Skip to main content

GDPR & data residency

TrueSign is designed for European organizations: documents and signature proofs never leave the European Union.

Where the data lives

DataWhereHandled by
Business records (requests, signers, templates)Your Salesforce orgYou (data controller)
Documents being signed, proof certificatesYousign — hosted in France (EU)Yousign, eIDAS-qualified trust service provider
Final signed PDFRe-attached to your Salesforce orgTrueSign, automatically

TrueSign is a native Salesforce package: there is no intermediate TrueSign server — no data transits or is stored anywhere other than your org and Yousign.

Personal data processed

For each signer: first name, last name, email, phone (if SMS authentication), and the signature proof data (timestamp, events). They serve exclusively to execute the signature — no secondary use.

For your processing register: Yousign acts as a processor under the GDPR (a DPA is available from Yousign).

Minimization and retention

  • The per-signer private note is forwarded to Yousign but not kept in Salesforce after sending.
  • Technical logs have configurable retention (90 days by default) with automatic purge — see Logs & audit.
  • Deleting a Salesforce record follows your own retention policies; on the Yousign side, durations are governed by your Yousign contract.

Sovereignty

  • A French, eIDAS-qualified signature provider, hosted in the EU — no signature-related transfer outside the EU.
  • eIDAS compliance across all 27 EU countries — see Signature levels.
This site too

This documentation site uses no cookies and collects no personal data.