Privacy Policy
Sign HUB
Last updated: 4 May 2026
In accordance with Reglamento (UE) 2016/679 (GDPR, General Data Protection Regulation) and
Ley Orgánica 3/2018, de 5 de diciembre, de Protección de Datos Personales y garantía de los
derechos digitales (LOPDGDD, Spanish Data Protection and Digital Rights Act), the user is hereby
informed of the processing of their personal data on the Sign HUB
Platform.
1. Data controller
| Identity | HUB DESPACHOS Y PYMES, S.L. (CIF B76816875) |
| Registered address | Avenida Benito Pérez Armas, 2 - PTL 2,6 B, Santa Cruz de Tenerife, España |
| Email | [email protected] |
| Data Protection Officer (DPO) | [email protected] |
2. Purposes of processing
We process the user's personal data for the following specific purposes:
- Managing the electronic signature process of the document sent to the user, which includes
verifying their identity by means of a one-time password (OTP) sent by email, collecting their digitized
handwritten signature and applying the electronic seal to the document.
- Generating the traceability evidence that attests to the signature performed (declared
identity, IP address, date and time, SHA-256 hash of the document, consents accepted).
- Sending the user a copy of the signed document and of the certificate of evidence.
- Retaining the signed document and the evidence for a minimum of 5 years as proof in the
event of a dispute, in accordance with the applicable legal obligations.
- Handling requests to exercise data protection rights addressed to us by the user.
3. Data processed
- Identification data: full name, DNI/NIF (Spanish ID number, if provided), email.
- Digitized handwritten signature (image).
- Connection data: IP address, date and time, browser user-agent.
- Cryptographic hash of the document (SHA-256).
- The user's acceptances (privacy, cookies, signing terms) with a timestamp.
4. Legal basis
The processing is based on:
- Consent of the data subject (Art. 6.1.a GDPR), which the user gives expressly
before signing the document.
- Performance of a contract or pre-contractual measures (Art. 6.1.b GDPR), where the
signing of the document forms part of a contractual relationship with the client that sent the document.
- Compliance with legal obligations (Art. 6.1.c GDPR), for the retention of the
electronic evidence in accordance with the trust services regulations.
- Legitimate interest (Art. 6.1.f GDPR) in guaranteeing the security of the Platform and
preventing fraud.
5. Retention periods
- Signed document and certificate of evidence: a minimum of 5 years from the signature, stored
under an immutable retention policy (S3 Object Lock COMPLIANCE) on infrastructure located within the
European Union.
- Processing data: for as long as necessary to manage the signature and handle any
claims (a minimum of 5 years).
- Technical cookies: as indicated in the Cookie Policy.
6. Recipients and international transfers
The data may be disclosed to:
- The client that sent the document for signature (controller of its own contractual
relationship with the signer), which receives the signed document and the evidence.
- Processors engaged by HUB Consultores for the provision of the service:
cloud storage provider (in the European Union), SMTP provider for sending emails, trust service
provider for the qualified electronic seal, Time Stamping Authority (TSA) service provider and
CRM platform (Bitrix24) where applicable.
- Public authorities where there is a legal obligation.
No international transfers of data are made to countries lacking an adequate level of protection.
7. Rights of the data subject
The user may exercise the following rights at any time by sending their request, together with a
copy of an identity document, to
[email protected]:
- Access to their personal data.
- Rectification of inaccurate data.
- Erasure ("right to be forgotten"), except with regard to the signature evidence, whose
retention is legally required for the minimum period indicated.
- Restriction of processing.
- Data portability.
- Objection to processing.
- Withdrawal of consent (without retroactive effect on signatures already performed).
- Lodging a complaint with the Agencia Española de Protección de Datos
(AEPD, Spanish Data Protection Authority) if they consider that the processing does not comply
with the regulations.
8. Security measures
HUB Consultores applies technical and organizational measures appropriate to the level
of risk, including:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 + Fernet) of sensitive data.
- Immutable WORM (Write-Once-Read-Many) storage during the retention period.
- Two-step authentication of the signer by means of an email OTP.
- Audit logging of access and critical operations.
- Access restricted to strictly necessary personnel.
9. Automated decision-making
No automated individual decision-making or profiling is carried out with the signer's data.