Privacy Policy
Last updated: September 2026
Siggy is operated by Ontology Analytics Pty Ltd (ABN 36 653 416 856), trading as Siggy Australia, of Canberra, Australia. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Scope
This policy covers personal information we collect as a business (about account users and visitors) and explains information we process on behalf of our customers when they use Siggy to send documents for signature. For customer-directed processing, our customer is responsible for that information and a Data Processing Addendum governs our role as processor.
2. What we collect
Account & billing: name, work email, organisation name, hashed password, role, and billing records. Usage & security: IP address, browser user-agent, timestamps, and security event logs. Signing data (for our customers): recipient name and email, a recipient mobile numberwhere the sender chooses to provide one, signer IP and user-agent, consent and intention records, signature/initials images, document contents, and the resulting sealed document and Certificate of Completion. We collect only what is needed to provide the Service. Website analytics on our public pages are described in section 11.
3. How we use it
- To operate the Service (send, sign, seal, deliver, and evidence documents).
- To deliver a signing link and reminders to a recipient by email and, where the sender has provided a mobile number, by SMS. A mobile number is used for that purpose only — never for marketing, and never disclosed to another customer.
- To authenticate users and secure the Service against fraud and abuse.
- To provide support and to bill for usage.
- To meet legal obligations and to establish or defend legal claims.
We do not sell personal information or use it for unrelated secondary purposes.
4. Identity verification and the Document Verification Service
How it works. Where the sender of a document asks for a signer's identity to be verified, the signer is asked to provide details from an identity document (for example a driver licence, passport or Medicare card). Ontology Analytics uses the Commonwealth Government's Document Verification Service (“DVS”) to verify identity, using information available from those identity documents: the details are checked against the records of the authority that issued the document — such as a state or territory roads authority, the Australian Passport Office or Services Australia — via the DVS, accessed on our behalf by an approved Australian gateway provider. The check confirms only whether the document details match the issuer's record. It does not retrieve, and we do not receive, any other information the issuer holds about the individual. You can find more information about how the DVS operates and is managed by the DVS Hub and the Framework Administrator at www.idmatch.gov.au.
Why we use it, and our legal obligations. We process identification information to verify identity at the sender's request — to reduce the risk of fraud and identity crime, and to help our customers meet their own client-verification and customer-due-diligence obligations. In processing it we comply with the Privacy Act 1988 (Cth), the Identity Verification Services Act 2023 (Cth), and the Document Verification Service participation terms agreed with the Commonwealth, which govern our use of the DVS. “Identification information” means personal information contained in your identity documents — such as your name, date of birth and document number, and other details used to confirm your identity — and information about the outcome of a comparison carried out through the DVS in relation to you.
PEP and sanctions screening. As part of a verification, the individual's name is also screened, at the time of the check, against publicly available politically-exposed-person and sanctions lists, including the DFAT Consolidated List. We retain only the screening outcome (whether possible matches were found, and any review of them); the sender reviews possible matches, which commonly arise from name similarity alone. Screening is point-in-time and separate from the identity result.
Consent, and what happens if you decline. No check is ever made without the individual's prior express and informed consent, which is recorded with the time it was given. Providing identity details is voluntary. If an individual declines, no check is made; the sender is notified and may offer an alternative way to verify identity, such as reviewing documents directly. Declining does not prevent a document being signed unless the sender independently requires verification.
What we collect and keep. The signer enters their document details directly with the gateway provider, so we do not receive identity document numbers at all, and we never store them. We receive and retain only the verification outcome (verified / could not confirm), the type of document used, a verification reference number, and the time of the check, which form part of the document's audit record. We do not use verification data for any other purpose, do not build profiles from it, and do not disclose the underlying match detail to the sender.
Our obligations and your rights. We handle identity information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and with the conditions of our participation in the government verification framework, which include collecting only what is reasonably necessary for the verification and using it only for that purpose. Individuals may ask what we hold about them and ask us to correct it (section 10). If a verification outcome appears wrong, an individual may query it with us — we will explain the outcome, arrange a fresh check where appropriate, and tell them where the underlying record can be corrected. Only the issuing authority can change its own records; we cannot alter them.
Concerns or complaints about the collection, use or disclosure of identity information can be raised with us using the details in section 12, and if you are not satisfied, with the Office of the Australian Information Commissioner.
5. Government related identifiers
Consistent with APP 9, we do not adopt government related identifiers (such as licence or passport numbers) as our own identifier of any individual, and we use or disclose them only where reasonably necessary to verify an individual's identity for the purposes of our functions, or as required or authorised by law.
6. Disclosure & sub-processors
We disclose personal information to service providers that help us run the Service, under contract and only as needed — for example hosting and SMS delivery (Amazon Web Services), edge/TLS (Cloudflare), and transactional email delivery. We may disclose where required by law. A current sub-processor list is available on request.
7. Where it is stored
We host personal information in Australia. Where a sub-processor operates from outside Australia, we take reasonable steps consistent with APP 8 to ensure comparable protection.
8. Security
We protect personal information with encryption in transit and at rest, tenant isolation, hashed credentials, an append-only tamper-evident audit trail, access controls, and security monitoring. See our Security & Compliance page. No method is perfectly secure; we maintain an incident and data-breach response process aligned with the Notifiable Data Breaches scheme.
9. Retention
We keep personal information only as long as needed or as required by law. Indicative periods: completed signing records up to 7 years (customer-configurable); drafts and voided envelopes 90 days; security logs 12 months; closed accounts purged after a 30-day grace period (subject to legal holds). We then delete or de-identify it.
10. Your rights
You may request access to, or correction of, your personal information by contacting us. We will respond within a reasonable period and may need to verify your identity. For information we process on a customer’s behalf, please contact that customer; we will assist them.
11. Website analytics
We use Google Analytics on the public pages of siggy.com.au to understand how visitors find and use our website. This collects usage information such as the pages you view, how you arrived at our site, your approximate location (derived from your IP address), your browser and device type, and the time you spend on each page. This information is collected by Google and handled in accordance with Google's privacy policy. Where we run advertising, we also record which advertisement or search term led you to us so that we can understand which marketing is effective.
We also use the Meta Pixel, provided by Meta Platforms (Facebook and Instagram), on the same public pages. It records the pages you view and whether you arrived from one of our Facebook or Instagram advertisements, so that we can measure and improve that advertising. This information is collected by Meta and handled in accordance with Meta's privacy policy.
We do not run analytics or advertising technology on the signing experience. If you have received a document to sign through Siggy, no analytics, advertising or session-recording technology runs on the pages where you review, verify your identity or sign that document. The same applies to identity verification and to the signed-in application. Those experiences carry only the technology required to deliver the service itself.
You can opt out of Google Analytics using Google's browser add-on, and control how Meta uses your information for advertising in your Facebook or Instagram ad settings. You can also use your browser's privacy controls to block analytics and advertising cookies. Doing so does not affect your ability to use Siggy or to sign a document sent to you.
If you have questions about how we handle your information, contact us at [email protected].
12. Cookies
Siggy uses a single strictly-necessary session cookie (siggy_token, httpOnly) to keep you signed in. Google Analytics and the Meta Pixel set their own cookies on our public marketing pages, as described in section 11. No analytics or advertising cookies are set on the signing experience, on identity verification, or in the signed-in application.
13. Complaints
If you have a privacy concern, contact us at [email protected]. If unresolved, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14. Contact
Privacy Officer, Ontology Analytics Pty Ltd (trading as Siggy) — [email protected].

