Legal
Privacy Policy
Version 2026.09 · effective 22 August 2026
1 · Who is responsible
This policy describes how Self Service Notary, operated at selfservicenotary.com handles personal data. Which role we play depends on whose data it is:
| Data | Controller | Us |
|---|---|---|
| Your account, workspace and billing data; visitors to our own marketing site | Self Service Notary | Controller |
| Documents, signers, clients, identity evidence and session recordings inside a workspace | The notary or firm whose workspace it is | Processor, under the DPA |
| Hashes and signed claims published in the transparency ledger | Self Service Notary | Controller |
So when a notary publishes a portal and their client submits a document, that notary decides why and how it is processed. We act on their instructions, and we route any request we receive directly to them.
Our postal address is 82801.
2 · What we hold
Account and workspace details, including who else you invite into it; documents you or your clients upload; participant names and email addresses; appointment times; audit events and ledger claims; delivery records for invitations and one-time codes; live-session recordings and the screenshots a notary captures during an act; and — where used — identity verification results and evidence. Phone numbers where they are given, and the content of the text messages we send to them. We also keep a record of which version of these documents each account accepted, and when, together with the network address and browser description at that moment — that record is what makes the agreement provable.
One thing we look at and do not keep: the country your network address suggests, used only to pick which currency to show beside a price. It is read per request and never stored.
3 · Identity evidence and biometrics
A photo-ID check with a liveness selfie involves biometric data used to identify a person, which the GDPR treats as a special category (Article 9). We process it only where the person has given explicit consent at the point of the check — in the product before the check starts, and again inside the provider's own flow — and only for that check.
Evidence is encrypted under a separate key, visible only to the notary reviewing it, and never embedded in the sealed document. What reaches the document is the verified name and the fact and method of verification — not the imagery. A person can decline; the notary then chooses another way to identify them, or does not proceed.
No decision about a person is taken by software alone. A check that fails or is flagged is reviewed by the notary, who decides whether to proceed, ask for another form of identification, or stop. That is a requirement of their office as much as of Article 22.
Some US states — Illinois, Texas and Washington among them — regulate biometric identifiers specifically. The notary requesting a check is the party collecting that consent and setting the retention for it; ask them for their schedule. We hold a data-protection impact assessment for identity verification and for session recordings, available to controllers on request.
4 · Verification is blind
When anyone verifies a document, their browser computes a one-way fingerprint of the file locally. Only that digest is transmitted. We do not receive the file, its name or its contents, and we cannot reconstruct any of them from the digest.
5 · Legal bases
| Processing | Basis |
|---|---|
| Providing the service to an account holder; billing | Contract (Art. 6(1)(b)) |
| Identity checks involving photo-ID and liveness | Consent (Art. 6(1)(a)) and explicit consent for the biometric element (Art. 9(2)(a)) |
| Security, abuse prevention, service integrity, keeping the ledger verifiable | Legitimate interests (Art. 6(1)(f)) |
| Delivering one-time codes and reminders by text; showing a price in your own currency; drafting an advisory summary from a job's own activity | Legitimate interests (Art. 6(1)(f)) |
| Keeping records a notary's jurisdiction requires them to keep | Legal obligation (Art. 6(1)(c)), and the notary's own duty |
| Keeping proof of which terms an account accepted | Legitimate interests, and the establishment or defence of legal claims (Art. 9(2)(f) where relevant) |
Where we rely on consent you may withdraw it at any time; that does not undo processing already carried out.
The service is for professionals and the adults they work with. We do not knowingly process the data of children under 16; if you believe we have, write to privacy@selfservicenotary.com and we will remove it.
6 · Sub-processors
We use a small number of providers — hosting and storage, identity verification, live video, email delivery, text-message delivery, payments, a qualified trust service provider when a qualified signature is requested, and — only where the operator has configured an external model — a provider for advisory job summaries. Each one, what it does, and where it operates is listed at Sub-processors, with the date of the last change. We update that page before a new provider starts processing, and the DPA gives you the right to object.
7 · Retention
| What | Kept for |
|---|---|
| Documents, audit trails, e-journal | Until you delete them or close the account — nothing expires on its own |
| Identity evidence | With the request or document it belongs to; deleting that (or the account) erases the evidence with it |
| Session recordings | The retention period set on the workspace; unset means kept until deleted by hand |
| Email delivery records and bounce suppressions | With the workspace that produced them |
| Ledger entries | Permanent by construction — hashes and signed claims, never document contents or files |
| Record of accepted terms | Kept after an account closes, as proof of the agreement that governed it |
The ledger is the one thing we cannot delete on request: a record that could be edited would prove nothing, and printed QR codes must still verify years later. Entries contain a hash and a signed claim — never the document, never its contents.
8 · Where data is processed
We are established in United Arab Emirates and use providers that operate globally. Documents and identity evidence for workspaces that ask for EU residency are stored in storage located in the EU jurisdiction. Service metadata — names, email addresses, fingerprints, the public record — and the delivery of email and text messages are processed globally either way. A session recording is captured by the video provider and moved into that storage afterwards, so the provider holds it briefly first. Where personal data is transferred out of the EEA or the UK, the transfer is covered by the safeguards in our agreements with those providers — the European Commission's standard contractual clauses and the UK addendum to them, where they apply. The current locations are listed at Sub-processors.
9 · Your rights
Access, rectification, erasure, restriction, portability and objection, exercised at privacy@selfservicenotary.com. Where you are a signer or a client rather than an account holder, the controller is the notary or firm that invited you: we will route your request to them and tell you who they are.
You can also complain to a data protection supervisory authority — in the EEA or the UK, the one for the country you live or work in.
10 · Cookies and local storage
We set these cookies, all first-party, and none of them for advertising or analytics: your sign-in session; which workspace you are acting in; your sign-in to a practice's own client portal; the language, the currency and the light-or-dark theme you chose; and a note that you have seen the cookie notice. The last three are choices you made, and the server reads them before it draws the page.
Your browser also keeps a few things on your own device, which are never sent to us: whether the sidebar is pinned, whether you have seen the product tour, whether the setup guide is folded away, a price list you have not finished ordering from, and the state of a signing ceremony you have not finished.
The current list, with what each one is for and how long it lasts, is in the cookie panel at the foot of any page — and it is generated from the same list the code uses, so it cannot drift.
The payment provider sets its own fraud-prevention cookies on the payment pages inside the app. The video provider stores call state while a live session is open. Identity checks and card payments happen on the provider's own site, under their privacy policy. There is no advertising, no analytics, no tracking pixel — in the product or in the emails a signer receives. .
11 · Changes
This policy is versioned. A material change gets a new version number and is put to account holders in the product before it takes effect; smaller corrections take effect on publication. Questions: privacy@selfservicenotary.com.
