# https://sendnda.com Free, no sign-up or password Send a free NDA and start talking business. ============================================= One-way or mutual, signed online by both sides. Most are done before the coffee is. Without Send NDA Recognise this? --------------- 1. 1 Search Google for an NDA template 2. 2 Ask the other side for their personal details 3. 3 Replace the example details in the template 4. 4 Look for clauses you never wanted 5. 5 Export to PDF and email it over 6. 6 Wait for a signed copy 7. 7 Sign it yourself and send it back **There's a shorter way.** Pick one-way or mutual, add the clauses you want, type a name and an email address. The recipient fills in their own details when they sign. > “I used to avoid creating NDAs because they're such a hassle to figure out. Why go to the trouble for only a 15-min meeting? Send NDA makes it so simple it's a no brainer. It literally took 60 seconds from start to finish.” [ ![](https://sendnda.com/assets/testimonials/dagobert.png) Dagobert Renouf Logology ](https://www.logology.co) How it works Sixty seconds, both signatures. --------------------------------- You send, they sign, you countersign. Both of you get the same sealed PDF, and anyone can check it against the original later. 1. ​ Sent Emailed to both of you 2. ​ Viewed You see when they open it 3. ​ 3 Signed They sign first 4. ​ 4 Completed You countersign, both get the PDF Your law, not ours The agreement is governed by the law of the country you send from, narrowed to your state or part of the UK, and in a federation the federal law that applies there too. One page of choices One-way or mutual, how long it runs, and the clauses you want. The contract wording follows your answers. Proof that holds its shape Every step is written to a chained log. The final PDF is frozen once both of you have signed. Check any copy Upload a PDF or its signing certificate on the verify page and see whether it is the one both parties signed. Mutual NDA | 2 years + 3 years confidential Governed by Dutch law Mutual Non-Disclosure Agreement **5.** The Receiving Party shall hold the Confidential Information in strict confidence and shall not disclose it to any person other than as permitted by this Agreement … Signed electronically by Completed Ada Visser for Northwind B.V. Ada Visser 21 Sep 2026, 10:48 UTC IP 203.0.113.12 Sam Okafor for Lumen Ltd Sam Okafor 21 Sep 2026, 10:46 UTC IP 198.51.100.30 For agents Send one from Claude. ----------------------- Send NDA is an MCP server. Connect it once, and your assistant can send an NDA, fill in your details on the ones sent to you and sign them, amend or delete one until someone signs, resend the link and read the docs. Add `https://sendnda.com/mcp` as a custom connector and sign in with your email address. Sending goes out straight away, so your assistant confirms the details with you first. [Read how to connect](https://sendnda.com/docs/agents/connect-over-mcp). Claude send-nda | create-nda you Send Sam at lumen.co a mutual NDA, two years, with non-circumvent. → create-nda recipient\_name="Sam Okafor" recipient\_email=sam@lumen.co disclosing\_party=both duration=2 has\_non\_circumvent=true claude Sent. You and Sam Okafor both get a link to it by email. --- # https://sendnda.com/verify Free, no sign-up or password Verify a signed NDA ===================== Every NDA sealed through Send NDA can be checked by its exact bytes. Upload the PDF you received, or its signing certificate, and see whether it is the one both parties signed. Check a PDF ----------- The signed PDF or its certificate Drop the PDF here or click to browse PDF, up to 20 MB. Once checked, it is deleted. Verify PDF What a match means The file is byte for byte the PDF Send NDA sealed when both parties had signed, and the record of every step behind it is intact. What no match means The file was changed, even by one character, it was never sealed here, or the record behind it no longer checks out. Ask the other party for the copy they received by email. What happens to your file Its fingerprint is compared with the sealed NDAs, then the file is deleted and nothing about it is kept. A file that is not a PDF or is over 20 MB is refused unchecked, and its temporary upload is cleared once it is a day old. --- # https://sendnda.com/legal Legal. ====== Each document says who it is for, so you read only what applies to you, and when it last changed. 01 What we hold to --------------- 4 promises Send NDA gives no legal advice. It builds the agreement you configure and runs the signing. Whether that agreement suits your situation is for you and, where it matters, your lawyer. What was signed stays provable. Every step goes into a chained log, and a completed agreement is frozen with the hash of its PDF. A later change to the template does not affect it, and a change to the stored document or its log would no longer match the PDF and certificate each party received. Two cookies, both essential. One keeps your session, one protects forms against forgery. No advertising or tracking cookies, and visitor statistics without any. Your agreements train no model. We do not sell personal information, we send no marketing email ourselves, and we do not use your agreements to train AI models. 02 Everyone -------- 4 documents [Disclaimer What Send NDA is, what it is not, and how far the agreement it builds reaches. ](https://sendnda.com/legal/disclaimer) [Terms of Service The agreement between you and Hold My Beer B.V. for using Send NDA. ](https://sendnda.com/legal/terms) [Privacy Policy What personal data Send NDA processes, why, for how long, and your rights over it. ](https://sendnda.com/legal/privacy) [Cookie Policy The two cookies Send NDA sets, and why neither needs your consent. ](https://sendnda.com/legal/cookies) 03 Senders, accounts and agents ---------------------------- 1 document [Acceptable Use Policy Who you may send an agreement to, how you may sign, and what the API and MCP server may be used for. ](https://sendnda.com/legal/acceptable-use) --- # https://sendnda.com/legal/disclaimer [ Legal ](https://sendnda.com/legal) Disclaimer ========== What Send NDA is, what it is not, and how far the agreement it builds reaches. 02 For everyone ------------ Document 1 of 5 Last updated on 25 September 2026. **Send NDA is not a law firm and gives no legal advice.** Nothing it produces is an opinion on your situation, and using it creates no client relationship with Hold My Beer B.V. or anyone else. What Send NDA does ------------------ Send NDA builds a non-disclosure agreement from the choices you make, emails it to both parties, and runs the signing. It records what happened in a chained log and freezes the completed agreement with the hash of its PDF, so what was signed can be shown later to be what is held now. That record is the thing Send NDA stands behind. What Send NDA does not do ------------------------- - It does not tell you whether an NDA is the right instrument for what you are doing, or whether these terms suit your situation. - It does not promise the agreement is enforceable. Whether a clause holds is for a court, under the law that governs the agreement and the law of the place where someone tries to enforce it. - It does not check who you are sending to, what you disclose to them, or whether you are entitled to disclose it. - It does not advise on the choices in the form. Which country governs, how long the agreement runs, and whether to add a penalty are yours to make. The law behind the agreement ---------------------------- The agreement is written against the law of the country the sender is in, and the other party's own country can take a clause out of it. How far a legal system has been read decides how far the agreement goes in answering it. Some have been read by a lawyer. Most we have read ourselves, from each country's own legislation, with the source and the date recorded. Some nobody has read, and there the agreement carries its general text, which is written to hold anywhere and asks nothing of a country in particular. That general text is not a lesser agreement. It is the same document without the parts that only make sense somewhere specific, and a penalty for a breach is left out of it, because an agreed sum is the clause most likely to be cut down by a court that was never asked about it. The other languages ------------------- Where the law of a party's own country asks for the agreement in that country's language, Send NDA issues a text in that language beside the English one, inside the same document and the same signature. Where they differ, the English text is the one the parties are bound by, and the other is a translation of it. That is stated in every text, in its own language. Before you rely on it --------------------- Read the agreement before you send it, and read it again before you sign it. It is short on purpose. Where a lot rides on what you are about to share, have a lawyer in your own jurisdiction read it first, and where the other party is somewhere you do not know the law of, have someone who does look at it. Liability --------- What Hold My Beer B.V. is liable for, and up to what amount, is set out under Limitation of liability in the [Terms of Service](https://sendnda.com/legal/terms). Send NDA is not a party to any agreement made through it, so a dispute about an NDA is between the parties to it. [ Every document ](https://sendnda.com/legal)Questions: --- # https://sendnda.com/legal/terms [ Legal ](https://sendnda.com/legal) Terms of Service ================ The agreement between you and Hold My Beer B.V. for using Send NDA. 02 For everyone ------------ Document 2 of 5 Last updated on 25 September 2026. Send NDA is operated by Hold My Beer B.V., Keizersgracht 520H, 1017 EK Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce under number 75807408, VAT NL860403063B01 ("we", "us", "our"). We operate the website at [sendnda.com](https://sendnda.com) and the services offered through it. These Terms of Service (the "Terms") are a legally binding agreement between you and us. By using Send NDA you agree to them, together with our [Privacy Policy](https://sendnda.com/legal/privacy), [Cookie Policy](https://sendnda.com/legal/cookies) and [Acceptable Use Policy](https://sendnda.com/legal/acceptable-use). If you do not agree, do not use Send NDA. What Send NDA is ---------------- Send NDA generates a non-disclosure agreement from the details you enter, emails a signing link to both parties, collects each party's electronic signature, and stores the signed document together with a signing record. Agreements can be one-way (either party discloses) or mutual. Sending an agreement, or opening one you received, creates an account for your email address, without a sign-up step or password. You sign in with a one-time link sent to that address or with a passkey, and you can also use Send NDA through our API and MCP server with a token issued to your account. Send NDA is free. We may change, limit, suspend or withdraw any part of it at any time. Nothing we make available for free entitles you to its continued availability, to any particular feature, or to support. Not legal advice ---------------- Send NDA provides a document template and a signing tool. It does not provide legal advice, and using it does not create a lawyer-client relationship. We are not a law firm and we do not review your agreement. The template is written to be reasonable in many jurisdictions, but whether it is suitable and enforceable for your situation depends on the parties, the information involved, and the law that applies to you. Have the agreement reviewed by a lawyer qualified in your jurisdiction where it matters. You are responsible for your agreement -------------------------------------- By creating an agreement you confirm that: - you are at least 18 years old and have the legal capacity to enter into contracts, and if you act for a company, you have the authority to bind it; - the details you enter about yourself and the other party are accurate, and you have a lawful basis to give us the other party's name and email address so we can send them the agreement; - you have chosen the options (who discloses, purpose, duration, optional clauses, governing law) yourself and understand their effect. Send NDA is not a party to any agreement made through it and has no obligations under it. Any dispute about an agreement is between the parties to that agreement. Electronic signatures and the signing record -------------------------------------------- By signing an agreement on Send NDA you consent to sign electronically and agree not to contest the agreement, or your signature on it, on the ground that it is electronic. What effect the law gives that signature is for the law that applies to you: under the eIDAS Regulation only a qualified electronic signature is automatically equivalent to a handwritten one, and Send NDA does not issue qualified signatures. You sign while signed in to the account for your email address, using a one-time sign-in link, a passkey, or an API or OAuth token used by an AI agent you have connected. When you sign, we record your email address, which credential was used (by reference, never the credential itself), the date and time, the IP address and user agent the signature came from, the template version and a cryptographic hash of the text you signed. When an agent signs for you, that IP address and user agent are the agent's, not your device's. We keep this signing record together with the signed document so that either party can later show what was signed, by whom, and when. The completed document and its signing certificate are sent to both parties by email and remain available in each party's account while that account exists and we keep the agreement. Both parties to a completed agreement rely on that record to establish or defend legal claims. A request by one party alone to delete a completed agreement will normally be refused on that ground; see our Privacy Policy for retention. Accounts, API tokens and AI agents ---------------------------------- You are responsible for everything done through your account and with your API tokens, including actions taken by AI agents you connect through our MCP server. Keep your tokens confidential, revoke any token you no longer use, and tell us immediately if you suspect unauthorised access. An agent you connect can, on your account, list, read, create, amend, resend and delete unsigned agreements, fill in your details as a recipient, and sign agreements when you instruct it to. It sends and amends without a separate confirmation step, and a signature it gives with a token issued to your account is your signature. Configure and