Ascripto

Privacy policy

Last reviewed 6 October 2026

This page covers three things: this website, the waitlist, and the Ascripto service at app.ascripto.com. For the service we play two different roles, and which one applies decides who you should ask about your data.

Who is responsible

The data controller is Gyrus Solutions sp. z o.o. w organizacji, a company in the course of registration in Poland. Registration details are published here as soon as the entry is issued. For anything on this page, including access and deletion requests, write to privacy@ascripto.com.

Our two roles

We are the controller for data about people who visit this site, join the waitlist, or have an Ascripto account: what you type in, how you sign in, and the security records of your sessions.

We are a processor for the data an organisation connects to Ascripto: its directory, its employees’ signatures, and the record of mail that passes through our relay. That organisation is the controller and decides what is processed; we act only on its instructions, under our Data Processing Agreement. If your employer uses Ascripto to manage your signature, your employer is the one to ask first. We will help them answer.

This website and the waitlist

DataWhyRequired
Work email addressTo tell you when the drift audit opens and when Ascripto launches.Yes
Approximate mailbox countTo sequence onboarding. It changes what we need ready before contacting you.No
Mail platformSo we contact Google Workspace and Microsoft 365 organisations about the channel that fits them.No
Time of submission and your consentTo evidence that consent was given, as consent-based processing requires.Recorded automatically
A one-way hash of your IP addressRate limiting, so the form cannot be used to flood the list. We cannot recover the address from the hash and do not store the address itself.Recorded automatically

The legal basis is consent, under Article 6(1)(a) of the General Data Protection Regulation (EU) 2016/679, given with an unticked checkbox. Withdrawing it is one click on the unsubscribe link or one email to the address above. The waitlist is stored on our own server in the European Union; no form provider, marketing platform or CRM sees it, and we do not sell, rent or share it. It is kept until launch plus a reasonable period to complete the announcement, or until you ask us to delete it. Unsubscribing removes your address rather than flagging it.

Analytics and cookies on this site

This site can use Google Analytics 4 to measure visits. It does not run until you say yes. On your first visit a banner offers Accept and Reject, and nothing is requested from Google until you choose Accept — not the script, not a cookie, not a connection. Rejecting is one click, exactly like accepting.

If you accept, it sets first-party _ga cookies and sends Google your page views with your IP address, an approximate location derived from it, and basic device and browser details. Google processes this on our behalf, which can involve servers outside the European Union. Cookie settings in the footer of every page withdraws consent and deletes the _ga cookies. Your choice is kept in your browser’s local storage, not a cookie. Analytics data is never joined to the waitlist or to an Ascripto account.

Our web servers keep standard access logs, including IP addresses, for a short period for security and troubleshooting.

Your Ascripto account

DataWhy
Your email address and nameTo identify you, and to send the messages the service needs: sign-in codes, password resets, invitations, security notices.
Your Google or Microsoft account identifier and your organisation’s identifierTo sign you in, and to recognise which organisation you belong to. We match on these, never on your email address.
Your password, if you set oneStored only as a one-way hash. We cannot read it.
Your second factorAn authenticator app’s secret, stored encrypted; or a passkey, of which we hold only the public key.
Sessions and sign-in history: time, IP address, and a description of your browser and deviceSo you can see and end your sessions, and so we can detect and investigate misuse of your account.
Your account record: invitations, roles, removals, security changesSo your organisation can see who did what, and so a disputed change can be answered.

The legal basis is the contract you or your organisation entered into (Article 6(1)(b)) and, for the security records, our legitimate interest in keeping accounts safe (Article 6(1)(f)).

The Ascripto app sets only the cookies it needs to sign you in and keep you signed in, and to protect forms against cross-site request forgery. It runs no analytics and no advertising code.

Data from Google

Ascripto uses Google APIs only for the features you or your Google Workspace administrator turn on:

Ascripto’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use this data only to provide and improve the features described above; we do not use it for advertising, we do not sell it, we do not use it to develop, improve or train generalised artificial intelligence or machine-learning models, and no person at Ascripto reads it except with the organisation’s permission for support, for security, or where the law requires.

Data from Microsoft

Data an organisation connects (as its processor)

Where it is kept, and who else is involved

The service runs on Microsoft Azure in the Germany West Central (Frankfurt) region, and credentials such as directory access tokens are kept in Azure Key Vault in the same region. Transactional email (codes, resets, invitations) is sent through our own mail server. The sub-processors we use, and their locations, are listed in the Data Processing Agreement; we name a new one there before it starts.

Google and Microsoft are your organisation’s own providers, not ours: data you connect stays subject to your agreements with them.

Ascripto staff do not browse customer data. Support can see an organisation’s data only through a support grant that is time-limited, carries a reason, is recorded, and is visible to the organisation. Every staff account uses multi-factor authentication.

How long we keep it

DataKept for
Your accountWhile it exists. Deleted within 30 days of you or your organisation closing it.
Account record and administrative audit13 months
Message log (relay)10 days searchable; an archive the organisation controls may keep it longer
Signature change history (“why does this person have this signature?”)90 days
Link and banner events90 days raw; monthly totals for 25 months
Background job history30 days
An organisation’s data when it leavesDeleted within 30 days of the end of the agreement, as the DPA sets out

Your rights

You can ask for a copy of your data, its correction or deletion, a restriction of what we do with it, or a portable copy, and you can object to processing based on our legitimate interests. Write to privacy@ascripto.com and we will respond within 30 days. Where we hold the data as a processor, we pass your request to the organisation that controls it and help them answer.

If you think we have handled your data badly you can complain to a supervisory authority. Ours is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO). You may also complain to the authority where you live or work. Visitors in the United Kingdom have equivalent rights under UK GDPR.

Ascripto is a service for organisations and is not directed at children.

Changes

The date at the top of this page reflects the last change. If a change affects what we do with data already collected, we tell account holders by email before it takes effect, and we ask the waitlist again rather than relying on a quiet update.