Who we are
bSign is an electronic signature service provided by Binarium, an IT services company in Ontario, Canada ("Binarium", "we", "us"). This policy covers the bSign website, the bSign app and the sites we run for our customers, the signing pages and the emails bSign sends.
Questions about privacy go to our privacy officer at support@binarium.ca.
Whose information it is
Organizations use bSign to send documents for signature. The documents, and the information about the people who sign them, belong to the organization that sent them. We process that information on the organization's behalf and following its instructions; the organization decides what to send, to whom, and how long it is kept. If you signed a document someone sent you, that organization is the one to ask about its use of your information, and we will help it answer you.
We are responsible for the information we collect for our own purposes: the accounts of the people who use bSign, billing, support requests and the website.
What we collect
Accounts
Name, email address, phone number, organization and job title; your password (stored only as a one-way hash, never in readable form); your sign-in settings, such as two-step verification; and your preferences.
Documents and signing records
The files you upload or create, the fields placed on them, the signatures and other entries recipients make, and the recipients' names, email addresses and phone numbers. For each document bSign keeps an audit trail and a certificate of completion: who was sent it, viewed it, signed, declined or approved it, and when, with the IP address, the approximate location worked out from that address (on our own servers, not by a third-party service) and the browser and device used.
Contacts
The contacts you add, import from a file, or sync from Microsoft 365 or Google (see below), used to pick recipients.
Messages to us
What you send through the website's forms or by email: your name, email address, organization and message. The website's forms email it to us; the website itself does not store it.
Technical information
Server logs with IP addresses, times and the requests made, kept to run bSign securely and to investigate problems.
Microsoft 365 and Google
Connecting a Microsoft 365 or Google account to bSign is optional. You choose what to connect, and you can disconnect at any time in Settings, Cloud storage, or remove bSign's access in your Microsoft or Google account settings.
- Signing in with Microsoft or Google: we receive your name, email address and an account identifier, to sign you in.
- OneDrive, SharePoint and Teams: bSign lists the files and folders you browse, opens the files you choose to send or sign, and saves signed documents and certificates to the folder you choose.
- Google Drive: bSign sees only the files you pick in Google's file picker and the files bSign itself saves there (a folder for signed documents).
- Contacts: if you turn on contacts sync, bSign reads the names, email addresses, phone numbers, company names and job titles in your Outlook contacts or Google Contacts, and keeps them in your bSign contact book so you can choose them as recipients. bSign only reads your contacts; it never changes or deletes them in Microsoft 365 or Google. Contacts sync again only when you press Sync. If you disconnect, the contacts already brought in stay in your bSign contact book until you delete them.
bSign keeps the connection's access token encrypted on our servers and uses it only for the features above, when you use them (or, if you ask for it, to save completed documents automatically).
bSign's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, we do not use information from Google or Microsoft accounts for advertising, we do not sell it, we do not use it to train artificial intelligence or machine learning models, and our staff do not read it unless you ask us to (for example, for support), it is needed for security or to investigate abuse, or the law requires it.
How we use information
- To provide bSign: sending, signing and sealing documents, sending the emails and codes signing needs, reminders, storing documents and their records, and the features you turn on.
- To keep bSign secure: preventing fraud and abuse, protecting accounts and investigating problems.
- To support you and to bill our customers.
- To meet our legal obligations.
We do not sell personal information, we do not use it for advertising, and we do not build profiles of the people who sign documents.
Who we share it with
- The people on a document, as its sender decides: recipients see the document and, once it is complete, its signatures and certificate.
- Your organization's administrators, who can see and manage the documents and users of their bSign site.
- Service providers that help us run bSign, such as email delivery, under contracts that require them to protect the information and use it only for us. A current list is available on request.
- When the law requires it, or to protect people's rights, property or safety. Where we can, we tell the organization concerned first.
- If Binarium's business is sold or merged, the new owner would continue under this policy.
Where it is stored
bSign stores documents, signing records and accounts in Canada, on servers operated by Binarium. When you or your recipients are elsewhere, information travels across borders as documents are sent, viewed and signed, and emails pass through the recipients' own email providers.
How long we keep it
- Documents and signing records: as long as the organization that sent them chooses. Each bSign site can set a retention period, after which finished documents are deleted automatically.
- Accounts: while the account is open. When an account or site is closed, we delete its information, except what the law requires us to keep.
- Backups: kept for a short period (currently 14 days) and then deleted.
- Server logs: kept only as long as needed for security and troubleshooting.
How we protect it
Connections to bSign are encrypted. Signing links stop working when a document expires or is voided, and can require a code sent to the signer; signed documents are sealed with a digital certificate so changes can be detected; tokens for connected accounts are encrypted; sign-in can require two-step verification; and each site has an access log of who opened what. Access to our servers is limited to the Binarium staff who run bSign. No system is perfectly secure, but we work to protect information and will tell affected customers promptly about a breach that puts their information at risk, as the law requires.
Cookies and browser storage
The website sets no cookies and loads no trackers. It asks about analytics and marketing on your first visit and remembers your answer in your browser; you can change it with Cookie settings at the bottom of any page. The bSign app stores what it needs in your browser to keep you signed in and to remember your settings.
Your choices and rights
You can ask to see the personal information we hold about you, to correct it, to have it deleted, or to receive a copy, and you can withdraw consent (for example, by disconnecting a Microsoft or Google account). For documents an organization sent you, contact that organization first; we will help it respond. Write to support@binarium.ca and we will answer within 30 days.
If you are not satisfied with our answer, you can contact the Office of the Privacy Commissioner of Canada, or, in the European Union or the United Kingdom, your data protection authority.
bSign is a service for organizations and is not directed at children.
Changes and contact
If we change this policy, we will post the new version here with a new date, and tell account holders by email about significant changes before they take effect.
Binarium, Ontario, Canada. support@binarium.ca. See also our terms of service.