Last updated’ date at the top of this document will reflect the most recent revision.
For minor changes (such as corrections or clarifications that do not affect your rights), we will update the document without individual notice. We encourage you to review this Policy periodically.
Continued use of GenieSign after the effective date of an updated Policy constitutes your acceptance of the changes.
18. Language
This Privacy Policy is published in English as the authoritative version. Where we operate in markets that require a local-language version (for example, Bahasa Malaysia for the Malaysian market), translated versions will be made available on our website. In the event of any inconsistency between the English version and a translated version, the English version shall prevail unless local law requires otherwise.
19. Governing Law
This Privacy Policy is governed by the laws of Malaysia. However, where mandatory local privacy laws (such as the GDPR or CCPA) apply to your data, those laws will govern the aspects of this Policy relating to your personal data, and the jurisdiction-specific rights described in Section 12 will apply. Nothing in this clause limits your rights under applicable mandatory local laws.
20. How to Contact Us and How to Complain
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us:
| Contact Method | Details |
|---|---|
| Privacy Email | [email protected] |
| WhatsApp Support | +92 302 8288217 |
| Postal Address | GenieSign Sdn. Bhd. 05-17 Kenwingston Business Centre Persiaran Bestari Cyberjaya 63000 Selangor, Malaysia |
| Website | geniesign.io |
If you are not satisfied with our response and are located in the EU/EEA, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents may complain to the ICO at ico.org.uk.