supervise it accordingly. We may suspend or close an account, or restrict access, with immediate effect where we reasonably believe it is used in breach of these Terms, poses a security risk, or exposes us or others to liability. Where the issue can be remedied and immediate action is not necessary, we will give you notice and an opportunity to remedy it first. Acceptable use -------------- You must not use Send NDA to send unsolicited or deceptive agreements, to harass anyone, to impersonate another person or company, to enter agreements you have no authority to enter, to interfere with the service, or in breach of any law. Our [Acceptable Use Policy](https://sendnda.com/legal/acceptable-use) sets this out in more detail. Your content and our rights --------------------------- You keep all rights in the details and documents you create. You grant us only the licence we need to operate the service: to store, render, send and make available your agreements to the parties to them, and to keep the signing record. We do not use your agreements for marketing, and we do not use them to train AI models. We own the Send NDA template, website, software and brand. You may use the agreements generated for you for your own purposes. You may not copy, resell or mirror the template or the service, or remove the Send NDA attribution from generated documents. Third-party services -------------------- We rely on third-party providers for hosting, email delivery and analytics, listed in our Privacy Policy. We are not responsible for failures caused by those providers, but we remain responsible to you for operating the service. Disclaimer of warranties ------------------------ Send NDA is provided "as is" and "as available". To the maximum extent permitted by law we disclaim all warranties, express or implied, including fitness for a particular purpose, non-infringement, and that the service will be uninterrupted, error-free or secure, or that any agreement generated is enforceable in your jurisdiction. Limitation of liability ----------------------- To the maximum extent permitted by law, we are not liable for indirect, incidental, special or consequential loss, or for loss of profit, business, goodwill, opportunity or data, arising out of or in connection with Send NDA or any agreement made through it. Our total liability to you for all claims together is limited to €100. Nothing in these Terms excludes or limits liability for death or personal injury caused by our negligence, for fraud, for our intent or deliberate recklessness (opzet of bewuste roekeloosheid) or gross negligence, or for any other liability that cannot be excluded or limited under applicable law. Where you are a consumer, your mandatory statutory rights are not affected. Indemnity --------- You will indemnify us against claims, losses and reasonable costs arising from your breach of these Terms, your infringement of a third party's rights, or an agreement you created or signed through Send NDA, to the extent permitted by applicable law. This indemnity applies only where you use Send NDA in the course of a business or profession. Changes to these Terms ---------------------- We may amend these Terms. Non-material changes take effect when published on this page. For material changes we will give reasonable notice by email to account holders or by a notice on the site. Your continued use after the effective date means you accept the revised Terms. Governing law and disputes -------------------------- These Terms are governed by the laws of the Netherlands. Before starting legal proceedings, contact us with a description of the dispute so we can try to resolve it within 30 days. Disputes that cannot be resolved are brought before the competent court in the Netherlands, unless mandatory consumer law gives you the right to bring them before the courts of your own country. General ------- If a provision of these Terms is held invalid or unenforceable, that provision is severed to the extent of the invalidity and the rest remains in force. Words may be removed from a provision in order to sever it, and no provision is rewritten or given a meaning it does not have. Our failure to enforce a right is not a waiver. You may not assign these Terms without our consent; we may assign them in connection with a merger, acquisition or sale of assets. The English version of these Terms prevails over any translation. Where an agreement made through Send NDA is issued in a second language beside the English, the English text of that agreement is the one its parties are bound by. These Terms, the Privacy Policy, the Cookie Policy and the Acceptable Use Policy are the entire agreement between you and us about Send NDA. Contact ------- Questions about these Terms: . [ Every document ](https://sendnda.com/legal)Questions: --- # https://sendnda.com/legal/privacy [ Legal ](https://sendnda.com/legal) Privacy Policy ============== What personal data Send NDA processes, why, for how long, and your rights over it. 02 For everyone ------------ Document 3 of 5 Last updated on 25 September 2026. This policy explains what personal information we collect when you use [sendnda.com](https://sendnda.com), why we collect it, who we share it with, how long we keep it, and the rights you have. Send NDA is operated by Hold My Beer B.V., Keizersgracht 520H, 1017 EK Amsterdam, the Netherlands, Chamber of Commerce number 75807408 ("we", "us", "our"), the controller for this processing under the General Data Protection Regulation (GDPR). Information we collect ---------------------- ### When you create an agreement To generate and send an agreement we collect the details you enter: your name, email address, postal address and, where you act for a company, its name and registration number; the name and email address of the other party; and the options you choose (who discloses, purpose, duration, optional clauses). The other party adds their own postal address and, if applicable, company details when they sign. If you enter another person's details, you are responsible for having a lawful basis to do so. We use their details only to send them the agreement and to operate the signing process. This policy applies to them as well, and we point them to it in the email they receive. If you received an agreement, we obtained your name and email address from the sender who created it. We use them to send you the agreement and run the signing process, and record your signing details as described below; your name, company, email address and the time and IP address of your signature appear in the completed document and its signing certificate, which both parties receive, and the certificate also shows the IP address from which you first opened the agreement. ### When you sign When the recipient first opens an agreement we record the date and time and the IP address. When a party signs it we record the date and time, the IP address and user agent (browser and device) used, the typed signature, and a cryptographic hash of the document as signed. When a party signs we also record which credential was used (a one-time sign-in link, a passkey, or an API or OAuth token used by an AI agent), by reference only and never the credential itself. When an agent signs, the IP address and user agent are the agent's, not the party's device. We keep a chained log of events (created, sent, resent, viewed, amended, redlined, notified, approved, signed, completed, frozen, certified) so that the history of an agreement can be verified later. An amendment event records the values before and after the change. A redlined event records that the sender was shown which clauses the other party's own law changed. A notified event records what a party was shown about the law of their own country, in the wording they were shown, before they signed. An approved event records that a party approved the clauses their governing law asks them to approve apart from the rest. We also record whether our emails about the agreement were delivered or bounced. This is the signing record both parties rely on as evidence of what was agreed. When an agreement is completed we issue a signing certificate with the signed PDF. For each party it shows the name, company and email address and the time and IP address of signing. It also shows the events in the signing record, among them the browser each party signed with and the IP address from which the recipient first opened the agreement, including any changes made before signing with the old and new values, and the hashes of the documents. Both parties receive the certificate, so each party's details on it are shared with the other party. When you are signed in and we show you the text of an agreement, the preview while you draft one included, we record that we showed it to you, and we mark that copy of the text with an identifier for that record. The mark is invisible and changes nothing the agreement says. It lets a copy of the text that turns up elsewhere be traced back to the account it was shown to. A copy you download before anyone has signed is printed with your name on it. Each agreement also words a few of its phrases in one of several equivalent ways, chosen for that agreement alone. Both parties sign that wording and the sealed PDF carries it, so a copy of the agreement found elsewhere can be traced to the agreement and its parties. ### When you have an account Sending an agreement, or opening one you received, creates an account for your email address. There is no sign-up step and no password: you sign in with a one-time link sent to that address or with a passkey. We store your name, email address, the public key of any passkey you register, and a hash of any API tokens you create (we cannot read the token itself), together with when they were last used. Agreements you sent or received at your email address appear in your account. ### When you use the API or MCP server We record when each API token was last used, and when an agent last used your account. The Agents page in your account lists every token and every connected app, and you can revoke either there. AI agents you connect act on your account with the details you give them; we do not receive your conversations with them. ### Automatically Our servers log standard request data (IP address, browser, pages requested, timestamps) for security and troubleshooting. If an error occurs we record technical details about it, which may include the request and the account involved. Website analytics are collected without cookies and in aggregate only, and not on sign-in pages or an agreement's own page, where you sign (see Cookies below). Why we process it and on what basis ----------------------------------- - **To provide the service** (generate, send, sign and store agreements; run accounts and the API): performance of our contract with you, and for the other party our legitimate interest in completing the agreement they were sent. - **To keep the signing record and issue the signing certificate**: our and both parties' legitimate interest in being able to prove what was signed, by whom and when. - **Security, abuse prevention and troubleshooting**: our legitimate interest in running a secure and reliable service. - **Service emails** (signing links, signature notifications, completed documents): performance of our contract. We do not send marketing email ourselves. - **Legal obligations**: where we must keep or disclose information by law. Providing the details requested when creating or signing an agreement is necessary to generate and execute it; without them we cannot provide the service. We do not make automated decisions with legal or similarly significant effects. Who we share it with -------------------- We share personal information only with providers that help us run Send NDA, under data processing agreements: - **DigitalOcean**, which hosts our application, database and stored documents on a server in Amsterdam, the Netherlands, managed through **Laravel Forge**. DigitalOcean is a US company; our data processing agreement with it includes Standard Contractual Clauses for any access from outside the EEA. - **Resend**, which delivers our email (signing links, notifications, completed documents). Resend is based in the United States and processes recipient email addresses and message content under Standard Contractual Clauses. - **Visitors** (visitors.now), which processes and stores its data in the European Union and gives us aggregate visitor statistics without cookies or personal identifiers. We may also disclose information where required by law, court order or a competent authority, to establish or defend legal claims, or to a successor if Send NDA is transferred to another operator, who will remain bound by this policy. We do not sell personal information and we do not use your agreements to train AI models. International transfers ----------------------- Your data is stored in the European Economic Area. Where a provider processes or can access data from outside the EEA, we rely on the European Commission's Standard Contractual Clauses. How long we keep it ------------------- - **Drafts** that were never sent are deleted 7 days after creation if they were never confirmed, and 90 days after they were last changed if they are saved in an account. - **Sent but incomplete agreements** are deleted 90 days after they were sent, or earlier if the sender deletes them from their account or through an agent. - **Completed agreements**, their signing records and signing certificates are kept until five years after the end of the confidentiality period stated in the agreement, which matches the ordinary limitation period for claims under it. Each party keeps its own sealed copy after that. Because the other party relies on the same record to establish or defend legal claims, a request by one party to delete a completed agreement will normally be refused on that ground (GDPR Article 17(3)(e)); we delete earlier where both parties ask us to or where the law requires it. - **Account data** is kept while your account exists. You can delete your account yourself at any time. Deletion is immediate and removes your profile, passkeys, tokens and connected apps; agreements you are a party to stay subject to the rules above. - **Records of who was shown an agreement** are kept while your account exists and are deleted with it. They outlive the agreement itself, so that a copy of the text found later can still be traced to the account it was shown to. - **Sign-in links and session data** are deleted within 30 days, and records of failed background tasks, which can contain email addresses and agreement details, within 14 days. - **Server and error logs** are kept for up to 14 days. Security -------- Traffic is encrypted in transit. Sign-in and signing links carry a single-use token that cannot be guessed and that expires: after 15 minutes for a sign-in link and after 7 days for the link in an agreement email. Completed documents are frozen: the rendered document and PDF are stored with a hash that is recorded in the event chain, so a later change to the template does not affect what was signed, and a change to the stored document or log would no longer match the PDF and certificate each party received. Access to the server is restricted to the people who operate Send NDA. No method of storage or transmission is completely secure; if a breach affects your data we will tell you and the supervisory authority as the law requires. Your rights ----------- You have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to restrict or object to its processing, and to receive it in a portable format. You can exercise these rights by emailing us. We may ask you to verify your identity. Deletion of a completed agreement is subject to the retention rules above, because the other party has the same interest in the record as you do. You also have the right to complain to a supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens. Children -------- Send NDA is not intended for anyone under 18 and we do not knowingly collect information from children. Cookies ------- We set only the cookies needed to run the site. Our analytics do not use cookies, and no third-party script sets anything on your device. See our [Cookie Policy](https://sendnda.com/legal/cookies). Changes ------- We update this policy when our processing changes, and publish the new version on this page with a new date. For material changes we notify account holders by email. Contact ------- Privacy questions and requests: . [ Every document ](https://sendnda.com/legal)Questions: --- # https://sendnda.com/legal/cookies [ Legal ](https://sendnda.com/legal) Cookie Policy ============= The two cookies Send NDA sets, and why neither needs your consent. 