Privacy and data protection

Privacy Policy

This Privacy Policy explains how Zerozilla Infotech Pvt Ltd collects, uses, stores, shares, retains, and protects personal data when you use Signeez.

Effective date 22 July 2026
Last updated 22 July 2026
Data operator Zerozilla Infotech Pvt Ltd

1. Introduction

Signeez is a document workflow and electronic-signing product owned and operated by Zerozilla Infotech Pvt Ltd, a company incorporated under the laws of India.

Signeez is a product and brand of Zerozilla Infotech Pvt Ltd. It is not a separate company, incorporated entity, partnership, or legal person.

In this Privacy Policy, “Signeez,” “Zerozilla,” “Company,” “we,” “us,” and “our” refer to Zerozilla Infotech Pvt Ltd.

“Services” refers collectively to the Signeez website, applications, electronic-signing platform, document-management features, artificial-intelligence features, integrations, APIs, support services, and related functionality.

This Privacy Policy explains how we collect, receive, use, disclose, store, retain, and protect personal data when you:

  • Visit the Signeez website;
  • Register for or use a Signeez account;
  • Upload, create, send, receive, review, approve, reject, or sign a Document;
  • Participate in a document workflow initiated by another person or organisation;
  • Use Aadhaar-enabled electronic-signature functionality;
  • Use artificial-intelligence-powered template-creation features;
  • Contact our support or grievance team; or
  • Otherwise interact with the Services.

This Privacy Policy is a notice of our data-processing practices. Where applicable law requires specific consent, we will seek that consent separately through an appropriate affirmative mechanism. Publication of this Privacy Policy does not replace any consent required by law.

2. Scope and Applicability

This Privacy Policy applies to personal data processed by Zerozilla through Signeez.

It does not apply to:

  • Information independently collected or processed by a Signeez Customer outside the Services;
  • Third-party websites, platforms, applications, or integrations that maintain their own privacy practices;
  • Employment-related information processed under a separate employee or applicant privacy notice;
  • Information lawfully made public by the individual concerned or under a legal obligation; or
  • Information otherwise excluded from applicable data-protection legislation.

When an organisation uses Signeez to upload Documents, collect information, or obtain signatures, that organisation generally determines the purpose and manner of processing.

In such circumstances, the organisation may act as the data fiduciary or equivalent responsible party, while Zerozilla acts as its data processor or service provider.

Questions concerning why an organisation requested information, the contents of its Documents, its choice of recipients, or its retention practices should ordinarily be directed to that organisation.

3. Definitions

For this Privacy Policy:

  • “Account Holder” means a person or organisation that creates, purchases, administers, or controls a Signeez account.
  • “Customer” means a person or organisation that contracts with Zerozilla to use the Services.
  • “Data Principal” means the individual to whom personal data relates.
  • “Document Participant” means a sender, signer, reviewer, approver, witness, recipient, authorised representative, or other participant in a document workflow.
  • “Personal Data” means information about an identifiable individual, including digital personal data and sensitive personal data where recognised by applicable law.
  • “Processing” includes collecting, recording, organising, storing, using, sharing, transmitting, retrieving, altering, restricting, anonymising, or deleting personal data.
  • “User” means anyone who accesses or uses the Services, whether or not that person has a registered Signeez account.

4. Information We Collect

The information we collect depends on how you interact with Signeez and which features are used.

4.1 Account and Profile Information

We may collect:

  • Full name;
  • Email address;
  • Telephone number;
  • Username;
  • Password or authentication credentials in protected form;
  • Company or organisation name;
  • Job title or designation;
  • Profile image;
  • Account preferences;
  • Language and time-zone settings;
  • Subscription information;
  • Billing information; and
  • Organisation membership and role information.

Signeez does not store account passwords in plain-text form.

4.2 Documents and Document Content

We may process:

  • Documents uploaded, created, transmitted, signed, or stored through Signeez;
  • Text, images, attachments, form fields, comments, annotations, and instructions;
  • Names, addresses, contact information, identification details, financial information, or other information included in Documents;
  • Signatures, initials, stamps, seals, and certificates;
  • Document versions, status, revision history, and workflow information; and
  • Supporting records supplied in connection with a transaction.

