SignMe compliance
Last updated: 7 September 2026
SignMe is the part of Decoder that sends a PDF out for signature. This page sets out what SignMe records when a document is signed, where that record is stored, and how electronic signatures are generally treated in the countries where Decoder is offered. It is a description of the product, not advice about your document. For a view on your own situation, ask a qualified professional.
1. What the record contains
Whether an electronic signature holds up usually turns on four questions: who signed, whether they meant to, whether the document changed afterwards, and when each step happened. SignMe keeps evidence for each of them and prints it in a completion certificate appended to the signed copy.
Who signed
Each recipient is named by the sender, with an email address. The signing link is unique to that recipient and is sent only to that address. When the recipient first opens the link, and when they consent, sign or decline, the time, the network address and the browser used are recorded against their name. The certificate also records whether the signature was drawn or typed.
Whether they meant to
Before the signing can be finished, the recipient ticks a statement that they will sign the document electronically. Nothing is submitted until that box is ticked. That consent is stored as its own event with its own time and appears on the certificate. A recipient can decline instead of signing, and a decline, with any reason given, is recorded the same way.
Whether the document changed
SignMe computes a SHA-256 fingerprint of the document it stores and prints it on the certificate. Anyone holding a copy can recompute the fingerprint with standard tools and compare it. A changed file gives a different fingerprint. SignMe does not change the wording of the pages. It places the signatures and field values on top and then appends the certificate. A page saved at an angle is rebuilt upright when the document is added, which can drop links and annotations on that page.
When each step happened
Every event is stamped in Coordinated Universal Time on the server, not on the signer's device: sent, viewed, consent, signed, declined, voided, completed and expired. The certificate lists them in order as a timeline, and the app shows the same timeline for each request.
2. How the record is kept
- The uploaded PDF, the placed fields, the recipients' details, their signatures and the completed copy are stored by our database provider in the Sydney, Australia region.
- Data moves between the app, the browser and our servers over encrypted connections. Signing links are stored as one-way hashes, so a copy of our database does not reveal a working link.
- Documents sent for signature are never sent to our artificial intelligence provider. Decoding and SignMe are separate: a document is only read by the model if you decode it.
- A completed document and its signatures are kept for 90 days after completion, or until the sender deletes the request, whichever comes first. After that the files are removed and only the request's event record remains. Unless the sender turns copies off, every recipient is emailed the finished copy at completion. Download it if you need it for longer.
- Document content is not sold, not used for advertising, and not used to train models. See the Privacy Policy for the full description.
3. Electronic signatures by country
Most countries where Decoder is available recognise electronic signatures for ordinary commercial and personal agreements, and treat a signature as valid where the signer intended to sign, consented to doing it electronically, and the record shows who signed and that the document was not changed afterwards. SignMe keeps the evidence described in Section 1 for that reason. The summaries below are general and are not a statement about any particular document.
Australia
The Electronic Transactions Act 1999 (Commonwealth) and the matching state and territory Acts provide that a signature requirement can be met electronically where a method identifies the person and indicates their intention, the method is reliable for the purpose, and the other party consents to the method.
United States
The federal Electronic Signatures in Global and National Commerce Act and the Uniform Electronic Transactions Act, adopted in most states, give an electronic signature the same effect as a handwritten one for most transactions where the parties agreed to deal electronically.
European Union
Regulation (EU) 910/2014, known as eIDAS, sets three levels of electronic signature. A SignMe signature is a simple electronic signature under that regulation: it cannot be denied legal effect solely because it is electronic, and its weight is a matter for the court considering the evidence.
United Kingdom
The Electronic Communications Act 2000 and the retained version of eIDAS treat electronic signatures as admissible evidence, and courts have accepted a range of electronic methods where intention to sign is shown.
Canada
The Personal Information Protection and Electronic Documents Act and the provincial electronic commerce Acts recognise electronic signatures for most agreements. Some provinces set their own requirements for particular document types.
New Zealand
The Contract and Commercial Law Act 2017 provides that a signature requirement is met by an electronic signature that identifies the signer, indicates approval, and is as reliable as is appropriate for the purpose, with the other party's consent.
Documents that are usually excluded
Each of these laws leaves out certain documents, and the list differs by place. Wills and codicils, some trusts and powers of attorney, documents that must be witnessed or notarised in person, court filings, and some family law, property transfer and immigration documents are commonly outside the electronic signature rules. If your document is one of these, check the rule that applies where you are before sending it through SignMe.
4. What SignMe does not do
- It does not verify identity beyond the email link and the signer's own entry. There is no government ID check, no text message code and no video step. If you need a higher level of identification, SignMe is not the right tool for that document.
- It does not produce an advanced or qualified electronic signature under eIDAS, and it does not use a certificate issued by a trust service provider.
- It does not read, check or judge the document you send, and it does not say whether the document will hold up. If you want to know what a document says, decode it first.
- MimicLabs does not hold ISO 27001 or SOC 2 certification and does not offer a business associate agreement for health information. The security measures we use are described in the Privacy Policy.
5. What is on us, and what is on you
MimicLabs keeps the signing service running, records the events described above, appends the certificate, stores the files as described, and removes them on the stated schedule. You choose the document, enter each recipient's name and email address correctly, share each link only with the person it names, and decide whether an electronic signature suits the document and the place where it will be relied on. See the Terms of Service for the full arrangement.
Questions about this document can be sent to support@mimiclabs.au.