This policy explains which personal data Ravisign processes, for what purpose, on which legal basis, for how long and how data subjects can exercise their rights, under Brazilian Law 13.709/2018 (General Personal Data Protection Law, LGPD).
1. Who we are
Ravisign is a service of Ravi Systems LTDA, a Brazilian company that develops software for internet providers and other businesses. This policy applies to the ravisign.com.br website, the dashboard, the signing page, the public validator and the Ravisign API.
2. Controller and processor
For account registration data, dashboard users and website visitors, Ravi Systems is the controller: it decides how and why such data is processed.
For signers' data and document content, the Ravisign customer decides to send the document and to whom, and is therefore the controller. Ravi Systems acts as processor, handling such data only to provide the signing service, according to the customer's instructions. Requests about such data should first be addressed to the customer that sent the document; Ravi Systems helps the customer respond to them.
3. Data we process
Customers and users: company name, tax ID, name, email, phone, language, access credentials (the password is stored only as an irreversible digest), access logs and logs of administrative actions.
Signers: name, email, phone, individual or company tax ID when provided by the customer, drawn or typed initials, and the signature evidence data: date and time, IP address, device and browser, confirmation code channel and, if the signer consents, the device geolocation. When required by the customer, also a selfie and a photo of the identity document.
Website and validator visitors: IP address and technical access data, kept as connection logs, plus language and theme preferences. A PDF submitted to the validator for checking is processed on the spot and is not stored.
4. Purposes and legal bases
Providing the subscribed service, creating and maintaining the account, sending invitations, codes and signed copies: performance of a contract and preliminary procedures (art. 7, V, LGPD).
Recording the signature evidence in the audit trail and keeping it to prove the authorship and integrity of the document: regular exercise of rights in judicial, administrative or arbitration proceedings (art. 7, VI) and, for connection logs, compliance with a legal obligation (art. 7, II, and Law 12.965/2014).
Collecting device geolocation: the signer's consent (art. 7, I), requested by the browser at signing time, which can be denied or revoked in the device settings.
Selfie and ID photo, when required by the customer: ensuring fraud prevention and the data subject's security in identification and authentication processes (art. 11, II, g), since such data may be considered biometric.
Protecting the platform against abuse and fraud, limiting attempts and maintaining security: legitimate interest (art. 7, IX), always respecting the rights and expectations of data subjects.
5. Audit trail
Each envelope event is recorded with date and time in UTC, IP, device and the signer identifier, and seals the previous record with a SHA-256 digest. The trail table is append-only: changes and deletions are refused. Once a day, the last record receives a timestamp, proving the history was not rewritten.
The trail never stores name, email, phone, tax ID, selfie or document: only the signer's internal identifier. Personal data stays in the signer record, encrypted with the account key when sensitive. That is why the trail can remain even after personal data has been deleted.
6. Selfie and identity document
Collection of selfies and ID photos is off by default and only happens when the customer requires it for an envelope. Images are encrypted with the account key, accessible only to the customer's authorized users, and deleted automatically 90 days after the envelope is completed, or within the period the customer configures.
7. Sharing
Ravi Systems does not sell personal data. Data may be shared with the customer that sent the document and with the other signers of the same envelope, as needed (for example, names in the signature manifest); with the timestamp authority, which receives only cryptographic digests, never the document; with the email provider used for invitations; and with authorities, when there is a legal order.
The public validator shows signers with masked data and the envelope's cryptographic digests, never the document content.
8. Retention and deletion
Signed documents, signer data and the trail are kept while the account is active and, afterwards, for the limitation period applicable to the documented transactions, allowing the parties to defend themselves. Selfie and ID follow the purge period in section 6. Connection logs are kept for the legal period.
Once the account is closed and the retention period has expired, documents and signers' personal data are securely deleted; the audit trail, with no direct personal data, remains to preserve the integrity chain.
9. Security
Data travels encrypted and is stored on Ravi Systems servers in Brazil. Sensitive data is encrypted with a separate key per account; the platform certificate is isolated from the rest of the system; administrative access is restricted and logged; backups are encrypted. Relevant incidents are reported to those affected and to the Brazilian National Data Protection Authority, as required by the LGPD.
10. Data subject rights
Data subjects may request confirmation that processing exists, access to the data, correction of incomplete or outdated data, anonymization, blocking or deletion of unnecessary data, portability, information about sharing and withdrawal of consent, under art. 18 of the LGPD.
Some requests may have legal limits: data proving a signature may be kept while needed for the regular exercise of rights. Requests from signers are forwarded to the controlling customer when applicable. Responses are given within a reasonable time, and data subjects may also petition the Brazilian National Data Protection Authority.
11. Cookies and browser storage
Ravisign uses only cookies needed for operation: dashboard and signing page sessions, protection against forged requests and remembering the chosen language. The light or dark theme choice is kept in the browser's local storage. We do not use advertising cookies or third-party trackers.
12. International transfer
Data is stored in Brazil. Should any supplier involve an international transfer, it will follow the cases in art. 33 of the LGPD, and this policy will be updated.
13. Data protection officer and contact
The Ravi Systems data protection officer can be reached at contato@ravisystems.com.br. Use this channel to exercise your rights, ask questions about this policy or report an incident.
14. Changes to this policy
This policy may be updated. The version in force is always the one published on this page, with the date at the top, and relevant changes are communicated to customers.