data · privacy · nda signing · 2026-06-19

Privacy Policy.

auriglyph collects a limited set of personal data to run access requests, DocuSeal signing, and the legal evidence trail around signed NDAs. This page says what is collected, why, where it is stored, and how long it is retained.

Effective: 2026-06-19Controller: Mikhail Kostan, Colombia · [email protected]Legal contact: [email protected]
01

Who we are

auriglyph is the trading name of Mikhail Kostan, an individual researcher and engineer resident in Colombia (the "Lab"). We operate the website at auriglyph.com, the disclosure gateway located at /access/, and the NDA signing page at /nda-document/. Mikhail Kostan is the data controller for personal data submitted through these services and can be reached on data-protection matters at [email protected] or on NDA and signing-record matters at [email protected].

02

What we collect and why

We collect personal data when you submit an access request or sign the NDA. The fields collected and their purpose are:

  • Legal name (first and last) — to identify the submitting individual and verify institutional authority.
  • Work email address — to communicate eligibility decisions, create signing sessions, and issue signed copies. Free-domain submissions are not processed for access.
  • Phone number (optional) — provided at your discretion; used only if you request it as a secondary contact channel.
  • Organisation name and title/role — to assess institutional qualification and the submitter's authority to bind the organisation.
  • Jurisdiction — required for governing-law determination under the bilateral NDA.
  • Institutional type and stated interest — to scope the evaluation and determine which artefacts may be relevant to your request.
  • Consent checkboxes — to record acceptance of electronic signatures and consent to data processing before signing begins.
  • Signing evidence — signed PDF, audit certificate, hashes, timestamps, IP address, user agent, DocuSeal submission ID, template ID, webhook payload, and email delivery log.

The website runs no analytics, sets no tracking cookies, and loads no third-party scripts; it does not log your browsing or device for marketing. When you sign, the server receives and stores legal evidence for the NDA. We do not place signed PDFs in a public directory and do not expose persistent public download URLs.

03

Legal basis for processing

Processing is based on:

  • Legitimate interests — evaluating access eligibility, protecting proprietary artefacts, and maintaining a verifiable audit trail for contractual obligations.
  • Contractual necessity — once an NDA is signed, processing is necessary to fulfil the agreement and administer the access relationship.
  • Consent — for the electronic-signature and data-processing acknowledgements shown before the embedded signing form.
  • Legal obligation — retention of certain records may be required by applicable law.
04

How your request and signing data are held

When you submit a request or complete the signing flow, your browser sends the data to our backend. The backend may create a DocuSeal submission, receive the completed webhook, download the signed PDF and audit certificate, compute SHA-256 hashes, and store the resulting records server-side. The website does not hash, encrypt, or otherwise transform this data on your device, and stores nothing in cookies, localStorage, or client-side state beyond simple UI preferences. Once processed, the legal evidence remains in controlled storage; no public link is used for permanent access.

We do not use automated decision-making or profiling. Every access request and signed packet is reviewed by a human before any protected material is unlocked.

05

Retention

Signed NDA records, including the signed PDF and audit certificate, are retained for at least 5 years after the user's last interaction with the project, unless a longer period is required by law, litigation hold, or contractual defence. Access requests that do not result in a signed NDA are retained for a maximum of 12 months from submission date to allow for re-evaluation, then securely deleted. If you request earlier deletion, we will assess that request against our legal preservation obligations.

06

Third-party sharing

We do not sell, rent, or share your personal data with third parties for marketing purposes. Data may be disclosed:

  • To legal counsel, solely for the purpose of reviewing, signing, or enforcing the bilateral NDA;
  • To infrastructure providers that host the self-hosted DocuSeal stack, storage, and email delivery, under appropriate data-processing arrangements and with access limited to the minimum necessary;
  • As required by law, regulation, or valid court order — with prior notice to you where legally permitted.
07

Your rights

Depending on your jurisdiction, you may have the right to access, correct, erase, or restrict processing of your personal data; to object to processing; and to data portability. To exercise any of these rights, write to [email protected] with the subject line Privacy request and a description of your request. We will respond within 30 days.

If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the supervisory authority in your jurisdiction.

08

Cookies and tracking

This site does not use analytics cookies, advertising cookies, or any third-party tracking scripts. No telemetry is collected from visitors. Session state within the NDA gateway is maintained in memory only and is not persisted beyond the browser session.

09

Changes to this policy

Material changes to this policy will be posted at this URL with an updated effective date. If changes affect how we process data you have already submitted, we will notify you directly at the email address provided.

Questions or requests: [email protected] · data protection: [email protected] · response within 30 days. © 2026 auriglyph.