Legal
Privacy Policy
This policy explains how Lean Data Pty Ltd (ABN 60 624 934 998), trading as LetSign, collects, uses, discloses and protects personal information when you use our website and the LetSign contract, e‑signature and payment platform. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and — where they apply to you — the EU/UK GDPR and US state privacy laws.
01Who we are
LetSign is agent‑native contract infrastructure: an AI agent drafts the deal document, your customer opens a link, verifies their email, signs a legally binding e‑signature and pays via Stripe. Agents orchestrate the workflow; a human always signs.
The LetSign website and platform are operated by:
Lean Data Pty Ltd
ABN 60 624 934 998, trading as “LetSign”
Sydney, New South Wales, Australia
Privacy enquiries: support@letsign.ai
In this policy, “we”, “us” and “our” means Lean Data Pty Ltd. “Personal information” has the meaning given in the Privacy Act and includes “personal data” as defined under the GDPR.
02Our role & the scope of this policy
LetSign handles personal information in two distinct roles, and it is important to understand the difference:
- As a controller (or “APP entity” / “business”) — for the personal information we collect to run our own business: your account and profile details, billing information, website visitors, and support enquiries. This policy governs that information.
- As a processor / service provider — for the content our customers create, upload and send through LetSign (proposals, contracts, recipient details and signatures). Here our customer is the controller and decides why the data is processed; we process it on their instructions under our Terms of Service and applicable data‑processing terms. If you are a recipient or signer, the sending business’s own privacy policy also applies to you (see section 12).
03Information we collect
We collect the following categories of personal information, depending on how you interact with us:
| Category | Examples |
|---|---|
| Account & profile | Name, email address, password (hashed), workspace and organisation details, role and seat assignments. |
| Document & contract content | Proposals, contracts, templates, pricing tiers, branding assets and any personal information you or your agent place inside them. |
| Signer & recipient data | Recipient name and email, email‑verification status, the electronic signature applied, and the parties named in a document. |
| E‑signature & audit‑trail metadata | IP address, timestamps, device/browser information, and a record of every generation, edit, view, open and signature — kept as an immutable audit trail to evidence the transaction. |
| Payment information | Payments and subscriptions are processed by Stripe. We receive limited transaction details (amount, status, last four digits, billing metadata); we do not collect or store full card numbers. |
| Integration data | Where you connect an integration, data from that service — for example meeting or call transcripts from Fathom, Granola or Fireflies used to generate a document, or Stripe Connect account data. |
| Usage & device data | Log data, feature usage, referring pages, approximate location derived from IP, and analytics events (see section 5). |
| Communications | Messages you send us, support requests, and your preferences. |
You do not have to identify yourself for general website browsing. If you choose not to provide certain information (such as an email for verification), we may be unable to provide part or all of the service.
04How we use information
We use personal information to:
- provide, operate and secure the platform — generating documents, verifying signers, capturing e‑signatures, maintaining the audit trail, and processing payments through Stripe;
- create and manage your account, workspaces and billing;
- respond to enquiries and provide support;
- improve and develop our products, including reliability, performance and new features;
- send service and transactional communications, and — where permitted — product updates you can opt out of; and
- comply with legal obligations, enforce our terms, and detect, prevent and respond to fraud, abuse or security incidents.
Where the GDPR applies, our lawful bases are: performance of a contract (to deliver the service you request), legitimate interests (to secure, improve and market our services, balanced against your rights), consent (for non‑essential cookies and certain marketing, which you may withdraw), and legal obligation.
06Disclosure & sub‑processors
We do not sell your personal information. We disclose it only as needed to run the service, and to the following categories of recipients, under contractual confidentiality and data‑protection obligations:
| Recipient | Purpose |
|---|---|
| Stripe | Payment and subscription processing, including Stripe Connect payouts. |
| Google Analytics | Website usage analytics. |
| AI / model providers (e.g. Anthropic, OpenAI) | Generating and updating document content when you or your agent use AI features (see section 7). |
| Cloud hosting & infrastructure | Storing and serving the platform, documents and assets. |
| Email & communications providers | Sending verification, notification and transactional emails. |
| Transcript integrations (Fathom, Granola, Fireflies) | Only where you connect them, to bring call/meeting content into a document. |
| Professional advisers & authorities | Where required by law, to enforce our terms, or in connection with a corporate transaction. |
Where LetSign acts as a processor for a customer, we disclose that customer’s content only on their instructions or as the law requires.
07AI & agent processing
LetSign is built to be operated by AI agents through a Model Context Protocol (MCP) server that connects to assistants such as Claude, Codex and ChatGPT. When you or your agent generate or update a document, the relevant content — which may include personal information and, where connected, call‑transcript data — is sent to third‑party AI model providers to produce the output.
Agents orchestrate; a human always signs. AI agents draft, update and track documents, but the binding signature is always applied by a person. We contract with model providers to process data on our instructions, and we do not permit them to use LetSign customer content to train their models except where you have separately agreed with that provider.
08Overseas & international transfers
We are based in Australia, and our service providers (including those in section 6) may store or process personal information in countries outside your own, including the United States. Under APP 8 we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Where the GDPR applies, transfers outside the EEA/UK are made under an adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
09Data retention
We keep personal information for as long as needed to provide the service, and then only as long as necessary for the purposes it was collected, to comply with legal, tax and accounting obligations, and to resolve disputes.
Signed documents and their audit trail are, by design, immutable and are retained to preserve the legal record of a transaction. Where we act as a processor, retention of a customer’s content is governed by that customer’s instructions and their agreement with us. When information is no longer required, we take reasonable steps to destroy or de‑identify it.
10Security
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure — including encryption in transit, access controls, and email verification of signers. No method of transmission or storage is completely secure; if we become aware of an eligible data breach we will respond in accordance with the Notifiable Data Breaches scheme and other applicable laws.
11Your rights & choices
Australia. Under the APPs you may request access to, and correction of, the personal information we hold about you. We will respond within a reasonable period; there is generally no charge, though we may recover reasonable costs of giving access.
GDPR (EEA/UK). If the GDPR applies, you may also have rights to erasure, restriction, portability, and objection, and to withdraw consent at any time.
US state privacy laws (e.g. California/CPRA). Where applicable, you may request access, deletion and correction, and may opt out of “sale” or “sharing” of personal information — we do not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights.
To exercise any right, contact support@letsign.ai. We may need to verify your identity before acting on a request.
12Signers vs. account holders
If you received a document to sign through LetSign, the business that sent it (our customer) is the controller of that document and decides how your information is used. LetSign processes it on their behalf. To access, correct or delete information within a document you signed, please contact the sending business directly. We will assist our customer in responding to your request, and you may also contact us at support@letsign.ai and we will route your request appropriately.
13Children
LetSign is a business tool intended for use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us personal information, contact us and we will delete it.
14Complaints
If you have a concern about how we handle your personal information, please contact us first at support@letsign.ai so we can investigate and respond. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. If you are in the EEA or UK, you may also lodge a complaint with your local supervisory authority.
15Changes to this policy
We may update this policy from time to time to reflect changes to our practices or the law. We will post the updated version here and revise the “Last updated” date above. If the changes are material, we will take reasonable steps to notify you.
16Contact us
For any privacy question or request, contact:
This Privacy Policy is provided for general information and is written to reflect the LetSign service. It is not legal advice. Lean Data Pty Ltd recommends reviewing it with a qualified Australian legal practitioner before relying on it.