CollectEsign← Back to home

Privacy Policy

Effective date: June 10, 2026 · Last updated: June 10, 2026

This Privacy Policy explains how CollectEsign (a product of Nur Behavioral Health) ("we", "us") collects, uses, and protects information through the CollectEsign application and related services (the "Service") — an electronic-signature platform for sending documents and collecting legally-binding signatures.

1. Information we collect

  • Account & identity — name, work email, and organization, managed through our identity provider (AWS Cognito). We do not store your password.
  • Documents & signing data — the PDFs you upload, the fields you place, recipient names and email addresses you enter, captured signatures, and the completion/audit trail for each envelope.
  • Usage & device data — log data needed to operate and secure the Service (e.g., timestamps, IP address for security and the signing audit trail). We keep document contents out of logs and URLs.

2. How we use information

We use information solely to provide, secure, maintain, and improve the Service — including authentication, preparing and routing documents for signature, generating tamper-evident sealed PDFs, and maintaining a signing audit trail. We do not sell personal information, and we do not use your documents or recipients' information for advertising.

3. Documents that contain health information

If your organization uses CollectEsign to send documents that contain Protected Health Information (PHI), we act as a Business Associate of your organization (the Covered Entity) under HIPAA and handle that information in accordance with a signed Business Associate Agreement (BAA). See our HIPAA Notice for details on safeguards and rights.

4. How information is shared

We share information only with subprocessors needed to run the Service, each under appropriate contractual and (where PHI is involved) BAA protections — for example, HIPAA-eligible AWS services for hosting, encryption, and document storage. We also share a document and its signing details with the recipients you designate. We disclose information when required by law or to protect rights and safety.

5. Data security

Documents are stored in private, encrypted object storage and are encrypted in transit (TLS 1.2+), hosted only on HIPAA-eligible infrastructure. We enforce multi-factor authentication (and passkeys), role-based access scoped to each organization, session timeouts, and an audit trail on signing activity.

6. Data retention

We retain your documents and signing records for as long as your organization maintains an account and as required by applicable law and your records-retention obligations. On termination, data is handled per your agreement and, where applicable, the BAA.

7. Your rights

You may access, correct, or delete your account information by contacting us. Where a document contains PHI controlled by your organization, requests regarding that PHI should be directed to your organization, which we support as its Business Associate. Contact us at info@collectesign.com.

8. Cookies

We use only the cookies/local storage necessary to keep you signed in and to operate the Service. We do not use advertising or cross-site tracking cookies.

9. Children's privacy

The Service is intended for business and professional use and is not directed to children. Any information about minors contained within a document is entered by the sending organization and handled under the terms of this policy and any applicable BAA.

10. Changes & contact

We may update this policy; material changes will be posted here with a new effective date. Questions: info@collectesign.com, 316 E Bloomingdale Ave, Brandon FL 33511.

Privacy PolicyTerms & ConditionsHIPAA NoticeSecurity
CollectEsignSend & sign documents online.
ProductFeaturesHow it worksLogin
LegalPrivacy PolicyTerms & ConditionsHIPAA NoticeSecurity
Contact1-656-222-0703info@collectesign.com
© 2026 CollectEsign · Send & sign documents online · v2026.06.28