Last updated 24 July 2026

This Privacy Policy explains what personal information Authent (the "Service") collects, why we collect it, who we share it with, how long we keep it, and what you can ask us to do with it. It sits alongside our Terms and Conditions.

Authent prepares documents, captures electronic signatures and maintains a tamper-evident audit trail. Much of what follows is a consequence of that purpose: a record that could be quietly altered or erased would not be evidence of anything. So some of the information described here is deliberately kept, and deliberately not editable — including by us.

1. Who this policy covers

Account holders create an account, upload documents and keep client records in the Service. Where an account holder keeps a record about you, they decide why your information is processed; we process it on their instruction.

2. Information we collect

Account information. Your first name, surname and email address, your role, your account number, and the dates on which you created the account and accepted the Terms.

Sign-in information. One-time codes sent to your email are stored only as a hash and expire within minutes. If you use a passkey we store its public key and the challenge used to verify it. There is no password to store, and the private half of a passkey never leaves your device.

Documents you upload. The file itself, its title, file name and type, and a cryptographic hash of it. Files are encrypted at rest.

Client records. If you keep client records in the Service: name, identity number, email address, telephone number, and postal and domicilium addresses.

Change records. When a record is changed, the Service notes which item changed, when, and who changed it — never the values before or after.

Notification subscriptions. If you turn on browser notifications, the endpoint and keys needed to deliver them.

3. Why we use it

To run the Service and sign you in; to store the documents and client records you put into it; to send service messages such as one-time codes; and to secure the Service, investigate misuse and meet our legal obligations.

We do not sell personal information. We do not use it for advertising or profiling, and we do not use your documents or their contents to train machine-learning models.

4. Who we share it with

Our email provider, which delivers one-time codes. It receives the recipient's email address and the message.

Our hosting and infrastructure providers, which store the data on our behalf.

We also disclose information where the law requires it, or where it is necessary to establish, exercise or defend a legal claim.

5. How we protect it

Documents are encrypted at rest, and each account's data is held under its own isolated storage path. Traffic to the Service travels over HTTPS. Sign-in uses a one-time email code or a passkey, so there is no password to be leaked or reused.

No system is perfectly secure and we cannot guarantee absolute security. Your email account is the key to your Authent account — please keep it secure.

6. How long we keep it

Documents and client records are kept for as long as the account exists, and are deleted when you delete them. One-time codes and authentication challenges expire within minutes.

7. Your rights

Under applicable data-protection law you may ask us to confirm whether we hold information about you and give you a copy of it; to correct information that is wrong or incomplete; to delete information; to stop or restrict a particular use, or to object to it; to withdraw consent where we rely on it; and to provide a copy in a portable form where that right applies.

Write to info@authent.io. We may need to confirm your identity first, and we will respond within the period applicable law allows. If we cannot do what you have asked — usually because we are required to keep the information — we will tell you why. You may also complain to the data-protection authority in your country.

If an account holder keeps a client record about you and you want it corrected or removed, they control that record. Please ask them first; if you contact us we will pass the request on and help where we can.

8. Cookies, analytics and email tracking

We set three first-party cookies. One keeps you signed in, a short-lived one carries a status message from one page to the next, and one records whether you agreed to analytics. There are no advertising cookies and no third-party analytics.

Our analytics are our own and are opt-in. If you accept when asked, we derive an identifier from your network address and browser so that repeat visits can be counted and we can see how people reach us. If you decline, or have not yet answered, nothing is derived and nothing is recorded.

Email we send carries open tracking and link tracking, applied by our email provider (see section 4). Open tracking embeds a small invisible image — a tracking pixel — so opening the message records that it was opened, when, and the device and network it was opened from. Link tracking rewrites the links in the message, so following one records that the link was followed and routes the click through that provider before it reaches us. If you would rather not be tracked this way, most email clients can be set to block remote images, which prevents the open pixel from loading.

9. International transfers

The service providers named in section 4 may be located in other countries. Where personal information crosses a border we take reasonable steps to see that it remains protected to a comparable standard.

10. Children

The Service is not intended for children, and we do not knowingly collect their personal information.

11. Changes to this policy

We may update this policy. The date at the top always reflects the current version, and we will tell you about material changes through the Service or by email.

12. Contact us

Questions about this policy, or about the information we hold: info@authent.io.