Legal & terms

Privacy notice

This notice covers everyone whose data passes through eFirma and every way in: the customers who send documents, the people in their workspaces, the signers who receive a link and never create an account, and anyone using the eFirma app for Android or iOS. If you are here about the app, sections 5 and 6 are the ones to read. If you are a signer, section 7 is.

Last updated 24 September 202613 sections

1Who is responsible for what

For your account data, we decide and are responsible. For the documents you send, you decide and we act on your instructions.

Our own processing

Habeshaware PLC, trading as eFirma, of Addis Ababa, is responsible for the personal data we hold about account holders, workspace members and website visitors.

Processing on your behalf

For the documents you upload and the signers you send them to, you decide what is sent and to whom; we process that data on your instructions in order to deliver, sign, seal and store it. Where a document contains other people's personal data, telling those people about it is your responsibility, not ours.

One notice, three ways in

The website, the workspace in a browser, and the eFirma app for Android and iOS are one service reaching the same records. Everything in this notice applies whichever you use; where the app does something a browser cannot, it is written out in section 5.

2What we collect

Six kinds of data, and no more than the service needs. Two of them exist only where somebody asked for an identity check.

  • Account data — name, email address, phone number, organisation, role, and the settings you choose.
  • Document data — the files you upload, the fields placed on them, and the finished sealed document.
  • Signer data — the name, email address and phone number you give us for a signer, the passcodes sent to them, and the record of what they did with the document.
  • Identity data — where a sender asks for a Fayda check, or where you link your national ID to your own account: photographs of the card, the name, gender, date of birth, card number and portrait carried in the card's own QR code, and photographs of a face taken by the camera during the check. On the website only, a voice recording and the voiceprint taken from it, where somebody chooses to enrol one. Section 6 sets out exactly what is kept and what is deleted.
  • Technical data — the IP address, device and browser recorded against each significant action, because a signature's evidence is made of exactly that. We do not collect satellite or network location, and we do not use an advertising identifier.
  • App data — where you install the eFirma app: the notification token the platform issues for that installation, the name of the device and whether it is Android or iOS, so that a notification reaches the right phone and you can retire one you no longer have.
  • Billing data — the contact and payment reference needed to raise and settle an invoice. Card details are handled by the payment provider and are never stored by us.

3Why we hold it

To provide the service you asked for, to prove that a signature happened, and to meet obligations we cannot opt out of.

To run the service

To deliver documents, verify signers, seal completed files, keep your archive searchable, and let you and your counterparties verify what was signed.

To check that somebody is who the sender says

Where a sender requires a Fayda check, the card and face data in section 6 are collected for that one purpose: to establish that the person opening the link holds the national ID the sender named. We ask for it with your consent, at the moment it is needed, and we use it for nothing else.

To keep the evidence

The audit trail exists to prove what happened. This is why some data cannot simply be erased on request: removing it would destroy the evidence behind a document someone may still need to rely on.

To keep the service safe

To detect abuse, prevent fraudulent sending, apply rate limits and investigate security incidents.

Because the law says so

To meet accounting, tax and regulatory obligations, and to respond to lawful requests from authorities.

4What we do not do

The short list, because it is the one people actually want.

  • We do not sell personal data, and we do not share it for anyone else's advertising.
  • We do not use your documents — or your card, your face or your voice — to train models, ours or anyone else's.
  • We do not read your documents except to provide support you have asked for, to keep the service running, or where the law requires it — and that access is named, time-limited and logged.
  • We do not open the camera in the background. It runs on the two screens that ask for it, while you are on them, and nowhere else.
  • We do not ask for your photo library, your contacts, your calendar, your location or your microphone. The app requests the camera, and your phone's own screen lock if you turn that on. Nothing else.
  • We do not carry advertising identifiers, third-party analytics or crash-reporting services in the app.
  • We do not track you across other websites. The site uses no advertising or analytics cookies from third parties.

5The eFirma app

What the app on your phone can reach, what it asks permission for, and what stays on the device.

The camera, and the two things it is for

The app asks for the camera at the moment it is needed, for two purposes and no others: scanning the QR code printed on a sealed document to check it is genuine, and photographing your Fayda card and your face where a sender has asked for an identity check. You can refuse, and the rest of the app carries on working. A scanned QR code is read on the device and nothing about it is uploaded; what happens to the card and face photographs is section 6.

