01 — Introduction and scope

This Privacy Policy (“Policy”) explains how personal data is collected, used, stored, shared, and protected in connection with the Requests Signer mobile application and this website (together, the “Services”).

Requests Signer lets authorised users review internal operational requests and approve or decline them using a hardware Ledger device (or a limited demo mode for review). By using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.


02 — Data controller

Product Requests Signer
Website
Contact

03 — Personal data we collect

3.1 Account and authentication data

  • Identifiers and credentials used to authenticate against our signing backend (for example session tokens, user or organisation identifiers returned by the API).
  • Where demo / review login is used: the username and password you submit for that limited mode.
  • Ledger-related identifiers shown or stored for the connected device (such as address or device selection state needed to route requests).

3.2 Request and signing activity

  • Contents of operational requests presented in the app for approval or decline.
  • Your approve / decline actions and related status information.
  • Technical details of the signing flow (connection stage, success or error outcomes). Private keys remain on the Ledger hardware; the app does not extract seed phrases or private keys from the device.

3.3 Device, permissions, and notifications

  • Device type, OS version, and app version.
  • Bluetooth usage for Ledger discovery and connection (permission required on supported platforms).
  • Camera access when you scan a QR code to authenticate or pair a Ledger.
  • Push notification tokens and notification payload metadata (for example request identifiers) when push is enabled via our notification provider.

3.4 Website and feedback

  • Information you submit through the feedback form (name, email, topic, message).
  • Basic technical logs that may be generated by our hosting provider (such as IP address and request timestamps) when you visit this website.

04 — How we collect personal data

  • Directly from you — authentication, demo login, feedback form, and in-app actions.
  • From your device — permissions you grant, device metadata, and push tokens.
  • From our backend and providers — request lists, auth responses, and notification delivery services operating on our behalf.

05 — Purposes of processing

  • Provide and operate request review and Ledger-backed signing.
  • Authenticate users and maintain session security.
  • Deliver operational notifications about pending or updated requests.
  • Support demo / review access where enabled.
  • Respond to feedback and support requests.
  • Maintain security, diagnose faults, and improve reliability.
  • Comply with legal obligations and enforce acceptable use of the Services.

06 — Legal bases

Depending on applicable law, we rely on one or more of:

  • Contractual necessity — to provide the Services you request.
  • Legitimate interests — security, abuse prevention, and service improvement, balanced against your rights.
  • Consent — where required for optional permissions (for example notifications) or certain website technologies.
  • Legal obligation — where processing is required by law.

07 — Sharing and disclosure

We may share personal data with:

  • Infrastructure and API providers that host or operate the signing backend.
  • Push notification providers (for example OneSignal / Firebase Cloud Messaging) to deliver alerts.
  • Website hosting and form delivery providers that process feedback submissions.
  • Professional advisers and authorities when required by law or to protect rights and safety.

We do not sell your personal data.


08 — International transfers

Providers may process data in countries other than your own. Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms recognised under applicable law.


09 — Retention

Category Typical retention
Account / session data For the duration of active use, then deleted or anonymised when no longer needed for security or legal purposes
Request and signing activity As required to operate the Service and meet organisational audit or legal requirements
Push tokens Until you disable notifications, uninstall the app, or the token is replaced
Feedback submissions As long as needed to handle your request, then archived or deleted
Website logs Short periods typical for hosting security (often up to 12 months unless investigating an incident)

10 — Security

We use technical and organisational measures appropriate to the nature of the Services, including transport encryption, access controls, and hardware-backed signing on Ledger for approval operations. No method of transmission or storage is perfectly secure.


11 — Your rights

Subject to applicable law, you may have rights to access, correct, delete, restrict, or object to processing of your personal data, and to withdraw consent where processing is consent-based. Contact us at . You may also lodge a complaint with a supervisory authority in your jurisdiction.


12 — Children

The Services are intended for authorised adult users in a business context and are not directed to individuals under 18. We do not knowingly collect personal data from minors.


13 — Third-party services

The app may interact with Ledger devices and third-party SDKs (for example Bluetooth, camera, and push). Those parties’ practices are governed by their own policies when they act as independent controllers.


14 — Updates

We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated in-app or on this website. Continued use after an update constitutes acceptance where permitted by law.


15 — Contact

Questions about this Policy or your personal data:

© Requests Signer. All rights reserved.