GDPR & data residency
TrueSign is designed for European organizations: documents and signature proofs never leave the European Union.
Where the data lives
| Data | Where | Handled by |
|---|---|---|
| Business records (requests, signers, templates) | Your Salesforce org | You (data controller) |
| Documents being signed, proof certificates | Yousign — hosted in France (EU) | Yousign, eIDAS-qualified trust service provider |
| Final signed PDF | Re-attached to your Salesforce org | TrueSign, automatically |
TrueSign is a native Salesforce package: there is no intermediate TrueSign server — no data transits or is stored anywhere other than your org and Yousign.
Personal data processed
For each signer: first name, last name, email, phone (if SMS authentication), and the signature proof data (timestamp, events). They serve exclusively to execute the signature — no secondary use.
For your processing register: Yousign acts as a processor under the GDPR (a DPA is available from Yousign).
Minimization and retention
- The per-signer private note is forwarded to Yousign but not kept in Salesforce after sending.
- Technical logs have configurable retention (90 days by default) with automatic purge — see Logs & audit.
- Deleting a Salesforce record follows your own retention policies; on the Yousign side, durations are governed by your Yousign contract.
Sovereignty
- A French, eIDAS-qualified signature provider, hosted in the EU — no signature-related transfer outside the EU.
- eIDAS compliance across all 27 EU countries — see Signature levels.
This site too
This documentation site uses no cookies and collects no personal data.