
Legal
Security & Data Retention
Last reviewed: 15 July 2026
1.How we protect your information
- All data is encrypted in transit using TLS 1.2+ between your browser, our servers and our infrastructure providers.
- Signed documents are stored in Google Firebase Storage in the europe-west2 (London) region, in a private bucket with deny-by-default access rules and admin-SDK-only reads. Downloads are always streamed through our server — no public storage URLs are ever exposed.
- Access to the administrative dashboard is protected by HTTP Basic authentication. No administrative function is available from a public signing link.
- Signing links use single-use, cryptographically random tokens which are linked to the email address the invitation was sent to and expire automatically after 30 days.
- Every signed submission is stamped server-side with the date, time, IP address and browser details of the signer, creating a verifiable audit record.
2.Retention policy
On submission of a completed agreement, PNC UNIQUE LTD applies the following workflow:
- Your submission is validated server-side.
- A final signed PDF is generated, embedding your details, signature, and the date, time and IP address of signing.
- The signed PDF is stored securely in Firebase Storage and a copy is delivered to PNC HR (admin@pncunique.com) using our transactional email provider.
- Signed agreements are contractual records. They are retained for the duration of your engagement with PNC and for up to 6 years afterwards, in line with the limitation period for contractual claims in England and Wales.
- Authorised administrators may delete individual records — including the stored signed PDF — from the administration dashboard where retention is no longer required.
3.What we retain
For every completed signing request, PNC UNIQUE LTD retains:
- Contractor full name, business name and invited email address.
- The service type (contract, invoice creation, insurance cover, or health & safety) and the response given.
- Sent, opened and signed/declined status timestamps.
- The IP address and browser user-agent recorded at the moment of signing (for audit and fraud prevention).
- The signed PDF document itself, for the retention period described in section 2.
4.Access controls
- The signing portal is invitation-only. Signing links are single-use and cryptographically linked to the email address the invitation was sent to.
- Signing links cannot be re-used once completed, and expire after 30 days.
- The administrative dashboard is protected by administrator credentials that are rotated per PNC internal policy.
- Firebase Admin SDK service-account credentials are held only server-side and are never exposed to browsers.
- Our email API keys are stored server-side only. No email provider API key is embedded in any frontend bundle.
5.Responsible disclosure
If you believe you have discovered a security vulnerability affecting the PNC UNIQUE LTD contract e-signature portal, please report it in confidence to admin@pncunique.com. We acknowledge reports within 5 working days.
6.Anti-phishing
Before entering personal information, always confirm that the address in your browser matches the link in the invitation email you received from PNC. PNC UNIQUE LTD will:
- Never request your signing link or personal details by telephone.
- Never ask you to complete an agreement through any unrelated domain.
- Never ask you to install browser extensions or unusual software.
- Always send invitations from admin@pncunique.com — the sender authenticated at our email provider.
If in doubt, do not enter your details. Contact us directly on 0333 090 5024 or by email at admin@pncunique.com to verify the invitation.
7.Company identity
PNC UNIQUE LTD, registered in England and Wales.
Registered office: Headlands House, 1 Kings Court, Kettering Parkway, Kettering, Northamptonshire, NN15 6WJ.
ICO Registration: ZB865873.
Website: https://www.pncunique.com
Contact: admin@pncunique.com · 0333 090 5024