Version 2026-10-10
Privacy Notice
How Geco Technologies Ltd uses personal data when you visit our site or use Geco Signatures.
Who is responsible
Geco Technologies Ltd (company number 16374153, Unit 78 Claydon Business Park) is the controller for the personal data described in this notice, except where we say we act as a processor. Questions and requests go to privacy@gecosign.com.
We are registered with the Information Commissioner’s Office (ICO), the UK supervisory authority. You can complain to the ICO at ico.org.uk if you are unhappy with how we handle your data, though we would prefer the chance to put it right first.
Two roles: controller and processor
For the people who sign up and administer Geco Signatures, and for billing, we decide how and why data is used, so we are the controller.
For the directory data we read from a connected Microsoft 365 tenant and for the mail that passes through our relay, the customer decides; we act only on their instructions as a processor under our Data Processing Addendum. If you are an employee of one of our customers and want to exercise your rights over that data, contact your employer, who can instruct us.
What we collect as controller, and why
- Account data: name, work email address, password hash, two-step verification settings. Used to run your account (performance of a contract).
- Workspace and billing data: business name, billing contact, VAT number, Stripe customer and subscription identifiers, invoices. Used to charge for and account for the service (contract and legal obligation). Card details go directly to Stripe; we never see the full card number.
- Sign-in and security logs: email address, IP address, time, outcome of sign-in attempts, and security events such as two-step verification changes. Used to protect accounts and detect abuse (legitimate interest in security). Kept for 90 days.
- Support correspondence: what you send us and our replies. Used to help you (contract and legitimate interest). Kept for 2 years.
- Website visits: our marketing site sets no analytics or advertising cookies. Our servers keep standard request logs with IP addresses for up to 30 days for security.
What we process as processor
- Directory data from the customer’s tenant: names, job titles, departments, phone numbers, email addresses, photos and similar attributes, used to populate signatures.
- Mail content in transit: the headers and body of messages routed through the relay, held in memory only for as long as it takes to insert a signature. We do not store message bodies or attachments. We keep delivery metadata (sender, recipient count, rule and outcome) for the customer’s own logs.
- Content the customer chooses to send to the AI template feature, which is processed by OpenAI to generate a draft and is not used to train their models.
Where data is held
The platform and its databases are hosted in Germany (European Union). Where a supplier processes data outside the UK we rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
How long we keep it
Account and workspace data are kept while the account is open and deleted 30 days after a workspace or account is closed. Invoices and related records are kept for 6 years as required by tax law. Security logs are kept for 90 days. Backups are overwritten in a rolling cycle of no more than 35 days.
Your rights
You can ask for a copy of your personal data, ask us to correct or delete it, restrict or object to how we use it, and ask for it in a portable format. You can withdraw consent where consent is the basis. Write to privacy@gecosign.com; we respond within one month.
Platform administrators can produce a subject-access export of any account directly from our admin tools, so these requests are normally met quickly.
Changes
We will post changes here and, for material changes, tell account holders by email. The date at the top shows the current version.