Docs › Legal & Compliance

Legal & compliance

How District Seal maps to the legal frameworks that govern electronic signatures and biometric data — with sources, and with clear boundaries on what this page does and does not establish.

This page is not legal advice. It is documentation. It describes how District Seal works and which provisions of which statutes it is designed to align with. It does not state that District Seal complies with, satisfies, or meets any specific law for any specific use case. Whether a District Seal certificate will be admitted in court, or whether your use of District Seal satisfies a legal requirement, is a question for a licensed attorney admitted in the relevant jurisdiction.

United States — ESIGN Act

The Electronic Signatures in Global and National Commerce Act (15 U.S.C. § 7001 et seq., "ESIGN") establishes that a signature, contract, or other record relating to a transaction in interstate or foreign commerce may not be denied legal effect, validity, or enforceability solely because it is in electronic form. ESIGN sets out several requirements for electronic records and signatures to be treated as equivalent to their paper counterparts.

ESIGN requirementHow District Seal addresses it
Consumer consent to electronic recordsDistrict Seal shows a plain-language consent notice before any data is captured. The signer must affirmatively accept. The acceptance is timestamped in the forensic event log.
Ability to retain and print recordsThe signed PDF and the certificate are both provided as downloadable files. They can be printed. No proprietary viewer is required.
Attribution of the signature to the person signingDistrict Seal records a WebAuthn credential binding the ceremony to a specific physical device, plus a biometric identity check against a reference photo provided by the sender.
Record integrityThe signed document is bound to a SHA-256 hash at the moment of upload. A manifest hash binds the certificate to the event log. Any modification after signing invalidates the certificate.

ESIGN specifically does not override state or federal rules governing wills, divorce, adoption, and certain other categories of documents (15 U.S.C. § 7003). District Seal does not claim to be usable for those categories.

United States — UETA

The Uniform Electronic Transactions Act ("UETA") is a model statute adopted in 49 U.S. states, the District of Columbia, and the U.S. Virgin Islands (as of this writing). UETA § 7(a) provides that a record or signature may not be denied legal effect solely because it is in electronic form. UETA § 9 addresses attribution: an electronic signature is attributable to a person if it was the act of that person, and the act may be shown by the effectiveness of any security procedure used to verify the signature.

District Seal's biometric verification — face match, spoken challenge, WebAuthn device binding — is designed to serve as such a security procedure. Whether it satisfies UETA § 9 for a specific transaction is a question for counsel.

European Union — eIDAS

Regulation (EU) No 910/2014 ("eIDAS") establishes three levels of electronic signature: Simple Electronic Signature (SES), Advanced Electronic Signature (AdES), and Qualified Electronic Signature (QES). District Seal produces signatures that are intended to be usable as Advanced Electronic Signatures when configured appropriately.

AdES requirement (eIDAS Article 26)How District Seal aligns
Uniquely linked to the signatoryBiometric face match against a sender-supplied reference photo, plus a WebAuthn device credential
Capable of identifying the signatoryLegal name, email, and a signed document record
Created using means under the signatory's sole controlWebAuthn binding to a physical device the signer controls
Linked to the data signed in a way that any later change is detectableSHA-256 document hash; change any byte, verification fails
Qualified Electronic Signatures (QES). eIDAS provides the strongest legal presumption of equivalence to handwritten signatures to QES. Producing QES requires a certificate from a Qualified Trust Service Provider listed on an EU Trust List. District Seal does not currently issue QES and does not claim to. If your transaction requires QES, a QES provider must be used alongside or instead of District Seal.

