DSign

Last updated August 14, 2026

DSign Privacy Policy

This policy describes the data processing performed by the current DSign implementation. DSign is operated by Shagya Tech.

Files and data we process

When you select files, the PDF and signature image remain in your browser while DSign reads the page count, cleans the image, and displays a preview. After you select Sign Document, the browser sends the PDF, signature image, page number, coordinates, and placement size to the DSign API in one request.

The API validates the data, creates private temporary working files, generates the signed PDF, and returns it directly in the response. The active workflow does not create document records in a database or provide public URLs for the original PDF, signature, or result.

Storage and deletion

Working files are needed only while a processing request is active. The temporary directory, original PDF, signature image, and result are deleted before the request finishes, whether processing succeeds or fails. The result received by the browser is exposed through a temporary local URL in your tab and released when the result is replaced or the page closes.

DSign does not intentionally retain a copy of a user's document after the response completes. The files still pass through the server during final processing; do not use the service if your organization prohibits sending documents to an external server.

Technical logs and service security

The server records requests for operation and diagnostics. Technical logs may include time, method, path, response status, duration, request ID, and network information available on the request. Application logs do not intentionally record PDF contents, signature contents, or uploaded filenames. The API also applies file type and size validation and request limits; these controls do not eliminate every security risk.

Cookies, analytics, and advertising providers

DSign loads Google Analytics 4 when a valid Measurement ID is configured. Analytics receives page paths and tool-stage events such as upload success or failure, signature method, generation, and download clicks. DSign events do not send filenames, PDF or signature contents, document IDs, file URLs, coordinates, or raw error messages. Google may still receive technical information such as IP address, browser, device, and page URL.

DSign may load Google AdSense, Adsterra, or Infolinks to display and measure advertising. These providers may receive the page URL, IP address, browser and device information, and may use cookies or similar technologies according to their policies.

Read how Google uses data from partner sites, the Adsterra Privacy Policy, and the Infolinks Privacy Policy. You can manage Google personalization through Google Ad Settings.

How we use data

Data is used to receive and validate files, display previews, generate signed PDFs, provide downloads, maintain service stability and security, understand feature usage through analytics, and display advertising when providers are configured.

Your choices and requests

You can stop before selecting the processing button, in which case the files are not sent to the API. For privacy questions, use the Contact page without attaching a sensitive document.

Policy changes

This policy may be updated when storage workflows, providers, features, or obligations change. The update date will appear at the top of this page.