Legal
Terms of Use – Handsal
Last updated: 20th of January 2026
1. Acceptance of Terms
By using Handsal, you agree to be bound by these Terms of Use. If you do not agree, you must not use the service. Handsal is operated by Handsal ApS, headquartered at Hammerensgade 1, 2. th, 1267 København K, Denmark.
These terms govern your access and use of the Handsal platform, including our website, mobile applications, and services related to digital signing and contract management.
2. Service Overview
Handsal provides electronic signature services. Unless otherwise specified, signatures are issued as Advanced Electronic Signatures (AES) in accordance with the EU eIDAS Regulation. It is the user's responsibility to ensure that the chosen signature level meets the specific legal requirements for their document type.
Handsal also offers contract management tools tailored for individuals, sole traders and SMEs, including document storage, audit trails, and features for advisor collaboration.
Handsal operates fully within the European Union, ensuring compliance with EU legislation, including eIDAS and the GDPR.
3. Account Registration and Responsibilities
To use Handsal, you must register an account. You agree to provide accurate information and to keep it updated. You are responsible for maintaining the confidentiality of your login credentials and for all activity that occurs under your account.
You may not use another user's account without permission. Handsal is not liable for any loss or damage resulting from your failure to comply with this obligation.
4. Usage Rights and Restrictions
Handsal grants you a non-exclusive, non-transferable license to use our platform for lawful purposes. You must not:
- Use the service for illegal or unauthorized purposes
- Tamper with, modify, reverse-engineer, or decompile the software
- Transmit malware or harmful code
- Interfere with or disrupt the service or servers
5. Subscriptions, Billing and Payments
You may subscribe to Handsal services via a monthly or annual plan. Pricing is based on user tiers and available on our website. Handsal may adjust pricing with at least 30 days' notice via email. Continued use of the service after the price change takes effect constitutes acceptance of the new pricing.
For any paid subscription:
• Fees are billed in advance
• Subscription renews automatically unless canceled
• Failed payments may result in account suspension
You may cancel at any time, and the service will remain active until the end of your current billing period. No refunds are offered unless required by law.
6. Fair Usage Policy
To ensure service quality, Handsal reserves the right to enforce fair usage limits. Excessive or abusive use may lead to account suspension or require migration to a higher-tier plan.
We define fair use in accordance with our pricing structure and standard usage expectations for SMEs.
7. Advisor Access
Advisors may access their clients' documents and dashboards only with client permission. The user maintains full control over advisor access. Handsal disclaims any liability for unauthorized data disclosure resulting from the user's failure to revoke an advisor's access permissions or the advisor's breach of confidentiality.
8. Document and Data Ownership
You retain ownership of all documents and data uploaded. Handsal does not claim any rights to your content.
You grant us a limited license to store, display, and process your content solely to provide our services.
By accepting these Terms, you also accept the Handsal Data Processing Agreement (DPA), which forms part of these Terms. The DPA governs our processing of personal data on your behalf as a data processor.
9. Third-party Integrations
Handsal integrates with external services such as MitID, BankID, SK ID Solutions (e-identity and digital signing), Microsoft Azure, GlobalSign (for timestamping), and Stripe (for payments).
Your use of these services is subject to their respective terms. Handsal is not responsible for issues resulting from third-party services.
10. Support and Service Levels
Handsal aims to maintain 99.5% uptime and provide support during business hours via email and chat. Premium users may access priority support.
We reserve the right to suspend services for maintenance with reasonable notice.
11. Termination
You may terminate your account at any time. Handsal reserves the right to suspend or terminate access for violations of these Terms, including misuse, non-payment, or unlawful activity.
Upon termination, we may retain your documents for up to 90 days unless otherwise required by law.
12. Limitation of Liability
Handsal is not liable for: (i) the legal validity or enforceability of documents signed through the service in specific jurisdictions, (ii) loss of data due to unauthorized access, or (iii) any indirect loss, including loss of business or profit.
Force Majeure: Handsal shall not be liable for failures caused by circumstances beyond our control, including but not limited to cyber-attacks (DDoS), infrastructure failures at third-party providers (e.g., Azure or MitID), or legislative changes.
To the extent permitted by law, Handsal disclaims liability for any other indirect, incidental, or consequential damages arising from the use or inability to use the service. Our total liability shall not exceed the amount paid by you in the 12 months prior to the claim.