02 For everyone ------------ Document 4 of 5 Last updated on 22 September 2026. This policy is part of our [Privacy Policy](https://sendnda.com/legal/privacy) and explains which cookies [sendnda.com](https://sendnda.com) stores on your device and why. What a cookie is ---------------- A cookie is a small piece of data a website stores on your device. It lets the site recognise your browser on your next request, for example to keep you signed in or to protect a form against forgery. Cookies set by the site you are visiting are first-party cookies; cookies set by other companies are third-party cookies and can be used to follow you across sites. The cookies we set ------------------ Send NDA sets only essential first-party cookies. They are necessary to run the site, so there is no consent banner and they cannot be switched off while you use it. - `sendnda_session` holds your session, so the site remembers you between requests while you create, preview or sign an agreement and while you are signed in to your account. - `XSRF-TOKEN` protects forms against cross-site request forgery. No tracking cookies ------------------- We do not use advertising, targeting or social media cookies. Our visitor statistics come from Visitors (visitors.now). Its script runs on our pages except the sign-in pages and an agreement's own page, where you sign, and works without cookies and without storing personal identifiers. No third-party script sets anything on your device. Controlling cookies ------------------- You can block or delete cookies in your browser settings. If you block our essential cookies you will not be able to sign in or complete an agreement. Changes ------- If we add cookies that are not essential, we will update this page and ask for your consent before setting them. Contact ------- Questions about cookies: . [ Every document ](https://sendnda.com/legal)Questions: --- # https://sendnda.com/legal/acceptable-use [ Legal ](https://sendnda.com/legal) Acceptable Use Policy ===================== Who you may send an agreement to, how you may sign, and what the API and MCP server may be used for. 03 For senders, accounts and agents -------------------------------- Document 5 of 5 Last updated on 22 September 2026. This policy describes how Send NDA may and may not be used. It is part of our [Terms of Service](https://sendnda.com/legal/terms). It exists to protect the people who receive agreements through Send NDA, other users, and the service itself. Accounts used in breach of it can be suspended or closed, and in serious cases we may be obliged to report the conduct to the authorities. Sending agreements ------------------ Send an agreement only to someone who expects it or with whom you are genuinely in discussions. Send NDA is not a tool for bulk or unsolicited mail. You must not: - send agreements to people who have not agreed to receive one from you, or to harvested or purchased address lists; - enter a name, company or address that is not yours or that you are not authorised to use, or otherwise impersonate a person or organisation; - enter another person's email address to get them to sign something they have not been told about; - use an agreement, or the threat of one, to harass, intimidate or defraud anyone. Signing ------- Sign only on your own behalf, or on behalf of a company you are authorised to bind. Do not sign as, or for, someone else without their authority. An AI agent may sign for you only on your instruction to sign that agreement. Do not set up an agent to sign without that instruction, or to sign for someone else. Accounts and API access ----------------------- You are responsible for everything done with your account and API tokens, including by AI agents and apps you connect through OAuth. Connect only apps you trust, and revoke any you no longer use on the Agents page. You must not share tokens with people who are not authorised to act for you, attempt to access another user's agreements or account, or probe, scan or test the service for vulnerabilities without our written permission. If you find a security issue, tell us at and give us a reasonable time to fix it before disclosing it. The service ----------- You must not interfere with the service or its infrastructure, circumvent rate limits or access controls, or scrape the site. Automated access is allowed only through the API, the MCP server (including its documentation tool) and the Markdown versions of our public pages. Do not copy, resell, mirror or white-label the template or the service. Lawful use ---------- Use Send NDA only in compliance with the laws that apply to you and to the other party, including data protection law when you enter someone else's details. Enforcement ----------- We decide at our reasonable discretion whether this policy has been breached. Where the breach can be remedied and immediate action is not needed, we will contact you first. Otherwise we may suspend or close the account, withdraw agreements that have not yet been completed, and revoke API tokens without notice. Contact ------- Report abuse or ask a question: . [ Every document ](https://sendnda.com/legal)Questions: --- # https://sendnda.com/docs Docs. ===== How to send an NDA and sign one, what every choice changes in the contract, what evidence Send NDA keeps, how to look after your account, and how an agent sends one for you. 01 Start here ---------- 3 articles [What Send NDA is A free way to send a non-disclosure agreement that both sides sign online, and what it deliberately is not. ](https://sendnda.com/docs/getting-started/what-send-nda-is) [Send your first NDA Fill in one form, confirm your email address, and both of you get a signing link. ](https://sendnda.com/docs/getting-started/send-an-nda) [Sign an NDA you received What the recipient sees, what they fill in, and what happens after they sign. ](https://sendnda.com/docs/getting-started/sign-an-nda) 02 Topics ------ 5 topics | 16 articles 3 articles [Getting started --------------- What Send NDA does, and the two sides of one agreement: sending it and signing it. ](https://sendnda.com/docs/getting-started)- [What Send NDA is](https://sendnda.com/docs/getting-started/what-send-nda-is) - [Send your first NDA](https://sendnda.com/docs/getting-started/send-an-nda) - [Sign an NDA you received](https://sendnda.com/docs/getting-started/sign-an-nda) 5 articles [The agreement ------------- Every choice on the form, in plain words, and what it changes in the contract. ](https://sendnda.com/docs/the-agreement)- [One-way or mutual](https://sendnda.com/docs/the-agreement/one-way-or-mutual) - [The optional clauses](https://sendnda.com/docs/the-agreement/clauses) - [Use of AI tools](https://sendnda.com/docs/the-agreement/ai-tools) - [How long it runs](https://sendnda.com/docs/the-agreement/how-long-it-runs) - [All 5 articles](https://sendnda.com/docs/the-agreement) 3 articles [Evidence -------- How Send NDA records what was signed, by whom and when, and how anyone can check a copy later. ](https://sendnda.com/docs/evidence)- [The signing record](https://sendnda.com/docs/evidence/the-signing-record) - [The sealed PDF](https://sendnda.com/docs/evidence/the-sealed-pdf) - [Verify a copy](https://sendnda.com/docs/evidence/verify-a-copy) 2 articles [Your account ------------ Signing in without a password, and looking after the NDAs you sent. ](https://sendnda.com/docs/your-account)- [Sign in](https://sendnda.com/docs/your-account/sign-in) - [Amend, resend or delete](https://sendnda.com/docs/your-account/amend-resend-delete) 3 articles [Agents and the API ------------------ Send NDA as an MCP server, the nine tools a model gets, and tokens for your own scripts. ](https://sendnda.com/docs/agents)- [Connect over MCP](https://sendnda.com/docs/agents/connect-over-mcp) - [The tools](https://sendnda.com/docs/agents/the-tools) - [API tokens](https://sendnda.com/docs/agents/api-tokens) --- # https://sendnda.com/docs/getting-started [ Docs ](https://sendnda.com/docs) Getting started. ================ What Send NDA does, and the two sides of one agreement: sending it and signing it. 01 Getting started --------------- 3 articles [What Send NDA is A free way to send a non-disclosure agreement that both sides sign online, and what it deliberately is not. ](https://sendnda.com/docs/getting-started/what-send-nda-is) [Send your first NDA Fill in one form, confirm your email address, and both of you get a signing link. ](https://sendnda.com/docs/getting-started/send-an-nda) [Sign an NDA you received What the recipient sees, what they fill in, and what happens after they sign. ](https://sendnda.com/docs/getting-started/sign-an-nda) --- # https://sendnda.com/docs/getting-started/what-send-nda-is [ Docs ](https://sendnda.com/docs) [ Getting started ](https://sendnda.com/docs/getting-started) What Send NDA is ================ A free way to send a non-disclosure agreement that both sides sign online, and what it deliberately is not. 01 Getting started --------------- Article 1 of 3 Send NDA builds a non-disclosure agreement from one form, emails a signing link to you and to the other side, and keeps a record of who signed what and when. It's free, with no sign-up or password to send one. It's made for the moment before a first real conversation: a founder about to pitch, a freelancer about to see a codebase, two companies about to compare numbers. The goal is that confidentiality takes a minute, not a week of emailing PDFs. What it does ------------ - **Builds the agreement.** You choose one-way or mutual, how the receiving side may use AI tools, which extra clauses you want and how long it runs. The contract wording follows your answers. - **Runs the signing.** The recipient gets an email with their own link, adds their address and signs. You countersign after them. Where either party's country asks for the agreement in its own language, a text in that language goes beside the English. - **Keeps the evidence.** Every step goes into a chained log, and the finished agreement is frozen as a PDF with its hash. Both of you get that PDF by email. - **Lets anyone check a copy.** The [verify page](https://sendnda.com/verify) tells you whether a PDF is the one both parties signed. What it is not -------------- Send NDA is not a law firm and gives no legal advice. It provides a document template and a signing tool, and nobody at Send NDA reads your agreement. Whether the template suits your situation depends on the parties, the information involved and the law that applies. Where it matters, have a lawyer in your jurisdiction review it. It's also not a party to any agreement made through it. A dispute about an NDA is between the two of you. Three ways in ------------- | Way | Who it suits | |---|---| | The form on the home page | Anyone. No account, one confirmation email. | | Your account | People who send more than one. Your details are filled in from your last NDA. | | MCP and the API | An AI assistant or your own script, sending on your behalf. | All three build the same agreement. [Send your first NDA](https://sendnda.com/docs/getting-started/send-an-nda) walks through the form, and [Connect over MCP](https://sendnda.com/docs/agents/connect-over-mcp) covers the assistant route. Who runs it ----------- Send NDA is a Steddle product, operated by Hold My Beer B.V. in Amsterdam. The [Terms of Service](https://sendnda.com/legal/terms) and the [Privacy Policy](https://sendnda.com/legal/privacy) say what that means for you and for the people you send an NDA to. Checked against the code on 25 September 2026. [ Send your first NDA ](https://sendnda.com/docs/getting-started/send-an-nda) --- # https://sendnda.com/docs/getting-started/send-an-nda [ Docs ](https://sendnda.com/docs) [ Getting started ](https://sendnda.com/docs/getting-started) Send your first NDA =================== Fill in one form, confirm your email address, and both of you get a signing link. 01 Getting started --------------- Article 2 of 3 Sending an NDA takes one form and one email. You fill in the agreement, preview it, confirm your email address, and both of you get a link. The recipient only needs a name and an email address from you. They fill in their own details when they sign. Fill in the form ---------------- The [form for a new NDA](https://sendnda.com#send) asks for three things. - **The terms.** Who shares confidential information, an optional purpose, the use of AI tools, the extra clauses and how long it runs. [The agreement](https://sendnda.com/docs/the-agreement) explains each choice. - **You.