DocPost · Legal

Privacy Policy

Effective date: 2026-06-24. Last reviewed: 2026-06-24.

DocPost is a legal technology platform. It is operated by Goliath Dynamics Inc. ("GDI", "we", "us"), a Florida corporation with its principal place of business at 7901 4th St N, STE 300, St. Petersburg, FL 33702.

This Privacy Policy explains what personal information we handle when you use DocPost, why we handle it, who we share it with, and the choices and rights you have. It applies to the DocPost web application, our marketing pages, our APIs, and the e-signature signing flow at signing links.

This policy is written to satisfy our obligations under the U.S. Electronic Signatures in Global and National Commerce Act (ESIGN), state Uniform Electronic Transactions Acts (UETA) and equivalent state law, the Health Insurance Portability and Accountability Act (HIPAA) where DocPost handles electronic protected health information ("ePHI"), the EU and UK General Data Protection Regulations (GDPR / UK GDPR), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Who this policy applies to

DocPost has two categories of users:

(a) Account holders — people who sign in to an organization workspace on DocPost. We are the data controller for account-holder personal information (name, email address, organization membership, authentication state, billing identity, and product activity).

(b) Signers — people who receive a signing link and complete an electronic signature inside a sender's signing flow. For signer personal information processed inside a specific signing transaction, the sender (the organization that initiated the signing request) is the controller and DocPost is the processor acting on the sender's instructions. The processing notice we surface to signers at signing time is the DocPost E-Sign Act & Data-Processing Disclosure that appears in the signing flow; the same notice is the E-Sign Act & Data-Processing Disclosure.

This Privacy Policy describes both categories. Where a section applies to only one, we say so.

2. Personal information we handle

We handle the following personal information:

Account-holder information

  • Identity: name, email address, phone number (optional, for SMS two-factor authentication if enrolled), profile photo (optional), organization name and role.
  • Authentication: one-time passcodes (OTPs) delivered to your email, session tokens, multi-factor authentication state, IP address and user-agent string at sign-in.
  • Billing: business name, billing email, payment method on file at our payment processor (Stripe; card numbers themselves are stored by Stripe, not by DocPost), invoice history, subscription plan, seat counts, and usage-pack balances.
  • Product activity: documents you create, upload, send, sign, and store; the contents of those documents; templates you define; signature requests you initiate; webhook destinations you configure; API keys you mint (we store only a salted hash of the secret, never the plaintext after creation); support requests; and the audit-log events your actions produce.

Signer information (signing transactions on behalf of senders)

  • Identity: name, email address, IP address, device fingerprint, user-agent string, and the image of the signature you draw or upload.
  • Signing activity: the time you opened the signing link, the time you completed each action, the content of every field you complete, your ESIGN / UETA consent affirmation, your intent-to-sign affirmation, and any decline or consent-withdrawal events.
  • Tamper-evidence: a SHA-256 hash of the final document, a hash-chained audit log (every event carries the SHA-256 of the previous event so any later tampering is detectable), and an RFC-3161 timestamp from a trusted timestamp authority.

Marketing-surface visitors

  • Server-side request logs for the public marketing pages (IP address, requested URL, user-agent, response status), retained as described in §6.
  • Information you voluntarily submit through public contact / chat / "Request access" / "Talk to sales" flows.

Electronic protected health information (ePHI)

  • A signing transaction or a document uploaded to a workspace may itself contain ePHI (for example, a HIPAA authorization, a release of medical records, or a BAA-covered services agreement). Where DocPost handles ePHI on behalf of a covered-entity customer, we do so as a HIPAA business associate under a Business Associate Agreement ("BAA"). We do not access, use, or disclose ePHI other than as permitted by the BAA, the customer's written instructions, and applicable law. We do not require ePHI to operate the service.

Inferred or derived information

  • Bot/abuse signals derived from request metadata (rate, fingerprint patterns) for in-house abuse prevention; we do not use third-party bot-management vendors or sell this signal.

What we do not handle

  • Government-issued identifier numbers (e.g. SSN, passport number) are not required by DocPost to use the service. If a customer's signing flow asks a signer for such an identifier as a form-field value, the value is treated as signer information above and surfaces to the controller (the sender), not to DocPost as controller.
  • Payment-card numbers are processed and stored by our payment processor (Stripe), not by DocPost.
  • We do not use cross-site advertising cookies and do not sell or "share" personal information for cross-context behavioral advertising.

