Privacy Policy | DottedSign
ds-logo

Privacy Policy

1. Scope

(1) When you (“user” or “you”) register to become a member of Kdan Mobile Software Ltd. (“Kdan” or “we”) and/or use relevant services or functions in DottedSign (collectively, “DottedSign Services”), you agree that your Personal Data (as defined below) will be collected, processed, and used in accordance with this privacy policy (“Privacy Policy”).

(2) Personal Data means any data that may be used to directly or indirectly identify a person, such as the name, user name, password, email address that you provide to us (collectively, “Personal Data”).

2. Data Collected

(1) Contents provided by users:

When you register to become a Kdan member, we will ask you to provide certain Personal Data for the registration, including but not limited to your email address, name, and password.

When you use a third party account to register as a Kdan member, we will store the user information from the third party account, including but not limited to your names, email address, language preference, and profile photos in our member center. We will only use this account information in accordance with this Privacy Policy.

When you use the DottedSign Services, we will collect the content that you create, upload or receive from others, including but not limited to the files you upload to Kdan Cloud, notes, documents and signing tasks that you create through use of Kdan products.

(2) Information collected through applications, browsers, and devices when using the DottedSign Services:

When you use the DottedSign Services through applications, browsers, and devices, the information we collect will include but is not limited to the IP address, identity information related to devices, the categories of browsers and devices used, operating system, internet service provider, internet protocol address, and events on devices, including but not limited to crash records, system activities, and other records generated automatically by the servers. Our websites may also use cookies to enhance users’ experience. More information can be found in our Cookies Policy (https://dottedsign.com/cookie_policy).

You may manage the categories of information that we collect, to a certain degree, through methods including changing the settings of browsers and devices.

(3) There is certain information that it is necessary for you to provide us to facilitate the contract for the DottedSign Services, which includes but is not limited to personal data that is used to register your account. If you fail to provide certain information when requested, we may not be able to perform our obligations under the contract.

3. Purpose and Use of Data

(1) Provision of Services

We will use the data collected to provide Services, including but not limited to: recording detailed information related to the electronic documents and work process for electronic signatures when you use DottedSign to perform signing tasks, as well as contacting you through your contact information when you submit comments or questions to us. We process this information to provide the services in the contract between us.

(2) Personalized services

We process the data collected to learn how our users use our Services and resources, and to provide personalized services. We process this data for our legitimate interests of improving our Services, and your legitimate interest to receive a tailored service.

(3) Send newsletter or marketing information to subscribers

If you subscribe to our newsletter, we will send newsletters or marketing information to you via email. It is our legitimate interest to market similar goods and services that we think would be of interest to Users. Users may cancel the subscription to newsletter at any time, and you may find details regarding how to cancel the subscription in the bottom of our emails.

(4) Manage special activities on our websites

If you participate in activities such as raffles, competitions, surveys, and special offers on our websites, we may use the information provided by you to manage or conduct such activities. We process this information for our legitimate interest to run these activities, and the Users' legitimate interest to access and participate in the activities.

(5) Improve our Services

We may process information gathered from research and/or analysis. This is our legitimate interest to improve our service experience, and to enhance the safety and stability of our Services. It is also the Users' legitimate interest to receive a secure and improving Service.

4. User Rights

(1) Through the “Contact us” page on our websites (https://www.kdan.com/contact), you may make an inquiry of, review, request a copy of, supplement or correct, demand the cessation of the collection, processing or use of, restrict the use of, and request the deletion of your Personal Data. Where you have the right to data portability under Article 20 of the EU and UK GDPR, you may request that we send the information you have provided to us in a format that can be read by a computer, to another organization designated by you.

(2) If you request Kdan to stop, or restrict, collecting, processing, using your Personal Data, or to delete your Personal Data, we may be unable to continue to provide the Services, or unable to provide a complete experience of the Services, pursuant to your request.

5. Safety Measures

(1) We will adopt appropriate protection, storage, and process mechanisms and safety measures to prevent your Personal Data from being stolen, altered, damaged, lost, or leaked.

(2) Our websites follow the PCI vulnerability standards to provide a safe environment to our users through our best efforts.

(3) To find out more about the safety measures we adopt, kindly refer to our Security Policy (https://dottedsign.com/security).

6. Retention Period

(1) You may alter or delete most of your Personal Data stored in the Kdan account, including but not limited to: the files you upload to Kdan Cloud, the notes and documents you established through Kdan products.