** Your name, email address and postal address. Sign as a company and you add its name and registration number. Your country decides the [governing law](https://sendnda.com/docs/the-agreement/governing-law), and for the United States, Canada, Australia and the United Kingdom you also pick a state, province or part of the UK. - **The recipient.** Their full name and email address. That's all. On the home page, tick that you've read the Terms of Service and choose **Preview NDA**. Signed in, the form is **Send an NDA**: one sheet with those three parts as sections, **You**, **Recipient** and **Terms**, divided by a rule, with the agreement beside them as you type. The sheet ends on a sunken foot with two buttons. **Save as draft** keeps it as an unsent NDA on your dashboard, finished or not, to come back to. A saved draft nobody touches for 90 days is deleted. **Send NDA** sends it with no confirmation email. Either one lands you back on your dashboard. Preview and send ---------------- The preview shows the full agreement as it will read, with your details in it. If something's off, close it and change the form. When it reads right, choose **Send NDA**. You can send five times a minute from one email address and IP address. After that the form asks you to wait a minute. Confirm your email ------------------ Unless you're signed in with the same address, we don't send anything yet. You get an email titled *Confirm your email to send your NDA*. Its link is valid for 15 minutes. Open it and you're signed in, the NDA is sent, and you land on the NDA's page. This step stops anyone from sending an NDA in your name. A draft nobody confirms is deleted after 7 days. Signed in already, with the email address on the form? Then the NDA goes out straight away. What happens next ----------------- Two emails go out at once. The recipient gets *\[your name\] has prepared an NDA for you to sign*, with a **Sign NDA** button and their own link. You get a confirmation with your own link, where you can follow the status: Sent, Viewed, Awaiting your signature and Completed. 1. The recipient opens the link, adds their address and signs. 2. You get an email that it's your turn, and you countersign from your link. 3. Both of you get the sealed PDF and its signing certificate by email. An NDA nobody finishes is deleted 90 days after it was sent. [Sign an NDA you received](https://sendnda.com/docs/getting-started/sign-an-nda) shows the other side of the same flow. Checked against the code on 25 September 2026. [ What Send NDA is ](https://sendnda.com/docs/getting-started/what-send-nda-is) [ Sign an NDA you received ](https://sendnda.com/docs/getting-started/sign-an-nda) --- # https://sendnda.com/docs/getting-started/sign-an-nda [ Docs ](https://sendnda.com/docs) [ Getting started ](https://sendnda.com/docs/getting-started) Sign an NDA you received ======================== What the recipient sees, what they fill in, and what happens after they sign. 01 Getting started --------------- Article 3 of 3 If someone sent you an NDA through Send NDA, you got an email titled *\[their name\] has prepared an NDA for you to sign*, with a **Sign NDA** button. That link is yours alone: the sender has a different one. There's no sign-up or password, and signing takes a couple of minutes. Add your details ---------------- The sender only gave us your name and email address. Before you can sign, the agreement needs your postal address: address line 1, city, postal code and country, plus line 2 where it applies. For the United States, Canada and Australia you pick your state, province or territory from a list, so it reads in the agreement the way the law names it. You also say whether you sign as a company or as a person. A company adds its name and registration number. A person gets one more question: whether you're signing for yourself, not for a business or profession. Tick it and the agreement carries no penalty for a breach and leaves the protections your own law gives a private individual in place. Your details go into the party block at the top of the agreement, and some of them reach its clauses: your country, your state and that answer can each take wording out. Once you continue, you see the full text with both parties in it, worked out from what you filled in. Where your country asks for the agreement in its own language, the document carries a text in that language beside the English, and tabs above it switch between them. You sign both at once. The English is the text you're bound by. [Governing law](https://sendnda.com/docs/the-agreement/governing-law#texts-in-your-language) lists the languages. Read it and sign ---------------- Read the agreement through. It shows who discloses, the purpose, the clauses the sender chose and the governing law. If something isn't what you discussed, ask the sender to change it before you sign: they can amend the NDA while neither of you has signed. If they change it while you have it open, your signature isn't recorded: the page shows the new version and asks you to sign again. Where Italian, Romanian, Chinese or South Korean law governs the agreement, a step comes first. The page lists the clauses that weigh on you by heading, and you approve those apart from the rest: those four legal systems hold that a clause in a form the other side drew up binds you only where you approved it separately. Your approval goes into the signing record as an event of its own, beside your signature. To sign, tick that you accept the Terms of Service and Privacy Policy, then choose **Sign NDA**. Your signature is your name as it appears in the agreement, set in a handwriting face. We record the time, your IP address, how you signed in and the hash of the exact text you signed. [The signing record](https://sendnda.com/docs/evidence/the-signing-record) explains what that log holds. The name on the agreement is the one the sender typed. If it's wrong, ask them to fix it before you sign. Before anyone has signed, **Download a copy** on the NDA's page gives you the agreement as it stands, as a PDF with your name on it, to read and to keep. It isn't signed and binds nobody. After you sign -------------- The sender gets an email that you've signed, and it's their turn to countersign. You can come back to it from your dashboard in the meantime. When the sender countersigns, the agreement is completed. We freeze it as a PDF and email it to both of you, with its signing certificate. The NDA's page then offers a **Download** menu with both, and your dashboard has the same download. Keep your copy -------------- Keep the PDF and the certificate from the email. Completed agreements and their signing record are kept until five years after the end of the confidentiality period, and anyone can check a copy against the original on the [verify page](https://sendnda.com/verify). The [Privacy Policy](https://sendnda.com/legal/privacy) covers what we hold about you and why. Checked against the code on 25 September 2026. [ Send your first NDA ](https://sendnda.com/docs/getting-started/send-an-nda) --- # https://sendnda.com/docs/the-agreement [ Docs ](https://sendnda.com/docs) The agreement. ============== Every choice on the form, in plain words, and what it changes in the contract. 02 The agreement ------------- 5 articles [One-way or mutual Who shares confidential information decides who is bound, and how the contract names both of you. ](https://sendnda.com/docs/the-agreement/one-way-or-mutual) [The optional clauses Non-solicitation and non-use, non-circumvent, a penalty for a breach, and group companies. ](https://sendnda.com/docs/the-agreement/clauses) [Use of AI tools Three levels for what the receiving party may do with AI tools, and why the default sits in the middle. ](https://sendnda.com/docs/the-agreement/ai-tools) [How long it runs The term of the agreement, the confidentiality period after it, and trade secrets. ](https://sendnda.com/docs/the-agreement/how-long-it-runs) [Governing law Whose law governs the NDA, why some countries ask for a state or a part of the UK, and when the agreement comes in a second language. ](https://sendnda.com/docs/the-agreement/governing-law) --- # https://sendnda.com/docs/the-agreement/one-way-or-mutual [ Docs ](https://sendnda.com/docs) [ The agreement ](https://sendnda.com/docs/the-agreement) One-way or mutual ================= Who shares confidential information decides who is bound, and how the contract names both of you. 02 The agreement ------------- Article 1 of 5 The first choice on the form is who shares confidential information. It decides who is bound, and how the contract names the two of you. There are three answers, and each one is a different agreement, not a setting on the same one. Pick the one that matches what happens in the meeting, not the one that sounds safest. If you'll both show each other things you'd rather keep quiet, that's mutual. Three answers ------------- | On the form | Kind | Who is bound | |---|---|---| | I share confidential information | One-way | The recipient keeps what you share. | | They share confidential information | One-way | You keep what the recipient shares. | | We both share confidential information | Mutual | Each of you keeps what the other shares. | The first is the default. It fits a founder pitching an investor, or a company briefing a freelancer. The second fits the reverse: you're the one being let in, and the other side wants it in writing before they talk. How the contract names you -------------------------- In a one-way NDA, each party block carries a role. The one who shares is the Disclosing Party, the one who receives is the Receiving Party, and every obligation runs one way: from the Receiving Party to the Disclosing Party. A mutual NDA leaves the roles out of the party blocks and adds a first article instead: > Each Party may disclose Confidential Information to the other Party. In respect of any Confidential Information, the Party disclosing it is the "Disclosing Party" and the Party receiving it is the "Receiving Party". … every obligation in this Agreement applies in both directions. So the same words, "the Receiving Party shall…", bind you for what the other side shares and bind them for what you share. What mutual adds ---------------- Two parts of the contract change when it's mutual. - **The title.** It reads "Mutual Non-Disclosure Agreement" instead of "Non-Disclosure Agreement", and the recital says the parties wish to exchange information, not that one wishes to disclose it. - **Jointly developed material.** A mutual NDA gets an extra article: what you build together in the course of the talks isn't owned jointly, or by either of you, by reason of the NDA alone. Each keeps its own contributions, and neither may exploit joint material that holds the other's confidential information until you've agreed on it in writing. Person or company ----------------- Who the Receiving Party is changes some of the wording too. If it's a company, it may share the information with its own people who need to know it, the directors, employees, contractors and professional advisers it calls its Representatives. If it's a person, it may share it only with professional advisers bound by a duty of confidentiality, and with anyone else the Disclosing Party has approved in writing. In a mutual NDA between a company and a person, both versions sit in one paragraph, each introduced by "Where the Receiving Party is an entity" or "an individual". You fill in whether you sign as a person or a company on the form; the recipient does the same when they sign. [The optional clauses](https://sendnda.com/docs/the-agreement/clauses) explains how group companies widen the company version. The purpose ----------- Whichever you pick, the Receiving Party may use the information only for the Purpose. Leave the purpose field empty and the contract reads: > "Purpose" means evaluating, and if the Parties so decide, pursuing a business relationship between them. Type one line of your own, up to 500 characters, and it replaces that wording. Keep it wide enough to cover the whole conversation you're about to have: information used outside the purpose is a breach, even if nobody else ever sees it. Send NDA provides a template, not legal advice. Where a lot rides on the agreement, have a lawyer in your jurisdiction read it before you [send it](https://sendnda.com#send). Checked against the contract template on 23 September 2026. [ The optional clauses ](https://sendnda.com/docs/the-agreement/clauses) --- # https://sendnda.com/docs/the-agreement/clauses [ Docs ](https://sendnda.com/docs) [ The agreement ](https://sendnda.com/docs/the-agreement) The optional clauses ==================== Non-solicitation and non-use, non-circumvent, a penalty for a breach, and group companies. 02 The agreement ------------- Article 2 of 5 Every NDA from Send NDA covers confidentiality: what counts as confidential, who may see it, and what happens when it leaks. Four clauses are optional. They're off by default, and each one you tick adds wording to the contract. Nothing else changes. Non-solicitation and non-use ---------------------------- Confidentiality stops the Receiving Party from telling others. This clause also stops them from using what they learned. It adds an article with these limbs: - **No use outside the purpose,** for as long as the information stays confidential. - **No product built on it.