The sender or Customer generally determines the nature and contents of a Document. Users must not include sensitive or unnecessary personal data unless they possess appropriate authority and a lawful reason to process it.

4.3 Signature and Audit-Trail Information

To establish the integrity, authenticity, sequence, and evidentiary history of a transaction, we may collect:

  • Signer name and contact details;
  • Date and time of Document delivery, access, viewing, approval, rejection, or signing;
  • IP address;
  • Device, browser, and operating-system information;
  • Authentication and verification events;
  • Document identifiers and version details;
  • Consent, acknowledgement, and acceptance records;
  • Signature placement and workflow actions;
  • Delivery and completion status;
  • Electronic-signature certificate details; and
  • Audit trails and transaction-completion certificates.

Some audit records may be retained after a Document or account is deleted where reasonably necessary to verify a transaction, prevent fraud, comply with law, enforce an agreement, or establish or defend a legal claim.

4.4 Aadhaar and Identity-Verification Information

Where a User elects to use Aadhaar-enabled eSign, the authentication and electronic-signature transaction is facilitated through VERASYS TECHNOLOGIES PVT LTD and the relevant authorised Aadhaar and electronic-signature infrastructure.

Depending on the transaction, the User may be asked to provide or authorise the processing of:

  • Aadhaar number or Virtual ID;
  • Aadhaar-registered mobile-number authentication;
  • One-time password;
  • Aadhaar-based identity or demographic information;
  • Name and masked identity information;
  • Authentication response or status;
  • Consent and transaction records;
  • Electronic-signature certificate information; and
  • Date, time, transaction identifier, and verification logs.

Aadhaar details, OTPs, and authentication inputs may be entered directly into systems operated by Verasys, UIDAI, or another duly authorised participant in the Aadhaar authentication and eSign ecosystem.

Zerozilla does not intend to collect or store Aadhaar OTPs, passwords, private signing keys, Virtual IDs, or core biometric information. We do not knowingly store or retain core biometric information used for Aadhaar authentication.

Signeez may receive and retain limited transaction information necessary to:

  • Complete the requested electronic signature;
  • Attach or verify an electronic-signature certificate;
  • Maintain an audit trail;
  • Demonstrate that authentication or signing occurred;
  • Prevent fraud;
  • Resolve disputes; and
  • Comply with applicable legal and regulatory obligations.

Any Aadhaar information received by Signeez will be used only for the disclosed and authorised purpose and handled in accordance with applicable Aadhaar legislation, regulations, security requirements, and consent conditions.

Aadhaar-based eSign is voluntary unless a particular transaction is subject to a lawful requirement. Refusing Aadhaar authentication may make the Aadhaar eSign feature unavailable, but alternative signing or identification methods may be offered where supported by the sender, applicable workflow, or law.

4.5 Artificial-Intelligence Feature Data

Signeez may provide artificial-intelligence-powered features for creating, drafting, formatting, suggesting, or improving Document templates.

When you use these features, we may process:

  • Prompts and instructions entered by you;
  • Selected text or content submitted to the AI feature;
  • Template titles, categories, and configuration information;
  • AI-generated responses and templates;
  • Feedback, ratings, corrections, and regeneration requests;
  • Technical logs and usage information; and
  • Safety, abuse-prevention, and diagnostic information.

You should not submit passwords, Aadhaar numbers, financial credentials, medical information, confidential client information, trade secrets, or other sensitive data to an AI feature unless the feature expressly requires it and you have sufficient authority and a lawful basis.

AI features may rely on approved third-party technology providers. Information submitted to those features may be processed by such providers solely to deliver, secure, monitor, or improve the requested feature, subject to applicable contracts and data-protection requirements.

Zerozilla will not use private Document content or AI prompts to train a publicly available or general-purpose AI model unless:

  • The proposed use is clearly disclosed;
  • The relevant Customer has expressly authorised it; and
  • Any additional legally required consent has been obtained.

