Skip to content

COUNTERSIGNED / LEGAL

Privacy statement

What we collect, why we need it, and the choices you have about your information.

Effective and last updated

AT A GLANCE

Your agreements belong to you. Hoss, Inc. uses your information to provide and protect Countersigned. We do not sell personal information or use your documents to train AI. Sharing a company with DocuPipe does not automatically share your documents with that service.

Who we are and what this covers

Hoss, Inc. (“Hoss,” “we,” “us,” or “our”) owns and operates Countersigned and DocuPipe. This Privacy Statement describes how we handle personal information when you visit Countersigned, use a workspace, receive an invitation, sign an agreement, or contact us. It applies to recipients even when they do not have a Countersigned account.

Hoss is responsible as a controller for account administration, service security, and its own communications. When a customer sends agreements containing personal information, we generally process that content on the customer’s instructions; the sender or their organization is responsible for the purpose and lawful basis of the transaction. Our role depends on the processing involved and applicable law.

For questions about why a document was sent, its content, or the sender’s use of your information, contact the sender. You can also contact us at privacy@docupipe.ai. This statement covers Countersigned; DocuPipe’s separate privacy notices apply when you use DocuPipe.

Information we collect

  • Account and profile information: name, email address, account identifiers, preferences, and any profile image or reusable signature you choose to save.
  • Agreement content: uploaded PDFs, templates, recipient names and email addresses, messages, field values, attachments, and typed, drawn, or uploaded signatures. A sender or another participant may provide information about you.
  • Signing evidence: agreement and recipient identifiers, consent version and time, signing and viewing events, other agreement activity, and document, signature, and field-value hashes used for integrity checks. Events may include an IP address and browser or device information.
  • Technical information: request timestamps, browser user-agent information, IP addresses, authentication events, errors, and operational logs used to run and protect the Service.
  • Communications: information you provide in support, privacy, security, or other correspondence.

The sensitivity of agreement content depends on what participants upload. Supply only information needed for your transaction. Countersigned does not currently collect payment-card information through the application. If you arrange a paid plan with Hoss, we may process business contact and billing information needed to manage that relationship.

How we use information

We use information to provide account access; prepare and route agreements; deliver invitations, reminders, and completion messages; capture consent and signatures; generate and retain completed documents and signing evidence; make authorized downloads available; and respond to requests.

We also use account and technical information to diagnose errors, maintain reliability, prevent fraud and abuse, investigate security issues, enforce our terms, and comply with law. We may send operational notices about your account or the Service. Where we send optional promotional communications, you can opt out through the message or by contacting us.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use agreement content, signatures, or attachments for advertising or to train artificial intelligence or machine learning models.

Who can access information

  • Agreement participants: the sender and authorized recipients can receive the agreement, completed document, attachments made available to them, and signing evidence. A completion record may include participant names, emails, signatures, timestamps, IP addresses, and browser information. Recipients can retain or share downloaded copies themselves.
  • Service providers: we use providers to host and store data, authenticate users, and deliver email. The hosted Countersigned service uses Amazon Web Services for these functions. Providers process information as needed to supply their services to us.
  • Authorized Hoss personnel: we may access information as necessary to operate or support Countersigned, respond to your requests, investigate abuse or security issues, or meet legal obligations.
  • Legal and safety recipients: information may be disclosed when required by applicable law or valid legal process, or as necessary to protect legal rights, safety, and the security of the Service.
  • Business successors: information may be transferred in a merger, acquisition, reorganization, or sale involving Countersigned, subject to applicable privacy obligations.
  • People you authorize: we may disclose information when you direct us to do so or give consent.

Invitations and download links can grant access to sensitive information. Keep them private. We cannot control the separate privacy practices of agreement participants or retrieve copies they have already downloaded.

DocuPipe and AI features

Countersigned and DocuPipe are both owned by Hoss, Inc. They are separate services. Opening a link to DocuPipe does not send your Countersigned documents to DocuPipe, connect your accounts, or begin AI processing.

The document-AI demonstrations on the Countersigned website use example documents and results. Integrated AI extraction is not currently part of the Countersigned signing service. If we introduce an integration, we will explain what information it uses and the choices available before you use it.

