Version 2026-10-10

Privacy Notice

How Geco Technologies Ltd uses personal data when you visit our site or use Geco Signatures.

Who is responsible

Geco Technologies Ltd (company number 16374153, Unit 78 Claydon Business Park) is the controller for the personal data described in this notice, except where we say we act as a processor. Questions and requests go to privacy@gecosign.com.

We are registered with the Information Commissioner’s Office (ICO), the UK supervisory authority. You can complain to the ICO at ico.org.uk if you are unhappy with how we handle your data, though we would prefer the chance to put it right first.

Two roles: controller and processor

For the people who sign up and administer Geco Signatures, and for billing, we decide how and why data is used, so we are the controller.

For the directory data we read from a connected Microsoft 365 tenant and for the mail that passes through our relay, the customer decides; we act only on their instructions as a processor under our Data Processing Addendum. If you are an employee of one of our customers and want to exercise your rights over that data, contact your employer, who can instruct us.

What we collect as controller, and why

  • Account data: name, work email address, password hash, two-step verification settings. Used to run your account (performance of a contract).
  • Workspace and billing data: business name, billing contact, VAT number, Stripe customer and subscription identifiers, invoices. Used to charge for and account for the service (contract and legal obligation). Card details go directly to Stripe; we never see the full card number.
  • Sign-in and security logs: email address, IP address, time, outcome of sign-in attempts, and security events such as two-step verification changes. Used to protect accounts and detect abuse (legitimate interest in security). Kept for 90 days.
  • Support correspondence: what you send us and our replies. Used to help you (contract and legitimate interest). Kept for 2 years.
  • Website visits: our marketing site sets no analytics or advertising cookies. Our servers keep standard request logs with IP addresses for up to 30 days for security.

What we process as processor

  • Directory data from the customer’s tenant: names, job titles, departments, phone numbers, email addresses, photos and similar attributes, used to populate signatures.
  • Mail content in transit: the headers and body of messages routed through the relay, held in memory only for as long as it takes to insert a signature. We do not store message bodies or attachments. We keep delivery metadata (sender, recipient count, rule and outcome) for the customer’s own logs.
  • Content the customer chooses to send to the AI template feature, which is processed by OpenAI to generate a draft and is not used to train their models.

Who we share data with

We use a small number of suppliers to run the service. They act on our instructions and are listed on our Subprocessors page with their locations. We do not sell personal data and do not share it for advertising.

We may disclose data where the law requires, for example to a regulator or court, and to professional advisers under confidentiality.

Where data is held

The platform and its databases are hosted in Germany (European Union). Where a supplier processes data outside the UK we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.

How long we keep it

Account and workspace data are kept while the account is open and deleted 30 days after a workspace or account is closed. Invoices and related records are kept for 6 years as required by tax law. Security logs are kept for 90 days. Backups are overwritten in a rolling cycle of no more than 35 days.

Your rights

You can ask for a copy of your personal data, ask us to correct or delete it, restrict or object to how we use it, and ask for it in a portable format. You can withdraw consent where consent is the basis. Write to privacy@gecosign.com; we respond within one month.

Platform administrators can produce a subject-access export of any account directly from our admin tools, so these requests are normally met quickly.

Cookies

The application uses strictly necessary cookies only: a session cookie once you sign in, a short-lived cookie between the password and authenticator steps of sign-in, and a cookie remembering the workspace you last used. No consent banner is needed for these and we set nothing else.

Changes

We will post changes here and, for material changes, tell account holders by email. The date at the top shows the current version.