AI-generated templates may contain errors, omissions, inappropriate language, or legally unsuitable provisions. Users are responsible for reviewing and validating AI-generated content before using, publishing, sending, or relying upon it.

4.6 Analytics and Usage Information

We may use analytics tools to understand how the Services are accessed and used.

Analytics information may include:

  • IP address;
  • Browser and device type;
  • Operating system;
  • Referring and exit pages;
  • Session identifiers;
  • Approximate location derived from an IP address;
  • Pages, screens, buttons, and features used;
  • Session dates, times, and duration;
  • Navigation paths;
  • Application errors;
  • Performance and diagnostic data; and
  • Aggregated or pseudonymised usage statistics.

Where legally required, non-essential analytics technologies will be activated only after obtaining appropriate consent.

We do not permit analytics providers to use private Document content for targeted advertising.

4.7 Payment and Billing Information

Where paid Services are used, we may collect:

  • Billing name and address;
  • Tax and invoicing information;
  • Subscription and payment status;
  • Transaction identifiers;
  • Invoice and refund records; and
  • Limited payment information received from a payment provider.

Complete card, bank-account, or UPI credentials may be processed directly by an authorised payment provider and may not be stored by Signeez. Such providers may process information under their own privacy policies and legal obligations.

4.8 Technical and Security Information

We may automatically collect:

  • IP address;
  • Browser type and version;
  • Device type and identifiers;
  • Operating system;
  • Language and time-zone settings;
  • Login and session history;
  • Security events;
  • Failed authentication attempts;
  • Application errors;
  • Network and server logs;
  • Malware or abuse indicators; and
  • Cookie and similar-technology information.

4.9 Support and Communication Information

When you communicate with us, we may collect:

  • Contact details;
  • Support enquiries;
  • Complaints and grievance correspondence;
  • Feedback and survey responses;
  • Screenshots or Documents supplied for troubleshooting;
  • Call or meeting records, where applicable; and
  • Other information included in your communication.

Users should avoid sending confidential or sensitive information through a support request unless necessary to investigate the issue.

4.10 Information Received from Other Users

A sender or organisation may provide your name, email address, telephone number, designation, or other details when inviting you to review or sign a Document.

Receiving an invitation does not necessarily create a registered Signeez account. We may use this information to:

  • Deliver the invitation;
  • Authenticate access;
  • Facilitate the requested transaction;
  • Send essential reminders;
  • Provide transaction status;
  • Prevent unauthorised access; and
  • Maintain the transaction record.

5. How We Collect Information

We may collect personal data:

  • Directly from you;
  • From the organisation that provides or administers your account;
  • From a person who invites you to participate in a Document workflow;
  • Automatically when you access or use the Services;
  • From Verasys and other electronic-signature or identity-verification providers;
  • From payment, communication, analytics, hosting, and security providers;
  • From integrations enabled by a Customer;
  • From authorised representatives acting on your behalf; and
  • From publicly available sources where legally permitted.

6. Purposes of Processing

We may process personal data to:

  • Register, authenticate, maintain, and administer accounts;
  • Provide Document creation, storage, transmission, and workflow services;
  • Enable Document review, approval, rejection, and signing;
  • Facilitate Aadhaar-enabled eSign through Verasys;
  • Generate electronic signatures, certificates, and audit trails;
  • Authenticate Users and verify signing actions;
  • Deliver invitations, reminders, notifications, and completed Documents;
  • Generate Document templates using AI;
  • Provide, monitor, secure, and improve AI features;
  • Process subscriptions, payments, invoices, and refunds;
  • Provide customer support;
  • Diagnose and resolve technical problems;
  • Prevent fraud, impersonation, abuse, malware, and unauthorised access;
  • Maintain backups, disaster recovery, and business continuity;
  • Improve accessibility, performance, reliability, and user experience;
  • Analyse aggregate, pseudonymised, or de-identified usage patterns;
  • Conduct internal security, compliance, and risk assessments;
  • Enforce our agreements, policies, and acceptable-use requirements;
  • Establish, exercise, or defend legal rights and claims;
  • Comply with legal, tax, accounting, regulatory, and law-enforcement obligations;
  • Send product updates and promotional communications where permitted; and
  • Fulfil another purpose disclosed at the time of collection.

