[ Legal ](https://sendnda.com/legal)     

Privacy Policy
==============

What personal data Send NDA processes, why, for how long, and your rights over it.

 02

For everyone
------------

Document 2 of 4

 Last updated on 21 September 2026.

This policy explains what personal information we collect when you use [sendnda.com](https://sendnda.com), why we collect it, who we share it with, how long we keep it, and the rights you have. Send NDA is operated by Hold My Beer B.V., Keizersgracht 520H, 1017 EK Amsterdam, the Netherlands, Chamber of Commerce number 75807408 ("we", "us", "our"), the controller for this processing under the General Data Protection Regulation (GDPR).

Information we collect
----------------------

### When you create an agreement

To generate and send an agreement we collect the details you enter: your name, email address, postal address and, where you act for a company, its name and registration number; the name and email address of the other party; and the options you choose (who discloses, purpose, duration, optional clauses). The other party adds their own postal address and, if applicable, company details when they sign.

If you enter another person's details, you are responsible for having a lawful basis to do so. We use their details only to send them the agreement and to operate the signing process. This policy applies to them as well, and we point them to it in the email they receive.

If you received an agreement, we obtained your name and email address from the sender who created it. We use them to send you the agreement and run the signing process, and record your signing details as described below; the IP address and time of your signature appear in the completed document that both parties receive.

### When you sign

When a party views or signs an agreement we record the date and time, the IP address used, the typed signature, and a cryptographic hash of the document as signed. We also keep a chained log of events (created, sent, viewed, signed, completed, frozen) so that the history of an agreement can be verified later. This is the signing record both parties rely on as evidence of what was agreed.

### When you have an account

Accounts use magic links and passkeys; we do not store passwords. We store your name, email address, the public key of any passkey you register, and a hash of any API tokens you create (we cannot read the token itself), together with when they were last used. Agreements sent from your verified email address appear in your account.

### When you use the API or MCP server

We record when each API token was last used, and when an agent last used your account. Your settings list every token and every connected app, and you can revoke either there. AI agents you connect act on your account with the details you give them; we do not receive your conversations with them.

### Automatically

Our servers log standard request data (IP address, browser, pages requested, timestamps) for security and troubleshooting. If an error occurs we record technical details about it, which may include the request and the account involved. Website analytics are collected without cookies and in aggregate only (see Cookies below).

Why we process it and on what basis
-----------------------------------

- **To provide the service** (generate, send, sign and store agreements; run accounts and the API): performance of our contract with you, and for the other party our legitimate interest in completing the agreement they were sent.
- **To keep the signing record**: our and both parties' legitimate interest in being able to prove what was signed, by whom and when.
- **Security, abuse prevention and troubleshooting**: our legitimate interest in running a secure and reliable service.
- **Service emails** (signing links, signature notifications, completed documents): performance of our contract. We do not send marketing email ourselves.
- **A review invitation**: when an agreement is completed, we pass the sender's name and email address to Trustpilot, which may invite the sender once to review Send NDA. Our legitimate interest in collecting reviews. Email us and we stop passing on your details.
- **Legal obligations**: where we must keep or disclose information by law.

Providing the details requested when creating or signing an agreement is necessary to generate and execute it; without them we cannot provide the service. We do not make automated decisions with legal or similarly significant effects.

Who we share it with
--------------------

We share personal information only with providers that help us run Send NDA, under data processing agreements:

- **DigitalOcean**, which hosts our application, database and stored documents on a server in Amsterdam, the Netherlands, managed through **Laravel Forge**. DigitalOcean is a US company; our data processing agreement with it includes Standard Contractual Clauses for any access from outside the EEA.
- **Resend**, which delivers our email (signing links, notifications, completed documents). Resend is based in the United States and processes recipient email addresses and message content under Standard Contractual Clauses.
- **Plausible Analytics** (EU), which gives us aggregate visitor statistics without cookies or personal identifiers.
- **Trustpilot** (Denmark), which receives the sender's name and email address when an agreement is completed, to invite them to review Send NDA. The recipient's details never go to Trustpilot.

We may also disclose information where required by law, court order or a competent authority, to establish or defend legal claims, or to a successor if Send NDA is transferred to another operator, who will remain bound by this policy.

We do not sell personal information and we do not use your agreements to train AI models.

International transfers
-----------------------

Your data is stored in the European Economic Area. Where a provider processes or can access data from outside the EEA, we rely on the European Commission's Standard Contractual Clauses.

How long we keep it
-------------------

- **Drafts** that were never sent and never confirmed are deleted after 7 days.
- **Sent but incomplete agreements** are deleted 90 days after they were sent, or earlier if the sender asks us to.
- **Completed agreements** and their signing records are kept for 10 years after completion. This covers the longest term and confidentiality period Send NDA offers and the limitation periods for claims under the agreement. Because the other party relies on the same record to establish or defend legal claims, a request by one party to delete a completed agreement will normally be refused on that ground (GDPR Article 17(3)(e)); we delete earlier where both parties ask us to or where the law requires it.
- **Account data** is kept while your account exists. If you ask us to delete your account we remove your profile, passkeys and tokens within 14 days; agreements you are a party to stay subject to the rules above.
- **Server and error logs** are kept for up to 14 days.

Security
--------

Traffic is encrypted in transit. Signing links are signed URLs that cannot be guessed. Completed documents are frozen: the rendered document and PDF are stored with a hash that is recorded in the event chain, so later changes to the template or to the database cannot alter what was signed. Access to the server is restricted to the people who operate Send NDA. No method of storage or transmission is completely secure; if a breach affects your data we will tell you and the supervisory authority as the law requires.

Your rights
-----------

You have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to restrict or object to its processing, and to receive it in a portable format. You can exercise these rights by emailing us. We may ask you to verify your identity. Deletion of a completed agreement is subject to the retention rules above, because the other party has the same interest in the record as you do. You also have the right to complain to a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.

Children
--------

Send NDA is not intended for anyone under 18 and we do not knowingly collect information from children.

Cookies
-------

We set only the cookies needed to run the site. Our analytics do not use cookies. When a sender completes an agreement, Trustpilot's invitation script stores an invitation reference in their browser. See our [Cookie Policy](https://sendnda.com/legal/cookies).

Changes
-------

We update this policy when our processing changes, and publish the new version on this page with a new date. For material changes we notify account holders by email.

Contact
-------

Privacy questions and requests: .

  [   Every document ](https://sendnda.com/legal)Questions:
