End User License Agreement (EULA)
Effective date: July 6, 2026 · Version 1.0
This End User License Agreement (“Agreement”) is a binding contract between you (“you”, “User”) and OwnSig Inc. (“OwnSig”, “we”, “us”) governing your use of the OwnSig email signature management service, including the web application, the tracking and asset delivery services, the Penna AI assistant, the API and MCP interfaces, mail-platform add-ins, and related documentation (together, the “Service”).
You accept this Agreement by creating an account, by clicking “I agree” at sign-up, or by using the Service. If you are accepting on behalf of an organisation, you represent that you have authority to bind that organisation, and “you” refers to that organisation. If your organisation has a separately executed master subscription agreement with OwnSig, that agreement controls over this EULA to the extent of any conflict.
1. Licence grant
Subject to this Agreement and payment of applicable fees, OwnSig grants you a limited, non-exclusive, non-transferable, non-sublicensable licence during your subscription term to access and use the Service for your internal business purposes, up to the user counts and feature entitlements of your plan (Free, Pro, Enterprise, or Enterprise Sovereign, plus any add-ons such as local data residency or managed AI).
2. Your account and acceptable use
- You must provide accurate registration information and keep credentials confidential. You are responsible for activity under your account.
- You must be at least 16 years old and legally able to enter contracts.
- You will not: (a) use the Service to send or facilitate spam or unlawful communications; (b) upload malicious code or content that infringes third-party rights; (c) reverse engineer, decompile, or attempt to extract source code except where such restriction is prohibited by law; (d) resell, rent, or provide the Service to third parties except to your authorised users; (e) circumvent usage limits, plan gating, or security controls; (f) use the Service to build a competing product.
- Click-tracking features must be used consistently with applicable law and your own privacy notices. The Service is designed so that no personal data of email recipients is collected (see Section 6), but you remain responsible for your use of analytics.
3. Trials, plans, and billing
- Premium preview. New organisations receive a 14-day preview of Pro features inside a free account. At expiry the account simply continues on the Free plan; there is no hard stop, no charge is made, and no data is deleted.
- Paid plans (monthly). Fees are per user per month as stated at purchase, billed in advance. Monthly self-serve plans carry no commitment: you may cancel at any time, in-app or by notice, with effect at the end of the then-current paid month. You will only ever be billed for the month you have already paid for — cancellation stops all future charges, and full service continues until that paid month ends. Add-ons (local data residency, managed AI, calendar booking) are billed per user per month alongside the base plan and end with it.
- Annual plans. Annual self-serve plans are discounted 20% and prepaid for the full year. Annual fees are non-refundable and the annual term cannot be terminated early; you may switch off renewal at any time, and full service continues until the end of the prepaid year.
- Changes. We may change pricing with at least 30 days' notice, effective at your next renewal.
- Taxes. Fees exclude taxes; you are responsible for applicable VAT/GST/sales tax unless you provide a valid exemption.
4. Customer Data and licence to us
“Customer Data” means data you or your users submit to, or that we process on your instruction through, the Service: employee profile details and the attributes we map from your connected identity and HR sources, signature content and templates, uploaded images, campaign creative, integration configuration, out-of-office and offboarding settings, and support communications. You retain all rights in Customer Data. You grant OwnSig a worldwide, non-exclusive licence to host, process, transmit, and display Customer Data solely to provide and support the Service. We obtain no rights in Customer Data beyond this licence. Except for the limited, PII-scrubbed structural training described in Section 9 (which applies only to Free and Individual/Pro plans and is subject to opt-out), we do not use Customer Data to train machine-learning models, and Enterprise-tier content is never used for model training.
5. Employee data, identity, and attribute mapping
When you connect HR systems (Workday, BambooHR, HiBob), identity providers (SAML/OIDC, including Azure AD via assertions or SCIM), or mail platforms (Microsoft 365, Google Workspace), you instruct OwnSig to process the directory attributes those systems expose — for example name, title, department, division, cost centre, employee ID, phone, office, country, and profile photo — to build, assign, and deploy signatures. The Service can assemble a single profile from multiple sources at once under a mapping you configure (for example department from Azure AD and photo from HRIS), and an administrator may set per-user overrides that take precedence over synced values. You represent that you have the authority and, where required, a lawful basis to share that data with us as your processor. Signature and template change history is recorded in a tamper-evident audit chain for compliance and dispute purposes.
