Privacy Policy
Effective date: September 24, 2026 • View previous version
1. Introduction
DocuMocu is an electronic signature platform provided by 2 Create Ltd (the "Company", "we"). Users create, send, sign, track and store electronically signed documents with it. This Privacy Policy explains what personal data we process as a controller in connection with the DocuMocu website and platform, for what purposes and on what basis, with whom we share it, how long we retain it and what rights you have.
We are committed to transparency and process personal data lawfully, fairly and in accordance with the principles of data minimisation and purpose limitation. This Policy should be read together with the Cookie Policy and — for our customers — with the Data Processing Agreement (DPA).
This Policy is published on the website and is presented upon registration; by creating an account you confirm that you have read it. It is informational in nature and does not limit your rights under the law.
2. Roles and scope
For account and profile data, billing, support, marketing and usage of account holders (senders) we are the controller and this Policy applies in full.
For documents sent for signing and for the data of signatories within a specific signing process, we act as a processor on behalf of the customer (the sender), who is the controller; that processing is governed by the DPA.
If you are a signatory or a recipient of a signing invitation, the processing of your data is determined primarily by the sender (the controller) and its policy. We process your data as a controller in our own right only for limited purposes — security, fraud prevention, service integrity, the evidential value of the process and legal compliance.
3. Controller and contact details
Controller: 2 Create Ltd, UIC 200659554, with its registered seat and address at 8 Neptun Street, Varna 9000, Bulgaria.
Data protection contact: for questions and requests relating to personal data, contact us at [email protected].
4. How we collect personal data
Directly from you: when you create and manage an account, use the platform, contact us and pay for a subscription/lifetime plans.
Automatically: when you use the service — log records, IP address, device and browser data, timestamps of actions, session identifiers and cookies.
From third parties: from the sender — if you are a signatory, the sender provides us with your name and e-mail address so that we can send you the document for signing; from an SSO or social login provider, if you use one.
5. What personal data we process
Account and profile: names, e-mail address, password (stored in hashed form), organisation, job title/role, profile picture (optional), language, time zone.
Signing data: name and e-mail of signatories, the electronic signature applied, signing status and order, metadata (date and time, IP address, location derived from the IP address) and the audit trail of the process.
Usage and technical data: log records, IP address, device and browser type, operating system, session identifiers, platform events, error diagnostics.
Payment and billing: billing name and address, subscription details, payment history; payments are processed by a payment service provider (e.g., Stripe) and, as a rule, we do not store payment card data.
Communications and support: content of enquiries, tickets and correspondence, feedback.
Marketing: e-mail address, marketing preferences, newsletter subscription status, interaction with our communications.
Special categories of data: we do not intentionally collect special categories of personal data (Art. 9 GDPR). Documents may contain personal data of third parties, for which the sender is responsible; this is customer content processed by us as a processor (see Section 2 and the DPA).
6. Electronic signatures and audit trail
DocuMocu provides an electronic signature within the meaning of Article 3(10) of Regulation (EU) 910/2014 (eIDAS). To maintain the integrity and traceability of the signing process, we record metadata (date and time, IP address, location derived from the IP address, actions) and build an audit trail that becomes part of the evidentiary record of the signed document.
The audit trail and cryptographic checks evidence the integrity of the document (whether it has been altered) but do not in themselves establish the identity of the signatory. Signed documents and the audit trail are retained on the customer’s instruction (as a processor) and, where necessary, for evidential and legal purposes.
7. Purposes and legal bases
We process personal data for the purposes and on the legal bases under Art. 6 GDPR set out below. Where we rely on legitimate interest (Art. 6(1)(f)), we state the specific interest; the balancing assessment between it and your rights is available on request.
| Purpose | Data subjects & data | Legal basis | Retention |
|---|---|---|---|
| Account registration | account holders & users; registration data | Contract, Art. 6(1)(b) | for the duration of the account + 1 year |
| Providing the e-signing service | holders, signatories; signing data | Contract, Art. 6(1)(b) | per customer instructions (DPA) |
| Audit trail & evidential value | signatories; metadata, audit trail | Legitimate interest (integrity & evidence) & legal obligation | for the duration of the document + 3 years |
| Authentication & access management | users; identifiers, logs | Contract & legitimate interest (access security) | up to 3 years |
| Billing, subscriptions & payments | holders; billing data | Contract & legal obligation | accounting data: 10 years |
| Accounting & tax compliance | holders; accounting data | Legal obligation | 10 years |
| Customer support | users; communications | Contract & legitimate interest (support quality) | up to 5 years |
| Security & fraud prevention | users; technical, logs | Legitimate interest (network & information security) | up to 5 years |
| Analytics & service improvement | users; usage, cookies | Consent (cookies) & legitimate interest (improvement) | see Cookie Policy |
| Direct marketing & newsletter | contacts, customers; email, preferences | Consent or legitimate interest (soft opt-in) | until withdrawal of consent |
| Legal compliance & claims | as relevant | Legal obligation & legitimate interest (defence of rights) | as required by law |
| Aggregated & anonymised statistics | users; aggregated data | Legitimate interest; anonymised data fall outside the GDPR | indefinitely (anonymous) |
| Marketing data | Website data subjects | Consent | until consent is withdrawn or you object |
8. Marketing and communications
We send marketing communications and newsletters only on the basis of your consent or, for existing customers, on our legitimate interest to offer similar services (a "soft opt-in"). Every message contains an unsubscribe option, and you can withdraw your consent at any time, without affecting processing before withdrawal.