We do not use private Document content for behavioural advertising.

7. Grounds for Processing

Depending on the circumstances and applicable law, we may process personal data:

  • With your free, specific, informed, unconditional, and unambiguous consent;
  • To provide Services requested by you or an organisation;
  • To perform a contract or take requested steps connected with a contract;
  • Where you voluntarily provide information for a specified purpose and have not indicated that you object;
  • To comply with a legal obligation;
  • To respond to a legally valid government, regulatory, judicial, or law-enforcement request;
  • To prevent, detect, investigate, or prosecute fraud, cyber incidents, or unlawful activity;
  • To protect the rights, safety, and property of Users, Zerozilla, and others;
  • To establish, exercise, or defend legal claims; or
  • Under another ground permitted by applicable law.

Where processing is based on consent, you may withdraw consent using available account controls or by contacting us. Withdrawal does not invalidate processing lawfully undertaken before withdrawal.

Withdrawal may prevent us from providing a feature that requires the relevant information.

8. Customer-Controlled Information

When a Customer uses Signeez to collect, upload, store, send, or sign Documents, the Customer is generally responsible for:

  • Determining whether it has a lawful basis for processing;
  • Providing legally required notices;
  • Obtaining required permissions and consents;
  • Ensuring Document content is accurate and lawful;
  • Selecting recipients;
  • Configuring access permissions;
  • Establishing appropriate retention periods;
  • Responding to privacy requests concerning Customer-controlled information; and
  • Complying with applicable privacy, employment, consumer, contract, electronic-signature, and records-management laws.

Zerozilla does not independently verify whether every Customer has obtained all permissions required for every Document uploaded to Signeez.

When we receive a request involving Customer-controlled information, we may refer the request to the relevant Customer or assist the Customer in responding.

9. Disclosure of Personal Data

We may disclose personal data to the following recipients where necessary and legally permitted.

9.1 Document Participants

Documents and associated information may be disclosed to senders, signers, reviewers, approvers, witnesses, authorised representatives, recipients, and other persons included in the relevant workflow.

9.2 Organisation Administrators

If an organisation provides or controls your Signeez account, its authorised administrators may be able to:

  • Manage your account;
  • View account and usage information;
  • Access Documents according to organisational permissions;
  • Configure security and retention settings;
  • Export organisational information;
  • Suspend or terminate account access; and
  • Delete or retain organisational data.

9.3 Verasys and Aadhaar/eSign Ecosystem Participants

Information necessary for Aadhaar authentication and eSign may be transmitted to VERASYS TECHNOLOGIES PVT LTD and other legally authorised participants involved in completing the transaction.

Verasys and other authorised participants may independently process certain information under applicable law, their regulatory obligations, and their own privacy terms.

Zerozilla does not control UIDAI’s authentication results, the independent systems of Verasys, or the availability of external Aadhaar and eSign infrastructure.

9.4 AI Technology Providers

Information intentionally submitted to an AI-powered feature may be disclosed to approved AI technology and infrastructure providers where necessary to generate the requested output, operate the feature, prevent abuse, or maintain security.

We seek to contractually restrict such providers from using Signeez Customer content for unrelated purposes.

9.5 Analytics Providers

Technical, cookie, device, and usage information may be disclosed to analytics providers to measure performance and understand product usage.

Where reasonably practicable, analytics information will be aggregated, pseudonymised, truncated, or otherwise limited.

9.6 Other Service Providers

We may use service providers for:

  • Cloud hosting and storage;
  • Content delivery;
  • Email, SMS, and notification delivery;
  • Payment processing;
  • Identity and authentication;
  • Customer support;
  • Cybersecurity;
  • Monitoring and error reporting;
  • Backup and disaster recovery;
  • Legal, audit, accounting, and compliance services; and
  • Other technical or operational functions.

These providers may process information only for authorised purposes and are expected to apply appropriate contractual, organisational, and technical safeguards.

9.7 Customer-Enabled Integrations

When a Customer enables a third-party integration, information may be transferred to or received from that integration.

