MusiSign Privacy Policy
This Privacy Policy explains how Musifacts Europe BV processes personal data when Users access or use MusiSign, including when they create an account, upload Documents, send signature requests, review Documents or apply Electronic Signatures.
1. Controller and contact details
Musifacts Europe BV, Hughersluys 23, 4536 HM Terneuzen, The Netherlands, VATNL858651592.B01, KvK 71285830, website https://www.musisign.com, phone +31 (115) 785010, email info@musifacts.com, is responsible for the operation of MusiSign. Privacy and legal requests may be sent to info@musisign.com.
2. Roles under GDPR
Depending on the specific use of MusiSign, Musifacts Europe BV may act as a data controller for account, security, audit, operational and business relationship data. Where Users upload Documents or personal data on behalf of their own organisation or another party, Musifacts Europe BV may process that information as a processor or service provider in accordance with applicable instructions and agreements.
3. Personal data we process
We may process the following categories of personal data:
- account information, such as name, email address, organisation and access rights;
- Document content and data entered into fields;
- Recipient information, such as name, email address and signing role;
- Electronic Signature data and signature images or marks;
- audit and traceability data, including timestamps, IP address, user agent and events;
- authentication data, including sessions, CSRF tokens, optional passkeys and 2FA status;
- integration data from enabled providers, such as SSO identifiers, webhook delivery data, API token metadata, document storage references or email delivery data;
- technical logs needed for security, troubleshooting and service operation;
- support communications and administrative correspondence.
4. Purposes of processing
We process personal data to:
- provide, operate and secure MusiSign;
- authenticate Users and manage accounts;
- send and manage Document workflows;
- record Electronic Signatures, audit trails and verification evidence;
- deliver transactional emails and service notifications;
- support S3-compatible storage, SMTP email delivery, APIs and webhooks;
- support optional authentication and security features, such as passkeys and 2FA;
- prevent abuse, investigate security events and protect legal interests;
- comply with legal, accounting, audit and regulatory obligations;
- respond to questions, support requests and legal requests.
5. Legal bases
Processing may be based on performance of a contract, legitimate interests, compliance with legal obligations, consent where required, or other lawful bases available under Regulation (EU) 2016/679 (GDPR) or applicable law.
6. Data location
Documents, metadata, audit records and associated platform data are stored on Musifacts-controlled infrastructure in Europe. Document files are stored using configured S3-compatible document storage, and transactional email is delivered through Mailgun Europe SMTP. Some limited data may be processed by external providers used for document storage, email delivery, domain routing, security, backup or operational support, subject to appropriate safeguards.
7. Configured storage and service providers
The current production configuration of MusiSign uses the following storage, delivery and integration functions. These providers or functions may process limited data needed for their purpose:
- S3-compatible document storage
- Mailgun Europe SMTP transactional email delivery
- webhooks and public API integrations
8. Sharing of personal data
Personal data may be shared with Senders, Recipients and authorised Users involved in a Document workflow; service providers supporting operation of MusiSign; professional advisers; public authorities where legally required; or other parties where necessary to protect rights, security or legal interests.
9. Retention
There is no fixed universal retention period for all signed Documents. Personal data is retained only for as long as necessary to provide MusiSign, maintain signed Documents and audit trails, meet legal obligations, preserve evidence, resolve disputes and support business records. Retention periods may vary depending on the type of Document, applicable European and national legal requirements and the relevant business relationship.
10. Security
Musifacts Europe BV applies technical and organisational measures designed to protect personal data, including access controls, encrypted transport, audit records, traceability features, system monitoring and controlled administrative access. No system can be guaranteed to be completely secure.
11. Your rights
Subject to applicable law, individuals may have rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. Requests can be sent to info@musisign.com. We may need to verify identity and assess whether the request affects legal retention of signed Documents or audit evidence.
12. International transfers
Where personal data is transferred outside the European Economic Area, Musifacts Europe BV will rely on appropriate safeguards where required, such as adequacy decisions, standard contractual clauses or other mechanisms recognised by applicable data protection law.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Updated versions will show a version number, effective date and last updated date.