** Until the end of the term and the confidentiality period after it, they may not "use the Confidential Information to develop, market or provide a product, service or venture". - **No poaching,** during the term and for 12 months after it: no soliciting a customer, supplier or employee they found out about through your information. General advertising and approaches they didn't invite stay allowed. The poaching limb is left out when the Receiving Party is a person rather than a company, and the article is then headed Non-Use instead of Non-Use and Non-Solicitation. Where the other side is a person in California, Washington, North Dakota or Oklahoma, it comes out too, along with [non-circumvention](#non-circumvent): those four states hold a person to no restraint on their trade. Under Indian law the poaching limb runs during the term only, because an Indian court enforces no restraint past it. Where either side is in Denmark or Norway, employees come out of the limb and customers and suppliers stay. It's not a non-compete. The article ends by saying so: > Nothing in this Agreement restricts either Party from carrying on any business or activity, including in competition with the other Party, provided it does so without use of the other Party's Confidential Information … No non-compete is on offer. A broad non-compete is unenforceable in several places, California among them, so the template leaves it out. Non-circumvent -------------- For the talks where your value is who you know. If you introduce the Receiving Party to a person or business in connection with the purpose, they may not do a deal with that contact that bypasses you, without your written consent. It runs for 12 months from the introduction or until the end of the term, whichever is later. Two exceptions: a contact they can show they already had a relationship with, and one they reach independently of your introduction. Penalty for a breach -------------------- A fixed sum per breach, on top of any damages, so the Disclosing Party doesn't first have to prove what the leak cost them. We offer it only where the law gives it effect, and in the shape that law asks for: the clause derogates from articles it names, so a legal system needs wording of its own before it can carry one. The form lets you tick it when the country you send from is one of them, and it falls away against a recipient who signs as a consumer. The sum is graded per clause and capped. A daily amount runs on top of it, but only after you have given the other side written notice to stop, and only while they keep using or disclosing the information or have not returned it: a daily sum for something the other side cannot undo is what makes a court reduce the whole penalty. Nothing is payable for a breach they did not cause. A court may always reduce a penalty it finds excessive, whatever the agreement says, and the agreement does not pretend otherwise. | Breach of | Penalty per breach | |---|---| | Confidentiality, and the no-use and no-product limbs | EUR 10.000 | | The no-poaching limb | EUR 7.500 | | Non-circumvent | EUR 5.000 | The daily amount is EUR 1.000, and the total is capped at EUR 100.000. A row only applies when its clause is in the contract, and any penalty paid is set off against damages for the same breach. Where a party bound as Receiving Party signs as a person rather than for a company, every amount halves: EUR 5.000, EUR 3.750 and EUR 2.500 per breach, EUR 500 a day, capped at EUR 50.000. A court reduces a sum set against a balance sheet when the one who owes it is a person, and a sum a court leaves standing is the only one that deters. Group companies --------------- By default a company that receives your information may share it only with its own directors, officers, employees, contractors and professional advisers who need to know it. Allow group companies and that widens to its Affiliates: entities that control it, are controlled by it, or are under common control with it, and their people. Leave it off when the information would be sensitive in the hands of a sister company. It makes no difference when the Receiving Party is a person. What every NDA already has -------------------------- You don't need a clause for these; they're in every agreement: a definition of confidential information that covers the fact you're talking at all, the usual exclusions, notice of a leak within two business days, no reverse engineering except where the law won't let that be restricted, return or destruction on request, the right to ask a court for an injunction, and a paragraph on [AI tools](https://sendnda.com/docs/the-agreement/ai-tools). [How long it runs](https://sendnda.com/docs/the-agreement/how-long-it-runs) covers the term. Three more are there for reasons nobody negotiates. Nobody can be gagged from reporting a suspected breach of law to a regulator, blowing the whistle, or discussing discrimination, harassment or a wage violation they experienced or witnessed, and nobody has to tell the other side they did it. A notice states the immunity US law gives an individual who hands a trade secret to a government official or files it under seal: leaving it out would cost a sender who sues an American freelancer their exemplary damages and legal fees. And nobody outside the two parties, their successors and their heirs can enforce any of it, so a group company named in the agreement can't sue on it. These summaries help you choose. The contract's own wording is what binds, and Send NDA provides a template, not legal advice. Checked against the contract template on 24 September 2026. [ One-way or mutual ](https://sendnda.com/docs/the-agreement/one-way-or-mutual) [ Use of AI tools ](https://sendnda.com/docs/the-agreement/ai-tools) --- # https://sendnda.com/docs/the-agreement/ai-tools [ Docs ](https://sendnda.com/docs) [ The agreement ](https://sendnda.com/docs/the-agreement) Use of AI tools =============== Three levels for what the receiving party may do with AI tools, and why the default sits in the middle. 02 The agreement ------------- Article 3 of 5 Most teams paste things into an AI tool now: a deck to summarise, a spreadsheet to check, a contract to explain. An NDA that says nothing about it leaves both sides guessing. Every Send NDA agreement says what the Receiving Party may do with AI tools, and you pick one of three levels. Whatever you pick, one line never moves: the Receiving Party may not use your information to train, fine-tune, adapt or otherwise improve a model. Three levels ------------ | On the form | What the Receiving Party may do | |---|---| | No AI tools | Use a service only if it keeps nothing after answering, doesn't train on the input and doesn't pass it on. | | AI tools that do not train on the information | Use a service whose terms rule out training on the input and sharing it, and let the provider keep it only as long as it needs to run and monitor the service. | | Any AI tool | Use any service for the purpose. They still may not train a model on it themselves. | Why the middle is the default ----------------------------- The strictest level reads well and is hard to live with. Few services keep nothing at all: most keep input for a while to watch for abuse, so under "No AI tools" the Receiving Party can use almost none of them. Pick it for information that shouldn't leave the building. The middle level matches how business and API plans are sold: no training on your input, no sharing beyond the provider's own subprocessors, retention only for running the service and watching it for security and abuse. That's where most teams working with AI already are, so it's the default. The wording: > The Receiving Party may make Confidential Information available to an artificial intelligence or machine learning service for the Purpose only where the terms on which that service is provided exclude use of the input to train or improve any model, exclude disclosure of the input to any third party other than the provider's subprocessors bound by the same terms, and allow the provider to retain the input only for as long as is needed to provide the service and to monitor it for security and abuse. The open level -------------- "Any AI tool" lets the Receiving Party use whatever they like, consumer apps included. What they may not do is train a model on your information themselves, or put it in a dataset for that. It doesn't stop a provider from doing what its own terms allow, which is the difference with the middle level. Pick it when the information is confidential but not sensitive, and friction matters more than the last bit of control. Naming a service ---------------- When the Receiving Party is a company, the contract adds one more sentence at every level: you may tell them in writing not to use a named service for your information, and they have to stop. It's the way to react when a provider changes its terms mid-deal. When the Receiving Party is a person, the sentence is left out, and so it is in a mutual NDA between a company and a person. These are summaries to help you choose. [The optional clauses](https://sendnda.com/docs/the-agreement/clauses) covers the rest of what you can switch on. The contract's own wording binds, and Send NDA provides a template, not legal advice. Checked against the code on 24 September 2026. [ The optional clauses ](https://sendnda.com/docs/the-agreement/clauses) [ How long it runs ](https://sendnda.com/docs/the-agreement/how-long-it-runs) --- # https://sendnda.com/docs/the-agreement/how-long-it-runs [ Docs ](https://sendnda.com/docs) [ The agreement ](https://sendnda.com/docs/the-agreement) How long it runs ================ The term of the agreement, the confidentiality period after it, and trade secrets. 02 The agreement ------------- Article 4 of 5 An NDA from Send NDA has two clocks. The term is how long the agreement itself runs. The confidentiality period is how long the Receiving Party keeps the information quiet after the term ends. You set both on the form, each from 1 to 5 years, and both default to 3. When it starts -------------- Not when you send it. The agreement takes effect on the day the last party signs: > This Non-Disclosure Agreement (the "Agreement") takes effect on the date on which the last Party signs it, as shown in the signing record (the "Effective Date"). The definition of confidential information reaches back, though: it covers what was shared "whether before or after the Effective Date". Information you showed in the meeting the day before the second signature is covered. Two clocks ---------- Say you pick a term of 2 years and a confidentiality period of 3. The contract reads: > This Agreement continues for 2 years from the Effective Date (the "Term"). The Receiving Party's obligations in respect of Confidential Information continue for 3 years after the end of the Term … So the Receiving Party keeps quiet for 5 years from the last signature: 2 while the agreement runs, and 3 after. Information shared late in the term is still protected for the full 3 years after it ends. Pick the term for how long the conversation lasts, and the confidentiality period for how long the information stays worth protecting. A pitch deck goes stale faster than a customer list. Trade secrets ------------- One kind of information outlasts both clocks. For anything that's a trade secret under the applicable law, the obligations continue "for as long as it remains a trade secret". A recipe, a source of supply or an algorithm you keep secret for a living doesn't fall free after 5 years because a date passed. The no-product limb of the [non-solicitation and non-use clause](https://sendnda.com/docs/the-agreement/clauses) is the one exception: the contract says it isn't extended by the trade secret rule. What survives the end --------------------- When the term ends, the articles needed to keep those obligations alive survive it. The contract lists them by name: return and destruction, remedies, governing law and jurisdiction, and electronic signature and evidence, plus non-use and non-circumvention where you included them and the governing law lets them run past the term. Rights that had already arisen before the end aren't affected either. The optional clauses keep their own durations. The no-poaching limb runs for the term and 12 months after it. Non-circumvent runs 12 months from each introduction or until the end of the term, whichever is later. Where the governing law ends a restraint with the term, as India's does, both stop at the end of the term and non-circumvention doesn't survive it. [Governing law](https://sendnda.com/docs/the-agreement/governing-law) has the details. After it ends ------------- At the end, or earlier if the Disclosing Party asks in writing, the Receiving Party returns or destroys the information, copies and notes included. They may keep one archive copy where law or a genuine retention policy requires it, and needn't purge backups until those are overwritten in the normal course. Whatever they keep stays covered by the agreement. Send NDA keeps a completed agreement and its signing record until five years after the end of the confidentiality period: the term, the confidentiality period and five years, counted from the last signature. That's 7 years at the shortest and 15 at the longest. The [privacy policy](https://sendnda.com/legal/privacy) has the details. Send NDA provides a template, not legal advice. Checked against the contract template on 25 September 2026. [ Use of AI tools ](https://sendnda.com/docs/the-agreement/ai-tools) [ Governing law ](https://sendnda.com/docs/the-agreement/governing-law) --- # https://sendnda.com/docs/the-agreement/governing-law [ Docs ](https://sendnda.com/docs) [ The agreement ](https://sendnda.com/docs/the-agreement) Governing law ============= Whose law governs the NDA, why some countries ask for a state or a part of the UK, and when the agreement comes in a second language. 02 The agreement ------------- Article 5 of 5 Every NDA from Send NDA is governed by the law of the country you send it from: the country in your address on the form. Not the recipient's, and not the Netherlands because Send NDA is Dutch. You pick the law by picking your country, and the form on the home page says so: "Its law governs the NDA." That holds whichever way the information flows. If you send a one-way NDA where the recipient discloses, it's still your law. The clause ---------- For a sender in Germany, the governing law article reads: > This Agreement is governed by the laws of Germany, without regard to its conflict-of-laws rules. Any non-contractual obligations arising out of or in connection with this Agreement are governed by the same laws, to the extent the Parties may choose the law that applies to them. The courts of Germany have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement. The Parties' choice of courts applies only so far as the law allows them to make it; where it does not, the ordinary rules of jurisdiction apply. Either Party may nevertheless seek injunctive or other interim relief in any court of competent jurisdiction. The last sentence matters in practice. If information leaks abroad, the Disclosing Party can ask a local court there to stop it, without first going home to sue. State, province or part of the UK --------------------------------- In four countries contract law isn't set nationally, so a country alone doesn't name a legal system. Pick one of them and the form asks for one more field. | Country | The form asks for | The contract reads | |---|---|---| | United States | State | the laws of California and the federal laws of the United States applicable there, and the state and federal courts located in California | | Canada | Province or territory | the laws of Ontario and the federal laws of Canada applicable there, and the courts of Ontario, Canada | | Australia | State or territory | the laws of New South Wales and the federal laws of Australia applicable there, and the courts of New South Wales and the Federal Court of Australia | | United Kingdom | Part of the UK | the laws of England and Wales, and the courts of England and Wales | For the UK you choose from its three legal systems: England