Privacy Policy
1. Scope. This policy explains how Khtoom collects, uses, discloses, and retains personal data when you use our sites, applications, platform tools, or related services, or when you contact us.
2. Legal roles. When the Customer processes individuals' data through the platform within its documents, Khtoom is — in most cases — a data processor on behalf of the Customer (which is the controller). For account, billing, security, fraud-prevention, support, and anonymized analytics data, Khtoom may act as an independent controller within the limits of the law.
3. Categories of data. Identification, contact, and account data; document and transaction data; signature data, technical events, and tracking logs; billing, support, device, and connection data; and any data the Customer or Signer voluntarily uploads or provides.
4. Purposes and bases of processing. We process data to provide the Service, manage the account, execute transactions, create evidence records, provide support, improve security, detect fraud or misuse, and meet legal obligations. The legal bases, as applicable: performance of a contract, legal obligation, balanced legitimate interest, and explicit consent where the law requires it.
5. Customer responsibility. The Customer is responsible for the lawfulness of the data it uploads or processes through Khtoom, and for providing notices and obtaining consents from Signers or data subjects where required. Khtoom is not responsible for determining whether a particular document is binding or whether a signature type is suitable for every case.
6. Disclosure and participants. We may share data with trusted service providers, professional advisers, regulatory authorities, courts, or other parties where necessary to provide the Service, protect rights, comply with law, or respond to lawful requests. Khtoom requires parties that process personal data on its behalf to follow appropriate confidentiality, security, and data-protection commitments.
7. Optional WhatsApp delivery. Sending via WhatsApp is an optional feature and is not required to use Khtoom. A team member may send the link from their own WhatsApp, or — to avoid sharing a personal number — have Khtoom send it from Khtoom's official number. In that case only a temporary, limited-validity link is sent. Khtoom does not retain the recipient's phone number or the document for this delivery; processing is limited to sending the link. Any messaging provider used to transmit the message acts only as a processor under appropriate confidentiality and data-protection terms. The document and its status remain inside Khtoom, and the Customer is responsible for obtaining the recipient's agreement to be contacted where required.
8. International transfer. If data is transferred outside the country where it was collected or primarily stored, Khtoom uses an appropriate legal mechanism permitted by applicable law. Transfers may take place where reasonably needed to provide, maintain, secure, or support the Service, subject to appropriate safeguards.
9. Security. Reasonable technical, administrative, and organizational measures: access control, encryption in transit and, where appropriate, at rest, logs, backups, logical separation, vulnerability management, access reviews, training, and incident response.
10. Data breach notification. Khtoom maintains incident-response measures to detect and address security incidents. If a personal-data breach occurs that is likely to affect a Customer's data, Khtoom will notify the affected Customer without undue delay after becoming aware of it, and will provide the information reasonably needed to help the Customer meet its own notification obligations. Where Khtoom acts as a controller and the law requires it, Khtoom will also notify the competent authority, and affected individuals where required, within the time limits set by applicable law.
11. Retention and deletion. We retain account data for the term of the relationship, and documents and evidence records for the period reasonably needed to provide the Service, comply with legal obligations, resolve disputes, and maintain evidence records or until early deletion on a legitimate request, subject to any legal obligation or pending dispute. After the relationship ends, we provide a download window of at least 30 days, then delete or anonymize the data.
12. Data subject rights. Subject to applicable law: access, rectification, erasure, restriction of processing, objection, portability, and withdrawal of consent. If Khtoom processes on behalf of the Customer, we forward the request to the Customer or coordinate with it, unless the law requires us to respond directly.
13. Children's and minors' data. Khtoom's services are intended for businesses and organizations, and accounts are not intended for individuals below the age required to enter into a contract. Where a Customer (for example, a school or institution) processes documents that contain a minor's personal data, the Customer acts as the controller and is responsible for having a valid legal basis and any required parental or guardian consent before submitting that data. Khtoom processes such data only as a processor, on the Customer's instructions and for the purpose of providing the Service. If we become aware that a minor has created an account directly without the required authorization, we will take reasonable steps to remove it.
14. Cookie Policy. Cookies are small files stored on your device. We use: (1) Essential cookies, required for the site to function and for security — these do not need consent; (2) Preference cookies, which remember choices such as language; (3) Analytics cookies, which help us understand how the site is used. Non-essential cookies are set only after you consent. You can change or withdraw your choice at any time through the cookie settings on the site, and you can manage cookies in your browser. For details on how we handle personal data, see the Privacy Policy.
15. Contact and updates. For privacy requests: support@khtoom.com. Responsible entity: Khtoom. Official notices are handled through the contact details provided by Khtoom, including support@khtoom.com when no dedicated legal address is published. This policy is updated as needed, and material changes are notified in a legally reasonable manner.