Last updated:
0. Data Controller
The data controller responsible for your personal data under this Privacy Policy is Ashwin Easo Zachariah, an individual operating TheTerms from Germany (“we,” “us,” or “our”). TheTerms is not currently operated through a separate incorporated legal entity; references in this Privacy Policy to “TheTerms” refer to Ashwin Easo Zachariah acting in that capacity. This mirrors the party description in our Terms of Service.
Contact details for data protection matters are set out in Section 11 (Contact) below.
1. Introduction
TheTerms (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains what data we collect, how we use it, and your rights in relation to it.
This policy applies to the Service at theterms.app.
2. Data We Collect
Account data. When you register, we collect your name, email address, and (if applicable) organisation name. OAuth sign-in via Google or Microsoft provides your email and display name.
Document and signing data. We store the documents, clauses, and versions you create. For signing events, we record the signer’s email address, IP address, user agent string, and timestamp for each action (clause accept/reject). The IP address is read from standard HTTP proxy headers (x-forwarded-for / x-real-ip) sent by the network infrastructure handling the request — it is not obtained via browser geolocation, and no permission prompt is shown to the signer. This capture is part of how the signing page functions and cannot be declined independently of using the signing page.
Usage data. We collect anonymised usage metrics including pages visited, features used, and error logs. This data cannot be used to identify individuals.
Communications. If you contact us by email, we retain that correspondence.
3. How We Use Your Data
We use your data to:
- Provide, operate, and improve the Service
- Send transactional emails (signing invitations, account notifications, password resets) via Resend
- Respond to support requests
- Comply with legal obligations
- Detect and prevent fraud or abuse
We do not sell your personal data to third parties.
4. Data Storage and Security
Storage location. Your data is stored on servers located in the United States, operated by our cloud hosting and infrastructure providers.
International transfers. Because TheTerms is operated from Germany and much of our infrastructure is US-based, personal data of users in the European Economic Area, United Kingdom, or Switzerland is transferred to a country that has not received a European Commission adequacy decision. Where this occurs, we rely on an approved transfer mechanism — such as the European Commission’s Standard Contractual Clauses — to safeguard your data in accordance with Chapter V of the GDPR (Articles 44–49).
Security measures. We implement industry-standard security measures including encryption at rest and in transit (TLS), access controls, and regular security reviews. We follow responsible disclosure practices — report suspected vulnerabilities to security@theterms.app.
Breach notification. In the event of a data breach affecting your personal data, we will notify you and relevant supervisory authorities as required by applicable law.
5. Third-Party Services
We rely on a limited number of third-party service providers to operate TheTerms, in the following categories:
- Transactional email delivery — to send account, invitation, and notification emails.
- Cloud hosting and infrastructure — to run the application and store your data (see Section 4 for storage location).
- Payment processing — for paid plans only; we do not store your card details ourselves.
We choose providers that offer contractual data protection commitments consistent with GDPR requirements. Because our infrastructure providers may change as the Service evolves, we describe them here by category rather than by name; this section is updated if the categories themselves change.
We do not sell your personal data, and we do not use advertising networks, social tracking pixels, or behavioural analytics.
6. Data Retention
Account data. Retained for as long as your account is active. Deleted within 30 days of account deletion.
Signing audit trail. For the Free plan, signing audit trail data is retained for 1 year. For Individual and Team plans, it is retained for 7 years to support legal enforceability of signed documents. For Enterprise plans, signing audit trail data is retained indefinitely. Once the applicable retention period elapses, the data is anonymised rather than deleted.
Usage logs. Retained for 90 days, then permanently deleted.
7. Your Rights (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the GDPR / UK GDPR:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Request correction of inaccurate personal data.
- Erasure. Request deletion of your personal data (“right to be forgotten”).
- Portability. Receive your data in a structured, machine-readable format.
- Restriction. Request that we restrict processing of your data in certain circumstances.
- Objection. Object to processing based on legitimate interests.
- Withdraw consent. Where processing is based on consent, withdraw it at any time.
To exercise any of these rights, contact us at privacy@theterms.app. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority in the European Economic Area, United Kingdom, or Switzerland — for example, the supervisory authority in the EEA member state, the UK, or Switzerland where you live, work, or where you believe an infringement of data protection law has occurred.
8. Cookies
The Service uses strictly necessary cookies for session management and authentication. We do not use tracking cookies, advertising cookies, or third-party analytics cookies.
We use Vercel Web Analytics sitewide to understand aggregate traffic to theterms.app. It is cookieless, collects no personal data, and does not track individuals across sites or sessions — it does not require a cookie-consent banner under EU/German cookie-consent rules because it does not read or write any device storage.
9. Children’s Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has provided us with personal data, contact us at privacy@theterms.app.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service at least 14 days before the changes take effect.
11. Contact
For privacy-related enquiries:
- Email: privacy@theterms.app
- Support: support@theterms.app
- Data Protection Officer: We have not appointed a DPO. TheTerms is operated by a single individual with no employees, and our processing activities do not meet any of the Article 37 GDPR thresholds that make a DPO appointment mandatory (we are not a public authority, our core activities do not involve large-scale, regular and systematic monitoring of individuals, and we do not process special-category or criminal-conviction data at scale). If our processing activities change such that Article 37 applies, we will appoint a DPO and update this policy.
- Postal address: TheTerms does not currently have a registered business address, as it is not yet operated through an incorporated legal entity (see Section 0 and our Terms of Service). A postal address will be added here once TheTerms incorporates.