13. Changes to Terms
We may update these Terms periodically. You will be notified of significant changes via email or within the platform.
Continued use of the service after changes constitutes acceptance.
14. Governing Law
These Terms are governed by the laws of Denmark and any dispute shall be subject to the exclusive jurisdiction of the Danish courts.
Privacy Policy – Handsal
Last updated: 20th of January 2026
1. Introduction
This Privacy Policy describes how Handsal ApS ("Handsal", "we", "us", "our") collects, uses, and protects your personal data when using our digital signing and contract management services.
We respect your privacy and comply with the General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following categories of personal data:
- Identity data: name, email, role
- Authentication data: IP address, device identifiers, MitID/BankID session information
- Contract data: files, audit logs, timestamps
- Billing data: invoices, payment method (processed via Stripe)
- Usage data: login times, feature usage, support interactions
3. How We Use Your Data
Your data is used to:
• Provide our services (signing, storage, and audit trails)
• Authenticate users securely
• Process subscriptions and payments
• Communicate updates and support
• Improve our service via anonymized analytics
We do not sell or rent your data to third parties.
4. Legal Basis
We process data on one or more of the following legal bases:
• Consent (e.g. newsletter signup)
• Contractual obligation (providing access to the platform)
• Legitimate interest (improving services, ensuring security)
• Legal obligation (retention for tax or regulatory compliance)
5. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services.
Upon termination, your data is retained for up to 90 days unless otherwise required by law.
6. Data Sharing and Processors
We use the following sub-processors:
• Microsoft Azure (hosting)
• Auth0 (user authentication)
• Stripe (billing)
• GlobalSign (timestamping)
• Idura (BankID/MitID signing)
• SK ID Solutions (timestamping and eIDAS)
All sub-processors are GDPR-compliant and process data only under our instructions.
7. International Transfers
Handsal primarily stores and processes data in the EU. Any transfer outside the EU/EEA follows standard contractual clauses approved by the European Commission.
8. Your Rights
Under the GDPR, you have the right to:
• Access your data
• Correct or delete your data
• Object or restrict processing
• Request data portability
• Withdraw consent (where applicable)
To exercise these rights, contact: [email protected]
9. Security
We employ industry-standard security measures:
• HTTPS encryption
• Two-factor authentication
• Audit trails for access and changes
• Regular security reviews
10. Cookies
We use cookies for functional and analytical purposes. You can adjust your preferences at any time through our cookie settings or your browser.
11. Children's Privacy
Handsal is not intended for children under the age of 18. We do not knowingly collect data from minors.
12. Contact
For questions about this policy, contact:
Handsal ApS, Hammerensgade 1, 2. th, 1267 København K, Denmark
GDPR Policy for Handsal
Last updated: 20th of January 2026
At Handsal, your privacy and trust are at the heart of everything we do. We are committed to protecting your personal data and ensuring transparency in how we process it. This policy outlines what data we collect, how we use it, and your rights under the EU's General Data Protection Regulation (GDPR).
1. Who We Are
Handsal is a digital signing and contract management platform operated by:
Handsal ApS
Hammerensgade 1, 2. th, 1267 København K, Denmark
Email: [email protected]
CVR: 45683621
We are the Data Controller for the personal data we process, unless otherwise stated (e.g., when a customer organization is the controller and Handsal acts as processor).
2. What Personal Data We Collect
Depending on your use of Handsal, we may collect the following categories of personal data:
- Account Information: Name, email address, company name, phone number, language preferences and time zone, login credentials (stored as encrypted hashes)
- Document & Signing Data: Names and emails of signers and recipients, signing metadata (e.g., time, IP address, authentication method used), documents uploaded to the system (note: Handsal does not read document contents unless required for support or legal reasons)
- Usage & Device Information: Device type, operating system, browser, IP address and general location, interactions with the platform (e.g., clicks, navigation paths, login times)
- Payment and Subscription Data: Billing name and address, VAT number (for business accounts), payment confirmations (via Stripe – we don't store credit card details directly)
- Communication Data: Emails or support messages, marketing preferences
3. How We Collect Personal Data
We collect personal data in the following ways:
• Directly from you: When you sign up, use our services, or contact support
• Automatically: When you use the platform (cookies, session data)
• From third parties: Such as your employer (if they invite you), or identity verification services (BankID, MitID, etc.)
