Privacy Policy
Last updated 25 July 2026. Applies to the TRUE Sign website and service, part of the TRUE platform by TRUE Value Software AB, Eriksbergsgatan 3, Stockholm.
1. Who is responsible
For your account, this website and our own communication, TRUE is the data controller. For the content of documents sent for signature and for the personal data processed during signing, the sender of the document is the controller and TRUE processes the data on the sender's behalf under a Data Processing Agreement.
2. What personal data we process
- Account holders: name, work email, organisation, plan and billing details, login events.
- Signing parties: name, email, mobile number when the sender requires SMS verification, IP address, browser identifier, and timestamps for opening, viewing, signing or declining. These form the evidence package of the sealed document.
- Documents: whatever personal data the sender's documents contain. We process it to deliver the service, never for our own purposes.
- Website visitors: anonymized, cookieless statistics only. No names, no emails, no full IP addresses.
3. Why, and on what legal basis
- To provide the service (contract, GDPR art 6.1 b): accounts, sending, signing, sealing, delivery.
- To make signatures provable (legitimate interest, art 6.1 f): the evidence package exists so that every party can rely on the signature afterwards.
- To keep the service safe (legitimate interest, art 6.1 f): abuse prevention, security logging.
- To meet legal duties (art 6.1 c): bookkeeping and similar obligations.
- To keep you informed about TRUE services (legitimate interest, art 6.1 f): news, improvements and offers we believe are relevant to you. Every message includes a simple way to opt out, and service messages about your documents are unaffected by your choice.
4. The blockchain and your data
When a document is sealed, only its cryptographic fingerprint (SHA 256) is anchored on a public blockchain. A fingerprint cannot be reversed into the document. No document content and no personal data is ever written to any blockchain. The anchoring is permanent by design; the personal data stays in the document and its evidence package, under the retention rules below.
5. How long we keep data
Account data is kept while the account is active and removed or anonymized after closure, except where law requires longer. Sealed documents and their evidence follow the document's life: they exist so the agreement can be proven, and are removed when the sender deletes them or the agreement with the sender ends and law permits deletion. Website statistics contain no personal data.
6. Sharing and sub-processors
We never sell personal data and never share it with third parties for their own use. We use a small number of sub-processors under data processing agreements, for hosting within the EU, email delivery and SMS delivery. AI models are not trained on your documents. The current sub-processor list is available on request.
7. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection. Signing parties should contact the document's sender first, since the sender is the controller of the signing data; we assist where the law requires. You can always complain to IMY, the Swedish data protection authority.
8. Cookies
The marketing site uses cookieless, first party statistics. The service uses only the cookies needed to keep you logged in. There are no advertising trackers.
9. Changes
We update this policy when the service changes. Material changes are announced in the service. This page always shows the current version and its date.
10. Contact
TRUE Value Software AB, Eriksbergsgatan 3, 114 30 Stockholm, Sweden. Email [email protected]. See also our Terms & Conditions and the TRUE GDPR page.