How COSigna processes personal data — and how little of it ever reaches our servers.
The data controller for your COSigna account and for the COSigna hosted service is Phileos, a company incorporated in France:
| Legal name | Phileos Security and Event Services (PSES) |
|---|---|
| SIRET | 937 831 899 |
| RCS | Paris |
| Registered address | 60 Rue François 1er, 75008 PARIS |
| Contact / DPO | privacy@phileos.eu |
Two different roles. When you use COSigna for your own purposes, Phileos is the controller of your account data. When a professional customer (for example, a law firm) runs ceremonies that process their signers' data, that customer is the controller and Phileos acts as a processor on their instructions — governed by our Data Processing Agreement (Art. 28 GDPR).
COSigna is an asynchronous, multi-party electronic-signature "ceremony" built around a blind server: the original document never reaches us — only its content-addressed SHA-256 hash does. We process your account email, the document hashes, ceremony metadata, a self-declared location, your credit ledger, and — only with your explicit consent — an end-to-end-encrypted consent selfie that our server stores as ciphertext it cannot read. Payment card data is handled entirely by Stripe; we never see it. All personal data is hosted in the EU. You can export everything and erase it — including crypto-erasure of the encrypted selfie — using endpoints that are already built and described below.
| Data | Why | GDPR category |
|---|---|---|
| Account email address | To create and secure your account; magic-link / passkey sign-in; service notices. | Personal data (Art. 4) |
| Consent selfie (encrypted) | The contemporaneous record that a human consented at the signing moment. Stored only as end-to-end-encrypted ciphertext. | Special category — biometric (Art. 9) |
| Document hashes (SHA-256) | The content-addressed reference that lets every party verify they signed the same document. Not the document itself. | Personal data (links an identity to a document) |
| Ceremony metadata | Who the parties are, ceremony state and timestamps, the hash-chained attestations. | Personal data |
| Self-declared location | A signer-entered statement of where they signed, recorded in the attestation. We do not capture GPS or EXIF. | Personal data (self-declared) |
| Credit ledger | To track the credits you hold and consume (perpetual, single-purpose vouchers). | Personal data |
| Payment data | Handled by Stripe as payment processor. We receive a transaction reference and the credits to grant — never the card number. | Personal data (held by Stripe) |
| IP address (transient) | Used transiently for rate-limiting and abuse prevention. Not retained as a tracking or profiling record. | Personal data (transient) |
A consent selfie is a photograph of your face, taken at the signing moment to evidence that a real person — you — consented. We treat it as special-category biometric data under Article 9 GDPR and handle it accordingly:
Honest note for reviewers. Because the server holds only ciphertext, we believe the server does not "process" biometric data for the purpose of uniquely identifying a natural person in the Art. 9 sense. We flag this as a position to confirm with counsel rather than a settled certainty, and we treat the selfie as Art. 9 data regardless, applying the stricter regime by default.
| Processing | Legal basis (GDPR Art. 6 / 9) |
|---|---|
| The consent selfie (biometric) | Explicit consent — Art. 9(2)(a), on top of Art. 6(1)(a). |
| The act of signing / participating in a ceremony | Consent (Art. 6(1)(a)) and/or contract (Art. 6(1)(b)) — you ask us to record your attestation. |
| Providing the service (account, ceremonies, credits) | Contract — Art. 6(1)(b). |
| Security, anti-fraud, rate-limiting (transient IP) | Legitimate interest — Art. 6(1)(f). We use the IP transiently to limit abuse; we do not build a tracking profile from it. |
| Retaining a closed ceremony as evidence | Contract / legitimate interest, with the legal-claims grounds of Art. 17(3)(e) for the non-reversible proof record (see retention). |
COSigna is engineered for data minimisation at the architectural level (Art. 5(1)(c), Art. 25):
COSIGNA_RETENTION_DAYS (default 90 days).The distinction matters: the personal data you can erase (your encrypted selfie, your account) is separate from the non-reversible cryptographic proof (hashes and timestamps) that carries no personal content and that you hold independently of us.
Under GDPR you have the rights of access, portability, rectification, erasure, restriction, and objection. These are not promises on paper — they are built into the service:
| Right | Article | How it works | Endpoint |
|---|---|---|---|
| Access / portability | 15 / 20 | A full, machine-readable export of your account and ceremony data. | GET /account/export |
| Erasure (selfie) | 17 | Crypto-erasure of the encrypted consent selfie; the non-reversible hash commitment remains so the proof stays structurally verifiable. | POST /faces/{hash}/erase |
| Erasure (account) | 17 | Account and sessions deleted; closed ceremonies are unlinked, with the evidentiary record retained under Art. 17(3)(e). | POST /account/delete |
| Accountability | 5(2) | Every erasure is recorded in an append-only, PII-free erasure_log. | — |
| Storage limitation | 5(1)(e) | Automatic expiry of draft/abandoned ceremonies after the retention window. | retention sweep (COSIGNA_RETENTION_DAYS, default 90) |
How to exercise them. You can use the in-app account controls, or contact privacy@phileos.eu. We will respond within one month (Art. 12(3)), extendable as permitted. We do not charge for the first request.
