Compliance Assistant

Nota Sign
Trust Center

Nota Sign insist on prioritizing the security and privacy of customer data. Nota Sign is committed to complying with laws and regulations related to data security and privacy protection in various countries and regions around the world, including but not limited to the stringent security standards of China, the EU, Singapore, the United States, and other global jurisdictions.

Contact Sales
Trust Center

U.S. ESIGN Act and UETA

The U.S. Electronic Signatures in Global and National Commerce (ESIGN) Act and the Uniform Electronic Transactions Act (UETA) each require four conditions for a valid electronic signature: (a) intent to sign, (b) consent to do business electronically, (c) association of the signature with the record, and (d) retention of records. Nota Sign ensures compliance with these requirements under U.S. ESIGN and UETA laws.

EU eIDAS

The Regulation on Electronic Identification and Trust Services for Electronic Transactions (eIDAS, Regulation (EU) No 910/2014) defines three types of electronic signatures—Simple Electronic Signature (SES), Advanced Electronic Signature (AES), and Qualified Electronic Signature (QES)—and establishes a legal framework for electronic signatures in EU. The UK continues to apply this framework through the retained UK eIDAS. As the highest-level electronic signature, QES has legal effect equivalent to a handwritten signature in accordance with Article 25 of eIDAS. Nota Sign supports the provision of QES-level signature services.

ISO 27001 & ISO27701

Nota Sign has obtained the ISO/IEC 27001 and ISO/IEC 27701 certifications which fully demonstrate Nota Sign’s firm commitment to customer information security and its proactive and forward-looking practices in protecting personal information.

SOC2

Nota Sign has implemented comprehensive controls designed to meet the SOC 2 Trust Services Criteria. Our services run on a hardened, multi-region cloud infrastructure with geo-redundant data centers, strong encryption, continuous monitoring, and strict access controls. This document describes our control environment and how we leverage industry-leading cloud security capabilities to protect customer data.

GDPR

The EU's General Data Protection Regulation (GDPR) aims to protect the "fundamental rights and freedoms of European citizens, in particular the right to the protection of personal data". Nota Sign is committed to strictly complying with the requirements of GDPR.

CCPA

The California Consumer Privacy Act (CCPA) of the United States establishes privacy rights for California residents and regulates corporate data processing activities (effective on January 1, 2020, and amended by the CPRA on March 29, 2023). As the first consumer privacy law in the United States, its stringency is equivalent to that of the EU's GDPR. Nota Sign is committed to strictly complying with the requirements of the CCPA.

Nota Sign’s priority is to ensure that your experience is both safe and secure.

Privacy First

Data & Privacy

Nota Sign always puts your data sovereignty first. It not only safeguards the privacy and security of information with stringent protection mechanisms, but also adheres to the principle of full-process transparency — in every link from data collection, transmission, storage to usage, it ensures you have absolute control over your own data, providing you with dual and comprehensive protection for your privacy and sovereignty.

Security

Security is deeply integrated into the infrastructure architecture from the underlying design on Nota Sign's cloud platform. Combined with built-in multi-layer protection mechanisms and a global network system, it builds comprehensive security safeguards for your information, identity, applications, and devices—covering every stage from the source to the end.

Security
Compliance

Compliance

As a professional organization deeply rooted in the electronic contract field, Nota Sign takes strict compliance standards as its core principle: it not only ensures that its own service system meets the requirements of various authoritative certifications, but also can deeply adapt to the characteristics of different industries. It helps customers accurately comply with the regulatory norms in their respective fields and provides solid support for the compliant operation of their businesses.

Discover a better way to e-sign your documents

Discover a better way to e-sign your documents