Skip to main content

Privacy Policy

Effective Date: January 26, 2026

Last Updated: August 26, 2026

🔒 Your Privacy Matters

Klyverity is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our electronic signature platform.

1. Introduction

Klyverity ("we," "us," or "our") provides a cloud-based electronic signature platform designed for FDA 21 CFR Part 11 compliance. This Privacy Policy describes our practices regarding the collection, use, and disclosure of information through our website at klyverity.com and our software platform (collectively, the "Service").

By using the Service, you agree to the processing of your information as described in this Privacy Policy. We process your data under various legal bases depending on the purpose (see Section 4.6). Where consent is required as a legal basis (such as for marketing communications), we will obtain your explicit consent separately. If you do not agree with this Privacy Policy, please do not use the Service.

2. Information We Collect

2.1 Information You Provide Directly

We collect information that you voluntarily provide to us when you:

  • Create an Account: Full name, email address, organization name, password
  • Use the Service: Documents you upload, signature data, workflow configurations, digital log entries
  • Contact Us: Name, email, phone number, message content, support inquiries
  • Subscribe: Billing information (processed by Stripe - see Section 2.5)
  • Team Management: Information about team members you invite

2.2 Information Collected Automatically

When you use the Service, we automatically collect:

  • Device Information: IP address, browser type, operating system, device identifiers
  • Usage Data: Pages visited, features used, time spent, referring URLs
  • Audit Trail Data: Timestamp, IP address, user agent, action performed (required for FDA 21 CFR Part 11 compliance)
  • Cookies and Similar Technologies: See Section 3 below

2.3 Signature Event Metadata

When electronic signatures are executed, we collect and store (as required by FDA 21 CFR Part 11):

  • Signer's full name
  • Date and time of signature
  • Meaning/purpose of signature
  • IP address
  • Device and browser information
  • Two-factor authentication verification data
  • Signature method (typed, drawn, or uploaded)

2.4 Information from Third Parties

We may receive information from:

  • Payment Processor (Stripe): Payment status, subscription tier, transaction history
  • Analytics Providers: Aggregated usage statistics and performance metrics

2.5 Payment Information

We use Stripe as our payment processor. We do not store your full credit card numbers. Stripe collects and processes:

  • Credit card information
  • Billing address
  • Payment transaction details

Stripe's privacy policy is available at stripe.com/privacy.

3. Cookies and Tracking Technologies

3.1 Types of Cookies We Use

We use cookies and similar technologies for two purposes:

  • Essential Cookies: Four cookies required for authentication and security. Our Cookie Policy names each one and gives its exact lifetime and scope
  • Analytics: Measure traffic and page load timings using Vercel Analytics and Vercel Speed Insights, which set no cookies and load only if you accept in our cookie banner

We set no cookies that store interface preferences, and none for advertising or profiling.

3.2 Managing Cookies

You can control cookies through your browser settings. However, disabling certain cookies may limit Service functionality. Essential cookies cannot be disabled as they are necessary for the Service to operate.

4. How We Use Your Information

We use collected information for the following purposes:

4.1 To Provide and Maintain the Service

  • Create and manage your account
  • Process electronic signatures
  • Store and manage documents
  • Generate audit trails and compliance reports
  • Provide customer support

4.2 To Process Payments

  • Process subscription payments
  • Send billing invoices
  • Manage subscription tiers and upgrades

4.3 To Communicate With You

  • Send service-related notifications (signature requests, document updates)
  • Respond to support inquiries
  • Send account and security notifications
  • Provide product updates and feature announcements (with your consent)

4.4 For Compliance and Security

  • Comply with FDA 21 CFR Part 11 and other regulatory requirements
  • Maintain audit trails for regulatory audits
  • Detect and prevent fraud, abuse, and security incidents
  • Enforce our Terms of Service

4.5 To Improve the Service

  • Analyze usage patterns and trends
  • Develop new features and functionality
  • Conduct research and analytics (using aggregated, de-identified data)

4.6 Legal Basis for Processing (GDPR)

For users in the European Economic Area, we process personal data under the following legal bases:

  • Contractual Necessity (Art. 6(1)(b)): Providing and maintaining the Service, processing electronic signatures, managing your account, processing payments, and sending service-related notifications
  • Legal Obligation (Art. 6(1)(c)): Maintaining audit trails and compliance records as required by FDA 21 CFR Part 11 and other applicable regulations
  • Legitimate Interest (Art. 6(1)(f)): Detecting and preventing fraud and security incidents, analyzing aggregated usage data to improve the Service, and enforcing our Terms of Service
  • Consent (Art. 6(1)(a)): Sending marketing communications and product announcements. You may withdraw consent at any time by unsubscribing or contacting us

5. How We Share Your Information

We do not sell, rent, or trade your personal information. Below we describe the circumstances in which we may share it, and one case in which your browser contacts a third party directly without us sharing anything.