The Customer is responsible for evaluating and authorising the integration. The third party’s privacy policy and contractual terms may apply to its subsequent processing.

9.8 Legal and Regulatory Disclosures

We may preserve or disclose information where we reasonably believe it is necessary to:

  • Comply with applicable law;
  • Respond to a legally valid order, notice, summons, warrant, or request;
  • Cooperate with a court, tribunal, regulator, government agency, or law-enforcement authority;
  • Prevent, investigate, or respond to fraud, security threats, cyber incidents, or unlawful conduct;
  • Protect the rights, property, and safety of Zerozilla, Users, or others; or
  • Establish, enforce, or defend legal claims.

Where legally permitted and reasonably practicable, we may notify the affected Customer before disclosure.

9.9 Corporate Transactions

Information may be disclosed in connection with an actual or proposed merger, acquisition, financing, corporate restructuring, sale of shares or assets, insolvency proceeding, or transfer of the Signeez business.

Any recipient will be expected to process the information in accordance with applicable law and the commitments that apply to it.

9.10 With Your Direction or Consent

We may disclose information to another person when you direct us to do so or provide legally valid consent.

Zerozilla does not sell personal data or private Document content for monetary consideration.

10. Data Location and International Transfers

Signeez may process or store information in India and in other jurisdictions where Zerozilla or its service providers maintain infrastructure or operations.

Where information is transferred outside India, we will take measures required by applicable law. These may include:

  • Contractual data-protection obligations;
  • Access restrictions;
  • Encryption;
  • Security assessments;
  • Vendor due diligence; and
  • Evaluation of applicable transfer restrictions.

If a Customer has purchased a contractual data-residency option, the applicable service agreement will govern the committed hosting location.

Data residency does not necessarily prevent limited remote access, technical support, security monitoring, disaster recovery, or legally required processing from another jurisdiction unless expressly agreed in writing.

11. Security

We maintain reasonable administrative, organisational, physical, and technical safeguards designed to protect personal data against unauthorised access, misuse, loss, alteration, disclosure, or destruction.

Depending on the Services and information involved, these safeguards may include:

  • Encryption in transit;
  • Encryption of stored information where appropriate;
  • Role-based access controls;
  • Authentication and session controls;
  • Logging and security monitoring;
  • Network and infrastructure protections;
  • Backup and recovery measures;
  • Vulnerability and patch-management processes;
  • Employee confidentiality obligations;
  • Service-provider security requirements; and
  • Incident-response procedures.

Aadhaar numbers, where lawfully received or retained, will be handled in accordance with applicable masking, encryption, access-control, confidentiality, and retention requirements.

No method of internet transmission, electronic storage, or security protection is completely secure. Zerozilla cannot guarantee absolute security, uninterrupted availability, or that every attempted security incident will be prevented.

Users are responsible for protecting their passwords, devices, authentication credentials, OTPs, Document links, and account access.

Suspected unauthorised access should be reported immediately to support@signeez.com or praveen.g@zerozilla.com.

12. Personal Data Breaches

If we become aware of a personal-data breach, we will take reasonable steps to:

  • Investigate the incident;
  • Contain and mitigate the breach;
  • Preserve relevant evidence;
  • Address identified vulnerabilities;
  • Assess the likely impact; and
  • Prevent recurrence where reasonably possible.

We will notify affected Customers, individuals, regulators, or authorities where and within the period required by applicable law.

A notification may be delayed or limited where permitted or required by a competent authority or where immediate disclosure could interfere with a lawful investigation.

Where Zerozilla processes information on behalf of a Customer, we may notify the Customer so that it can fulfil its own legal obligations.

13. Data Retention and Deletion

We retain personal data only for as long as reasonably necessary to:

  • Provide the Services;
  • Fulfil the purpose for which the information was collected;
  • Maintain Document integrity and audit trails;
  • Complete or verify an electronic-signature transaction;
  • Comply with contractual commitments;
  • Meet legal, tax, accounting, regulatory, and security obligations;
  • Prevent fraud or abuse;
  • Resolve disputes; and
  • Establish, exercise, or defend legal claims.