and Wales, Scotland, or Northern Ireland. The states above are examples; yours takes their place. What your country changes ------------------------- Most of the agreement reads the same everywhere. Where a country's own law asks for something different, the agreement says it: which statutes a clause cites, whether a penalty for a breach takes effect at all, which courts a dispute goes to, and whether a restraint runs past the term. You see what your country does to the agreement in the preview beside the form as you type. The [penalty for a breach](https://sendnda.com/docs/the-agreement/clauses) is the clearest case. It holds only where the governing law gives an agreed sum effect, and the clause has to derogate from that law's own articles by name, so a legal system needs wording written for it before it can carry one at all. Where the governing law has none, the tick on the form stays disabled and the agreement carries no penalty, whatever was submitted. ### Senders in the Netherlands A Dutch NDA names the articles where other NDAs refer to "applicable law": - injunctions under Article 3:296 of the Dutch Civil Code, in summary proceedings (kort geding), backed by a penalty payment (dwangsom); - whistleblowers under the Wet bescherming klokkenluiders, and trade secrets under the Wet bescherming bedrijfsgeheimen; - the electronic signature under Article 3:15a of the Dutch Civil Code and the eIDAS Regulation, and the signing record as an agreement on evidence under Article 153 of the Dutch Code of Civil Procedure, conclusive subject to the counterproof Article 151 allows. ### Senders in the European Union An NDA from any EU member state adds a paragraph on personal data under the GDPR: roles follow Article 4, processing on the other's behalf needs an Article 28 agreement first, and a transfer outside the EEA needs a Chapter V basis. ### Senders in India An Indian NDA ends its restraints with the term. Section 27 of the Contract Act voids a restraint of trade beyond it, between businesses as well, so the poaching limb runs during the term only and non-circumvention runs until the term ends rather than twelve months past an introduction. Confidentiality and non-use are untouched and keep their full length. ### Senders in Italy, Romania, China or South Korea Those four hold that a clause in a form one party drew up, where it weighs on the other, binds only where that other approved it apart from the rest. An NDA governed by one of them asks each signer to approve those clauses by heading, in a step of its own before they sign, and the signing record holds the approval as an event beside the signature. [Sign an NDA you received](https://sendnda.com/docs/getting-started/sign-an-nda) shows what that looks like. Notices ------- Where a country's law asks something of you rather than of the agreement, you get a notice instead, on the NDA's page and in the email: stamp this within three months, these courts will keep the dispute. Those are things to act on, and they name the statute they come from so you can check them or hand them to a lawyer. Texts in your own language -------------------------- Some countries ask for the agreement in their own language when one of their companies or citizens is a party. Send NDA then issues a text in that language beside the English, in the same document and under the one signature: Bahasa Indonesia, French for Quebec, Turkish, Korean, Lithuanian, Slovene and Serbian. Tabs above the agreement switch between the texts. The English is the text you're both bound by, and every text says so in its own language. The language follows either party's country, so a text can appear once the recipient fills in their details. It's one of the changes you see before you countersign. The other party's law --------------------- The law that governs is yours. The other party's own law still reaches the agreement, and it can only take something away: a rule that added an obligation would need the party it binds to agree to it again. That's what takes employees out of the no-poaching limb where either of you is in a country that protects them, and what takes the restraints out altogether against a person in a state that holds them to none. [The optional clauses](https://sendnda.com/docs/the-agreement/clauses) names which. The recipient's own answers do the same. Their country, their state and their answer to the consumer question land when they fill in their details, and the agreement is worked out again there and then: a recipient signing for themselves rather than for a business takes the penalty and the agreement on how loss is proved out of it, and puts in a sentence saving the protections their own law gives a private individual. Before you countersign you see what moved, clause by clause, and the signing record notes that you saw it. Choosing well ------------- Your own law is usually the one you and your lawyer know best, and the courts you can reach. If the other side insists on theirs, they can send the NDA to you instead: whoever sends it sets the law. Send NDA doesn't tell you whether the template holds up under a particular law. It provides a template, not legal advice, and the [terms](https://sendnda.com/legal/terms) say the same. Where a lot rides on it, have a lawyer in your jurisdiction review the NDA first. Checked against the contract template on 25 September 2026. [ How long it runs ](https://sendnda.com/docs/the-agreement/how-long-it-runs) --- # https://sendnda.com/docs/evidence [ Docs ](https://sendnda.com/docs) Evidence. ========= How Send NDA records what was signed, by whom and when, and how anyone can check a copy later. 03 Evidence -------- 3 articles [The signing record The chained log of every step, and what each entry holds. ](https://sendnda.com/docs/evidence/the-signing-record) [The sealed PDF How a completed agreement is frozen, what its signing certificate holds, and why a later change cannot reach either. ](https://sendnda.com/docs/evidence/the-sealed-pdf) [Verify a copy Upload a PDF and see whether it is, byte for byte, the one both parties signed, or its signing certificate. ](https://sendnda.com/docs/evidence/verify-a-copy) --- # https://sendnda.com/docs/evidence/the-signing-record [ Docs ](https://sendnda.com/docs) [ Evidence ](https://sendnda.com/docs/evidence) The signing record ================== The chained log of every step, and what each entry holds. 03 Evidence -------- Article 1 of 3 Every NDA on Send NDA carries its own log. Each step, from the moment the agreement is saved to the moment its PDF is sealed, is written as an event. So is every delivery report on its emails, even one that arrives after the seal. Nothing in the log is edited later: a new fact is a new event at the end. The events are chained. Each one's hash covers the event before it, so taking an event out, changing one, or putting them in another order breaks every hash after it. That's what lets anyone check the record later instead of taking our word for it. What gets recorded ------------------ These are the events an NDA can collect, in the order they usually happen: | Event | When | What it holds | |---|---|---| | `created` | The NDA is saved | Both names and email addresses, who discloses, the AI tools level, the purpose, the four optional clauses, and both durations. | | `sent` | The signing emails go out | The template version and the SHA-256 of the agreement as it went out. | | `resent` | The sender resends the recipient's link | Nothing beyond the time. | | `viewed` | The recipient first opens the NDA | The IP address, `credential` and `link_id`. | | `redlined` | The sender is shown what the recipient's own details changed in the agreement | The SHA-256 of the text they were shown, and a code for each adjustment the recipient's own law made. Written once per text, so a second look adds nothing. | | `notified` | A party is shown what their own country's law asks of them, and goes on to sign | Which party, a code for each thing they were told, and the wording they were shown with its sources, under the same template version, SHA-256, consent, `credential`, `link_id` and user agent their signature carries. Some statutes turn on whether a party knew, so the record holds what they were told rather than only that something was shown. | | `approved` | A party approves the clauses that weigh on them, where the governing law asks for that | Which party, the headings of the clauses they approved, and the same template version, SHA-256, consent, `credential`, `link_id` and user agent their signature carries. | | `signed` | A party signs | Which party, the signature (the party's name as entered on the NDA), the IP address, `credential` and `link_id`, the browser's user agent, that consent was given, the template version, and the SHA-256 of the agreement as that party saw it. | | `completed` | The second signature lands | Nothing beyond the time. | | `frozen` | The sealed PDF is stored | The template version and the SHA-256 of both the PDF and the HTML it was printed from. | | `certified` | The signing certificate is stored | The SHA-256 of the certificate. | `credential` says how the party signed in: `magic_link` for a link from an email, `passkey`, `session`, `api_token` for an API token, or `oauth_token` for a connected app. `link_id` is a hash that identifies that credential without being it, and is `null` for a session. Two more kinds of event can appear. `amended` records a change either party made before anyone signed: the sender's to the terms, or the recipient's to their own details. It holds which party, which fields, the values before and after, whether the recipient's email address changed, which withdraws their unused links, and the party's `credential` and `link_id`. It also holds the template version, the SHA-256 of the amended agreement and the SHA-256 of the text it superseded, which is what the redline reads back to show what moved. Where the recipient's answer to the consumer question changed, the question goes in too, in the words they were asked. And the email provider reports back when an email about the NDA was delivered or bounced, as `resend.email.delivered` and `resend.email.bounced`, with the provider's own message id and timestamp. These reports can arrive after `certified`. How the chain works ------------------- Every event is first written out as one fixed piece of text, the canonical payload. It has a version line, the NDA's id, the event's sequence number, its type, the time in UTC, and then every field sorted by name. Each field carries its length in bytes, so a value that contains a line break can't pass itself off as a second field. The event's hash is the SHA-256 of the previous event's hash, a line break, and that canonical payload. The first event has no previous hash. Sequence numbers start at 1 and have no gaps, and the database refuses two events with the same number for one NDA. ``` hash = sha256(previous_hash + "\n" + canonical_payload) ``` The canonical payload is stored exactly as it was hashed, next to the fields it came from. A check hashes the stored text, and also rebuilds it from the stored fields to see that the two still agree. How it's checked ---------------- A check walks the events in order and stops at the first one that fails. An event passes when: - its sequence number is the next one, with no gap; - it points at the hash of the event before it; - its stored canonical payload is what its stored fields produce, so changing a field alone is caught; - its hash is what the previous hash and its canonical payload produce. This check runs every time someone verifies a PDF. A PDF only counts as a match when its NDA's chain passes. See [Verify a copy](https://sendnda.com/docs/evidence/verify-a-copy). Who sees what ------------- Both parties get the result in the sealed PDF: each signature with its date, time in UTC and IP address. The signing certificate that comes with it prints every event up to the seal, with its hash. Both of you see the steps on the NDA's page, with the time of each: sent, viewed, signed and completed. Once it's completed, the page's **Signing record** lists when the recipient viewed it and when each of you signed, each with its time in UTC and IP address. The full chain stays on Send NDA's side, and the [Privacy Policy](https://sendnda.com/legal/privacy) says how long it's kept. Checked against the code on 25 September 2026. [ The sealed PDF ](https://sendnda.com/docs/evidence/the-sealed-pdf) --- # https://sendnda.com/docs/evidence/the-sealed-pdf [ Docs ](https://sendnda.com/docs) [ Evidence ](https://sendnda.com/docs/evidence) The sealed PDF ============== How a completed agreement is frozen, what its signing certificate holds, and why a later change cannot reach either. 