We collect what we need to verify who signed a document and to keep a defensible record. We delete biometric media immediately after the ceremony completes. We do not sell your data. We do not train models on it. We will delete everything we hold about you on request, within 30 days — with one exception: a signed certificate is a historical record, and we will keep the certificate itself for 7 years as U.S. record-keeping standards require.
1. Who we are
District Seal is operated by NEXSIM LLC, Montana, USA. All data lives in the U.S.
District Seal is a biometric-verified document signing service operated by NEXSIM LLC, a Montana limited liability company incorporated in the United States ("we," "us," "our"). Our principal place of business is Montana, United States.
All servers, databases, and document storage we operate for District Seal are physically located in the United States. We do not currently operate or plan to operate any data centers outside the United States.
For questions about this notice, contact privacy@districtseal.com.
2. What we collect
Identity, contact, documents, and the ceremony record. Nothing extra. Biometric media destroyed immediately.
From account holders
- Identity: legal name, email address, position, industry, organization name, company registration number, company size, city, country.
- Authentication: password hash (never the password itself), email verification code hash, password reset token hash, optional TOTP secret if you enable 2FA.
- Billing: plan, subscription status, signup date, monthly signature count, transaction history. Payment card details are never stored by us — they are handled entirely by our merchant of record, Dodo Payments.
- Forensic: IP address at signup, IP address at each login, user-agent string, timestamps.
From signers (the people who sign a document)
- Identity at signature: legal name, email address, and the reference photo you provided the account holder to use as comparison.
- Ceremony record: WebAuthn hardware-attestation result, scroll completion percentage, consent acknowledgment timestamp, spoken challenge phrase result, head-turn liveness result, face-match distance score.
- Device and network: IP address at signing, user-agent string, and (when supplied by the browser) a device fingerprint hash comprising screen dimensions, timezone, platform, language, canvas hash, and available memory. This fingerprint is a hash — it cannot be reversed to reveal your actual device state.
- Documents: the PDF contract signed, the certificate produced, the forensic audit trail.
We do not keep the raw biometric media. Voice recordings, liveness video, and the frames used for face matching are destroyed immediately after each ceremony completes — before the certificate is issued. What remains is only the derived result: whether the check passed or failed, and a numeric distance score.
What we do not collect
- We do not collect biometric templates — the raw face geometry that could be reused for other identification.
- We do not collect browsing history outside our own service.
- We do not collect precise geolocation. IP addresses may be resolved to country-level location by network infrastructure.
- We do not run advertising trackers or third-party analytics on the signer flow.
- We do not use your content to train machine learning models.
3. Why we collect it
To verify identity, produce a defensible certificate, run the service, and comply with law.
- To verify identity at signature. The entire purpose of the service is to be able to prove that a specific, verified person signed a specific document at a specific time. Without identity data, we cannot perform the service.
- To produce a court-admissible certificate. The certificate must contain the identity record, the forensic timeline, and the document hash.
- To operate the service. Account management, billing, support, security monitoring.
- To detect and prevent fraud and abuse. IP logging, rate limiting, anomaly detection.
- To comply with legal obligations. Subpoenas, court orders, law enforcement, regulatory requests.
4. How long we keep it
Biometric media: destroyed immediately. Certificates & forensic records: 7 years. Account data: until you ask us to delete it.
- Raw biometric media (voice, video, face frames): destroyed immediately after each ceremony, before the certificate is issued. Retention measured in seconds.
- Certificates and signed documents: 7 years from the date of signature, per U.S. record-keeping standards for signed instruments.
- Forensic event logs: 7 years, alongside the corresponding certificate.
- Account data (name, email, organization): until you request deletion, then within 30 days.
- Server access logs: 90 days, then automatically purged.
- Health check records: 90 days, then automatically purged.
When you delete your account, we delete your account data and any unused uploaded documents. We do not delete certificates for transactions that were already completed — those are the historical records the signer and the counterparty are entitled to reference. If you need a certificate destroyed, you must contact legal@districtseal.com and we will review the request against our legal retention obligations.
5. Who sees it
You, the parties you invite, and our support team. Nobody else — unless required by law.
- You, the account holder: full access to your account and to every transaction you created.
