DRAFT · PENDING LEGAL REVIEW
Privacy Policy
How Kodar OÜ (“Sign by Kodar”, “we”) processes personal data when you use the platform, and — importantly — how we process the data of people invited to sign a document. This notice is provided under Articles 13 and 14 of the GDPR.
LAST UPDATED 9 July 2026 · Kodar OÜ · Tallinn, Estonia
01Who is responsible for your data
Sign by Kodar is an e-signing platform. Two roles matter under the GDPR:
The sender is the controller. When a business uploads a document and invites you to sign, that business decides why your data is processed and is the data controller for the signing. Kodar OÜ acts as their processor and handles your data only on their documented instructions (see our Data Processing Agreement).
We are the controller for the platform itself — account holders, billing, security logs, and running the service. For anything about a specific signing request, contact the sender who invited you; for the platform, contact us at privacy@kodar.io.
02What we process
- Signer identity
- First and last name, national personal identity code, country, and email; phone number where Mobile-ID is used.
- Signature data
- Your qualified certificate, the cryptographic signature, verification timestamps, and OCSP validity proofs, sealed into the ASiC-E container.
- Account data
- For registered users: name, email, hashed password, workspace and role.
- Usage & security
- Document/event metadata, IP-based rate-limit signals, and audit logs of sent/viewed/signed/sealed events.
- Billing
- For paying workspaces: plan, billing email, and payment order references (handled by our payment provider Montonio; we do not store card data).
03Why, and on what legal basis
To create your qualified electronic signature — your name and personal identity code are sent to SK ID Solutions AS (the Smart-ID / Mobile-ID trust service provider) to obtain your qualified certificate and produce the signature. The legal basis is the performance of, or steps toward, the contract you are signing (Art. 6(1)(b)), and the signing itself relies on your explicit action.
To run and secure the service — account management, fraud/abuse prevention, rate limiting, and audit logging, on the basis of our legitimate interests (Art. 6(1)(f)) and, for account holders, the contract with the workspace (Art. 6(1)(b)).
To meet legal obligations — retaining signed containers and audit records as evidence of a validly executed agreement (Art. 6(1)(c)).
A national identity code is not a special category of data under Art. 9, but it is sensitive national-ID data; we process it only to request your qualified certificate and to bind the signature to you.
04Who we share it with
SK ID Solutions AS (Estonia) — to issue your qualified certificate and perform Smart-ID / Mobile-ID signing. The sender who invited you — they receive the completed, signed container. Infrastructure and email providers that host the platform and deliver notifications, bound by data-processing terms. Montonio — for workspace payments. We do not sell personal data.
05International transfers
We host and process data in the EU/EEA. Where a provider processes data outside the EEA, we rely on an adequacy decision or Standard Contractual Clauses with appropriate safeguards.
06How long we keep it
Signed ASiC-E containers and the audit trail are the legal record of an executed agreement and are retained by the sender for as long as they need that evidence, subject to their retention policy and applicable law. Account data is kept while the account is active. When you close your account, or when a sender purges a signing, we delete or anonymise the associated personal data within a reasonable period, except where retention is legally required.
07Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your data, and to data portability. Because the sender is the controller for a specific signing, direct those requests to the sender; we will assist them as their processor. For platform data, contact privacy@kodar.io. You may also lodge a complaint with your supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon).
08Security
Passwords are hashed, single-use signing links are cryptographically bound to one signer and document, transport is encrypted, and access is scoped per workspace. Containers carry qualified timestamps and validity proofs so their integrity can be independently verified.
09Changes
We may update this policy; the effective date above reflects the latest version. Material changes will be communicated to account holders.
Questions about this document? Contact privacy@kodar.io. See also our Privacy Policy, Terms, DPA, and Cookie Policy.