03 Evidence -------- Article 2 of 3 When the second party signs, Send NDA prints the agreement to a PDF and seals it. Sealed means stored once, with its SHA-256 recorded in the [signing record](https://sendnda.com/docs/evidence/the-signing-record), and never written again. That PDF is the one both of you get by email and the one you download afterwards from the NDA's page or your dashboard. It comes with a second sealed PDF, its [signing certificate](#the-signing-certificate). What gets sealed ---------------- The agreement you both signed is fixed earlier than the PDF. When the NDA goes out, Send NDA renders the contract once, stores that HTML, and records its SHA-256 in the `sent` event. From then on both parties see that stored copy, not a fresh render. An amendment before anyone signs is a fresh invitation: it renders and stores again, and the `amended` event records the new SHA-256 beside the one it superseded. A template deployed between the sending and the last signature can't reach the agreement, and both parties sign exactly the same text. At completion, the sealed PDF is printed from that stored agreement plus the signatures. Three things are stored: - the PDF, and its SHA-256; - the HTML it was printed from, and its SHA-256; - a snapshot of every input that shaped the agreement: both parties' names, email addresses, addresses and company details, whether the recipient signs for themselves, who discloses, the AI tools level, the purpose, the optional clauses, both durations, and the template version. The stylesheet and fonts are copied into the stored HTML instead of linked, so it renders the same years from now, after the site's own styles have moved on. Where the agreement carries a text in a party's own language beside the English, both texts are in that one document, under the one hash. Before anyone has signed, a party can download the agreement as it stands from the NDA's page. That copy is printed on request, marked *Not signed* on every page and stored nowhere. It carries no seal and the verify page can't check it; the sealed PDF is the one Send NDA stands behind. Why it can't change ------------------- Once stored, the sealed document can't be edited or deleted by the application. The only thing it may still update is when the completion emails went out. A later version of the template, a change in the database, or a redesign of the site leaves the stored PDF and its recorded hash alone. That's a statement about the application, not a promise that no file on any disk can ever be touched. It's why the hash sits in the chained record as well: a file that doesn't match its recorded SHA-256 shows it was changed. The order of things ------------------- Sealing is a barrier. The PDF is printed, stored and recorded in a `frozen` event, then the signing certificate is printed, stored and recorded in a `certified` event, before any completion email is sent. The emails attach those same stored files. If a step fails, the job runs again, five attempts in all, without sealing twice or mailing twice. Each sealed file is named by its own hash and never written over. Right after the second signature, the PDF may take a moment. Download it before it's ready and you're asked to try again in a moment. The format ---------- The PDF is printed on Letter paper when the sender's address is in the US or Canada, and on A4 everywhere else. The first page opens on a band with the parties, the time of the last signature and the agreement's id. The agreement's own text is set in Spectral, as on the signing page, and a clause heading never ends a page. The signatures open a page of their own, set in the handwriting face you saw when signing. Each signature carries the signer's name, the company they signed for if any, and the date, time in UTC and IP address of the signature. Every page carries the agreement's title and the parties at its foot, with the page number. The signing certificate ----------------------- The certificate is a separate PDF, and it states that it's an official Send NDA document. It holds: - both parties: name, company, email address, and the time, IP address and browser of their signature; - the SHA-256 of the agreement text both of you signed, of the sealed PDF, and of the HTML it was printed from; - every event in the [signing record](https://sendnda.com/docs/evidence/the-signing-record) up to the seal, each with its time in UTC and its hash, and that the chain held when the certificate was issued: a chain that doesn't hold gets no certificate; - where to check both documents. It's a PDF of its own because it records the sealed agreement's hash, and a file can't hold its own hash. It's sealed the same way: stored once, with its SHA-256 in the `certified` event. The completion emails attach it beside the PDF, and the NDA's page offers it in its **Download** menu: the agreement and certificate together as a ZIP, or each PDF on its own. To check a PDF someone sends you, see [Verify a copy](https://sendnda.com/docs/evidence/verify-a-copy). Checked against the code on 25 September 2026. [ The signing record ](https://sendnda.com/docs/evidence/the-signing-record) [ Verify a copy ](https://sendnda.com/docs/evidence/verify-a-copy) --- # https://sendnda.com/docs/evidence/verify-a-copy [ Docs ](https://sendnda.com/docs) [ Evidence ](https://sendnda.com/docs/evidence) Verify a copy ============= Upload a PDF and see whether it is, byte for byte, the one both parties signed, or its signing certificate. 03 Evidence -------- Article 3 of 3 Someone sends you a PDF and says it's the NDA you both signed. The [verify page](https://sendnda.com/verify) tells you whether it is, byte for byte, the PDF Send NDA sealed. It checks a [signing certificate](https://sendnda.com/docs/evidence/the-sealed-pdf#the-signing-certificate) the same way. It's free and needs no account. How to check ------------ 1. Open the [verify page](https://sendnda.com/verify). 2. Drop the PDF on it, or click to pick the file. It has to be a PDF of 20 MB or less. 3. Press **Verify PDF**. The answer is one of three: the file matches an NDA sealed on a given date and time, it's the signing certificate of one, or it matches none. What a match means ------------------ Send NDA takes the SHA-256 of the file you uploaded and looks for a sealed PDF or signing certificate with the same hash. Finding one isn't enough on its own. It then checks that NDA's whole [signing record](https://sendnda.com/docs/evidence/the-signing-record), event by event. You only see a match when both hold: - the file's SHA-256 equals the one recorded when the PDF or its certificate was sealed; - the chain of events behind that NDA passes every check. A match says the file is the one both parties received at completion, and that the record of how it came about is intact. It doesn't say the agreement is enforceable, or that it applies to the situation you have in mind. That's for you and, where it matters, your lawyer. Why a real copy can fail ------------------------ The check compares exact bytes. Any change makes the hash different, including changes that leave the text looking identical: - printing the PDF to a new PDF, or saving it again from a viewer; - adding a comment, a highlight or a signature on top; - compressing it, or running it through a scanner; - a PDF from before completion, which was never sealed. If a copy fails, ask for the file exactly as it arrived by email, or download it again from the NDA's page or your dashboard. Both are the sealed original. What happens to your file ------------------------- Your upload is hashed, compared and then deleted, whether it matches or not. Nothing about it is kept, and the check isn't written to the NDA's signing record. To stop anyone trying hashes at scale, the page allows 10 checks per minute from one IP address; past that, you're asked to wait a minute. Checked against the code on 24 September 2026. [ The sealed PDF ](https://sendnda.com/docs/evidence/the-sealed-pdf) --- # https://sendnda.com/docs/your-account [ Docs ](https://sendnda.com/docs) Your account. ============= Signing in without a password, and looking after the NDAs you sent. 04 Your account ------------ 2 articles [Sign in Magic links and passkeys, and which NDAs show up in your account. ](https://sendnda.com/docs/your-account/sign-in) [Amend, resend or delete What you can still change before anyone signs, and what you cannot after. ](https://sendnda.com/docs/your-account/amend-resend-delete) --- # https://sendnda.com/docs/your-account/sign-in [ Docs ](https://sendnda.com/docs) [ Your account ](https://sendnda.com/docs/your-account) Sign in ======= Magic links and passkeys, and which NDAs show up in your account. 04 Your account ------------ Article 1 of 2 Send NDA has no passwords. You sign in with a link we email you, or with a passkey once you've added one. The first time you sign in, your account is made for you. Magic links ----------- On the [sign-in page](https://sendnda.com/login), enter your email address and choose **Email me a sign-in link**. The form makes way for a card that says where the link went. - The link is valid for 15 minutes and works once. A forwarded link can't sign anyone else in afterwards. - Opening it signs you in straight away. Mail scanners that open links to check them don't use it up. - Signed in as someone else? Opening the link asks whether to switch to the account it was sent for. - A link or a passkey keeps you signed in on that browser until you sign out. - You can ask for five links a minute from one address and IP address. Confirming an NDA you sent from the home page works the same way: that email's link signs you in as well. Passkeys -------- A passkey signs you in with your fingerprint, face or device PIN, without waiting for an email. Add one under **Settings** once you're signed in, and give it a name so you can tell your devices apart. From then on, the sign-in page offers to sign in with it. We store only the public key of a passkey. You can remove one from the same settings page at any time. Which NDAs you see ------------------ Your dashboard lists every NDA you're a party to: - the ones you sent while signed in, from the dashboard or through an agent; - the ones sent from your email address through the public form, once you've confirmed that address; - the ones sent to your email address, once you've confirmed it; - your drafts, the NDAs you saved and haven't sent yet. The NDAs waiting for your signature and your drafts come first, under **Needs you**. Sending from your account ------------------------- A new NDA has a page of its own, **Send an NDA**. It takes your name and email address from your account, fills in your company and address from the last NDA you sent or received, and sends without a confirmation email, because you're already signed in. **Save as draft** keeps the form as it stands, finished or not, on your dashboard, to pick up later. [Amend, resend or delete](https://sendnda.com/docs/your-account/amend-resend-delete) covers what you can do with an NDA after it's gone out. Checked against the code on 25 September 2026. [ Amend, resend or delete ](https://sendnda.com/docs/your-account/amend-resend-delete) --- # https://sendnda.com/docs/your-account/amend-resend-delete [ Docs ](https://sendnda.com/docs) [ Your account ](https://sendnda.com/docs/your-account) Amend, resend or delete ======================= What you can still change before anyone signs, and what you cannot after. 04 Your account ------------ Article 2 of 2 Until someone signs, an NDA is still a draft of an agreement, and you can change it, send it again or delete it. From the first signature on, the text is fixed: a change would be a different agreement, not an edit. Amend ----- From your dashboard, choose **Edit** on an NDA neither of you has signed. You can change any part of the form: the terms, your details, and the recipient's name or email address. A preview shows the new text as you go. - Every change is recorded in the agreement's log, with what each field was before and after. - The recipient's page shows the new text. Tick **Email the recipient the updated NDA** to tell them it changed. It's ticked for you if they've already opened it. - Change the recipient's email address and it goes to the new person. The previous recipient loses access to it, and their unused links stop working. Your own access stays as it is. Resend ------ Lost in someone's inbox? While the recipient hasn't signed, open the NDA from your dashboard. The page says you're waiting for them, with a **Resend** button, and the NDA's menu on the dashboard has one too. It emails the recipient a new signing link and records the resend in the log. One NDA is resent at most once in ten minutes, so a recipient isn't flooded. An agent connected over MCP can do the same with `resend-nda`. It refuses once the recipient has signed, because there's nothing left for them to do. Delete ------ Choose **Delete** in the NDA's menu on your dashboard and confirm. The agreement and its log are removed, and the links in its emails stop working. The recipient isn't told. This can't be undone. An agent connected over MCP can do the same with `delete-nda`, and should confirm with you first. You can only delete an NDA nobody has signed. You don't have to, either: an NDA nobody finishes is deleted by itself 90 days after it was sent. After a signature ----------------- Once either of you has signed, **Edit** and **Delete** are gone. The signature is bound to the hash of the text it was given, and the completed agreement is evidence both of you rely on. It's kept until five years after the end of the confidentiality period, counted from the last signature. A request by one party alone to delete it is normally refused, as the [Privacy Policy](https://sendnda.com/legal/privacy) explains. Need different terms after signing? Send a new NDA. Checked against the code on 24 September 2026. [ Sign in ](https://sendnda.com/docs/your-account/sign-in) --- # https://sendnda.com/docs/agents [ Docs ](https://sendnda.com/docs) Agents and the API. =================== Send NDA as an MCP server, the nine tools a model gets, and tokens for your own scripts. 05 Agents and the API ------------------ 3 articles [Connect over MCP Add Send NDA to Claude or any MCP client, and sign in with your email address. ](https://sendnda.com/docs/agents/connect-over-mcp) [The tools list-ndas, get-nda, create-nda, amend-nda, set-recipient-details, sign-nda, resend-nda and delete-nda for NDAs you sent and received, read-docs for these docs, and what each one answers. ](https://sendnda.com/docs/agents/the-tools) [API tokens Create a token on the Agents page for a client that does not speak OAuth. ](https://sendnda.com/docs/agents/api-tokens) --- # https://sendnda.com/docs/agents/connect-over-mcp [ Docs ](https://sendnda.com/docs) [ Agents and the API ](https://sendnda.com/docs/agents) Connect over MCP ================ Add Send NDA to Claude or any MCP client, and sign in with your email address. 