Privacy Policy

    Effective date: August 13, 2026

    This Privacy Policy explains how Docufoundry LLC ("Docufoundry," "we," "us," or "our"), a Georgia limited liability company, collects, uses, and shares information in connection with Formaliq (the "Service"). It applies to our customers and their authorized users ("you"), as well as to individuals who interact with the Service without an account — for example, people who fill out a form or sign a document sent through Formaliq by one of our customers.

    See also our Terms of Service, which govern use of the Service generally.

    1. Two Roles: Controller and Processor

    Formaliq is a B2B platform. Our direct customers are organizations, and this policy distinguishes between two kinds of data:

    • Account data — information about you as a Formaliq user or organization administrator (e.g., your name, email, and login activity). For this data, Docufoundry is the data controller and this policy describes our own collection and use practices directly.
    • Customer content data — information that our customers collect from their own form recipients, signers, and other end users through templates, forms, generated documents, and signature requests built on the Service (for example, names, email addresses, phone numbers, physical addresses, or other information a customer chooses to ask for). For this data, our customer is the data controller and Docufoundry acts as a data processor or service provider, handling it only under our customer's instructions and our agreement with them. If you submitted a form or signed a document through Formaliq and have questions about how that specific data is used, please contact the organization that sent you the form or signature request — they control that data. You may still contact us using the details in Section 10 and we will route or respond to your request as appropriate.

    2. Information We Collect

    a. Information you provide

    • Account registration: first name, last name, email address, password (stored as a salted hash, never in plain text), and organization name.
    • Organization and workspace data: organization name, description, and configuration you provide as an administrator.
    • Templates, forms, and generated documents: the content you build and the documents the Service generates from them.
    • Form submissions: data entered by form recipients, which can include names, addresses, phone numbers, email addresses, and other fields your organization defines. Our customers are responsible for determining what information to collect through their forms and for obtaining any consents or providing any notices required for sensitive categories of information (such as government identification numbers, financial account details, or health information) they choose to collect through the Service.
    • E-signature data: signer name and email, the document being signed, and signature events.
    • Billing information: plan and subscription details. Full payment card details are collected and stored by our payment processor, Stripe, directly — we retain only identifiers such as your Stripe customer and subscription IDs, not card numbers.
    • Support requests: information you include when you contact support, including any attachments or message content.

    b. Information collected automatically

    • Session and authentication data: a session identifier stored in an HTTP-only cookie used to keep you signed in.
    • Signup and security metadata: at signup, we log the email used, IP address, browser user agent, and a device fingerprint to help detect abusive or repeat fraudulent signups.
    • E-signature audit data: for each action taken on a document sent for signature (e.g., sent, opened, signed, declined), we record the actor's name/email, a timestamp, IP address, and browser/device (user agent) information. This data forms an audit trail intended to support the legal integrity of the signed document and, once created, is not editable or deletable by Formaliq staff.
    • Action/audit logs: we maintain internal logs of create, update, and delete actions taken within an organization's account, for security, troubleshooting, and accountability purposes.

    Drawn signatures are captured and stored as an image of the signer's input; they are not used for biometric identification or verification purposes.

    We do not currently use third-party analytics, advertising, or tracking cookies (such as Google Analytics or similar tools) on the Service. If that changes, we will update this policy.

    3. How We Use Information

    We use the information described above to:

    • Provide, operate, and maintain the Service, including authenticating users and generating documents;
    • Process payments and manage subscriptions through Stripe;
    • Send transactional communications, such as email verification, password resets, and signature-related notifications;
    • Detect, investigate, and prevent fraud, abuse, and security incidents (including signup-abuse detection via IP address and device fingerprinting);
    • Maintain the e-signature audit trail described in Section 2(b), which may be relied on as evidence of the signing process;
    • Provide customer support; and
    • Comply with legal obligations and enforce our Terms of Service.

    We do not sell personal information, and we do not use customer content data (Section 1) for our own advertising or marketing purposes.

    4. How We Share Information

    We share information with the following categories of service providers, each acting as our subprocessor and only as needed to provide the Service:

    • Stripe — payment processing and subscription billing.
    • Cloud file storage (e.g., AWS S3 or a compatible service) — storage of uploaded templates and generated documents.
    • Email delivery providers (e.g., SMTP, Amazon SES, or Resend, depending on configuration) — delivery of transactional emails such as verification, password reset, and signature-request emails.
    • Infrastructure/hosting and caching providers — to run and scale the Service.

    We do not share personal information with third parties for their own independent marketing purposes. We may also disclose information if required by law, to protect the rights, property, or safety of Docufoundry, our users, or others, or in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality protections.

    5. Data Retention

    We retain account data for as long as your account is active and as needed to provide the Service. Customer content data (templates, forms, submissions, generated documents, and signature records) is retained for as long as the owning organization's account remains active, or as instructed by that organization, except that completed e-signature audit trails are retained as immutable records to preserve their evidentiary value. We may retain limited information after account closure where necessary for legal, tax, security, or fraud- prevention purposes.

    6. Your Choices and Rights

    Depending on your state of residence, you may have rights under laws such as the California Consumer Privacy Act (CCPA/CPRA) and similar laws in states including Colorado, Connecticut, Virginia, Utah, and Oregon. These may include the right to know what personal information we hold about you, the right to request correction or deletion of that information, the right to obtain a portable copy of it, and the right to be free from discrimination for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising, so opt-out rights related to sale or sharing are not applicable to our practices.

    Formaliq does not currently offer a fully self-service account-deletion or data-export tool. To make a request, contact us using the details in Section 10 (or, if you are a form recipient or signer whose data was collected by one of our customers, contact that organization directly, since they control that data as described in Section 1). We will verify your identity, respond within the time required by applicable law, and handle requests consistent with our obligations to the organizations that use our Service.

    7. Security

    We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction — including password hashing, HTTP-only session cookies, and organization-scoped access controls that keep each organization's data isolated from others. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

    In the event of a security incident that compromises personal information we control or process, we will notify affected customers and, where required by law, affected individuals or regulators, without undue delay and in accordance with applicable legal requirements.

    For customers who require a Data Processing Agreement governing our handling of customer content data — including subprocessor obligations, data deletion upon termination, and incident notification timing — contact us at privacy@formaliq.com to execute one.

    8. International Data Transfers

    We are based in the United States and store and process information primarily in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, which may have data protection laws different from those in your jurisdiction.

    9. Children's Privacy

    The Service is a business tool intended for use by working professionals and organizations. It is not directed to, and we do not knowingly collect personal information from, children under 13. If you believe a child has provided us with personal information, please contact us so we can address it.

    10. Contact Us

    If you have questions about this Privacy Policy or wish to make a request regarding your information, contact us at privacy@formaliq.com.

    Docufoundry LLC
    Georgia, USA

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by email or an in-product notice) before the changes take effect.

    © 2026 Docufoundry LLC. All rights reserved.