(2) Kdan Account Information and the DottedSign Services-Related Information:

a. Kdan account information includes your email address, name, and password. This information will be retained until you delete your Kdan account or until your Kdan account expires due to any reason.

b. If you use the same Kdan account to connect to multiple Kdan products, then we will retain your Kdan account information during the term that you continue to use your Kdan account to access or subscribe to any of Kdan products.

c. If your Kdan account belongs to any team subscription plan, Kdan will continue to retain your Kdan account information until your Kdan account is removed from such team subscription plan (please note that the team administrator’s permission is required for you to be removed from a team subscription plan).

d. If you wish to delete or stop using your Kdan account, you may contact our customer service through https://www.kdan.com/contact. Since you are using the DottedSign Services under the same Kdan account, once you delete the Kdan account, you will no longer be able to use the DottedSign Services with that account, and any data in that original account cannot be restored.

e. Regarding the data you have obtained or uploaded through the DottedSign Services, you understand that before deleting or deactivating your Kdan account, you should save or back up such data (including but not limited to the signed tasks obtained from DottedSign, etc.) if you deem necessary. After completing the backup and obtaining consent from the relevant signer (if applicable), you should move the data to the Trash to ensure it will be deleted along with your Kdan account. You also understand that the removal of such data (including personal data) should be carried out only after obtaining the consent of the relevant parties (if applicable). Furthermore, you understand that in order to protect the interests of the relevant parties or under the circumstances mentioned in Article (3), we may continue to retain such data.

f. Kdan is not responsible for retaining any data from your original account (including but not limited to the signed tasks obtained from DottedSign, etc.). If you need to retain any data from your original Kdan account, you should download and save it before deleting or deactivating your account.

g. If you subscribe to the DottedSign Services and receive cloud storage space as part of your subscription plan, and later stop your subscription, you understand that any files uploaded to the DottedSign Services will be deleted in accordance with Personal Data Protection Law and other relevant regulations after 60 days from the expiration of your subscription. For information regarding the subscription expiration policy, please refer to our Terms of Service under the Section which is titled as the 'Subscription Expiration'.

(3) To comply with laws and course of business (including but not limited to regulations and accounting procedures), or to provide services related to Kdan products, we will retain your Personal Data to the extent necessary.

7. Information Sharing and Disclosure

7.1 Unless one of the following conditions is met, we will not disclose or share your personal data with any third party:

(1) We have obtained your prior consent

Within the scope of your consent, we may share your personal data with third parties.

(2) Cooperation with Judicial or Government Authorities for Investigations and Notification Mechanisms

When a judicial authority or a legally authorized investigative agency requests access to, inquires about, or demands the provision of your personal data through formal documentation, or when a government agency requests access to or inquiries about your personal data pursuant to legal provisions or its official duties, we will verify the legality of such requests first.
Once we confirm the legitimacy of the request, we may provide your personal data to the requesting authority in order to comply with legal requirements and cooperate with the lawful requests of judicial authorities, legally authorized investigative agencies, or government agencies.
If the law or a court order does not prohibit or restrict us from disclosing such requests, we will, after evaluation, notify you at an appropriate time and in the most suitable manner, providing an overview of the request, the scope of the requested information, and the personal data that may be disclosed.
If the law or a court order prohibits, restricts or exempts us from disclosing such information, we may not be able to inform you of any details.

(3) Cooperation for Business or Operational Needs

When we enter into agreements with our partners, advertisers, trusted affiliates, or any other third parties for business or operational needs, or when we use third-party services to support our business operations, website functions, or manage activities, we may share your data with such third parties. However, we will make every effort to ensure that these third parties comply with our instructions, adhere to this Privacy Policy, and implement appropriate confidentiality and security measures within the authorized scope.

(4) De-identified Data

We may share aggregated or de-identified data with third parties, as such data cannot reasonably be used to identify an individual.
We may disclose, sell, trade, and/or rent generalized and aggregated statistical information to third parties. These statistical data, which have been aggregated or de-identified, do not constitute personal data and may include, but are not limited to, application names, installation/uninstallation timestamps, and location data (such as country), which cannot reasonably be used to identify an individual.

(5) Compliance with Terms of Service

To enforce applicable terms of service(https://www.dottedsign.com/terms_of_service), including investigating potential misuse by users and addressing security or technical issues, we may share personal data with third parties.

(6) Transfer and Notification Mechanism

In the event of a merger, acquisition, or sale of assets, we will continue to take measures to protect the confidentiality of personal data and notify affected users before transferring any personal data to a new entity.

7.2 To keep your trust in our Services, and subject to legal and confidentiality requirements, we may publish the number, types, or notifications of data access requests annually or at an appropriate time. However, we will not disclose any restricted or sensitive details.

