Skip to content

Compliance

Every signing event is recorded with an immutable audit trail:

FieldWhat is recorded
TimestampUTC time of the signing submission
IP addressThe signer’s IP address at the time of signing
User agentThe browser/client user agent string
Signer decisionsPer-clause accept/reject for each clause
Document versionThe exact version that was signed

The audit trail cannot be modified after creation.

  • User accounts: email address, hashed password (bcrypt), display name
  • Organisation data: containers, documents, clauses (your content)
  • Signing records: signer email, IP address, user agent, timestamp, clause decisions
  • Team data: members, roles, invitation records

TheTerms is a cloud-hosted service — all data is stored and processed within TheTerms’ hosting infrastructure. There is no self-hosted deployment option.

For organisations processing EU personal data:

Right of access: User account data is available to the user in their profile settings.

Right to erasure: Users can delete their account from account settings. Organisation administrators can remove member accounts. Signing records associated with deleted accounts retain an anonymised record for audit integrity.

Data portability: Signing records and audit trails are accessible through the application interface.