Plain-language summary
- ContextSign is a Microsoft 365 tenant-administered service for selecting and writing an approved Outlook signature.
- It does not upload or store message bodies, subjects, attachments, or plaintext recipient addresses.
- The default measurement mode has no recipient tracking or open pixel. Individual measurement is disabled unless the customer has configured an approved purpose, consent, and suppression controls.
- Customers control their tenant data. Digital David AG operates the service and processes that data under the customer agreement.
1. Who is responsible
Digital David AG
Weserstraße 4
60329 Frankfurt am Main
Germany
Email:
hello@digitaldavid.io
Digital David AG is registered with Amtsgericht Frankfurt am Main under HRB 121238 (VAT ID DE337018659).
For the public website, account administration, service security, support relationship, and Digital David's commercial records, Digital David AG acts as controller. For Microsoft 365 directory data, signature configuration, operational tenant data, and any consent-based recipient measurement configured by a customer, the customer organization normally acts as controller and Digital David AG acts as its processor. The customer determines its legal basis and gives its users and contacts any additional notices that are required.
2. Data ContextSign processes
Microsoft identity and tenant access
ContextSign validates Microsoft Entra tenant and user identifiers, the token issuer and audience, assigned application scope or role, and the selected ContextSign company membership. The administration portal displays identity claims such as name and work email. Stored memberships use the Entra tenant and object identifiers, assigned roles, state, and, where needed, a one-way email hash.
Tenant configuration and directory data
Administrators may store company and legal-entity information, approved sender names, roles, work addresses and aliases, group or mailbox references, brand assets, signature content, audience and rule configuration, approvals, releases, and audit records. If a tenant enables Microsoft Graph directory synchronization, the separate sync connection admits only the approved directory profile, alias, group, and mailbox fields needed for that configuration.
Outlook compose context
In Outlook, the add-in reads the active From identity, normalized recipient domains, message kind, locale, client capabilities, and protection state locally to select an approved signature. It writes only through Outlook's signature API. The add-in keeps Microsoft authentication state and token entities in same-origin local storage to support silent sign-in. Access tokens are sent only as TLS-protected authorization credentials to the intended ContextSign API and are validated there; ContextSign does not persist them in PostgreSQL, R2, KV, logs, analytics, or support systems. ContextSign does not upload or store the message body, subject, attachments, or raw recipient addresses. It does not use Microsoft Graph to read or send mail.
Operational and measurement data
Strict allowlists admit internal tenant, deployment, policy, campaign, variant, capability, result, reason-code, count, and timing fields. Unknown fields and values shaped like email addresses, mail content, authorization material, cookies, or unapproved URLs are rejected. Random correlation identifiers carry no intended user meaning.
- T0, the default: no recipient identifier, open pixel, or click tracking. Conversation-local state stays in the Outlook item session.
- T1, if approved by the customer: aggregate company-level campaign dimensions without a recipient identifier.
- T2, only if expressly configured: a tenant-scoped pseudonymous 64-character hash bound to an approved purpose, current consent, retention, revocation, and suppression record.
Subscription and support data
If ContextSign is acquired through Microsoft Marketplace, Digital David may process the Marketplace subscription identifier, customer and tenant identifiers, plan, seat quantity, lifecycle state, and associated administrative contact needed to activate and support the entitlement. Microsoft handles Marketplace payment processing; ContextSign does not receive full payment-card details. Support data is the information a requester chooses to provide, together with diagnostic codes and correspondence needed to resolve the request.
Marketplace configuration uses short-lived, first-party secure cookies and a maintenance-only activation record containing SHA-256 digests of browser state plus verified Microsoft tenant, user, and subscription identifiers. Authorization codes, purchase tokens, ID tokens, access tokens, PKCE verifiers, email addresses, and payment details are not stored in that record. Each authorization stage has a short server-enforced deadline, no stage can continue for more than 30 minutes, and the entire flow has a two-hour hard limit. A completed result can be replayed for five minutes only to recover a lost response. After those logical deadlines the record cannot authorize access; it becomes eligible for bounded deletion on new flow starts and during daily scheduled maintenance, so physical removal can occur later than the authorization deadline.
Network and security data
The hosting and identity services necessarily process connection metadata such as IP address, timestamp, user agent, TLS and request information to deliver and protect the service. Application logs are limited to structured security and operational evidence and exclude mail content and raw addresses.
3. Purposes and legal bases
Digital David processes data to:
- authenticate users, enforce tenant boundaries, and provide the contracted ContextSign service;
- compile, distribute, and apply approved signature policy and keep required approval and audit evidence;
- maintain security, prevent misuse, diagnose faults, and meet service obligations;
- administer subscriptions, entitlements, support, accounting, and legal obligations; and
- process optional measurement only at the privacy level approved by the customer.