Our privacy and support email addresses use the DocuPipe domain because they belong to our shared company. Contacting those addresses about Countersigned does not enroll you in DocuPipe.

Cookies and browser storage

Countersigned uses essential cookies to support account sign-in, maintain a session, and authorize access to invitations protected by an access code. We also use local browser storage to remember workspace display preferences, such as your agreement-list columns. These technologies support service functionality and security. The current Countersigned application does not use advertising cookies, third-party analytics trackers, or session-replay tools.

You can block or delete cookies through your browser settings. Doing so may prevent sign-in or protected signing links from working. Browser privacy signals do not disable cookies necessary to provide a service you request. If we introduce optional tracking, we will update this statement and provide choices or obtain consent where required.

How long we keep information

We retain information for as long as reasonably needed to provide Countersigned, preserve agreement records for authorized participants, meet legal obligations, resolve disputes, and protect against fraud or abuse. The period depends on the type of information, the transaction, applicable law, and deletion requests. We do not promise indefinite storage or a single automatic deletion deadline for every agreement.

Moving an agreement to Deleted is a reversible workspace action. It does not permanently erase the underlying files, signatures, audit history, or another participant’s records. Ask for permanent deletion or account closure at privacy@docupipe.ai. We assess requests subject to identity verification, the sender’s instructions where applicable, legal requirements, and other participants’ rights.

Backup copies, stored object versions, and security records may remain after removal from active use where necessary for recovery, security, or legal purposes. Those copies are not made available for ordinary use. Copies already downloaded by other parties are controlled by those parties. Download the agreements and completion records you need for your own recordkeeping.

Security, storage, and transfers

The hosted Countersigned configuration uses HTTPS for connections, private document storage with encryption at rest, authenticated owner access, and recipient-specific invitation links. The Trust Center explains these controls and their limits. No transmission or storage method is completely secure.

Countersigned’s cloud infrastructure is configured in the United States. Information may also be processed where our authorized personnel or providers operate. Privacy laws in those locations may differ from the laws where you live.

Where applicable law requires safeguards for an international transfer, those safeguards must be in place for that transfer. Contact privacy@docupipe.ai about processing locations, a data processing agreement, or transfer arrangements for your organization before submitting information subject to such requirements. This statement does not itself create a data processing agreement or certify that a particular transfer mechanism covers your use.

Your privacy rights and choices

Depending on your location and applicable law, you may have rights to access, correct, delete, or receive a portable copy of your personal information; restrict or object to processing; and withdraw consent for future processing based on that consent. Withdrawal does not affect processing that was lawful before it. You may also complain to your local data protection authority.

California and other US state residents may have rights to learn what personal information is collected and disclosed, request access, correction, or deletion, use an authorized agent, appeal a decision where applicable, and exercise rights without unlawful discrimination. We do not sell personal information, share it for cross-context behavioral advertising, or use sensitive personal information to infer personal characteristics.

Send a request or appeal to privacy@docupipe.ai with “Countersigned” in the subject. Tell us the email address involved and the nature of your request; do not send your password or signing link. We may request proportionate information to verify your identity or an agent’s authority and will respond within the time required by applicable law.

If your request concerns an agreement controlled by a sender, we may refer it to or coordinate with that sender. Some information may be retained where an exception applies, such as legal obligations or the establishment, exercise, or defense of legal claims. We will explain applicable limitations in our response.

You can update available profile information in your workspace and download agreements you are authorized to access. For a different signing method or changes to an agreement, contact its sender.

Children’s information

Countersigned is intended for adults and is not directed to children under 18. We do not knowingly offer accounts to children. If you believe a child has provided information directly to Countersigned without appropriate authorization, contact privacy@docupipe.ai so we can investigate and take appropriate action.

Customers are responsible for having the authority and lawful basis to include another person’s information, including a minor’s information, in an agreement.

Changes and how to contact us

We may update this statement to reflect changes in Countersigned or legal requirements. The effective and last-updated date is shown above. We will provide appropriate notice of material changes and obtain consent where required by law.

Contact Hoss about Countersigned privacy, security, or data requests using the details below. Our shared company contact addresses use the DocuPipe domain.

Hoss, Inc.
145 W 67th St, New York, NY 10023, United States
Privacy and legal: privacy@docupipe.ai
Countersigned support: countersigned@docupipe.ai