Legal

Privacy Policy

How MEGITS Intelligent SL collects, uses and protects personal data when you use CloudSignLab, and how to exercise your data protection rights.

Last updated: 27 September 2026. This policy is also available in Spanish; where the two versions differ, the Spanish version prevails.

CloudSignLab is a service of MEGITS Intelligent SL. This policy explains what personal data we process when you use the CloudSignLab website and application, why we process it, how long we keep it and what rights you have. CloudSignLab is a business service intended for organizations and professionals aged 18 or over.

Who is responsible for your data

Data controllerMEGITS Intelligent SL
Tax ID (CIF)B93978385
AddressCalle Alejandro Dumas 17, 29004 Málaga, Spain
Privacy contactprivacy@cloudsignlab.com

We have not appointed a Data Protection Officer because our processing does not require one under Article 37 GDPR. You can contact us about any privacy matter at the address above.

What data we process and why

Your account

  • Data: name, email address, password (stored only as a one-way cryptographic hash, never readable by anyone), optional profile photo, language, and your two-factor and passkey settings.
  • Purpose: to create and run your account, let you sign in and provide the service.
  • Legal basis: performance of our contract with you or your organization (Art. 6(1)(b) GDPR).
  • Retention: while your account exists. When you delete your account, it is removed from our active systems (see "Security logs" for the exception).

Organizations and team members

  • Data: organization name and logo, members and their roles, and invitations (the invited person's email address and role).
  • Purpose: to let organizations work together and manage who has access.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR). Invited people are processed on the basis of the inviting organization's legitimate interest (Art. 6(1)(f) GDPR).
  • Retention: while the organization exists; invitations expire if they are not accepted.

Security logs

To protect your account and our service, we record security-relevant events:

  • sign-ins (including the sign-in method), failed sign-in attempts on existing accounts, and sign-outs;
  • security changes such as password changes and resets, two-factor authentication and passkey changes, email changes and account deletion;
  • team management actions (for example inviting or removing members) and actions performed by our administrators.

Each entry stores the date and time, the account's email address, the IP address and the browser/device used. Passwords, codes and access tokens are never recorded.

  • Purpose: to detect and investigate unauthorized access, abuse and fraud, and to show you your own recent security activity in your account settings.
  • Legal basis: our legitimate interest in keeping the service and its users secure (Art. 6(1)(f) GDPR).
  • Retention: up to 365 days, after which entries are deleted automatically. Entries are kept for this period also after an account is deleted, so that abuse can still be investigated.

We also use these events to warn you: you see security notifications in your account (for example a sign-in from a new device, several failed sign-in attempts or a changed password), and we email you when your account is used from a device we have not seen recently. Notifications store the type of event, the device and the IP address, and are deleted automatically after 90 days.

Emails we send you

  • Data: your email address and the content of the message (for example verification links, sign-in codes, password resets and invitations).
  • Purpose: to operate your account securely.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

Mailing list (news and updates)

  • Data: email address, language, where you signed up, and the dates you subscribed, confirmed or unsubscribed.
  • Purpose: to send you news about CloudSignLab.
  • Legal basis: your consent (Art. 6(1)(a) GDPR). We use double opt-in: you are only added after confirming through the link we email you.
  • Retention: until you unsubscribe. Every email includes an unsubscribe link. After you unsubscribe we keep a record of it, so that we do not contact you again.
  • Sending records: for each newsletter we keep who it was sent to and whether it was delivered, so that nobody receives the same newsletter twice. Every newsletter can be unsubscribed from with one click.

Contact form

  • Data: name, email address and your message.
  • Purpose: to answer your enquiry. Messages are sent to our team by email and are not stored in the application.
  • Legal basis: our legitimate interest in responding to enquiries, or steps prior to a contract (Art. 6(1)(f) and (b) GDPR).
  • Retention: up to two years after the enquiry is closed.

Visitor statistics and error monitoring

We measure how our website and application are used with our own system. The data stays on our servers in the European Union and is not shared with any analytics provider.

  • Everyone (no consent needed): we count page views: the page, the website you came from, campaign tags in the link, your approximate location (country, region and city, looked up from your IP address, which is then discarded and never stored), your browser language, and your browser, system and device type as your browser reports them. No cookie is set, nothing is read from your device, and these records cannot be linked to you or to each other.
  • Only if you accept measurement cookies: in addition, a random visitor identifier in the csl_vid cookie, a visit identifier in your browser tab, your screen size and time zone, the time spent on pages and page-speed measurements. When you are signed in, your page views in the application are linked to your account so that we can see which features are used. If your browser sends a privacy signal (Global Privacy Control or Do Not Track), we treat it as a refusal.
  • Errors: when a page or our server fails, we record the error message, the page (without its query string), browser and system, and, if you are signed in, your account, so that we can fix the problem. Email addresses, tokens and keys are removed before anything is stored.
  • Email results: for each email we send, we record which kind of email it was and whether it was sent, bounced or reported as spam, never the address or the content.
  • Purpose: to understand how the service is used, to keep it fast and working, and to fix errors.
  • Legal basis: our legitimate interest in running a secure and working service (Art. 6(1)(f) GDPR) for page views without identifiers, errors and email results; your consent (Art. 6(1)(a) GDPR) for the measurement cookie and everything linked to it. You can withdraw your consent at any time using "Cookie settings" in the footer.
  • Retention: detailed records for 90 days; after that only daily totals without any identifier, for up to 2 years. Records linked to your account are deleted when you delete your account.
  • Location: IP Geolocation by DB-IP, looked up on our own servers.

Payments

  • Data: billing details and payment information. Card data is entered directly with our payment provider, Stripe; we never see or store full card numbers.
  • Purpose: to process subscriptions and payments.
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and compliance with legal obligations (Art. 6(1)(c) GDPR).
  • Retention: invoices and accounting records are kept for six years, as required by Spanish commercial law.

Server and backup data

Our servers keep technical request logs (IP address, time, requested address) for a short rolling period to operate and secure the service. Database backups are kept on a rolling basis for disaster recovery and are overwritten automatically.

Who we share data with

We do not sell your personal data. We share it only with service providers that process it on our behalf under data processing agreements:

ProviderPurposeLocation
Amazon Web Services (AWS)Hosting, database, file storage and email deliveryEuropean Union
StripePayment processingEuropean Union / see below

We may also disclose data where required by law or by a competent authority.

Where your data is stored

All our servers, our database and file storage are hosted by Amazon Web Services in the European Union. Some providers (for example Stripe, or support staff of our providers) may process data outside the European Economic Area; when that happens, the transfer is protected by the European Commission's Standard Contractual Clauses or the EU-US Data Privacy Framework.

How we protect your data

We use encrypted connections (HTTPS), store passwords only as secure hashes, offer two-factor authentication and passkeys, restrict internal access to what each role needs, keep uploaded files private except profile photos, and record administrative actions in an audit log.

Your rights

You can ask us to:

  • give you a copy of your personal data (access);
  • correct inaccurate data (rectification);
  • delete your data (erasure);
  • restrict or object to certain processing;
  • provide your data in a portable format (portability);
  • withdraw any consent you have given, at any time, without affecting earlier processing.

Write to privacy@cloudsignlab.com. We will reply within one month. We may ask you to confirm your identity before acting on a request.

If you believe we have not handled your data correctly, you can complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).

Automated decisions

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects.

Changes to this policy

We may update this policy when our service or the law changes. We will publish the new version on this page with a new date and, for significant changes, notify account holders by email.