Where Digital David is controller, the legal bases may include performance of a contract or steps requested before a contract (Article 6(1)(b) GDPR), compliance with legal obligations (Article 6(1)(c)), and legitimate interests in secure service delivery, support, fraud prevention, and business administration (Article 6(1)(f)). Consent is used where the relevant processing requires it (Article 6(1)(a)). Where Digital David is processor, it acts on the customer's documented instructions under Article 28 GDPR.
4. Recipients and service providers
Access is limited to authorized customer administrators and users, authorized Digital David personnel, and providers needed to operate the service. Current core providers and boundaries include:
- Microsoft: Entra identity, Microsoft 365 and Outlook add-in platform, optional Graph directory connection, and Marketplace subscription services where used;
- Cloudflare: Workers hosting and security, an EU-region connection through Hyperdrive to PlanetScale PostgreSQL, R2 objects configured for the EU jurisdiction, KV policy material, and queues; and
- Perspectify: allowlisted production observability signals containing internal references, codes, counts, and timings, without mail content or raw address data. In the signed-in administration portal, a user may submit feedback through the Perspectify widget. That submission contains the text the user enters, an opaque user and tenant reference, the current portal route, and an optional screenshot only when the user chooses to capture it. While the signed-in administration portal is open, ContextSign also captures a privacy-masked session replay, console diagnostics, network request and response diagnostics, and same-origin trace correlation. Form inputs are masked, known personal-data patterns are redacted, sensitive authentication headers are removed, and captured payload excerpts are bounded. Automatic email disclosure remains disabled.
Data may also be disclosed when required by law, to protect legal rights or service security, or in a corporate transaction subject to appropriate confidentiality and data-protection safeguards. Digital David does not sell personal data or use ContextSign tenant data for third-party advertising.
5. Locations and international transfers
ContextSign selects an EU-region operational data plane using PlanetScale PostgreSQL through Cloudflare Hyperdrive and R2. Microsoft, Cloudflare, and other providers can operate global networks and support functions. Where data is transferred outside the European Economic Area, Digital David and its providers rely on an applicable adequacy decision, approved standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where required.
6. Retention
Customer policy can shorten or, within the documented range, extend several operational periods. Current defaults and limits are:
| Data | Default | Control or limit |
|---|---|---|
| Outlook policy cache and pending telemetry outbox | Until refreshed or delivered | Maximum seven days |
| Runtime decision and error events | 30 days | 30–90 days |
| Aggregate conversions | 90 days | 30–365 days |
| Pseudonymous T2 events and conversions | 30 days | 1–30 days |
| Operational alert delivery records | 90 days | 30–90 days |
| Revoked or expired consent evidence | 365 days | 365–3,650 days |
| Security and administration audit | Append-only evidence | No automated audit-row deletion is currently enabled; records are retained for the service relationship and applicable legal limitation, evidence, or defense periods |
| Active mutable tenant data after final offboarding | Deletion workflow | Maximum seven days |
| Revoked signed archives not needed for privacy evidence | Eight days | Fixed safety horizon |
Active suppressions are retained while needed to honor an objection. Membership and append-only evidence can remain after offboarding when required to verify deletion, meet legal obligations, establish or defend claims, or honor privacy rights. Recovery copies follow the verified provider or export lifecycle and are protected from normal application use until expiry. Commercial and support records are kept for the applicable contract, limitation, tax, and statutory periods.
7. Local storage and cookies
The public legal and product pages do not set advertising or analytics cookies. The administration portal uses the Microsoft authentication library's same-origin session storage for the security and token state required for sign-in. The Outlook add-in uses same-origin local storage for Microsoft authentication state and token entities, and Office session or local storage for a signed policy cache, safe offline operation, conversation-local choices, and a bounded delivery outbox. These items are functional and are not used for cross-site advertising.
8. Security
ContextSign uses encrypted transport, validated Microsoft token issuer and audience boundaries, explicit company membership, role-based access, tenant-scoped database predicates, signed and immutable policy releases, restricted content schemas, protected secrets, rate limits, and auditable administration. No system can guarantee absolute security; suspected incidents should be reported through the protected process described on the support page.
9. Your rights
Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. Where a ContextSign customer controls the data, contact that organization first; Digital David will assist it with authenticated, tenant-scoped search, export, correction, deletion, objection, and suppression tools.
Requests may be sent to hello@digitaldavid.io. Digital David may verify identity and authority before responding. You may also complain to the competent supervisory authority, including the Hessian Commissioner for Data Protection and Freedom of Information, or the authority where you live or work.
10. Automated selection and children
ContextSign automatically selects an approved signature from tenant rules. That selection governs email presentation and does not produce a legal or similarly significant decision about a recipient or user. The service is intended for organizations and is not directed to children.
11. Microsoft and external links
ContextSign is an independent Digital David AG product. Microsoft controls Microsoft 365, Outlook, Entra, Graph, and Marketplace under Microsoft's own terms and privacy notices. Approved signature links may lead to customer-selected external sites, whose operators are responsible for their own content and privacy practices.
12. Changes and contact
Material changes will be published here with a new effective date and communicated to customer administrators when required. Questions about this notice can be sent to hello@digitaldavid.io.