Privacy policy
Last updated 29 July 2026
We store the documents you upload, who you sent them to, and what happened to them. We do not sell any of it, we do not use it to train models, and we do not read your documents.
The short version
Baton exists to move documents between people, so the data we hold is the documents and the people. We do not sell it, share it for advertising, or use it to train machine-learning models. Nobody at Baton reads your documents; the only automated processing is extracting their text so that you can search them, which happens inside our own systems.
The rest of this page is the specific version. If something here is unclear, ask us before you rely on it.
Who is responsible
[LEGAL ENTITY NAME], of [REGISTERED ADDRESS], is the controller for account data and the processor for the documents you upload. For those documents, your organization is the controller: you decide what to upload, who to send it to, and how long to keep it.
Contact for any privacy question, including the requests described below: [PRIVACY CONTACT EMAIL].
What we collect
Because you gave it to us
- Your account. Name, email address, and an optional profile image. There is no password, because sign-in is a code sent to your email.
- Your organization. Its name, the people in it, their roles, and optionally the team each person belongs to.
- Your documents. The files you upload and everything inside them. Also the text extracted from them, which is what makes search work.
- Your recipients. The name and email address of everybody you send a document to, including people who have no Baton account.
- Signatures. The drawn or typed signature image, and the name typed alongside it.
Because the record would be worthless without it
- IP address and browser user agent, recorded at the moment a document is opened, signed, approved, declined or downloaded.
- Timestamps for every one of those events.
This is evidence, not analytics. It is what makes a signature stand up if it is ever questioned, and it is why it appears on the certificate page attached to the signed document. It is not used to profile anybody and it is not combined with anything else.
Because a server has to keep logs
Ordinary operational logs: request paths, error traces, and the counters behind our rate limits. These are kept for a short period for reliability and abuse prevention, and are not used to build a picture of any individual.
What we do not collect
- No advertising or cross-site tracking cookies. The only cookie Baton sets is the one that keeps you signed in.
- No third-party analytics on the application.
- No payment details, because there is nothing to pay for.
- No special-category data is asked for. If your documents contain it, such as a safeguarding file or a health record, it is processed as document content and we never inspect it.
Why we are allowed to hold it
Where the UK GDPR or EU GDPR applies, our lawful bases are: contract, for everything needed to provide the service you asked for; legitimate interests, for security, abuse prevention, and the integrity of the audit record; and legal obligation, where we are required to retain something. We do not rely on consent for anything described here, which is why there is no consent banner to dismiss.
How long we keep it
- Documents you delete stay recoverable for a window your organization chooses: thirty days by default, at least one day and at most a year. After that the file is permanently destroyed.
- The audit record survives the file. When a document is destroyed, a tombstone remains: the sequence of events, the hashes, and the certificate. Without it, deleting a document would also delete the proof of what was signed, which would make the record useless for exactly the situations it exists for.
- Accounts and organizations are kept while the organization is in use, and removed on request.
- Sign-in codes expire in ten minutes.
- Signing links stop working when used, when the document finishes, or when they expire.
Who else processes it
As few parties as we can manage. Every one of these is under a data processing agreement and none of them is permitted to use your data for their own purposes.
- Hosting and application infrastructure: [HOSTING PROVIDER], in [REGION].
- Database and object storage: [DATABASE / STORAGE PROVIDER], in [REGION].
- Transactional email: Resend, which delivers sign-in codes, signing invitations, reminders and outcome notices. It necessarily sees recipient email addresses and the subject and body of those messages. It does not receive your documents.
- Document summaries (optional, off unless an administrator turns it on): Anthropic, which runs the model that writes the summary. It receives the text and title of the document being summarised. It does not receive names, email addresses or signature images.
- Search by meaning (optional, off unless an administrator turns it on): Voyage AI, which converts document text into the numerical form that makes searching by meaning possible. It receives document text in passages, for documents as they arrive, while the feature is on. It does not receive names, email addresses or signature images.
Scanned documents are read on our own machines. The text recovered from a scan is treated like any other document text, but the page image itself — which contains signatures — is never sent to anybody.
There is no analytics vendor, no advertising network and no customer-messaging widget.
The two AI processors above read document text only while an administrator has turned the feature on, and only for the organization that turned it on. Every request is recorded — what it was for, when, and what it cost — so an administrator can always answer what was sent and when.
Where it goes
Data is processed in [REGION]. Where a transfer leaves the UK or EEA, it relies on the UK International Data Transfer Addendum or the European Commission’s Standard Contractual Clauses, as applicable.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to our processing, receive it in a portable form, and complain to a regulator. To exercise any of them, write to [PRIVACY CONTACT EMAIL]. We will respond within one month.
One honest limitation. Erasure cannot remove an entry from the audit chain, because removing a link from a hash chain destroys the integrity of everything after it, because the same property that makes the record trustworthy is what makes it unremovable.
What we do. Everywhere your identity is held in a form we can change, we replace it with a reference that does not identify you, and the same reference each time, so records stay coherent while you do not. That covers your account, every recipient record, every delivery record and any pending invitation, and your drawn signature image is destroyed outright rather than replaced, because it is a reproduction of your handwriting.
What remains, and why. The audit entries themselves keep the address that was recorded at the time. Those entries are hashed into a chain where each one commits to the one before it, so changing any of them destroys the integrity of every entry after it, which is the property that makes a signature on those documents provable at all. We keep them on the basis of the legitimate interest in the integrity of a signature record, which UK and EU data protection law contemplates as an exception to erasure.
When we complete an erasure we will tell you exactly how many audit entries remain and on which documents, rather than reporting it as complete. We would rather give you a number you can check than a reassurance you cannot.
If you are a recipient rather than an account holder, meaning somebody who was sent a document to sign, the organization that sent it to you is the controller of that document. Ask them first; write to us and we will help you reach them.
If something goes wrong
If a breach affects your personal data and is likely to present a risk to you, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and we will tell you directly and promptly rather than waiting to be asked.
Children
Baton is for organizations and is not directed at children. We do not knowingly create accounts for anyone under 16. Documents an organization sends may concern a child, such as a school consent form or a safeguarding record, and that content is processed on the organization’s instructions as described above.
Changes
When this policy changes materially we will email account holders and update the date at the top. We will not make a material change quietly and rely on you re-reading the page.
Related reading: the security page describes the mechanisms behind these commitments, and the terms of service set out the agreement itself.
Questions about this document? Start here, or write to us at the address in the text above.