3. Why we handle personal information

We handle personal information for these purposes:

(a) To deliver the service you asked for — sending and receiving signing requests, generating the certificate of completion, storing documents in your workspace, fulfilling API calls, and so on.

(b) To produce tamper-evident evidence that a signature happened — the audit log, document hash, and TSA timestamp described in §2 exist so that the resulting contract is enforceable against the parties.

(c) To prevent and investigate fraud, impersonation, link sharing, and replay attacks against the signing flow.

(d) To bill account holders accurately, including computing seat counts and pack-balance consumption.

(e) To send transactional notices that the service requires — signature-request invitations, completion notices, decline notices, security alerts, billing receipts. These are not marketing; you cannot opt out of them while you continue to use the service.

(f) To send product, marketing, and account-status emails you have opted in to receive. You can manage these at /notifications and unsubscribe from the link in any such message.

(g) To comply with applicable law and respond to lawful requests from courts, regulators, and law-enforcement authorities.

(h) To improve the service through aggregated, deidentified usage analytics. We do not train AI models on customer documents — see §10.

4. Lawful basis (GDPR / UK GDPR)

When we process personal information of individuals in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following Article 6 lawful bases:

  • Article 6(1)(b) — performance of a contract — for account-holder data necessary to provide the service you signed up for and for billing.
  • Article 6(1)(f) — legitimate interests — for (i) producing tamper-evident evidence of who signed, when, from where, and on what device, so that the resulting contract is enforceable against the parties; and (ii) detecting and preventing fraud, impersonation, link sharing, and replay attacks against the signing flow. We have weighed these interests against the rights and freedoms of data subjects and reasonably consider that participants in a commercial e-signature workflow expect this evidentiary processing and would not reasonably object to it. The balancing record for the signing-transaction case is in the published E-Sign Act & Data-Processing Disclosure.
  • Article 6(1)(a) — consent — for optional features that are not necessary to the service (for example, opting in to product-marketing emails or to SMS two-factor authentication). You can withdraw this consent at any time without affecting your access to the service.
  • Article 6(1)(c) — legal obligation — when we must process personal information to comply with a law that applies to us.

For signing-transaction personal information, the sender is the controller and DocPost is the processor; the sender determines and notifies the lawful basis.

5. Who we share personal information with

We share personal information only as follows:

(a) Sub-processors and infrastructure providers acting on our written instructions:

  • Google Cloud Platform — hosting, compute, object storage (Google Cloud Storage), managed databases. Region(s): primarily United States. Bound by Google's Cloud Data Processing Addendum.
  • Stripe — billing and payment processing for paid plans. Card data is collected directly by Stripe.
  • Amazon Web Services (Simple Email Service) — outbound transactional email delivery.
  • A trusted timestamping authority — RFC-3161 timestamps for signature events. Only a SHA-256 hash of the content being timestamped is sent; the document itself is not transmitted to the timestamp authority.
  • Large-language-model providers used to power optional product features (e.g. Google Gemini). LLM use is governed by §10 (no-training guarantee); the per-provider enumeration, contractual terms, and per-call-site verification are published in our Data Processing Agreement.
  • Where you connect a third-party storage provider yourself (e.g. Google Drive), DocPost exchanges the documents you direct it to with that provider under the OAuth grant you authorize.

(b) Other users in your organization — documents, signature requests, and activity are visible to other members of your organization workspace based on role and access settings the workspace administrator controls.

(c) Counterparties — signers and approvers you invite to a signature request receive the documents, fields, and metadata necessary to complete their step.

(d) Senders (for signer information) — when you sign a document on DocPost, the sender (the organization that initiated the request) receives your signing-transaction information described in §2 and the audit trail.

(e) Recipients of contracts you elect to share — for example, when you elect to export a completed envelope into a connected cloud-storage provider, that provider receives the export.

(f) Professional advisors and acquirers — auditors, accountants, lawyers, and counterparties involved in a corporate transaction (financing, merger, reorganization, sale of assets, or insolvency), subject to confidentiality and proportionate to the legitimate need.

(g) Government and law enforcement — when required by valid legal process or as needed to protect the rights, property, or safety of GDI, our customers, or others.

We do not sell personal information and we do not "share" personal information for cross-context behavioral advertising as defined by California Civil Code §1798.140.

6. Retention

We retain personal information only for as long as we need it for the purposes described above and to meet our legal, accounting, and reporting obligations.

