Legal & compliance
How District Seal maps to the legal frameworks that govern electronic signatures and biometric data — with sources, and with clear boundaries on what this page does and does not establish.
United States — ESIGN Act
The Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001 et seq., "ESIGN") establishes that a signature, contract, or other record relating to a transaction in interstate or foreign commerce may not be denied legal effect, validity, or enforceability solely because it is in electronic form. ESIGN sets out several requirements for electronic records and signatures to be treated as equivalent to their paper counterparts.
| ESIGN requirement | How District Seal addresses it |
|---|---|
| Consumer consent to electronic records | District Seal shows a plain-language consent notice before any data is captured. The signer must affirmatively accept. The acceptance is timestamped in the forensic event log. |
| Ability to retain and print records | The signed PDF and the certificate are both provided as downloadable files. They can be printed. No proprietary viewer is required. |
| Attribution of the signature to the person signing | District Seal records a WebAuthn credential binding the ceremony to a specific physical device, plus a biometric identity check against a reference photo provided by the sender. |
| Record integrity | The signed document is bound to a SHA-256 hash at the moment of upload. A manifest hash binds the certificate to the event log. Any modification after signing invalidates the certificate. |
ESIGN specifically does not override state or federal rules governing wills, divorce, adoption, and certain other categories of documents (15 U.S.C. § 7003). District Seal does not claim to be usable for those categories.
United States — UETA
The Uniform Electronic Transactions Act ("UETA") is a model statute adopted in 49 U.S. states, the District of Columbia, and the U.S. Virgin Islands (as of this writing). UETA § 7(a) provides that a record or signature may not be denied legal effect solely because it is in electronic form. UETA § 9 addresses attribution: an electronic signature is attributable to a person if it was the act of that person, and the act may be shown by the effectiveness of any security procedure used to verify the signature.
District Seal's biometric verification — face match, spoken challenge, WebAuthn device binding — is designed to serve as such a security procedure. Whether it satisfies UETA § 9 for a specific transaction is a question for counsel.
European Union — eIDAS
Regulation (EU) No 910/2014 ("eIDAS") establishes three levels of electronic signature: Simple Electronic Signature (SES), Advanced Electronic Signature (AdES), and Qualified Electronic Signature (QES). District Seal produces signatures that are intended to be usable as Advanced Electronic Signatures when configured appropriately.
| AdES requirement (eIDAS Article 26) | How District Seal aligns |
|---|---|
| Uniquely linked to the signatory | Biometric face match against a sender-supplied reference photo, plus a WebAuthn device credential |
| Capable of identifying the signatory | Legal name, email, and a signed document record |
| Created using means under the signatory's sole control | WebAuthn binding to a physical device the signer controls |
| Linked to the data signed in a way that any later change is detectable | SHA-256 document hash; change any byte, verification fails |
Identity assurance — NIST SP 800-63-3
NIST Special Publication 800-63-3 defines Authenticator Assurance Levels (AAL) for digital identity. AAL2 requires two distinct authentication factors. District Seal's design maps to AAL2 as follows:
| NIST AAL2 element | How District Seal implements it |
|---|---|
| Something you have | WebAuthn device credential — a phone, laptop, or hardware security key |
| Something you are | Biometric face match against the sender-provided reference photo |
| Presentation Attack Detection (PAD) | Randomized spoken challenge, randomized gesture sequence, sensor-noise variance, and virtual-camera detection |
| Replay resistance | Challenge phrase and gesture order are random per session and cannot be pre-recorded |
Biometric privacy — BIPA, GDPR, CCPA
Illinois Biometric Information Privacy Act (BIPA)
BIPA (740 ILCS 14) is one of the strictest biometric privacy statutes in the United States. It requires: (1) written notice of the specific purpose and length of time for which biometric data is collected, stored, and used; (2) a written release from the individual; (3) destruction of the biometric data when the initial purpose is satisfied or within three years of the individual's last interaction, whichever comes first; and (4) a publicly available retention and destruction schedule.
District Seal's consent flow is designed to satisfy BIPA's notice and release requirements. District Seal's published retention schedule (see Security Architecture) publishes the retention period for biometric data. Raw biometric video and audio are destroyed within 24 hours; face embeddings are retained for the certificate retention period, which defaults to 7 years but is configurable. Whether a specific deployment complies with BIPA is a fact-specific question for counsel, particularly as BIPA case law continues to develop.
EU General Data Protection Regulation (GDPR)
GDPR Article 9(1) classifies biometric data used for the purpose of uniquely identifying a natural person as a "special category" of personal data. Processing is prohibited unless one of the exceptions in Article 9(2) applies — most commonly explicit consent (Article 9(2)(a)). GDPR also grants data subjects the right to withdraw consent (Article 7(3)), the right of access (Article 15), the right to erasure (Article 17), and the right to data portability (Article 20).
District Seal's consent flow captures explicit consent before biometric data is collected. Biometric data can be deleted on request by emailing legal@districtseal.com. Data is stored in the United States; transfers from the EU rely on the European Commission's Standard Contractual Clauses. A copy of the SCCs is available on request.
California Consumer Privacy Act (CCPA / CPRA)
The CCPA, as amended by the CPRA, provides California residents with the right to know what personal information is collected, the right to delete, the right to correct, and the right to opt out of sale or sharing. Biometric information is treated as sensitive personal information under the CPRA. District Seal does not sell personal information. Deletion requests are honored within 45 days. Requests can be sent to legal@districtseal.com.
What District Seal is not
To avoid ambiguity, District Seal does not claim to be:
- A notary public. District Seal is not a commissioned notary in any U.S. state or any other jurisdiction. It does not provide notarial acts, and the certificate it produces does not claim notarial authority.
- A qualified trust service provider under eIDAS. It does not issue Qualified Electronic Signatures.
- A law firm or provider of legal advice. Nothing in the District Seal product, documentation, or website constitutes legal advice.
- A court of law. Whether a signed document is enforceable, admitted, or binding is decided by courts and arbitrators, not by District Seal.
Records retention
The default retention period for signed documents, certificates, and forensic event logs is seven years from the date of issuance. This default is chosen to match common record-retention practices for signed instruments in the United States, including many state bar retention guidelines. Retention can be shortened or extended per account within the limits allowed by law. Full details of District Seal's retention policy are published on the Privacy Notice.
Duress reporting
District Seal maintains a dedicated duress reporting channel at duress@districtseal.com. If a signer believes they were forced or coerced into signing, they can write to that address with the certificate reference. District Seal will respond within 24 hours, flag the certificate as under active dispute (visible on the public verification page), and record the report permanently in the audit trail. District Seal cannot erase a signature that has already occurred, and only a court can void a legal agreement.
Governing law and jurisdiction
District Seal is operated by NEXSIM LLC, a Montana limited liability company. The District Seal Terms of Service are governed by the laws of the State of Montana, without regard to its conflict of laws principles. Nothing in this paragraph modifies or limits any right a user may have under the laws of their own jurisdiction.
Requests and contact
Legal notices, data subject access requests, deletion requests, and inquiries regarding the Standard Contractual Clauses should be sent to:
NEXSIM LLC
Attn: Legal
Email: legal@districtseal.com
Security disclosures should be sent to security@districtseal.com. Duress reports should be sent to duress@districtseal.com.
District Seal is a product of NEXSIM LLC, Montana, United States.