PNC UNIQUE LTD

Legal

Security & Data Retention

Last reviewed: 15 July 2026

1.How we protect your information

  • All data is encrypted in transit using TLS 1.2+ between your browser, our servers and our infrastructure providers.
  • Signed documents are stored in Google Firebase Storage in the europe-west2 (London) region, in a private bucket with deny-by-default access rules and admin-SDK-only reads. Downloads are always streamed through our server — no public storage URLs are ever exposed.
  • Access to the administrative dashboard is protected by HTTP Basic authentication. No administrative function is available from a public signing link.
  • Signing links use single-use, cryptographically random tokens which are linked to the email address the invitation was sent to and expire automatically after 30 days.
  • Every signed submission is stamped server-side with the date, time, IP address and browser details of the signer, creating a verifiable audit record.

2.Retention policy

On submission of a completed agreement, PNC UNIQUE LTD applies the following workflow:

  • Your submission is validated server-side.
  • A final signed PDF is generated, embedding your details, signature, and the date, time and IP address of signing.
  • The signed PDF is stored securely in Firebase Storage and a copy is delivered to PNC HR (admin@pncunique.com) using our transactional email provider.
  • Signed agreements are contractual records. They are retained for the duration of your engagement with PNC and for up to 6 years afterwards, in line with the limitation period for contractual claims in England and Wales.
  • Authorised administrators may delete individual records — including the stored signed PDF — from the administration dashboard where retention is no longer required.

3.What we retain

For every completed signing request, PNC UNIQUE LTD retains:

  • Contractor full name, business name and invited email address.
  • The service type (contract, invoice creation, insurance cover, or health & safety) and the response given.
  • Sent, opened and signed/declined status timestamps.
  • The IP address and browser user-agent recorded at the moment of signing (for audit and fraud prevention).
  • The signed PDF document itself, for the retention period described in section 2.

4.Access controls

  • The signing portal is invitation-only. Signing links are single-use and cryptographically linked to the email address the invitation was sent to.
  • Signing links cannot be re-used once completed, and expire after 30 days.
  • The administrative dashboard is protected by administrator credentials that are rotated per PNC internal policy.
  • Firebase Admin SDK service-account credentials are held only server-side and are never exposed to browsers.
  • Our email API keys are stored server-side only. No email provider API key is embedded in any frontend bundle.

5.Responsible disclosure

If you believe you have discovered a security vulnerability affecting the PNC UNIQUE LTD contract e-signature portal, please report it in confidence to admin@pncunique.com. We acknowledge reports within 5 working days.

6.Anti-phishing

Before entering personal information, always confirm that the address in your browser matches the link in the invitation email you received from PNC. PNC UNIQUE LTD will:

  • Never request your signing link or personal details by telephone.
  • Never ask you to complete an agreement through any unrelated domain.
  • Never ask you to install browser extensions or unusual software.
  • Always send invitations from admin@pncunique.com — the sender authenticated at our email provider.

If in doubt, do not enter your details. Contact us directly on 0333 090 5024 or by email at admin@pncunique.com to verify the invitation.

7.Company identity

PNC UNIQUE LTD, registered in England and Wales.

Registered office: Headlands House, 1 Kings Court, Kettering Parkway, Kettering, Northamptonshire, NN15 6WJ.

ICO Registration: ZB865873.

Website: https://www.pncunique.com

Contact: admin@pncunique.com · 0333 090 5024