4. Why We Process Your Data (Legal Basis)
Under the GDPR, we must have a legal basis for processing your data. These include:
| Legal Basis | Example |
|---|---|
| Contractual necessity | To create and manage your account, deliver services |
| Consent | For optional features like marketing emails |
| Legal obligation | To comply with tax and accounting rules |
| Legitimate interest | To improve our service and prevent fraud |
5. How We Use Your Personal Data
We use your data to:
• Provide and maintain the Handsal platform
• Authenticate users and manage access
• Facilitate signing workflows
• Notify users of signing requests and updates
• Handle support inquiries
• Comply with legal obligations
• Analyze platform usage for improvements
• Send service-related and optional marketing messages (only if opted in)
We never sell your data.
6. Data Retention
We retain personal data:
• For active users: As long as you use the service
• For contracts and documents: As agreed or required by law (e.g., bookkeeping rules)
• For audit trails: For as long as required to prove legal compliance
• For support and billing: Up to 5 years in accordance with local tax laws
You can request deletion of your account at any time.
7. Where Data Is Stored & Transferred
• Handsal hosts all data within the EU (primarily in Microsoft Azure data centers).
• Some services, like payment processing (Stripe), may involve data processors outside the EU.
• All data transfers are made with appropriate safeguards, including Standard Contractual Clauses (SCCs) where necessary.
8. Subprocessors
We work with trusted subprocessors such as:
• Microsoft Azure – hosting infrastructure
• Stripe – payment processing
• Auth0 (Okta) – authentication
• Idura – identity verification (e.g., BankID/MitID)
• SK ID Solutions – timestamping and eIDAS
• SendGrid – email dispatch
All subprocessors are bound by strict data processing agreements in line with GDPR requirements.
9. Your Rights Under GDPR
As an EU resident, you have the following rights:
• Right to access – You can request a copy of your data
• Right to rectification – Fix incorrect or incomplete data
• Right to erasure ("right to be forgotten")
• Right to restrict processing
• Right to data portability
• Right to object – Especially in marketing use
• Right not to be subject to automated decisions without consent
To exercise your rights, email: [email protected]. We aim to respond within 30 days.
10. Security Measures
We implement technical and organizational security practices including:
• Data encryption at rest and in transit
• Role-based access control (RBAC)
• Regular audits and penetration testing
• Two-factor authentication (2FA)
• Secure logging of all data access and signing events
11. Cookies and Tracking
We use cookies for:
• Session management
• Language and preference settings
• Analytics: We may use analytics tools to understand platform usage. Any data collected is anonymized. We will update this policy if a specific tool is introduced.
You can manage cookie preferences at any time.
12. Data Breaches
In case of a serious data breach affecting your rights and freedoms, we will:
• Notify the relevant data protection authority within 72 hours
• Notify you as a user if necessary under GDPR Article 34
Data Processing Agreement (DPA) – Handsal ApS
Last updated: 20th of January 2026
Appendix 1: Description of Processing (The "Hard" Facts)
This appendix is what most IT lawyers look for first. It defines precisely what happens in the "engine room":
| Subject | Description |
|---|---|
| Categories of Data Subjects | Users, employees of the Controller, signatories (counterparties), and authorized advisors. |
| Types of Personal Data | Name, email address, IP address, phone number, MitID/BankID log data (for verification), and any personal data contained within uploaded documents. |
| Nature of Processing | Collection, storage, organization, structuring, retrieval, and digital signing of documents. |
| Data Location | All primary data is stored within the European Economic Area (EEA) via Microsoft Azure. |
1. Purpose and Scope
This DPA applies to the processing of personal data by Handsal ApS ("Processor") on behalf of the User ("Controller") when using the Handsal platform. This agreement ensures that the Processor complies with the requirements of the GDPR.
2. Instructions
The Processor shall only process personal data in accordance with the Controller's documented instructions. The Controller's use of the Handsal platform (uploading documents, initiating signings, managing advisors) constitutes the primary instruction.
3. Security of Processing
The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Encryption: Data is encrypted during transit (TLS) and at rest (AES-256).
Access Control: Access to data is restricted to authorized personnel only.