05 Agents and the API ------------------ Article 1 of 3 Send NDA is an MCP server. Connect it to Claude or another MCP client once, and your assistant can do what the NDA's page does, on either side: send an NDA and change it, check the ones sent to you, fill in your details, and sign when you tell it to. It acts as you: the NDAs it sends come from your account. The address ----------- The server answers at one URL, over streamable HTTP: ``` https://sendnda.com/mcp ``` It needs a signed-in account. There are two ways in: OAuth, which is what connectors in Claude and ChatGPT use, and an [API token](https://sendnda.com/docs/agents/api-tokens) for a client that doesn't do OAuth. Connect Claude -------------- In Claude, add a custom connector and paste the address above. In Claude Code, run: ``` claude mcp add --transport http send-nda https://sendnda.com/mcp ``` Your client registers itself with Send NDA and sends you to sign in. Signing in works as it does on the site: type your email address and open the link we send you, or use a passkey. There's no password. An address we haven't seen before gets an account on the spot. Then you see a consent screen that names the client asking for access and the host it receives that access at. Approve it and the client gets a token with one scope, `mcp:use`. That scope only opens the MCP server. Other clients ------------- Send NDA publishes its OAuth details where MCP clients look for them, at `/.well-known/oauth-protected-resource` and `/.well-known/oauth-authorization-server`, and accepts dynamic client registration. A client may only register a redirect address on `claude.ai`, `claude.com`, `chatgpt.com` or `localhost`. The last one is there for the MCP inspector. Any other client can use an API token instead. What your assistant can see --------------------------- Every tool is scoped to your account. It sees the NDAs created on your account, the ones sent from your verified email address through the public site, and the ones sent to your verified email address. Nobody else's. The nine tools are `list-ndas`, `get-nda`, `create-nda`, `amend-nda`, `set-recipient-details`, `sign-nda`, `resend-nda`, `delete-nda` and `read-docs`. [The tools](https://sendnda.com/docs/agents/the-tools) covers what each one takes and returns. Two things to know up front: `create-nda` sends straight away, with no draft step, so a well-behaved assistant confirms the details with you before it calls it. And `sign-nda` signs for you, so it shows you the agreement first and signs only when you say so. The server tells it both. Limits ------ The server allows 120 requests per minute per account, and one IP address can register ten clients an hour. We note when your account last used the MCP server, at most once a minute. We never receive your conversation with the assistant, only the tool calls it makes. Disconnect an app ----------------- The **Agents** page lists every app you connected under **Connected**, with when you connected it and the host it receives its access at. Choose **Disconnect** and confirm, and it loses access straight away: its access and refresh tokens are revoked, so it cannot renew them. To use it again, connect it again. Checked against the code on 25 September 2026. [ The tools ](https://sendnda.com/docs/agents/the-tools) --- # https://sendnda.com/docs/agents/the-tools [ Docs ](https://sendnda.com/docs) [ Agents and the API ](https://sendnda.com/docs/agents) The tools ========= list-ndas, get-nda, create-nda, amend-nda, set-recipient-details, sign-nda, resend-nda and delete-nda for NDAs you sent and received, read-docs for these docs, and what each one answers. 05 Agents and the API ------------------ Article 2 of 3 Connected over MCP, your assistant gets nine tools. Eight act as you, on the same NDAs: the ones you sent, from your account or from your verified email address through the public site, and the ones sent to your verified email address. It does for you what the NDA's page does, on either side. An NDA is named by its `uuid`, which `list-ndas` and `create-nda` return. The summary ----------- Every tool that answers with an NDA starts from the same summary: ``` { "uuid": "…", "role": "recipient", "status": "viewed", "next_action": "recipient_signs", "sender": { "name": "Ann de Vries", "email": "ann@studio.nl" }, "recipient": { "name": "Sam Okafor", "email": "sam@lumen.co" }, "created_at": "2026-09-21T10:42:00+00:00", "sent_at": "2026-09-21T10:42:00+00:00", "url": "https://sendnda.com/ndas/…" } ``` - **role**: your side of the NDA, `sender` or `recipient`. - **status**: where it stands, the same for both of you: `sent` (nobody opened it), `viewed` (the recipient opened it), `awaiting_sender` (the recipient signed, the sender countersigns next) or `completed`. `list-ndas` filters on the same values. - **next\_action**: the step the NDA waits for. See [The lifecycle](#the-lifecycle). - **url**: the NDA's page on Send NDA. It opens for you and the other party, each signed in, and for nobody else, so your assistant can hand it to you. list-ndas --------- Lists the NDAs you sent and received, newest first, as summaries. It takes three optional fields. `role` is `sender` or `recipient`, your side of the NDA. `status` filters on one stage, as the summary names it. `limit` caps the list between 1 and 100, and is 25 when left out. get-nda ------- Takes a `uuid` and returns the whole NDA: the summary, both parties with their name, email, company name and number and address, whether the recipient signs for themselves (`is_consumer`), the terms, the audit trail and the agreement itself. A value that isn't filled in is `null`. - **terms**: every term under the name and value `create-nda` takes, so your assistant can pass them back to `amend-nda` as they are: `disclosing_party`, `ai_use`, `purpose` (`null` for the default), the four clause switches, `duration` and `confidentiality_duration` in years. Beside them, `governing_law` and `clauses`, every clause that takes effect in words (non-disclosure, and any of non-solicitation, non-circumvent, penalty for a breach and group companies). - **audit\_trail**: when and from which IP address the recipient viewed and signed, and when and from which IP address the sender signed. A step that hasn't happened is `null`. - **agreement\_text**: the full agreement as plain text, a line per heading, paragraph and list item, the same text both of you sign. Where a party's own country asks for the agreement in its language, the text in that language follows the English inside it. Your assistant shows it to you before you sign. - **key\_clauses\_to\_approve**: where the governing law binds the clauses that weigh on a signer only on a separate approval, their headings; otherwise `null`. See [Sign an NDA you received](https://sendnda.com/docs/getting-started/sign-an-nda). - **document\_sha256**: the SHA-256 hash of that agreement. Your assistant passes it to `sign-nda`, so what it signs is the text you read. When you're the recipient, your assistant's first read counts as opening the NDA, as opening its page does: the sender sees it as viewed, and the signing record notes the token it came from. create-nda ---------- Creates an NDA with you as the sender and emails you and the recipient a link to it **at once**. There's no draft step, so your assistant should confirm the details with you first. Only two fields are required: `recipient_name` and `recipient_email`. The recipient fills in their own address before they sign. Everything else has a default: | Field | Default | |---|---| | Your name, company and address | Taken from the last NDA you sent; your name falls back to your profile | | Your email address | Always your account's | | `disclosing_party` | `sender`; or `recipient`, or `both` for mutual | | `ai_use` | `business`; or `strict`, or `open` | | `duration` | 3 years, from 1 to 5 | | `confidentiality_duration` | 3 years after it ends, from 1 to 5 | | `purpose` | Evaluating, and if the parties decide so, pursuing a business relationship | | `has_non_solicitation`, `has_non_circumvent`, `has_penalty`, `includes_affiliates` | All off. `has_penalty` holds only where the governing law gives an agreed sum effect. Where it doesn't, it's stored as false before the NDA is written, so an agent that sets it and reads it back gets false and no error. | It sends at most five NDAs a minute, as the form on the home page does. Your first NDA has nothing to default from, so it needs your street address, city, postal code and country, the last as a lowercase two-letter code like `nl` or `us`. For the United States, Canada, Australia and the United Kingdom it also needs `sender_address_state`, because that fixes the governing law; for the United Kingdom that's England and Wales, Scotland or Northern Ireland. See [Governing law](https://sendnda.com/docs/the-agreement/governing-law). The answer is the NDA as `get-nda` returns it, without the agreement text, so your assistant can show you what went out. amend-nda --------- Changes an NDA you sent, until either of you signs. It takes the `uuid` and any field `create-nda` takes except your email address, and only the ones that change. `notify_recipient` emails the recipient what changed; it's on by default once they've opened the NDA. A new `recipient_email` sends the NDA to that address, and the previous recipient loses access. The answer is the NDA as `get-nda` returns it, without the agreement text, plus `changed`, the fields that changed, which is empty when nothing did. See [Amend, resend or delete](https://sendnda.com/docs/your-account/amend-resend-delete). set-recipient-details --------------------- Fills in your details on an NDA you received, until either of you signs: your address (street, city, postal code and country are required before you can sign), and your company name and number when you sign for a company. For the United States, Canada and Australia, `recipient_address_state` is required as well, by name or by its standard abbreviation, and it has to be one that country's own registry knows. `recipient_is_consumer` is the answer with the largest effect on the text your assistant is about to sign for you: true says you sign for yourself and not for a business or profession, which takes the penalty for a breach and the agreement on how loss is proved out of the agreement and puts in a sentence saving the protections your own law gives a private individual. A company name overrides it to false. Pass only what changes. The answer is the summary plus `changed`. sign-nda -------- Signs the NDA as you, on your side of it: the recipient signs first, the sender countersigns. It takes the `uuid`, the `document_sha256` `get-nda` returned with the text you read, and `consent`, which must be `true`. That states that you read the agreement, accept the [Terms of Service](https://sendnda.com/legal/terms) and the [Privacy Policy](https://sendnda.com/legal/privacy), and told your assistant to sign it electronically for you. Where `get-nda` returned `key_clauses_to_approve`, it also takes `approve_key_clauses`, which must be `true`: your assistant has shown you those clauses by name and you approved them apart from the rest. The server tells your assistant to show you `agreement_text` first and to sign only when you say so. If the sender changed the terms after you read them, the hash no longer matches and nothing is signed: your assistant reads the NDA again and shows you the new text. It also refuses without `approve_key_clauses` where the governing law asks for it, while the recipient's details are missing, while the recipient hasn't signed when you're the sender, and once you've signed. The answer is the summary plus `signed_at` and `document_sha256`, the hash of the text you signed. The signing record credits the token your assistant used, as it credits a mail link on the page. The countersignature completes the NDA: both of you get the sealed PDF by email. resend-nda ---------- Takes a `uuid` and emails the recipient their link again. Only the sender can, only while the recipient hasn't signed, and at most once in ten minutes. It answers with the address it sent to. delete-nda ---------- Takes a `uuid` and deletes an NDA you sent, as the dashboard does, until either of you signs. The agreement and its log are removed, both links stop working, and the recipient isn't told. It can't be undone, so your assistant should confirm with you first. read-docs --------- Reads Send NDA's public pages as markdown: these docs, the legal documents, and the home and verify pages. It's the same text as each page's `.md` version. Without a `path` it lists every page with its path, title and description; with one, such as `/docs/the-agreement/clauses` or `/legal/terms`, it returns that page. Your assistant uses it to quote what a clause means rather than paraphrase it, and to show you the Terms of Service and the Privacy Policy that signing accepts. The lifecycle ------------- `next_action` names the step the NDA waits for, and the tool for it: - `recipient_details`: the recipient fills in their address with `set-recipient-details`. - `recipient_signs`: the recipient signs with `sign-nda`. - `waiting_for_recipient`: you sent it and the recipient hasn't signed yet. `resend-nda` nudges them. - `sender_countersigns`: you sent it, the recipient signed, and you countersign with `sign-nda`. - `waiting_for_sender`: you signed and the sender hasn't countersigned yet. - `completed`: both signed, and both of you get the sealed PDF by email. Errors ------ A `uuid` you're no party to answers the same as one that doesn't exist, with an error that won't change, so your assistant shouldn't retry it. An NDA from the public site whose sender hasn't confirmed their email address yet belongs to nobody's account, so no tool returns it. Checked against the code on 25 September 2026. [ Connect over MCP ](https://sendnda.com/docs/agents/connect-over-mcp) [ API tokens ](https://sendnda.com/docs/agents/api-tokens) --- # https://sendnda.com/docs/agents/api-tokens [ Docs ](https://sendnda.com/docs) [ Agents and the API ](https://sendnda.com/docs/agents) API tokens ========== Create a token on the Agents page for a client that does not speak OAuth. 05 Agents and the API ------------------ Article 3 of 3 Most MCP clients sign in with OAuth. Some don't, and a script of your own might not either. For those, create an API token on the **Agents** page and send it as a bearer token. It opens the same MCP server with the same nine tools. Create a token -------------- 1. Sign in and open **Agents**. 2. Under **API tokens**, give the token a name you'll recognise later, like *Claude Desktop*, and press **Create token**. 3. Copy the token right away. It's shown once, and we can't show it again: we only keep a hash of it. A token lasts one year from the day you create it. It carries one ability, `mcp:use`, which opens the MCP server and nothing else. Use a token ----------- Point your client at the MCP address and send the token in the `Authorization` header: ``` POST https://sendnda.com/mcp Authorization: Bearer YOUR_TOKEN Content-Type: application/json ``` The server speaks MCP over streamable HTTP, so the body is an MCP message, not a plain REST call. Most clients let you add a header to a remote server in their configuration. The limit is the same as over OAuth: 120 requests per minute per account. Keep it safe ------------ A token acts as you. Whoever holds it can send an NDA in your name, and `create-nda` emails both parties straight away. So: - keep a token out of code you share and out of repositories; - give each client its own token, so you can cut one off without the others; - revoke a token you no longer use. You're responsible for what's done with your tokens, including by agents you connect. The [Acceptable Use Policy](https://sendnda.com/legal/acceptable-use) sets out the rules. Revoke a token -------------- The **Agents** page lists every token with when it was created and, once it's been used, when it was last used. Press **Revoke** next to one and confirm. It stops working immediately, and any agent using it loses access. Deleting your account removes all your tokens with it. For clients that do speak OAuth, [Connect over MCP](https://sendnda.com/docs/agents/connect-over-mcp) is the simpler route: no token to copy, and nothing to store. Checked against the code on 22 September 2026. [ The tools ](https://sendnda.com/docs/agents/the-tools)