7.3 Kdan strive to follow the principles of minimal collection and necessary disclosure to avoid using your data beyond the scope of your consent or legal requirements.

8. Third-party Websites or Services

(1) Our websites, applications, and Services may contain links, services, and advertisements run by third parties. These third-party links, services, and advertisements are not run by Kdan, and this Privacy Policy does not apply to said links, services, and advertisements. Kdan takes no legal responsibility regarding how these third parties collect, process, and use users’ Personal Data. It is the user’s own responsibility to review the terms of service or privacy policy of these third parties before contacting, clicking, or using said links, services, and advertisements.

(2) Our websites, applications, and Services may use services such as YouTube API services (including but not limited to that users may upload videos to YouTube through such services). Users must carefully review the relevant terms below before using such services:

YouTube API Services Terms of Service: https://developers.google.com/youtube/terms/api-services-terms-of-service

YouTube API Services - Developer Policies: https://developers.google.com/youtube/terms/developer-policies

Google’s Privacy Policy: https://policies.google.com/privacy?hl=en&gl=ZZ

Google API Services User Data Policy: Our use and transfer of information received from Google APIs to any other app adheres to Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy#additional_requirements_for_specific_api_scopes). This may include but not limited to file names, file content, folder structure, and metadata. We use information received from Google APIs solely to provide or improve user-facing features. This includes facilitating file management, storage, and any additional features or functionalities enabled through our integration with the Google Drive API. We transfer such information only as allowed under the Limited Use Requirements and does not transfer or sell this information to third parties or to serve advertising.

Microsoft API Services User Data Policy: Our use and transfer of information received from Microsoft APIs to any other app adheres to Microsoft API Services User Data Policy (https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use). This may include but not limited to file names, file content, folder structure, and metadata. We use information received from Microsoft APIs solely to provide or improve user-facing features. This includes facilitating file management, storage, and any additional features or functionalities enabled through our integration with the Microsoft API. We transfer such information only as allowed under the Limited Use Requirements and does not transfer or sell this information to third parties or to serve advertising.

(3) We utilise automated processes to provide emails and notifications to Users depending on events that occur when using our Services, as well as determining the User's access level and operating a Chatbot.

We employ a third-party to facilitate User payments. This incorporates automated decision making to block high-risk payments.

9. Team Administrator’s Liabilities

(1) Team Administrators of Kdan’s team subscription plan(including the payer for the fees of such team subscription plan, and the administrator appointed for each team) hereby warrant that its/his/her management and use of the Personal Data contained in the Kdan accounts that belong to such team subscription plan is in compliance with local regulations (including but not limited to the Personal Data Protection Act in Taiwan, the GDPR in EU).

(2) Team Administrators hereby agree to indemnify Kdan, from and against any damages (including but not limited to attorney fees, legal expenses, the settlement costs Kdan pays to third parties, and any amount the court awards to third parties) arising out of or in any way connected with any claim made by third parties (including the individual Kdan account users that belong to a team subscription plan) due to its/his/her unlawful acts.

10. Data Transfers

Your Personal Data may be processed on servers located outside of the country where you live. Regardless of where your Personal Data is processed, we apply the same protections described in this Privacy Policy. We also comply with legal requirements relating to cross-border transfers of Personal Data.

If your Personal Data is transferred to a third country or organisation, we will ensure there is either an adequacy decision in place, or in the absence of an adequacy decision we will implement appropriate standard contractual clauses to ensure the security of your data.

11. Changes to Privacy Policy

(1) Due to rapid technological developments, Kdan may update this Privacy Policy from time to time, to reflect the legal, technical, and commercial changes in accordance with relevant regulations. You agree that it is your responsibility to review the latest Privacy Policy regularly, and your continued use of Kdan products or Services will be deemed that you agree to the updated Privacy Policy. Should you disagree with any updated Privacy Policy, please discontinue your use of Kdan products or Services.

(2) Whenever we update this Privacy Policy, we will publish the updated Privacy Policy on Kdan’s websites, and will notify you soon through the applications or emails.

12. Right to lodge a complaint

You have the right to lodge a complaint with the appropriate supervisory authority in your country. If you do have any concerns about how we have handled your data we would kindly ask that you contact us in the first instance, before you speak to the supervisory authority, so that we have an opportunity to put things right.

13. Contacting Us

If you have any questions about this Privacy Policy, data transfers, or Kdan products, please contact us at: Kdan Mobile Software Ltd. https://www.kdan.com/contact
Kdan Mobile Software Ltd fully understands our obligations concerning your personal data under the EU and UK GDPR.
This Privacy Policy applies to all Personal Data we collect.
This Privacy Policy was last updated on the 21st day of April 2025.