Confidentiality: All personnel authorized to process personal data have committed themselves to confidentiality.
4. Use of Sub-processors
The Controller grants the Processor a general authorization to engage sub-processors. The current list of sub-processors includes:
• Microsoft Azure (Cloud Infrastructure – EU regions)
• Stripe (Payment Processing)
• GlobalSign (Digital Certificates/Timestamping)
• MitID/BankID via Idura (Identity Verification)
• SK ID Solutions (timestamping and eIDAS)
• Auth0 – user authentication
• SendGrid – email dispatch
The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, giving the Controller the opportunity to object.
5. Data Subject Rights
The Processor shall assist the Controller, where possible, in fulfilling obligations to respond to data subject rights requests (e.g., access, rectification, or erasure).
6. Personal Data Breach
In the event of a personal data breach, the Processor shall notify the Controller without undue delay after becoming aware of the breach.
7. Audit and Inspection
The Processor shall make available to the Controller all information necessary to demonstrate compliance with Art. 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
8. Termination and Deletion
Upon termination of the service, the Processor shall delete or return all personal data to the Controller after a retention period of 90 days, unless EU or Member State law requires storage of the personal data.
Handsal Trust Center
Last updated: 20th of January 2026
Security, transparency and trust are the foundation of every handshake.
At Handsal, the security of your documents, agreements and personal data is our highest priority. We have combined classic Nordic trust with modern, enterprise-grade technology. The result is a platform where digital agreements are not only fast, but also legally indisputable, technically unalterable and always available to you and your business. We take care of your data so you can focus on running your business.
1. Legal Validity & Identification
Handsal is developed to meet the highest requirements for digital identification, ensuring that a digital handshake in our system is as binding as one on paper.
Signing with BankID & MitID: We use the most widely recognised and secure identification solutions in the Nordics. By integrating directly with BankID and MitID, we verify the identity of every signer with certainty. This means you always have full certainty about who has signed and when.
eIDAS Compliance: Handsal complies with the EU's eIDAS regulation on electronic signatures. We use advanced electronic signatures (AES) that are legally recognised throughout the EU, making your agreements and contracts legally valid across borders.
Qualified Electronic Seal (eSeal): To guarantee document authenticity, Handsal applies a digital company seal to all completed agreements. This seal acts as a digital wax seal that proves the document's origin and ensures the content has not been tampered with after the last signature.
GDPR & Data Protection: We know that contracts contain confidential information. Therefore, all data is processed in strict accordance with GDPR. Your documents and sensitive personal information are stored securely and are never transferred to servers outside the EU.
2. Technical Integrity & Irrefutable Evidence
A document in Handsal is more than just a PDF – it is a complete package of digital evidence that is technologically locked.
Long-Term Validation (LTV) & Timestamping: To ensure your documents remain valid for many years, we apply a qualified digital timestamp. This timestamp is independent of the signer's certificate, meaning the agreement can be verified as valid even if a BankID or MitID expires or is replaced in the future.
Advanced Cryptographic Hash Validation: Each document is assigned a unique digital fingerprint (a hash value). This value is mathematically bound to the content. If so much as a single comma is changed in the document after signing, the digital seal will break, and any PDF reader will warn that the document is no longer intact.
Comprehensive Audit Log: We log the entire process. From the moment a contract is sent until it is signed by all parties, a detailed audit log is generated. This log contains precise timestamps (UTC), IP addresses and verified identity data that can be used as evidence in case of dispute.
3. Infrastructure, Operational Security & Validation
We have built an infrastructure designed to support SMEs' needs for stability and independence.
Secure European Hosting: Handsal is hosted in certified, highly secure data centres within the EU. Our infrastructure runs across multiple locations, so your data is never lost due to technical failures.
24/7 Monitoring & Status: We monitor the platform's performance and security around the clock. Our target is 99.5% uptime so you can always send and sign documents when you need to.
Platform Independence: It is important to us that you own your own evidence. All documents from Handsal follow the international PAdES standard. This means you do not need Handsal to prove the agreement's validity – the document can be verified independently in Adobe Reader or via official EU validation tools.
Want to verify the integrity of a document?
If you have received a signed document from Handsal and want to confirm that it has not been altered and that the signatures are valid, you can use our validator. Here you upload the file, and our system instantly checks the digital fingerprint and confirms the document's integrity.