Identity assurance — NIST SP 800-63-3

NIST Special Publication 800-63-3 defines Authenticator Assurance Levels (AAL) for digital identity. AAL2 requires two distinct authentication factors. District Seal's design maps to AAL2 as follows:

NIST AAL2 elementHow District Seal implements it
Something you haveWebAuthn device credential — a phone, laptop, or hardware security key
Something you areBiometric face match against the sender-provided reference photo
Presentation Attack Detection (PAD)Randomized spoken challenge, randomized gesture sequence, sensor-noise variance, and virtual-camera detection
Replay resistanceChallenge phrase and gesture order are random per session and cannot be pre-recorded

Biometric privacy — BIPA, GDPR, CCPA

Illinois Biometric Information Privacy Act (BIPA)

BIPA (740 ILCS 14) is one of the strictest biometric privacy statutes in the United States. It requires: (1) written notice of the specific purpose and length of time for which biometric data is collected, stored, and used; (2) a written release from the individual; (3) destruction of the biometric data when the initial purpose is satisfied or within three years of the individual's last interaction, whichever comes first; and (4) a publicly available retention and destruction schedule.

District Seal's consent flow is designed to satisfy BIPA's notice and release requirements. District Seal's published retention schedule (see Security Architecture) publishes the retention period for biometric data. Raw biometric video and audio are destroyed within 24 hours; face embeddings are retained for the certificate retention period, which defaults to 7 years but is configurable. Whether a specific deployment complies with BIPA is a fact-specific question for counsel, particularly as BIPA case law continues to develop.

EU General Data Protection Regulation (GDPR)

GDPR Article 9(1) classifies biometric data used for the purpose of uniquely identifying a natural person as a "special category" of personal data. Processing is prohibited unless one of the exceptions in Article 9(2) applies — most commonly explicit consent (Article 9(2)(a)). GDPR also grants data subjects the right to withdraw consent (Article 7(3)), the right of access (Article 15), the right to erasure (Article 17), and the right to data portability (Article 20).

District Seal's consent flow captures explicit consent before biometric data is collected. Biometric data can be deleted on request by emailing legal@districtseal.com. Data is stored in the United States; transfers from the EU rely on the European Commission's Standard Contractual Clauses. A copy of the SCCs is available on request.

California Consumer Privacy Act (CCPA / CPRA)

The CCPA, as amended by the CPRA, provides California residents with the right to know what personal information is collected, the right to delete, the right to correct, and the right to opt out of sale or sharing. Biometric information is treated as sensitive personal information under the CPRA. District Seal does not sell personal information. Deletion requests are honored within 45 days. Requests can be sent to legal@districtseal.com.

What District Seal is not

To avoid ambiguity, District Seal does not claim to be:

Records retention

The default retention period for signed documents, certificates, and forensic event logs is seven years from the date of issuance. This default is chosen to match common record-retention practices for signed instruments in the United States, including many state bar retention guidelines. Retention can be shortened or extended per account within the limits allowed by law. Full details of District Seal's retention policy are published on the Privacy Notice.

Duress reporting

District Seal maintains a dedicated duress reporting channel at duress@districtseal.com. If a signer believes they were forced or coerced into signing, they can write to that address with the certificate reference. District Seal will respond within 24 hours, flag the certificate as under active dispute (visible on the public verification page), and record the report permanently in the audit trail. District Seal cannot erase a signature that has already occurred, and only a court can void a legal agreement.

Governing law and jurisdiction

District Seal is operated by NEXSIM LLC, a Montana limited liability company. The District Seal Terms of Service are governed by the laws of the State of Montana, without regard to its conflict of laws principles. Nothing in this paragraph modifies or limits any right a user may have under the laws of their own jurisdiction.

Requests and contact

Legal notices, data subject access requests, deletion requests, and inquiries regarding the Standard Contractual Clauses should be sent to:

NEXSIM LLC
Attn: Legal
Email: legal@districtseal.com

Security disclosures should be sent to security@districtseal.com. Duress reports should be sent to duress@districtseal.com.

Not legal advice (repeated intentionally). This page is documentation of technical and design choices. It is not a legal opinion. Before relying on District Seal for a signature with legal consequences, consult a licensed attorney in the relevant jurisdiction. This page does not create an attorney-client relationship, and no reader should act on the basis of this page without independent counsel.

District Seal is a product of NEXSIM LLC, Montana, United States.

Back to documentation · Terms · Privacy