Retention periods may vary according to:

  • The type of information;
  • Customer instructions;
  • Account configuration;
  • Subscription status;
  • Document status;
  • Applicable law;
  • Contractual requirements; and
  • The nature of the transaction.

Deleting an account or Document does not necessarily cause immediate deletion of every associated record. Information may remain:

  • In another Document Participant’s account;
  • Under the control of a Customer;
  • In an electronic-signature certificate or audit trail;
  • In restricted backups until overwritten;
  • Under a legal or regulatory hold; or
  • Where retention is required or permitted by law.

Where deletion is appropriate, information will be securely deleted, anonymised, aggregated, or placed beyond ordinary operational use.

Aadhaar authentication inputs, OTPs, Virtual IDs, and core biometric information are not intended to be retained by Signeez. Limited Aadhaar eSign transaction and audit information may be retained where necessary and legally permitted.

14. Cookies and Similar Technologies

We may use cookies, local storage, pixels, software development kits, and similar technologies to:

  • Maintain login sessions;
  • Remember preferences;
  • Authenticate Users;
  • Provide security features;
  • Detect fraud and misuse;
  • Measure performance;
  • Diagnose errors;
  • Conduct analytics; and
  • Understand how the Services are used.

Essential cookies may be required for Signeez to operate.

Where required by law, optional analytics or marketing cookies will be used only after obtaining appropriate consent.

You may control cookies through available cookie controls or your browser settings. Blocking certain cookies may prevent parts of the Services from operating correctly.

15. Communications and Marketing

We may send transactional communications necessary to operate Signeez, including:

  • Document invitations;
  • Signing reminders;
  • Authentication messages;
  • Security alerts;
  • Billing notices;
  • Support messages;
  • Service announcements; and
  • Important policy or account updates.

These communications are not promotional and may continue while you use the relevant Service.

We may send marketing communications where legally permitted. You may unsubscribe using the link included in the message or by contacting us.

Unsubscribing from marketing will not prevent essential transactional or security communications.

Document senders may configure workflow reminders and notifications. Concerns about sender-configured communications may also need to be directed to the sender.

16. Your Rights and Choices

Subject to applicable law, identity verification, and permitted exceptions, you may have the right to:

  • Obtain information about your personal data being processed;
  • Request access to your personal data;
  • Request correction of inaccurate or misleading information;
  • Request completion of incomplete information;
  • Request updating of outdated information;
  • Request erasure of eligible personal data;
  • Withdraw previously provided consent;
  • Manage communication and cookie preferences;
  • Raise a grievance regarding our processing;
  • Nominate another individual to exercise specified rights in the event of death or incapacity, where applicable; and
  • Submit a complaint to the competent data-protection authority.

Privacy and data-rights requests may be submitted to praveen.g@zerozilla.com.

We may request information necessary to verify your identity, request, and authority.

If a request concerns Customer-controlled information, we may refer the request to the relevant Customer or require the Customer’s instructions before acting.

A request may be refused, restricted, or delayed where permitted by law, including where retention is necessary for:

  • Legal or regulatory compliance;
  • Fraud prevention;
  • Security;
  • Transaction integrity;
  • Enforcement of contractual rights;
  • Protection of another person’s rights; or
  • Establishment, exercise, or defence of legal claims.

Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.

Where applicable law requires exhaustion of our grievance process, you should first submit your complaint to the Grievance Officer before approaching the Data Protection Board of India.

17. Responsibilities of Users and Customers

Users and Customers must not upload, disclose, or process another person’s personal data unless they have sufficient authority and a lawful basis.

Users and Customers are responsible for:

  • Providing accurate and current information;
  • Protecting account credentials;
  • Restricting Document access to intended recipients;
  • Avoiding unnecessary collection of sensitive information;
  • Providing required privacy notices;
  • Obtaining required permissions and consents;
  • Verifying the identity and authority of Document Participants where appropriate;
  • Configuring suitable access and retention controls;
  • Reviewing AI-generated templates before use;
  • Ensuring AI prompts do not contain unauthorised sensitive information; and
  • Complying with applicable privacy, employment, consumer, electronic-signature, Aadhaar, contract, and records-management laws.