We do not disclose your data to third parties for their own marketing purposes and do not carry out profiling with legal effects for marketing purposes.
9. Recipients and sub-processors
We share personal data with categories of recipients acting on our behalf: hosting and infrastructure (DigitalOcean), object storage and CDN (Cloudflare), e-mail delivery for signing (AWS SES, Postmark) and inbound file storage (AWS S3), file previews (Filepreviews.io), error and performance monitoring (Sentry, Laravel Nightwatch), push notifications (Firebase), customer support (Intercom), payments (Stripe), e-mail marketing (Mailchimp) and analytics (Google). We also share data with professional advisers (e.g., accountants, lawyers) and competent authorities where required by law.
The providers that process personal data on our behalf act only on our instructions. These relationships are governed by data processing agreements (DPAs) that apply through acceptance of each provider's standard terms and that contain the obligations required under Art. 28 GDPR. We do not sell personal data and do not disclose it to third parties for consideration.
10. International transfers
Some of our providers are established outside the European Economic Area (EEA), including in the USA (e.g., Google, Stripe, Intercom and e-mail providers). When we transfer personal data outside the EEA, we ensure appropriate safeguards under Chapter V GDPR:
- an adequacy decision of the European Commission — for US providers certified under the EU–US Data Privacy Framework (DPF);
- the European Commission’s standard contractual clauses — for other cases or as a fallback, accompanied by a transfer impact assessment (TIA).
A copy of the applicable safeguards (e.g., the standard contractual clauses) and information about the transfer impact assessment are available on request.
11. Retention periods
We keep personal data only for as long as necessary for the relevant purposes. The criteria include the term of the account and our relationship with you, statutory retention periods and any legal claims. After they expire, data are deleted or anonymised.
12. Your rights
Under the GDPR you have the following rights, which you can exercise at any time. If you are a signatory, some requests may need to be addressed to the sender (the controller), and we will assist in accordance with the DPA:
Access: to obtain confirmation of whether we process your data and a copy of it, together with information about the processing.
Rectification: to request correction of inaccurate, or completion of incomplete, data.
Erasure ("right to be forgotten"): to request deletion of the data where there are grounds.
Restriction: to request restriction of processing in certain cases.
Portability: to receive your data in a structured, commonly used and machine-readable format or to request its transfer.
Objection: to object to processing based on legitimate interest and, at any time, to direct marketing.
Withdrawal of consent: to withdraw a given consent at any time, without affecting the lawfulness of processing before withdrawal.
Complaint: to lodge a complaint with the supervisory authority (Section 18).
To exercise your rights, contact us at [email protected]. We may request additional information to verify your identity. We respond free of charge and without undue delay, within one month, which may be extended by a further two months for complex or numerous requests (Art. 12 GDPR).
13. Security
We implement appropriate technical and organisational measures commensurate with the risk, including:
- access control and authentication on a least-privilege basis;
- encryption of data in transit (TLS) and measures to protect data at rest;
- logging and monitoring, backups and restoration capability;
- vulnerability management and regular updates; environment segregation;
- staff training, confidentiality commitments and a personal data breach procedure.
No service can guarantee absolute security. In the event of a personal data breach, we act in accordance with our internal procedure and applicable law, including notification obligations.
14. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing within the meaning of Art. 22 GDPR. To the extent we use analytics tools, they serve aggregated statistics and service improvement and do not lead to such decisions.
15. Children
The service is intended for business users and is not directed at children. We do not knowingly process personal data of children under 14 — the age of valid consent for information society services under Bulgarian law (the Personal Data Protection Act). If we learn that we have collected such data without the required consent, we delete it.
16. Third-party links
Our platform and website may contain links to third-party sites and services with their own privacy policies. We are not responsible for their content or practices and recommend that you review their policies.
17. Changes to this policy
We may update this Policy when the processing, the technologies used or the applicable requirements change. The current version is published on the website with an effective date; for material changes we will notify you by appropriate means (e.g., by e-mail or via a notice in the platform).
18. Contact and supervisory authority
Controller: 2 Create Ltd, UIC 200659554, 8 Neptun Street, Varna 9000, Bulgaria; [email protected].
If you believe we process your data unlawfully, you have the right to lodge a complaint with the Commission for Personal Data Protection (CPDP), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, [email protected], www.cpdp.bg, as well as with the supervisory authority of your habitual residence in the EU.