6. Recipient privacy and email tracking
- Signature link tracking is performed server-side. By default the Service records the link token, timestamp, coarse browser/OS family, device type, a truncated network prefix (never a raw IP address), network operator and coarse country/region, referrer domain, recipient client language, and whitelisted routing headers. It does not store raw IP addresses, full user agents, cookies, or any direct identifier of the email recipient. Automated security-scanner and proxy fetches are classified and excluded from human analytics.
- Open tracking is optional and off unless your administrator enables it; when on, it records opens with a confidence classification and the same privacy-preserving metadata.
- Per-message tokens (optional) mint a unique token per sent email so opens and clicks are attributable to a single message and anti-tracker caching is defeated; the token is a random value and is not a recipient identifier.
- Forwarding-entropy analysis (optional; requires per-message tokens) measures the diffusion of a single message across distinct networks, countries, and device classes to infer forwarding. It operates on the same non-identifying metadata above.
- Message log (optional; off by default): your administrator may enable storage of the subject line and To addresses of your organisation's signature-carrying sends so analytics can be searched by subject or recipient. This is the one exception to the no-recipient-identifiers default above: metadata only (never message bodies), scoped to your organisation, used solely for your organisation's own analytics, and deletable on request. Your organisation is responsible for the lawful basis of this processing and for informing its users.
- Adaptive signature state machine (optional; requires the message log to be on): varies which signature an outbound email carries based on how many times, and how recently, its sender has emailed the current recipient, and on that draft's detected topic and tone. Looks up the current recipient's address against the message log for this purpose; stores only a per-recipient count, first/last contact date, and a coarse topic label — never message content.
- You configure these features and remain responsible for using them consistently with applicable law and your own privacy notices.
7. Website visitors, cookies, and product analytics
- Marketing site. We use first-party, cookieless page analytics (path, UTM parameters, referrer host, coarse country, device class — no identifier, no stored IP) that run in every region. Optional first-party behavioural analytics using a single first-party cookie run only per the applicable consent regime (opt-in in the EU/UK/Switzerland/Canada/Brazil; opt-out elsewhere, with Global Privacy Control honoured automatically). We use no third-party trackers or advertising pixels. Full detail is in the Cookie Policy; your choices can be changed at Your privacy choices.
- In-product telemetry. To operate, secure, and improve the Service we record first-party, pseudonymous usage events (for example feature usage, page views within the app, sync and deployment events, and AI-tool invocations), audit logs of administrative and security-relevant actions, and aggregate engagement signals used to surface in-product guidance and nudges. We do not sell this data.
- Acquisition attribution. On sign-up we record first-touch attribution (UTM parameters, referral code, coarse country, and — where analytics consent applies — a hashed visitor identifier) to measure acquisition.
8. Offboarding, leaver mail, and CRM attribution
- Leaver mail coverage. When you offboard a person, the Service can deploy a successor auto-reply and watch the mailbox for inbound messages using metadata only (sender name and domain, subject, timestamps, and reply status) so messages are answered; it does not read or store message bodies. On Enterprise plans a standard out-of-office may be applied automatically.
- CRM integration. Where you connect a CRM (HubSpot, Salesforce), the Service pushes aggregate, bot-filtered campaign-banner click activity as CRM campaign activity and can surface CRM campaigns as banner suggestions. It does not export your employee directory, recipient email addresses, or message content to the CRM. Integration credentials are stored encrypted and are never displayed after entry.
9. Product improvement and model training
On Free and Individual/Pro plans only, and subject to the AI Features Addendum, OwnSig may capture the structure of saved signatures to improve its signature-creation features — template, styling, which field types are used, and a rendered layout skeleton in which every personal value is replaced by a placeholder token before anything is stored. Names, email addresses, phone numbers, postal addresses, URLs, photos, and free-text content are never captured, and the dataset is keyed by a salted one-way hash so it cannot be traced back to a workspace. Administrators can opt out at any time, which also deletes anything previously captured from that workspace. Enterprise and Enterprise Sovereign tenants are excluded from this at the source — no such capture occurs regardless of settings.
10. AI features (Penna)
- AI features are optional and disabled until an administrator enables them for your organisation.