Files you choose, and only those

The app has no access to your photo library or to your storage. Sending a document opens your phone's own file picker, which hands the app the single file you chose; a working copy is kept in the app's private storage while the composer is open, and the file is uploaded to your workspace when you send it.

Checking a document never uploads it

On the verify screen, a file you choose is fingerprinted on the phone and only the 64-character fingerprint is sent. The document itself does not leave the device, which is both the promise the screen makes and the whole of the check.

Unlocking the app with your face or fingerprint

If you turn on the app lock, your phone asks for the same face or fingerprint it already uses to unlock itself. That check happens entirely on the device, by the operating system; eFirma receives no fingerprint, no face and no biometric template from it, and cannot. It is not connected to the identity check in section 6, which is a different thing done for a different reason.

Notifications

If you allow them, the platform issues a token for that installation and we store it against your account. A notification carries the title of the document and the name of the person or workspace it concerns — the same words as the email you were already sent — and never a signing link, because that link is the whole authority over your contract and it is not handed to anyone on the way. Turn them off in the app or in your phone's settings and the token is retired.

Closing your account from the app

Deletion is in the app under Profile, and on the public page at efirma.et/legal/delete-account if the app is already gone from your phone. Section 10 sets out what is destroyed and what has to survive.

6Identity checks, and the biometric data behind them

Card and face are collected only where somebody asked for a check, are processed on our own servers, and most of what is captured is deleted within minutes.

When it happens at all

Never by default. A check runs in one of two situations: a sender required one of you for a particular document, or you chose to link your national ID to your own eFirma account. Where no one asked, the screen does not exist and nothing is captured.

What the check does

The QR code on a Fayda card carries the holder's details and portrait signed by the issuer. We verify that signature against FIN's published keys on our own servers, without contacting Fayda and without telling anyone that you were checked. The portrait inside the card is then compared with frames taken while the camera asks you to turn your head, which is what establishes that a living person is present rather than a photograph. Nothing is judged on your phone; the frames are uploaded and checked by us.

Nobody else receives it

Card images, portraits, face frames and voice recordings are processed on eFirma's own servers, in region, and are not sent to any third-party identity, biometric or verification provider. No sub-processor in our list receives them.

What is deleted, and what is kept

For a signer's check: the photographs of the card are deleted as soon as the QR code has been read, and the extra face frames as soon as the comparison is done. What remains with the document is the portrait the card itself vouches for, one frame of the face, the verdict and its measurements, the last four digits of the card number and a one-way fingerprint of the full number. The number itself is not kept. For a national ID linked to your own account, the card images are kept as the evidence of the link, and are deleted when you unlink it.

Why a verified check stays with the signature

The record of a check that passed is part of the evidence behind that signature, in the same way the audit trail is: a counterparty relying on the document is relying on it. It is kept with the envelope and survives the account, which is why unlinking your ID or closing your account does not remove it. What it holds about you is listed in the clause above.

Voice, and the microphone

A voiceprint can be enrolled on the website by somebody who has already linked their national ID. The recording and the voiceprint are kept until the enrolment is removed, and removing it deletes both. The app does not ask for the microphone and does not record audio at all.

If you would rather not

You can decline a check, and you can stop part way through. Nothing is kept from an abandoned attempt beyond the fact that it was abandoned. What that means for the document is between you and the sender, who chose to require it — write to them, and to us if you want to know what we hold.

7If you are a signer

You did not choose eFirma; someone sent you a document. Here is what that means for your data.

How we got your details

The organisation that sent you the document gave us your name and the phone number or email address the link went to. We did not obtain them from anywhere else.

What is recorded when you sign

That the document was delivered, opened, and signed or declined; the time; the passcode check that confirmed it was you; and the address and device it came from. That record is the evidence behind your signature, and it is kept with the document.

If you were asked to prove your identity

Some senders require a Fayda check before you can sign. Section 6 says what that collects, what is deleted and what stays with the document. The sender asked for it; we carried it out and hold the result.

Who to ask about it

Because the sender decides what happens to the document, requests about it should go to them first. Write to us and we will tell you who the sender is and pass your request on.

8Who else touches it

Message delivery, notifications, payments and hosting involve other companies. They are named, not summarised as partners.

Sub-processors

The companies that process data on our behalf, what each of them does, and what each can see, are listed in the sub-processors document. They act on our instructions, under contract, and only for the purpose named there.