  • Audit-trail data on a completed envelope is retained for the duration of the signed contract plus any limitation period applicable to claims arising from it. Deletion of audit data after a signature has been affixed may invalidate the legal effect of the signature; if you require earlier deletion, contact the sender (controller).
  • Account-holder records are retained while the account is active and for a reasonable post-termination window to honor open billing and legal-hold obligations.
  • Server-side request logs for public marketing pages are retained on a rolling per-month basis for abuse prevention and capacity planning, and then aged out.
  • Backups containing the above categories are retained on a rolling schedule and rotate out within the backup window.
  • ePHI handled under a BAA is retained per the BAA, the customer's instructions, and HIPAA requirements; on termination, we return or destroy ePHI as the BAA specifies.

7. Storage location and international transfers

GDI stores personal information in the United States through the DocPost platform. If you access DocPost from outside the United States, you understand and agree that your personal information will be transferred to, processed in, and stored in the United States.

For transfers of EEA, UK, or Swiss personal information into the United States, we rely on the European Commission's Standard Contractual Clauses and equivalent UK and Swiss addenda as the transfer mechanism, supplemented by appropriate technical and organizational measures.

8. Your rights

Account holders. You may at any time:

  • access, correct, or update your account information through your profile and organization settings;
  • export the documents and signing data that your role permits;
  • close your account by contacting us at the address in §13 (we will then delete or anonymize your personal information, subject to the retention rules in §6 and any legal-hold obligation).

Signers. DocPost acts as a processor for signing-transaction personal information; the sender is the controller. Direct rights requests (access, rectification, restriction, portability, erasure, objection) to the sender. We will assist the sender as required by applicable data-protection law. The published E-Sign Act & Data-Processing Disclosure — the same notice surfaced at signing time — also explains your right to receive a paper copy, your right to withdraw consent before completing your signature, and what happens to your slot if you do. The published PIPEDA Canadian-Handling Notice records the PIPEDA-specific appropriate-purposes / business-necessity basis (subsection 5(3) and Principles 4.2/4.4/4.5) for the same signing-transaction processing, parallel to the GDPR Article 6(1)(f) framing in the disclosure.

General. You also have the right to lodge a complaint with a supervisory authority — your local data-protection authority in the EEA/UK, the Office of the Privacy Commissioner of Canada under PIPEDA (see the PIPEDA Canadian-Handling Notice §9 for routing), or the relevant authority in your jurisdiction.

We do honor Global Privacy Control signals where the law requires it for opt-out of sale or sharing; because we do not sell or share personal information for cross-context behavioral advertising, this signal does not change our processing.

9. HIPAA and ePHI

Where DocPost handles ePHI on behalf of a covered entity, we do so under a Business Associate Agreement. We maintain administrative, physical, and technical safeguards for ePHI as required under the HIPAA Security Rule. To request a BAA, contact us at the address in §13.

We do not use ePHI for any purpose other than the permitted purposes set out in the BAA and applicable law. We do not train AI models on ePHI.

10. No AI training on customer data

We do not train any AI or machine-learning model on the contents of customer documents, signing fields, audit trails, or ePHI. Where optional product features call an external large-language-model provider on behalf of a customer (for example, to support natural-language search over the customer's own executed agreements), we use the provider under contractual terms that prohibit the provider from training or fine-tuning models on the content we submit and that require zero-retention or short-retention handling of inputs and outputs. Our published Data Processing Agreement is the public source of truth — it names every LLM provider DocPost calls, the contractual no-training terms each call is bound by, and the per-call-site verification that no customer document content is sent under terms that permit provider-side training. A customer who wants to disable LLM-powered product features against their content can do so per organization under §8 of that page.

11. Security

We protect personal information with technical and organizational safeguards including encryption in transit (TLS) and at rest (Google Cloud Storage), least-privilege access controls, multi-factor authentication for workforce access, tamper-evident audit logging (hash-chained audit log; RFC-3161 timestamps), backup and disaster-recovery procedures, vendor management, vulnerability management, and workforce security training. No system can be guaranteed against every possible breach; if a breach occurs, we follow documented breach-notification procedures.

12. Children

The DocPost platform is a contracts and e-signature service for business use. It is not directed to children under 16 and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us at the address in §13 and we will delete it.

13. Contact

For privacy questions, rights requests, or to request a BAA, or contact:

Goliath Dynamics Inc. Attn: Privacy 7901 4th St N, STE 300 St. Petersburg, FL 33702 United States

For questions about a specific signing transaction, contact the sender — they are the controller for that flow.

14. Changes to this policy

We may update this Privacy Policy from time to time. The "Effective date" at the top of this policy records the date of the current version.