Data protection
Data protection
We protect uploaded documents and related information using secure cloud hosting, encryption, and ongoing monitoring.
Golo Sign collects and stores document information, signature records, and account details solely to provide electronic signature and workflow services. We apply administrative, technical, and organisational measures designed to protect that information throughout its lifecycle.
Secure cloud hosting
Golo Sign uses secure cloud hosting to store documents and related platform data. Our approach prioritises reliability, availability, and alignment with Australian privacy expectations.
- Documents stored using enterprise-grade cloud infrastructure
- Data residency aligned with Australian operations
- Controlled access to stored files and generated records
- Separation between uploaded content and completed outputs
- Availability designed to support business signing workflows
We do not sell customer document content. Files are retained while your account is active and as required for legal and compliance purposes.
Encryption and transmission
We implement strong security measures including encryption in transit and at rest to reduce the risk of unauthorised access to documents and account information.
- TLS encryption for data in transit across web and API connections
- AES-256 encryption at rest for stored files and records
- Secure backups and recovery processes
- Controlled retrieval paths for document viewing and signing
- Monitoring systems to support operational security
Users should also protect their own devices, networks, and credentials when accessing Golo Sign.
Document handling and retention
Uploaded documents are processed only to provide electronic signature and workflow services. Integrity checks and audit records support review when disputes arise or compliance teams require evidence.
- Documents processed solely to deliver the Services
- Audit logging across key document lifecycle events
- Retention aligned with legal and compliance requirements
- Deletion requests handled in accordance with our Privacy Policy
- Completed envelopes produce records intended for audit review
Third-party service providers
We may use third-party providers for hosting, payments, analytics, and customer support. These providers process data only as necessary to deliver services on our behalf.
- Providers bound by contractual confidentiality obligations
- Processing limited to the purpose of delivering the Services
- Reasonable steps taken to ensure adequate data protection
- Some providers may store data outside Australia where disclosed in our Privacy Policy
For questions about subprocessors or data handling, contact [email protected].
Questions about security?
For security reviews, vendor questionnaires, or compliance discussions, contact our team. We can provide additional detail relevant to your organisation.
Australian Owned & Operated
AES-256 Encryption
Electronic Transactions Act Ready
Audit Trails & Logging
Multi-Factor Authentication