PAM Group

Privacy Policy

PAM e-Sign · Effective 4 August 2026

PAM e-Sign is a workplace tool, not a consumer app. Accounts are created by your organisation's administrator — you cannot sign up on your own — and everything in it belongs to your employer.

We do not sell your data, show you advertising, or track you across other apps and websites. There is no analytics or advertising software of any kind in this application.

1. Who is responsible

The application is developed and operated by PT Nusantara Solusi Teknologi, a member of PAM Group, on behalf of the organisation that issued your account.

Your employer decides who has an account, what documents are placed in the system, and who may see them. For questions about a specific document, contact your organisation's administrator first — they can act on it immediately, and we generally cannot.

2. What we collect

Only what the service needs in order to work. Nothing is gathered in the background.

CategoryWhat it contains and why
Account details Name, email address, job position, department, business unit, and role. Entered by your administrator so that documents can be routed to the right person and signatures can be attributed correctly.
Signature specimen The image of your signature and your initials, either drawn on screen or uploaded from your camera or photo library. This is stamped onto the documents you sign.
Documents and notes The PDF files uploaded to the system, their titles and numbers, the approval route, and any notes written about them.
Activity record Every action taken on a document — who, what, and when — together with the IP address and the browser or device identification reported by your device. This is what makes a signature defensible later; see section 6.
Device registration If you use the mobile app, an anonymous notification token issued by Google, the platform name, and the device model — so that a notification can reach that specific phone. It is deleted when the token stops working or you are removed.
Sign-in record The time you last signed in and the time you last changed your password.

3. What we do not collect

  • No advertising identifier and no advertising of any kind.
  • No analytics or crash-reporting software. The application contains no third-party tracking library.
  • No location data. The app never requests location access.
  • No contacts, calendar, call logs, messages, or files other than the image you deliberately choose as your signature.
  • No biometric data. See below — this one is worth being precise about.

Fingerprint and Face ID

Your fingerprint or face is never sent to us, never stored by us, and never leaves your phone. The app asks the operating system a single yes-or-no question — "is this the owner of this device?" — and only receives the answer. The biometric itself stays in secure hardware that no application can read, ours included.

4. Permissions the app asks for

PermissionWhen and why it is used
Notifications To tell you that a document is waiting for your signature. You may decline, and the app keeps working — you will simply have to open it to find out.
Camera and photo library Requested only at the moment you choose to photograph or upload a signature specimen. The image is used for that and nothing else, and it is not examined for any other purpose.
Biometrics To confirm it is you before a signature is applied, where your organisation requires it.
Internet To reach your organisation's server. The app talks to that server and to Google's notification service — nowhere else.

5. Who else can see it

We do not sell personal data and we do not share it for advertising. It leaves your organisation's server in only three circumstances, all of them necessary for the service to function.

The public verification portal

Every signed document carries a QR code and a verification link so that a recipient can confirm it is genuine. Anyone holding that link or QR code can open it without signing in, and will see the document title and number, the issuing business unit, and the full approval trail — the name, position, action, and timestamp of every person who signed it. While the file is still within its retention period, they can also download the signed PDF.

This is the point of the feature: a signature nobody can check is worthless. But it does mean that anyone you hand a signed document to can see who signed it, and can pass that link on. Treat the link as being as sensitive as the document itself.

Push notification delivery (Google)

Mobile notifications are delivered through Firebase Cloud Messaging, operated by Google. To reach your phone, the notification passes through Google's servers — and because a notification has to be useful at a glance, it contains the document title and, where relevant, the name of the person who acted on it. The document file itself is never sent, and Google receives no other information about you. If this matters for a particular class of document, turn notifications off for the app.

Email

The same alerts are sent by email through your organisation's mail provider, and they contain the same document titles and names.

Beyond these three, document files never leave your organisation's server. They are not sent to any third party, and they are not used to train any machine-learning or artificial-intelligence system.

6. How long it is kept

Files. Signed PDF files are deleted automatically 90 days after final signature.

The record is not. The approval trail, the list of signers, the timestamps, and the SHA-256 fingerprint of the file are kept indefinitely, and this is deliberate. Certificates and QR codes printed on paper outlive the file; if we erased the record along with it, every document already in circulation would become unverifiable. After the file is gone, the verification portal still answers the question that matters — who signed this, and when — but the file can no longer be downloaded.

Account details are kept for as long as your organisation keeps your account open. When an account is closed, past signatures remain attributed to the person who made them; a signature that could be detached from its signer would not be a signature.

7. How it is protected

  • All traffic is encrypted in transit (HTTPS).
  • Passwords are stored only as a one-way hash. Nobody — including administrators and including us — can read your password.
  • Temporary passwords must be changed on first sign-in.
  • Access is limited by role and by business unit: you see the documents you are part of, not everything on the server.
  • Every signed file carries a SHA-256 fingerprint, so any later alteration of the file is detectable.
  • Optional biometric confirmation before signing.
  • Document files are stored outside the public web directory and are served only to people entitled to them.

No system is perfectly secure, and we will not claim otherwise. If you believe an account has been compromised, tell your administrator immediately so it can be suspended.

8. Your rights

You may ask to see the personal data held about you, to have it corrected, or to have your account and its details deleted.

Start with your organisation's administrator — the account belongs to them and they can act at once. You may also write to us at pamplusofficial@gmail.com, and we will respond within 30 days.

One limit, stated plainly. Deleting an account does not withdraw signatures already made. Documents that have been signed are business and legal records belonging to your organisation, and they are retained as described in section 6. Everything else — your profile details, your signature specimen, your device registration — is removed.

9. Children

PAM e-Sign is a tool for employees and business partners. It is not directed at children, and we do not knowingly create accounts for anyone under 18.

10. Changes to this policy

If what the application does with your data changes, this page changes with it and the effective date at the top is updated. Material changes will also be announced inside the application.

11. Contact

PT Nusantara Solusi Teknologi — a member of PAM Group
pamplusofficial@gmail.com

© 2026 PT. Nusantara Solusi Teknologi — a member of PAM Group