Signeez must not be used to conduct unlawful surveillance, discrimination, harassment, fraud, impersonation, identity theft, or any other unlawful activity.

18. Children’s Privacy

Signeez is intended primarily for business and professional use and is not directed to individuals below 18 years of age.

We do not knowingly permit a child to independently create a Signeez account.

Customers must not use Signeez to process a child’s personal data or conduct Aadhaar-based verification of a child unless:

  • The processing is legally permitted;
  • Required consent has been obtained from a parent or lawful guardian;
  • The processing is necessary for a lawful purpose; and
  • Applicable notice, verification, and safety requirements have been satisfied.

If we learn that a child’s personal data has been processed improperly, we may suspend the relevant workflow or account and take reasonable steps to delete or restrict the information, subject to legal, regulatory, contractual, and evidentiary retention requirements.

19. Third-Party Services

The Services may contain links to or integrations with third-party websites, applications, identity providers, AI providers, payment providers, analytics services, and other platforms.

Zerozilla does not control the independent privacy, security, availability, or data-processing practices of those third parties.

You should review the applicable third party’s privacy policy and terms before providing information or enabling an integration.

Use of Aadhaar eSign through Verasys may additionally be subject to Verasys’s terms, privacy policy, regulatory requirements, and consent notices.

20. Business and Organisation Accounts

If you use an email address supplied by an employer or another organisation, that organisation may associate your account with its Signeez business account.

The organisation may obtain administrative control over the account and associated information in accordance with its agreement with Zerozilla.

Where the relevant workflow permits it, you should use a personal email address for transactions that you do not want managed by an organisation.

21. Automated Processing

Signeez may use automated systems to:

  • Detect suspected fraud or abuse;
  • Identify unusual login activity;
  • Filter malicious content;
  • Generate Document templates;
  • Recommend fields or formatting; and
  • Support technical monitoring.

Unless expressly disclosed, Signeez does not make legally significant decisions about individuals solely through automated processing.

AI-generated suggestions are assistive and should be independently reviewed by the User.

22. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in:

  • Applicable law;
  • Regulatory guidance;
  • Technology;
  • Service providers;
  • Security practices;
  • Business operations; or
  • Signeez features.

The revised policy will state its effective date and will be published through an appropriate Signeez channel.

Where a change materially affects how we process personal data, we will provide additional notice or obtain consent where required by law.

Unless otherwise required by law, changes will apply prospectively from their effective date.

23. Applicable Data-Protection Requirements

This Privacy Policy is intended to operate consistently with applicable Indian laws and regulations, including applicable provisions of:

  • The Information Technology Act, 2000;
  • The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
  • The Digital Personal Data Protection Act, 2023;
  • The Digital Personal Data Protection Rules, 2025;
  • The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016;
  • Applicable Aadhaar authentication, offline-verification, information-sharing, and security regulations;
  • Applicable electronic-signature requirements under the Information Technology Act, 2000; and
  • Other applicable statutory, regulatory, and governmental requirements.

If any provision of this Privacy Policy conflicts with a mandatory legal requirement, that legal requirement will prevail to the extent of the conflict.

Nothing in this Privacy Policy limits any non-waivable right available to an individual under applicable law.

24. Contact and Grievance Redressal

For privacy questions, requests, grievances, complaints, or suspected misuse of personal data, contact:

Praveen Gowda
Grievance Officer
Zerozilla Infotech Pvt Ltd
Operator of Signeez

Grievance Email: praveen.g@zerozilla.com

Support Email: support@signeez.com

Address:
3rd Floor, #35, 35-600, 11th Main Road, 5th Block,
Jayanagar, Bengaluru, Karnataka – 560041, India

The Grievance Officer will acknowledge, investigate, and respond to complaints within the period prescribed by applicable law.

If your grievance remains unresolved after you have exhausted the available grievance-redressal process, you may approach the Data Protection Board of India or another competent authority through the officially prescribed mechanism, where applicable.