- Signers: access to their own signing ceremony, the document they signed, and the resulting certificate.
- Invited parties: any additional signers on a transaction see the same documents.
- Public verification: anyone with the certificate URL can see the verification status — a green check, the signer's name, the reference number, and the document hash prefix. They cannot see the document itself without authorisation.
- Our support team: read access to your account for the purpose of responding to your support requests, plus write access to certain administrative fields (e.g., marking your account verified) with full audit logging.
- Service providers: Dodo Payments (billing), Resend (email delivery), our cloud storage provider (encrypted backup). Each of these processors is bound by a data-processing agreement and sees only what they need to perform their function.
- Legal authorities: when served with a valid subpoena, court order, or equivalent legal process.
We do not sell or rent your data. We do not share it with advertising networks. We do not disclose it to any third party except as described above.
6. Legal basis (for visitors in the EEA, UK, and Switzerland)
Contract performance, legal obligation, and legitimate interest. Not consent for most processing.
- Performance of a contract — to provide the service you signed up for.
- Legal obligation — to comply with U.S. record-keeping requirements for signed instruments.
- Legitimate interests — fraud prevention, security monitoring, and defending against legal claims. We have assessed these interests against your rights and concluded that identity verification for signed documents is a legitimate and proportionate interest.
- Consent — where we specifically ask for it, such as enabling optional features.
7. Your rights
Access, correction, deletion, portability, objection. Email privacy@ and we act within 30 days.
Whether you are in the EEA, the UK, Switzerland, California, or elsewhere, we extend the following rights to every user of District Seal. Send your request to privacy@districtseal.com.
- Access. You can request a copy of the data we hold about you.
- Correction. You can request that inaccurate data be corrected.
- Deletion. You can request that we delete your account and all data associated with it. We will comply within 30 days, except where retention is legally required (see section 4).
- Portability. You can request your data in a structured, machine-readable format (JSON or CSV).
- Objection. You can object to processing carried out on the basis of legitimate interests.
- Restriction. You can ask us to pause processing while a dispute is resolved.
- Complaint. If you are in the EEA or UK, you have the right to lodge a complaint with your national data protection authority.
We do not charge for these requests and do not require you to justify them.
8. Cookies and local storage
We use one cookie-equivalent (localStorage) to keep you logged in. No tracking cookies.
District Seal does not set advertising or analytics cookies. We use browser localStorage for exactly two purposes:
- To store your authentication token (JWT) so you stay logged in between page visits.
- To store your interface theme preference (dark or light).
Both are cleared when you sign out or clear your browser storage. You can decline them at any time by signing out — the service will simply require you to sign in again next time.
9. Security
Encrypted in transit, hashed in storage, access logged. We do not store card details.
- All traffic to and from District Seal is encrypted with TLS 1.2 or higher.
- Passwords are stored only as one-way hashes — never in plaintext.
- Card details are handled entirely by Dodo Payments. We never see or store them.
- Every administrative action on your account is logged with the acting admin's ID, IP address, and timestamp.
- Signed documents are hashed with SHA-256 and the hash is bound to the certificate. Any modification of the document breaks the seal.
- Access to production systems is limited to our operations team and protected by SSH keys.
10. Children
You must be 18 or older. We do not knowingly collect data from minors.
District Seal is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a minor has used the service, contact privacy@districtseal.com and we will delete the account.
11. International transfers
All data stays in the U.S. If you are in the EEA, your data is transferred under Standard Contractual Clauses.
All District Seal data is stored in the United States. If you are located in the EEA, UK, or Switzerland, using District Seal involves transferring your personal data to the U.S. We rely on the European Commission's Standard Contractual Clauses as the lawful mechanism for that transfer. A copy of the relevant SCCs is available on request from legal@districtseal.com.
12. Changes to this notice
We will post any changes to this notice on this page and update the "Last updated" date at the top. If we make a material change — for example, if we begin collecting a new category of personal data — we will notify account holders by email at least 30 days before the change takes effect.
13. Contact
privacy@districtseal.com — monitored, answered within 30 days by law.
For any question about this notice, or to exercise any of the rights described in section 7, contact:
NEXSIM LLC — Privacy Office
Email: privacy@districtseal.com
Entity: NEXSIM LLC, Montana, United States