Notifications pass through three hands

A notification to a phone travels through Expo's push service and then through Apple or Google to reach it. Each can see the token, the title of the document and the name in the message; none receives a signing link, a document or anything from an identity check.

Identity checks do not leave us

Card images, portraits, face frames and voiceprints are the one category no sub-processor handles. They are processed and stored by eFirma, in region.

Authorities

We disclose data to an authority only where we are legally required to. Where we are permitted to tell you that it happened, we will.

A change of ownership

If the business is ever sold or merged, data moves with it, subject to this notice. We would tell you before it happened.

9Where it is kept, and for how long

In region, for as long as your retention setting says — with the exception the evidence forces.

Location

Documents, evidence, identity checks and signer records are stored in region. Some sub-processors, particularly for message delivery, notifications and network protection, operate internationally; what leaves the region is limited to what that service needs, and is listed in the sub-processors document.

Retention

Completed documents and their evidence are kept for as long as the workspace's retention setting says, and for 90 days after the workspace closes so that you can export them.

Identity and biometric data

The captures a check does not need are deleted within minutes of it finishing, as set out in section 6. What a check keeps is retained with the envelope it belongs to, on the same clock as the rest of that envelope's evidence. A national ID linked to an account, and any voiceprint, live as long as you keep them and are deleted when you unlink or when the account is erased.

The exception

Where a document has been signed, the record proving it was signed is retained even if the underlying file is deleted, for as long as the law allows someone to raise a claim about it. A signature without its evidence would be worth nothing to either side.

10Your rights, and closing your account

Ask for a copy, ask for a correction, ask us to delete or export. Ask a person, in the same time zone.

Deleting your account

You can ask for deletion from inside the app under Profile, from your workspace settings, or from efirma.et/legal/delete-account without signing in to either. It takes effect after 30 days, the account works normally throughout, and you can change your mind at any point in that window.

What deletion destroys

Everything that exists only to describe you: your linked national ID and its images, any voiceprint, the record of your identity checks against your account, the phones registered for notifications, your preferences, and every session that could still be resumed. The account row itself is overwritten so that it can no longer be read as a person.

What deletion cannot destroy

Documents other people signed with you, the evidence behind those signatures, the name and address a document was actually sent to, and the invoices either of us may need. That half of the record belongs to your counterparty as much as to you, and a signature that vanishes when one party asks is not evidence at all.

  • A copy of the personal data we hold about you, in a form you can use.
  • Correction of anything inaccurate — most of it you can correct yourself in the workspace.
  • Deletion, subject to the evidence exception in section 9 and to any legal retention obligation.
  • Withdrawal of consent to an identity check, which removes an enrolment you chose to make; a check already carried out for a document you signed is covered by section 6.
  • Export of your documents, their evidence and the audit trail, at any time and without asking us.
  • An explanation of anything in this notice, in plain language, from someone who understands the system.

11Cookies, and storage on your device

Only what makes signing in work, in a browser and on a phone. There is nothing here to consent to on anyone else's behalf.

What the website sets

Cookies and equivalent storage needed to keep you signed in, to remember which workspace you are in, and to protect forms against cross-site request forgery. They expire with the session or shortly after.

What the app stores

Your session is held in the keystore the operating system provides for secrets, along with your preferences and a cached copy of what you last looked at, so the app opens to something rather than to a spinner. Signing out clears the session and retires the notification token. Uninstalling removes all of it.

What neither sets

No advertising cookies, no advertising identifier, no third-party analytics, no cross-site tracking.

12Children

eFirma is for adults entering into agreements, and is neither designed for nor directed at children.

Who the service is for

Accounts are for people old enough to enter into a binding agreement, and documents should not be sent for signature to anyone who is not. We do not knowingly collect personal data from a child.

If it happens anyway

Write to [email protected] and we will delete what we hold, subject only to the evidence a document someone else relies on has already created.

13Changes and contact

Dated changes, and a mailbox with a person behind it.

Changes

The date at the top of this notice is the date it last changed. Material changes are notified to workspace administrators by email before they take effect.

Contact

Write to [email protected] with anything about this notice or about data we hold. We answer within five working days, and we do not require a particular form of words to treat a request seriously.

Questions about this document, a signed copy on letterhead, or an Amharic version: [email protected]. Published in English; where an Amharic copy differs, the English version governs.