Skip to content

Site search

Type to search Pages

Privacy Policy

How Signura collects, uses and protects personal data through signura.ai, and the rights you hold over it. In effect since 2026-09-01.

Who we are

Signura is operated by Cohort Ventures Limited (DIFC, Dubai, UAE), which is the controller of the personal data described here. This policy covers signura.ai, our mobile and desktop apps. It does not cover other companies' websites we link to; when you leave for one, its own policy applies.

Questions about this policy, or about data we hold, go to hello@signura.ai.

The short version

We collect what we need to answer you, to run the site and to provide the service — and nothing we have no use for.

We do not sell personal data, we run no advertising network, and we set no cross-site tracking cookies of our own.

We use a small, named set of service providers, listed in our Sub-processor List at /legal/subprocessors.

You can ask us what we hold about you, ask us to correct it, and ask us to delete it.

What we collect, and why

Enquiries. When you write to us through the contact form we receive the name, work email, company and message you submit. We keep the enquiry so we can answer it and so we can find the thread again if you write back.

Newsletter subscriptions. The email address you subscribe with, and the fact that you confirmed. Subscriptions are double opt-in — nothing is sent until you click the confirmation link — and every email carries a one-click unsubscribe.

Usage measurement. Aggregate, anonymous usage statistics collected without cookies via Plausible Analytics. No cookie is set, no cross-site identifier exists, and individual visitors are not identified.

Anti-abuse signals. Public forms are protected by Cloudflare Turnstile, which examines signals about your browser to tell a person from a bot. It is not used to identify or track you.

Consent choices. Your cookie choice is stored in your browser so we do not ask again on every page.

Server logs. Like every web server, ours records the IP address, browser user agent and pages requested for each request. We use these to keep the site running and to investigate abuse.

What we do not collect

We do not buy personal data from data brokers, and we do not sell, rent or trade the personal data we hold.

We do not run advertising or cross-site tracking, and we set no advertising cookies.

We do not ask for special categories of personal data — health, biometrics, political opinions, religious beliefs and the like — and you should not send them to us.

signura.ai is a business service and is not directed at children. If you believe a child has given us personal data, write to hello@signura.ai and we will delete it.

Who processes it for us

We use a small set of service providers — sub-processors — to run this site and the service. Each one is engaged under its own published data-processing terms, receives only the data its job requires, and is listed by name.

Netlify — website hosting and delivery. What reaches it: the request data any web server sees — IP address, browser user agent, the pages requested — plus whatever you type into a form as it is submitted.

Neon — the managed Postgres database this site stores its records in. What reaches it: enquiries submitted through the contact form.

Resend — transactional email delivery. What reaches it: the email address a message is sent to and the content of that message.

Plausible Analytics — privacy-first, cookieless usage measurement. What reaches it: aggregate page-view events with no cookie and no cross-site identifier. Loaded only after you consent.

Cloudflare — Turnstile anti-abuse verification on public forms. What reaches it: signals about the browser submitting a form, used only to tell a person from a bot.

The same list, with the same detail, is published as our Sub-processor List at /legal/subprocessors and is updated whenever it changes.

Where it goes

Our providers operate internationally, so personal data may be processed outside DIFC, Dubai, UAE. Where that happens we rely on the transfer safeguards available under the DIFC Data Protection Law (DP Law 2020), including the data-processing terms we have with each provider.

We do not transfer personal data to a provider that gives us no such safeguard.

How long we keep it

We keep personal data only as long as the purpose it was collected for requires, or as the law requires, and then delete it. Concretely:

Enquiries are kept while we are dealing with them and afterwards as a record of the conversation, so we can pick up a thread you return to.

Newsletter subscriptions are kept until you unsubscribe; unsubscribing removes the address from the sending list.

Server logs and error diagnostics are short-lived and are kept for operational and security purposes only.

Where we have not set a fixed period for a category, we say so rather than state one we do not keep to. If you want to know how long we hold something specific, ask at hello@signura.ai and we will tell you.

How we protect it

Traffic between your browser and our servers is encrypted in transit. Access to systems holding personal data is limited to the people and services that need it, and is removed when it is no longer needed.

No system is perfectly secure, and we do not claim certifications we do not hold. If you believe you have found a vulnerability, our Vulnerability Disclosure Policy at /legal/security-disclosure tells you how to report it.

Your rights

You may ask us to give you a copy of the personal data we hold about you; to correct it if it is wrong; to delete it; to restrict or object to how we use it; and, where processing rests on your consent, to withdraw that consent — withdrawing it does not undo processing that already happened lawfully.

To exercise any of these, write to hello@signura.ai. We may need to check who you are before we act, and we may have to keep records the law requires us to keep even after a deletion request; if that applies we will say which records and why.

We do not charge for answering a request, and we answer within the period the applicable law allows.

If you are not satisfied with our answer, you may complain to the DIFC Commissioner of Data Protection.

Business customers and data-processing terms

Where we process personal data on a customer's behalf rather than our own, that customer is the controller and we are the processor. Those arrangements are governed by written data-processing terms rather than by this policy.

If you need those terms before your organisation can use the service, ask at hello@signura.ai and we will provide the current version for signature. We will not process customer personal data under an arrangement that has none in place.

Changes to this policy

We update this policy when what we do changes — a new sub-processor, a new surface, a new purpose. The current version is always the one published on this page, and the register at /legal shows where each of our documents stands.

Where a change materially affects how we handle your personal data, we will tell you before it takes effect rather than after.

Document status

This privacy policy was reviewed by legal counsel on 2026-09-01 and has been in effect since that date. It may be revised; the current version is always the one published on this page, and material changes are announced before they take effect.