We rely on a small, EU-anchored set of subprocessors. No document content ever leaves to any third party — the blind-server design makes that structurally impossible.
| Subprocessor | Role | Location | What it sees |
|---|---|---|---|
| Scaleway | Hosting + object storage | France (EU) | Encrypted/at-rest service data; selfie ciphertext (opaque); hashes. Never plaintext documents or selfies. |
| Stripe Payments Europe | Payment processing | Ireland (EU) | Card and billing data (we never receive the card number). |
| Scaleway TEM | Transactional email | France (EU) | Your email address + sign-in / service messages. |
| OpenTimestamps calendars + Bitcoin network | Public timestamp anchoring | Public infrastructure | Hashes only — no personal data, no document content. |
The current subprocessor list is also maintained in the DPA. Material changes are communicated as described there.
Personal data is hosted and processed within the EU/EEA. We do not transfer your personal data outside the EU/EEA in the ordinary course. The OpenTimestamps/Bitcoin anchor is public infrastructure that carries only hashes — no personal data and no document content — so it does not constitute an international transfer of personal data. Should any transfer ever become necessary, we would put appropriate safeguards (such as Standard Contractual Clauses) in place first.
Honest note. An independent security assessment / penetration test is planned and not yet complete. We describe our measures accurately and do not claim certifications (e.g. ISO 27001, SOC 2) we do not hold.
Minimal, and no third-party trackers. COSigna uses only first-party localStorage to remember your session and your language preference. There are no advertising cookies, no analytics trackers, and no third-party tracking pixels. This is a deliberate design choice.
Do Not Track and Global Privacy Control are honored. If your browser sends the DNT: 1 or Sec-GPC: 1 signal, COSigna excludes your visit from ALL of its first-party measurement — the anonymous feature-usage counters, the performance beacons, and even the identifier-free aggregate traffic and country-of-origin counts. We take the stricter reading: although these aggregates contain no identifier to opt out of, an opt-out signal means you are not counted at all.
Because COSigna processes data tied to legally significant acts together with a biometric consent artefact, a Data Protection Impact Assessment (DPIA, Art. 35) is appropriate and is commissioned / in progress. We will reflect its conclusions here.
Questions, requests, or concerns: privacy@phileos.eu.
You also have the right to lodge a complaint with a supervisory authority. For Phileos (France) this is the CNIL (Commission Nationale de l'Informatique et des Libertés), www.cnil.fr. You may also contact the authority in your own EU/EEA country of residence.
This is provisional draft v0.1. We will version every material change, date it, and — once the policy is finalised with counsel — give notice of significant changes. The version and date appear at the top of this page.
Provisional — pending Counsel review (CR-11). This section describes a proposed two-tier comms model that is not yet fully implemented. It will be confirmed, and the mechanism completed, before the first non-transactional email is sent.
Your email address is the only personal data we hold about you, and we use it as minimally as possible. Here is exactly what we do and do not do with it:
The honest data claim. Your email is the only personal data we keep, and only to send you the magic link to sign in (and these rare updates). We never see your documents, who you sign with, or what you sign — and we never sell, share, or profile your address.
Because email is our only way to reach you, we occasionally use it for important technical information. Opt out of updates and you will need to check the platform yourself for news.
| Tier | What it covers | Can you opt out? | Legal basis |
|---|---|---|---|
| Tier 0 — Transactional | The magic-link sign-in email. Without it you cannot use the service. | No — it is the service itself. | Performance of contract (Art. 6(1)(b)) |
| Tier 1 — Critical platform | Security notices, data-breach notifications, service migrations, and similar messages required by law or by the GDPR Art. 33/34 breach-duty. Rare. | No — we are required or obligated to send these. | Legitimate interest + legal obligation (Art. 6(1)(c)/(f)) |
| Tier 2 — Product updates | Release notes, new-feature announcements, Alpha milestone emails. Occasional. | Yes — one-click, no login required. Default-ON during Private Alpha; you can opt out at any time via the unsubscribe link in any such email. | Legitimate interest (soft opt-in for existing platform users) (Art. 6(1)(f)) |
Every Tier-2 email carries a one-click unsubscribe link in its footer. Clicking it:
If you opt out, you can still find product news by checking the platform directly.