Terms and Conditions
These terms apply to Project Signet, operated by Exclusive Information Technology Service (UEN 53524260C) (“EITS”, “we”, “us”). By using Signet, uploading a document, paying for a signing package, or creating an account, you agree to these terms.
Effective date: 16 July 2026
1. Service overview
Signet is a digital document signing service. You prepare a PDF in your browser, place signature fields for named recipients, pay for delivery of signing invitations, and each recipient signs only after verifying access through the email signing link they receive. There is no separate “sender signs in the prepare UI” path: if you must sign, add yourself as a recipient and complete your own email link.
2. Payments are non-refundable
All fees paid for Signet signing packages are non-refundable, including where a recipient does not open the invitation, does not complete signing, an email is delayed or undelivered, a document code is lost, or an envelope expires or is cancelled after payment processing has completed.
Payments are processed by Airwallex via embedded card fields. Signet does not store credit card numbers, CVC, expiry, or other full card secrets. Optional “save card” is an Airwallex vault feature under Airwallex’s terms; Signet never retains card data for that purpose. Chargebacks and payment disputes must be raised with your card issuer or payment provider under their rules; they do not create a contractual right to a Signet refund except where required by applicable Singapore law that cannot be excluded.
3. Email delivery and recipient responsibility
Signing invitations are sent by email (and, where configured, secondary channels). Email should be treated as readable transport and is not a reliable delivery channel. You are responsible for:
- providing correct recipient email addresses;
- ensuring recipients can receive and open the invitation;
- spam filters, mailbox full conditions, corporate gateways, and forwarding rules;
- lost, delayed, or undelivered messages.
EITS is not liable for lost or undelivered email, missed signing deadlines caused by delivery failure, or any loss arising because a recipient did not receive or act on an invitation. You may cancel and purge an unpaid or eligible draft under product rules, but payment after checkout remains non-refundable as stated above.
4. Encryption and the two requirements to open a package
Documents are encrypted in the browser before upload. At rest, Signet stores only ciphertext and a wrapped form of the envelope key—not readable PDF content and not the document code.
Opening or stamping a package always needs two different things:
- A server-minted invitation (signing link) — proves which recipient may start a short-lived signing session (then OTP as designed). The link is capability and identity for the workflow; it is not the full decryption key by itself. Only Signet’s application can mint a working link; you cannot invent one.
- The document code — the participant-held secret used to unwrap the envelope key for that request. Signet does not store, email, look up, reset, or reconstruct the document code.
During an authorised request, the server may unwrap and decrypt in memory only, apply allowed stamps, re-encrypt, and discard plaintext. Without the document code for that package, ciphertext on our storage is useless—including to operators and to anyone who only steals blobs from the data store. Account login alone cannot open a PDF.
If the document code is lost, Signet cannot recover the PDF—even with payment history or a dashboard row. After purge, content-bearing storage is removed; retained records are metadata only (title, hashes, counts, payment and audit facts as implemented). See Trust.
5. Lost invitations vs lost document codes
Losing an invitation email is not the same as losing the document code. A preparer may request that Signet mint a new signing link for a recipient (re-invite), subject to product limits; the raw prior token is not recoverable from our database (we store hashes). Re-invite does not recreate or reset the document code. If the document code is gone, re-sending links does not restore the ability to open the PDF.
6. Two operating modes (anonymous vs signed-in)
Mode 1 — Anonymous preparer. You may add recipients, place fields, upload an encrypted PDF, and pay without an account. Ownership of that package uses a one-time sender access token for that envelope. Signing invitations go to each recipient by email link. When every required recipient has signed, the completed package is delivered per product rules and content-bearing storage is purged. Anonymous preparers do not receive a long-lived dashboard history.
Mode 2 — Signed-in preparer. The same prepare → pay → invite → sign → complete → purge flow applies. Envelopes you create while authenticated are tied to your account so the dashboard can show metadata: document title, how many signaturefields were placed, how many recipients have status signed, package status, and whether content is still available or already purged.
What is not true: Mode 2 does not mean “only counts exist in the database.” During the active signing window Signet must store operational recipient records (for example email addresses and signing-state) so invitations, OTP, and field assignment can work for both modes. What the signed-in dashboard is designed to emphasise for you is progress metadata—not PDF content, document codes, or signature drawings. After purge, content is gone; retained history for accounts is metadata-oriented (title, counts, status, payment/audit facts as implemented).
7. Acceptable use and your content
You must have the right to process the document and recipient contact details you submit. You must not use Signet for unlawful content, fraud, or abuse of payment or messaging systems. You are responsible for the accuracy of titles, signer lists, and field placement.
8. Privacy
We process personal data as needed to operate Signet under Singapore PDPA principles of reasonable security arrangements. Email addresses, payment metadata, and operational logs are handled for service delivery and abuse prevention. Content-bearing PDFs are not retained after purge. Contact details for the operator appear on the site footer (Exclusive Information Technology Service, UEN 53524260C).
9. Limitation of liability
To the fullest extent permitted by law, EITS is not liable for indirect, incidental, or consequential loss; for inability to open a document after loss of the document code; for email non-delivery; or for disputes between signers about the substance of a signed document. Our aggregate liability arising from a paid package is limited to the amount you paid for that package, except where liability cannot be limited under applicable law.
10. Changes and contact
We may update these terms by publishing a revised page with a new effective date. Continued use after publication constitutes acceptance of the revised terms for new envelopes created thereafter. For product questions, see About or open an EITS Support case (Signet product). Support cannot recover document codes or re-send sealed packages.