Privacy Policy
This policy explains what personal information COSIGN collects, why we collect it, how we use and share it, how long we keep it, and the privacy rights available to you. It applies to our website and to the COSIGN service.
Summary
COSIGN is the authorization layer for the AI era. We are a business-to-business service, so most of the personal information we handle is work contact details and the transaction metadata our customers send us to authorize a consequential action.
- We collect the work contact details you submit, limited automatic technical data (logs and privacy-respecting analytics), and — for customers — the transaction metadata needed to describe and authorize an action.
- We do not sell or share your personal information for cross-context behavioral advertising, and we honor Global Privacy Control (GPC) signals.
- We do not use customer transaction data to train models, and we do not store raw banking credentials.
- You have rights to access, correct, delete, port, and object to certain processing of your data. Exercise them anytime at privacy@usecosign.com.
The sections below provide the full detail required under the GDPR, UK GDPR, CCPA/CPRA, other US state privacy laws, and Canada’s PIPEDA.
1. Who we are & scope
“COSIGN,” “we,” “us,” and “our” refer to the entity that operates the COSIGN service and the usecosign.com website and is the controller of personal information described in this policy. The contracting COSIGN entity, its registered address, and any EU/UK representative are identified in your order form or master services agreement (MSA).
This policy covers our public website and marketing activities, where COSIGN acts as a controller. When we process transaction data on behalf of a customer to provide the service, COSIGN acts as a processor(or “service provider” under US law), and that processing is governed by the data processing addendum (DPA) in the customer’s MSA, which controls in the event of any conflict with this policy.
2. Information we collect
Information you provide. Contact details submitted through the fraud-audit form or other inquiries — your work email, and optionally your name, company, role, and approximate payment volume — plus any content of messages you send us.
Information collected automatically. Standard server logs (IP address, user agent, request timestamps, pages requested) and privacy-respecting product analytics covering page performance and aggregate usage. We do not use cross-site advertising trackers or third-party advertising cookies.
Customer product data. For customers, the transaction metadata required to describe and authorize a consequential action (for example, the action type, amount thresholds, the named approver, and the cryptographic cosign decision and its immutable ledger entry). We do not store raw banking credentials.
Sources. We collect information directly from you, automatically from your device when you use the website, and from our customers and their connected systems (bank, ERP, AP, payroll, and identity providers) when we provide the service on their behalf.
3. How we use information & legal bases
We use personal information for the purposes below. Where the GDPR/UK GDPR applies, the legal basis is noted.
- Respond to inquiries and schedule fraud audits — contract / legitimate interest.
- Provide, operate, secure, and support the service — contract / legitimate interest.
- Monitor, debug, and improve performance and reliability — legitimate interest.
- Send service and, where permitted, relevant business communications — legitimate interest / consent.
- Meet legal, regulatory, audit, and security obligations and establish or defend legal claims — legal obligation / legitimate interest.
We do not sell personal information, we do not “share” it for cross-context behavioral advertising, and we do not use customer transaction data to train models. Where we rely on legitimate interests, we balance those interests against your rights; contact us to learn more or to object.
4. How we share information
We disclose personal information only in these circumstances:
- Subprocessors under contract — vetted vendors who process data on our instructions, such as cloud hosting, transactional email delivery, and product analytics. They are bound by confidentiality and data-protection terms and may use the data only to provide services to us.
- Your organization — for customer accounts, with the customer that controls the account and its authorized administrators and approvers.
- Legal & safety — where required by law, legal process, or regulatory request, or to protect the rights, safety, and security of COSIGN, our customers, or the public.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to this policy and applicable law.
A current list of subprocessors is available to customers on request at privacy@usecosign.com.
5. International data transfers
We may process and store information in the United States and other countries. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum) — together with supplementary measures where needed. A copy of the relevant safeguard is available on request.
6. Retention & security
We retain personal information only for as long as necessary for the purposes described above, to comply with our legal, tax, audit, and regulatory obligations, and to resolve disputes and enforce agreements. Audit-trail and ledger records tied to the service are retained for the period set in the customer’s MSA. When data is no longer needed, we delete or de-identify it.
Data is encrypted in transit and at rest. Access is least-privilege, authenticated, and logged. We maintain administrative, technical, and organizational safeguards designed to protect personal information; no method of transmission or storage is perfectly secure, but we work to protect your data and to notify affected parties and regulators of incidents as required by law.
7. Cookies & similar technologies
We keep our use of cookies minimal. We do not use advertising or cross-site tracking cookies. The technologies we do use fall into these categories:
- Strictly necessary — required to serve the site securely (no consent required).
- Functional — remember preferences such as theme or session state.
- Analytics — privacy-respecting, aggregate measurement of page performance and usage.
Where consent is required (EU/UK), non-essential technologies load only after you opt in. In US states that recognize it, we honor Global Privacy Control (GPC) browser signals as a valid opt-out of any sale or sharing. You can also control cookies through your browser settings.
8. Your privacy rights
EEA, UK & Switzerland (GDPR/UK GDPR). You may request access to, correction of, deletion of, restriction of, or portability of your personal data; object to processing based on legitimate interests; and withdraw consent at any time without affecting prior processing. You also have the right to lodge a complaint with your supervisory authority.
California (CCPA/CPRA) & other US states (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws). You may request to know the categories and specific pieces of personal information we collect, their sources, our purposes, and the categories of recipients; request correction or deletion; opt out of any sale or sharing; and limit the use of sensitive personal information. We do not sell or share personal information and do not use sensitive personal information for purposes requiring a right to limit. We will not discriminate against you for exercising any right.
Canada (PIPEDA). You may access your personal information and challenge its accuracy, and you may direct complaints to us and to the Office of the Privacy Commissioner of Canada.
How to exercise your rights. Email privacy@usecosign.com from the address associated with your data. We will verify your request and respond within the timeframes required by applicable law. You may use an authorized agent where the law permits. If COSIGN processes your data on behalf of a customer, we will refer your request to that customer and assist them in responding.
9. Children
COSIGN is a business service intended for organizations and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
10. Changes to this policy
We may update this policy to reflect changes in our practices or the law. We will revise the effective date and version above and, for material changes, provide additional notice through the website or, where appropriate, by email. Your continued use of the website or service after an update means you accept the revised policy.
11. Change log
- v1.0 · June 20, 2026 — First published full policy: layered notice, controller/processor roles, legal bases, subprocessor disclosure, international transfers, retention, cookie categories, and GDPR / CCPA-CPRA / US state / PIPEDA rights.
12. Contact us
Questions, requests, or complaints about this policy or your personal information: email privacy@usecosign.com. For security matters, contact security@usecosign.com.