- Bring-your-own-key. If you configure your own AI provider credentials, prompts and signature context are sent to that provider under your agreement with them. Keys are stored encrypted and are never displayed after entry.
- Managed AI. If you purchase the managed AI add-on, OwnSig routes requests to its contracted model providers under data-processing terms that prohibit training on your content.
- AI output can be inaccurate. Review generated signature content before deploying it. You are responsible for AI output you adopt.
11. Data protection, security, and residency
- We process personal data in Customer Data as your processor under our Data Processing Addendum (incorporating the EU Standard Contractual Clauses where applicable), available on request.
- We maintain an information security programme aligned to SOC 2 and ISO/IEC 27001 control standards, including encryption in transit and at rest, access controls, audit logging, and incident response with notification without undue delay and within 72 hours of confirming a personal-data breach.
- If your plan includes or you purchase data residency, we store Customer Data in the contracted region(s); with per-employee pinning, personal data of tagged employees is stored in their designated region.
- Upon termination you may export Customer Data for 30 days, after which it is deleted from production systems within 35 days and from backups on backup expiry.
12. Intellectual property; feedback
OwnSig retains all rights in the Service, including software, templates, and documentation. Signature layouts you create from our templates may be used by you freely in your email. If you provide feedback, we may use it without obligation.
13. Third-party services
The Service interoperates with third-party platforms (Microsoft 365, Google Workspace, CRMs, HRIS, identity providers, AI providers). Their availability and terms are outside our control; a third party's suspension of API access does not constitute our breach, though we will use reasonable efforts to restore or replace affected functionality.
14. Availability and support
We target the service levels published for your plan. Enterprise and Enterprise Sovereign plans carry a 99.95% monthly uptime SLA with service credits as the exclusive remedy, a 30-minute first-response target for urgent issues (24×7), and a named Customer Success Manager. Current and historical availability is published at our status page. Support channels and response targets are described on the support page.
15. Term, suspension, and termination
- This Agreement applies while you have an account. Either party may terminate for material breach not cured within 30 days of notice.
- We may suspend the Service immediately where reasonably necessary to prevent harm (security incident, unlawful use, non-payment after notice), scoped and limited in duration to what is necessary.
- You may cancel self-serve subscriptions at any time as described in Section 3 (no further charges; service runs to the end of the paid period) and delete your account at any time; Section 11(4) governs data return and deletion. Enterprise subscriptions follow the executed order form.
16. Warranties and disclaimers
We warrant that the Service will perform materially as described in the documentation. EXCEPT AS EXPRESSLY STATED, THE SERVICE IS PROVIDED “AS IS”, AND WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. WE DO NOT WARRANT THAT EMAIL DELIVERABILITY OUTCOMES, WHICH DEPEND ON FACTORS OUTSIDE OUR CONTROL, WILL MEET ANY PARTICULAR RESULT.
17. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW: (a) NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, REVENUE, OR DATA; AND (b) EACH PARTY'S AGGREGATE LIABILITY ARISING OUT OF THIS AGREEMENT IS LIMITED TO THE FEES PAID OR PAYABLE BY YOU IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY (OR US $100 FOR FREE ACCOUNTS). THESE LIMITS DO NOT APPLY TO YOUR PAYMENT OBLIGATIONS, EITHER PARTY'S INDEMNIFICATION OBLIGATIONS, INFRINGEMENT OF THE OTHER PARTY'S INTELLECTUAL PROPERTY, OR LIABILITY THAT CANNOT BE LIMITED BY LAW.
18. Indemnification
OwnSig will defend you against third-party claims that the Service infringes their intellectual property and pay resulting damages finally awarded, provided you promptly notify us and allow us to control the defence. You will defend OwnSig against claims arising from Customer Data or your use of the Service in violation of this Agreement or law.
19. General
This Agreement, the order form, the DPA, and referenced policies are the entire agreement regarding the Service. Neither party may assign it without consent, except to an affiliate or in connection with a merger or sale of substantially all assets. Notices to OwnSig: legal@ownsig.com. Governing law and venue: Delaware, USA (or, for customers contracting with our EU entity under an order form, Ireland). If any provision is unenforceable, the remainder stays in effect. We may update this EULA with 30 days' notice for material changes; continued use after the effective date constitutes acceptance.