Privacy Policy
Last updated: 10 July 2026
Qfile B.V. ("we") processes personal data through OurDigitalContract. In this policy we explain which data we process, why, on what legal basis, for how long and what rights you have.
Who is responsible?
For the data of your own employees and signers, your organisation is the data controller and we then act as the processor (see the data processing agreement). For the data of our own account holders, we are the controller.
Which data do we process?
- Account data: name, email address, role and a hashed password.
- Contract and record data: names, contact details, job title, contract terms and, where entered, national identification number, IBAN, date of birth, signature and the contents of documents.
- Usage and security data: login events, the IP address at the moment of signing and an audit log.
Cookies and analytics (with consent)
On our public website we use Google Tag Manager and Google Analytics only with your consent to measure how the website is used and to improve it. These measurement cookies are only placed after you click "Accept" on the cookie bar; your choice is stored in your browser (localStorage). If you click "Decline", we do not load Google Tag Manager and place no analytical cookies. We never use these measurement services on the secured app and signing pages.
This measurement may process data such as your (truncated) IP address, the pages visited, the time, device and browser information and the referring website. We use this solely for anonymised, statistical insights, not to identify you personally. The processor for this is Google Ireland Limited. You can withdraw your consent at any time by clearing your cookies; on your next visit the cookie bar will appear again. See our cookie policy for the full details.
Purposes and legal bases
- Providing the service (performance of the contract).
- Security, fraud prevention and evidencing a legally valid signature. The legal basis for this is our legitimate interest in a secure, reliable and legally sound service; where a specific law requires us to do so, the legal basis is a legal obligation. We have weighed your interests against ours and consider this processing not to be disproportionate.
- National identification numbers (BSN) are only processed where legally permitted (for example payroll administration), on the instructions of the controller.
- Analysis of website use through Google Tag Manager and Google Analytics, solely on the basis of your consent.
Mandatory provision of data
Some of the data is needed to perform the contract or arises from a legal obligation. Without account data, for example, we cannot create an account, and without a signature and the associated verification data a document cannot be signed in a legally valid way. If you do not provide this data, we cannot deliver (that part of) the service. Data such as a national identification number (BSN) is only processed where it is legally required or permitted and the customer instructs us to do so.
Automated decision-making and profiling
We do not take decisions with legal effects or similarly significant effects based solely on automated processing, and we do not carry out profiling.
How do we secure it?
Encryption at rest with a separate key per customer (AES-256-GCM), encrypted connections (HTTPS with HSTS), separated storage with a dedicated database per customer, hashed passwords (bcrypt), role-based and permission-based access, revocable sessions, rate limiting and an append-only audit log.
If we discover a data breach, we act in accordance with our data breach procedure.
Electronic signature
Signing is done with a simple electronic signature (eIDAS SES): identity is evidenced through control of an email address and a one-time link, and integrity through a tamper-evident attestation and an audit log. There is no strong identity verification (no advanced or qualified signature, AES or QES).
Retention periods
We do not keep data longer than necessary for the stated purposes or than legally required. We keep account data for as long as you have an account and up to 6 months after termination, after which we delete or anonymise it. We keep invoices and accounting records for 7 years due to the statutory tax retention obligation. Data we hold as a processor on behalf of a customer is retained according to that customer's instructions and deleted or returned after termination (see the data processing agreement). Security and audit log data (including login events and the IP address at the moment of signing) is retained for as long as necessary to evidence signing and to secure the service, and at the latest until the associated record is deleted in accordance with the periods above.
Where does the data come from?
We receive account data directly from you. Data about signers and the individuals involved in a record we receive from the customer (the controller) who submits the document for signing, or directly from you when you sign yourself. If you are a signer and have questions about the origin or use of your data, you can turn to the organisation that sent you the document.
Sub-processors and recipients
- Hosting: TransIP B.V.
- Email: TransIP B.V.
- Payments: Mollie B.V.
- Website analytics (only with consent): Google Ireland Limited (Google Tag Manager and Google Analytics).
We do not sell data.
A current overview of our sub-processors is available on the sub-processors page. The arrangements for the data we process as a processor are set out in the data processing agreement.
Transfers outside the EEA
No processing or storage of personal data takes place outside the European Economic Area (EEA).
Your rights
You have the right of access, rectification, erasure, restriction, objection and data portability. Where we process data on the basis of your consent (such as analytical cookies), you may withdraw that consent at any time; this does not affect the lawfulness of the processing carried out beforehand.
If you wish to exercise one of these rights, send a request to info@ourdigitalcontract.com. To prevent misuse, we may ask you to identify yourself. We respond within one month at the latest; for a complex or large number of requests we may extend this period by two months and will let you know within the first month. Requests about data we hold as a processor are handled through your own organisation (the controller).
You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).
Changes
We may amend this policy. The current version is always available on this page. In the event of significant changes we will actively inform you, for example through a notification in the app or by email.