Notara

Legal

Privacy Policy

Last updated: July 1, 2026

Notara Inc. ("Notara," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our remote online notarization platform, electronic signature services, identity verification tools, and related services (collectively, the "Services").

By accessing or using our Services, you consent to the practices described in this Privacy Policy.

1. Information We Collect

1.1 Personal Information You Provide

  • Account Information: Name, email address, phone number, company name, and billing information when you create an account.
  • Identity Verification Data: Government-issued photo identification (e.g., driver's license, passport), date of birth, address, and Social Security Number (last 4 digits) for knowledge-based authentication (KBA).
  • Notary Commission Information: State commission number, commission expiration date, E&O insurance details, digital certificate information, and notary bond details.
  • Documents: Documents uploaded for notarization or electronic signature.
  • Biometric Data: Facial recognition data used during identity verification to match the signer's face to their photo ID. This data is processed in real-time and not stored beyond the session unless required by state law.

1.2 Information Collected Automatically

  • Session Recordings: Audio-video recordings of all RON sessions, as required by applicable state law.
  • Device and Usage Data: IP address, browser type, operating system, device identifiers, pages visited, features used, timestamps, and referring URLs.
  • Location Data: General location derived from IP address to verify session compliance with state jurisdictional requirements.
  • Audit Trail Data: Detailed logs of all actions taken during notarization and signing sessions, including timestamps, IP addresses, and document hash values.

1.3 Information from Third Parties

  • KBA Providers: Credit bureau and public records data used to generate knowledge-based authentication questions.
  • Identity Verification Services: Document authentication results and fraud detection signals from our credential analysis partners.
  • Payment Processors: Transaction confirmations and billing information from Stripe.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To facilitate notarizations, electronic signatures, and identity verification sessions.
  • Identity Verification: To verify signer identities through credential analysis, KBA, and biometric matching as required by applicable law.
  • Compliance: To maintain records (journals, recordings, audit trails) as required by state RON laws and MISMO standards.
  • Security: To detect and prevent fraud, unauthorized access, and other security threats.
  • Communication: To send session invitations, status updates, receipts, and account-related notifications.
  • Improvement: To analyze usage patterns and improve our platform, features, and user experience.
  • Legal Obligations: To comply with applicable laws, regulations, legal processes, or enforceable government requests.

3. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Session Participants: Document contents, names, and session details are shared with all participants in a notarization or signing session.
  • Identity Verification Partners: Government ID data and biometric data are shared with our credential analysis and KBA providers solely for identity verification purposes.
  • Service Providers: Cloud hosting (AWS), payment processing (Stripe), email delivery, and analytics providers who are bound by data processing agreements.
  • Regulatory Bodies: Notary commission information and session records may be disclosed to state regulatory authorities upon lawful request.
  • Legal Requirements: When required by law, subpoena, court order, or government investigation.
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users.

4. Data Retention

Retention Periods by Data Type

RON Session Recordings5–10 years (per state law)
Electronic Notary Journal10 years minimum
Notarized Documents10 years minimum
Audit Trail Logs10 years minimum
Identity Verification DataDuration of account + 5 years
Account InformationDuration of account + 3 years
Biometric Data (facial recognition)Deleted after session verification

Retention periods are determined by the most restrictive applicable state law. Some states require longer retention periods than others. Data is securely deleted after the applicable retention period expires.

5. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: All data is encrypted using 256-bit AES encryption at rest and TLS 1.3 in transit.
  • SOC 2 Type II: Our infrastructure undergoes annual SOC 2 Type II audits by independent third-party auditors.
  • Access Controls: Role-based access controls (RBAC) with multi-factor authentication required for all administrative access.
  • Tamper-Evident Technology: All notarized documents and recordings use cryptographic hashing to detect any unauthorized modifications.
  • Monitoring: 24/7 security monitoring, intrusion detection, and automated threat response.
  • Disaster Recovery: Geographically redundant data centers with automated failover and regular backup testing.

6. Your Rights and Choices

6.1 All Users

  • Access: You may request a copy of the personal information we hold about you.
  • Correction: You may request correction of inaccurate personal information.
  • Account Deletion: You may request deletion of your account, subject to legal retention requirements.
  • Communication Preferences: You may opt out of marketing communications while still receiving transactional notifications.

6.2 California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to: know what personal information is collected; delete personal information; opt out of the sale of personal information (we do not sell personal data); and non-discrimination for exercising privacy rights.

6.3 Virginia, Colorado, Connecticut, and Other State Residents

Residents of states with comprehensive privacy laws (VCDPA, CPA, CTDPA, and others) have similar rights to access, correct, delete, and opt out. Contact us to exercise these rights.

7. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Essential Cookies: Required for platform functionality, authentication, and security. Cannot be disabled.
  • Analytics Cookies: Help us understand how you use the platform to improve our services. Can be disabled.
  • Preference Cookies: Remember your settings and preferences. Can be disabled.

We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings.

8. International Data Transfers

Our servers are located in the United States. If you access our Services from outside the United States, your information will be transferred to, stored, and processed in the United States. We implement appropriate safeguards for any international data transfers in compliance with applicable data protection laws.

9. Children's Privacy

Our Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete such information.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and/or by posting a prominent notice on our platform at least 30 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.

11. Contact Us

For questions about this Privacy Policy or to exercise your privacy rights, please contact us:

Notara Inc. — Privacy Team
Email: privacy@notara.com
Address: Miami, FL 33131
Phone: (305) 555-0100

For data protection inquiries, you may also contact our Data Protection Officer at dpo@notara.com.