5.1 With Service Providers

We share information with trusted third-party service providers who assist us in operating the Service:

  • Hosting: Amazon Web Services (AWS) - data storage and infrastructure
  • Payment Processing: Stripe - subscription billing and payments
  • Email Delivery: Resend - transactional emails such as signature requests, account notifications, and password resets
  • Frontend Hosting: Vercel - website and application hosting
  • API Delivery: Cloudflare - DNS and reverse proxy for our API domain (api.klyverity.com). API requests pass through Cloudflare in transit. The website itself is served by Vercel and does not route through Cloudflare
  • Analytics: Vercel Analytics and Vercel Speed Insights - page view counts and page load timings. These load only if you select Accept in our cookie banner; if you decline, or leave without choosing, they are never loaded
  • Error Monitoring: Sentry - application error reports, so we can find and fix faults. We configure Sentry not to attach personal data to error reports (its sendDefaultPii option is off), but a report can still include the page you were on and your browser and device details

These providers are contractually obligated to protect your information and use it only for the purposes we specify.

5.2 Public Content Delivery Networks

Our in-browser document viewer uses the open-source PDF.js library. Two public content delivery networks, unpkg.com and cdn.jsdelivr.net, serve the static PDF.js files it needs: a worker script, character maps, and standard fonts. Your browser loads these files directly from those CDNs when you view or sign a document, including when you are an external signer who has no account with us.

They are described here rather than in Section 5.1 because they are not our service providers. We have no contract with either one, and we send them none of your information. They never receive the document or anything in it: document content is served only from our own systems. What they do receive is the metadata that any web request carries, meaning your IP address, your browser and device details, the time of the request, and the site the request came from. Our referrer policy sends them only our domain, not the address of the page you were on, so they do not learn which document you were viewing.

5.3 With Your Consent

We may share information when you explicitly consent, such as:

  • When you invite team members to your organization
  • When you send signature requests to external signers
  • When you share documents or workflows

5.4 For Legal Reasons

We may disclose information if required by law or in good faith belief that such action is necessary to:

  • Comply with legal obligations (subpoenas, court orders)
  • Respond to regulatory requests (FDA audits, inspections)
  • Protect our rights, property, or safety
  • Prevent fraud or abuse
  • Investigate potential violations of our Terms of Service

5.5 Business Transfers

If Klyverity is involved in a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website before your information is transferred.

6. Data Security

We implement industry-standard security measures to protect your information:

6.1 Technical Safeguards

  • Encryption at Rest: 256-bit AES encryption for stored data
  • Encryption in Transit: TLS 1.2 or above for all data in transit. The CDN edge your browser connects to negotiates TLS 1.3 where your browser supports it, and refuses the legacy TLS 1.0 and 1.1; our load balancer accepts only TLS 1.2 and above, and only from the CDN
  • Access Controls: Role-based access control (RBAC)
  • Authentication: Secure password hashing (bcrypt), multi-factor authentication (MFA)
  • Audit Logging: Comprehensive logging of all system access and actions

6.2 Organizational Safeguards

  • Regular security assessments
  • Security awareness practices for team members
  • Incident response procedures
  • Data backup and disaster recovery plans

6.3 No Absolute Security

While we implement robust security measures, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but will notify you promptly of any data breach affecting your information, as required by law.

7. Data Retention

7.1 Retention Periods

  • Active Paid Subscriptions: Data retained for the duration of your active subscription, plus any applicable regulatory retention period (e.g., 25 years for FDA 21 CFR Part 11 regulated records)
  • Trial Accounts: Data retained in read-only mode after trial expiration
  • Canceled Accounts: Data is retained after cancellation. No automatic process deletes it on a schedule. Deleting the data of a canceled account is a manual step we take on request, subject to legal and regulatory retention requirements
  • Audit Trails: Retained for the life of the record (typically 25 years for FDA compliance)
  • Marketing Communications: Retained until you unsubscribe

7.2 Automatic Retention Enforcement

Some retention is enforced by scheduled jobs that run without anyone asking:

