Privacy Policy
Last updated: 1 October 2026
1. Who we are
This Privacy Policy describes how Deploy d.o.o. (“we”, “us”) processes personal data when you use FingerInk at https://fingerink.app and https://my.fingerink.app.
- Controller: Deploy d.o.o., Ljudevita Posavskog 12b, 21000 Split, Croatia
- OIB: 83735032133
- Contact: hello@fingerink.app
Company details are also listed on our Imprint.
2. What data we process
Account and workspace users
- Name, email address, and authentication data
- Workspace membership, role, and billing-related identifiers
- Templates, signing requests, and settings you create
- Support messages you send us
Signers and document parties
- Name, email, and phone number provided for a signing request
- Data entered into document fields
- Electronic signature image or advanced signature artefacts
- Audit metadata (e.g. timestamps, IP address, user agent) related to viewing and signing
- The signed document content
Technical data
- Basic server logs needed to operate and secure the service
- Cookies or similar technologies required for login and security
3. Purposes and legal bases
- Providing the signing service and your workspace — performance of a contract (Art. 6(1)(b) GDPR)
- Billing, fraud prevention, and service security — legitimate interests (Art. 6(1)(f) GDPR)
- Legal obligations (e.g. tax/accounting) — Art. 6(1)(c) GDPR
- Where a signer must tick a privacy consent on a request, that consent is collected for that signing flow (Art. 6(1)(a) GDPR) in addition to other applicable bases
4. Controllers and processors
For your own workspace content (templates, requests, signed files), you are typically the controller and we act as a processor. For account, billing, and platform operation data, we act as controller.
We use infrastructure and service providers (hosting, object storage, email delivery, payment processing) strictly as needed to run FingerInk. Business customers may request a Data Processing Agreement via Contact.
5. Retention
We keep data only as long as needed for the purposes above, your plan’s retention settings, and legal requirements. Free and paid plans may apply different document retention periods; deleting a workspace or request removes associated files subject to backup cycles and legal holds.
6. Security
Documents are stored with encryption at rest (envelope encryption). Access is limited to authenticated workspace members and the systems required to deliver the service. No method of transmission or storage is 100% secure; we apply measures appropriate to the risk.
7. International transfers
If processing occurs outside the EEA, we use appropriate safeguards under the GDPR (such as standard contractual clauses) where required.
8. Your rights
Under the GDPR you may have the right to:
- Access, rectify, or erase your personal data
- Restrict or object to certain processing
- Data portability
- Withdraw consent where processing is based on consent
To exercise these rights, email hello@fingerink.app. You may also lodge a complaint with Agencija za zaštitu osobnih podataka (AZOP), Selska cesta 136, 10000 Zagreb, Croatia, https://azop.hr.
9. Children
FingerInk is intended for business use. We do not knowingly offer accounts to children.
10. Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the service after changes means you accept the updated policy, where permitted by law.