  • IP addresses erased at 90 days: A job runs every day at 04:00 UTC and sets to null the raw IP addresses older than 90 days that we hold in session records, the audit trail, signer records, subscription events and blocked-access records. One address is deliberately exempt: the IP captured at the moment a signature is executed is part of the FDA 21 CFR Part 11 signature manifestation and is retained for the life of the signature record, so that signature evidence stays complete. That address is printed on the Certificate of Completion attached to the finished document, which is the standard way an electronic signature is evidenced, so every party to the document can see it. Security event records older than 90 days, which hold hashed IP addresses, are deleted outright on the same schedule. We do this for data minimization under GDPR Article 5(1)(e). The audit trail is the interesting case: it is protected by a database trigger that normally rejects any modification at all, and that trigger permits this one field to be set to null while raising an error if any other column in the row has changed by so much as a byte. The IP address goes and the FDA 21 CFR Part 11 record stays intact.
  • Session records deleted at 90 days: A job runs every six hours, marks expired sessions inactive, and deletes inactive session records older than 90 days.
  • Log archival: Each day at 05:00 UTC the previous day's application and background-job logs are exported to a dedicated storage bucket. Those archives move to colder storage after 90 days and again after a year, and are not set to expire, because we keep them for FDA 21 CFR Part 11 retention purposes. Logs can contain IP addresses and account identifiers recorded before the 90 day erasure above ran.

These jobs apply only to the data described. None of them deletes account, document or audit-trail data on a schedule; see the canceled-account entry in 7.1.

7.3 Legal Obligations

We may retain certain information longer if required by law, regulation, or to resolve disputes and enforce our agreements.

8. Your Privacy Rights

8.1 General Rights

You have the following rights regarding your personal information:

  • Access: Request a copy of your personal information
  • Correction: Update or correct inaccurate information
  • Deletion: Request deletion of your information (subject to legal retention requirements)
  • Export: Download your data in portable formats (PDF, CSV, JSON)
  • Objection: Object to processing of your information for marketing purposes

8.2 GDPR Rights (EU Users)

If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):

  • Data Portability: Receive your data in a structured, machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Withdraw Consent: Withdraw consent for processing at any time
  • Lodge a Complaint: File a complaint with your local data protection authority

8.3 CCPA Rights (California Users)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):

  • Know: What personal information we collect, use, and share
  • Delete: Request deletion of personal information (subject to exceptions)
  • Opt-Out: Opt-out of the sale of personal information (Note: We do not sell personal information)
  • Non-Discrimination: Exercise your rights without discriminatory treatment

8.4 How to Exercise Your Rights

To exercise any of these rights, contact us at privacy@klyverity.com or through your account settings. We will respond within 30 days (or as required by applicable law).

9. International Data Transfers

Your information may be transferred to and processed in the United States or other countries where our service providers operate. These countries may have different data protection laws than your jurisdiction.

For EEA users, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other lawful transfer mechanisms under GDPR

10. Children's Privacy

The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately, and we will delete such information.

11. Third-Party Links

The Service may contain links to third-party websites or services not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any personal information.

12. Do Not Track and Global Privacy Control

Some browsers include "Do Not Track" (DNT) features. Our Service does not currently respond to DNT signals. However, you can control cookies and tracking through your browser settings.

Some browsers send a Global Privacy Control (GPC) signal, which is designed to communicate an opt out of the sale or sharing of personal information under laws such as the California Consumer Privacy Act (CCPA/CPRA). Our Service does not read that signal. There is nothing for it to change: we do not sell personal information and we do not share it for cross-context behavioral advertising, so the outcome a GPC signal asks for is already how we treat every visitor, whether or not the signal is sent.

13. Automated Decision-Making

We do not engage in automated profiling or algorithmic decision-making that produces legal or similarly significant effects on you. We do use rules-based security and operational measures, including:

  • Account Security: Automatic account lockout after repeated failed login attempts to protect against unauthorized access
  • Rate Limiting: Automatic throttling of excessive requests to maintain service stability and security
  • Subscription Lifecycle: Automatic enforcement of trial expiration and grace periods, and the scheduled retention jobs described in Section 7.2 (IP address erasure, session record deletion and log archival). Account, document and audit-trail data is not deleted on an automatic schedule

These measures are based on fixed rules and thresholds, not on profiling or automated assessment of personal characteristics. If you believe you have been adversely affected by an automated decision, please contact us at privacy@klyverity.com.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated Privacy Policy on this page
  • Updating the "Last Updated" date at the top
  • Sending an email notification for significant changes
  • Displaying a prominent notice in the Service

Continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Klyverity - Privacy Team

Email: privacy@klyverity.com

Website: klyverity.com

Mail:
Evostera LLC dba Klyverity
1519 E Chapman Ave. #278
Fullerton, CA 92831

For GDPR-related inquiries, please include "GDPR Request" in the subject line.

For CCPA-related inquiries, please include "CCPA Request" in the subject line.

By using Klyverity, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.

Last Updated: August 26, 2026