Legal

Acceptable use policy

What you may not do with DropTheDoc, the content categories Indian law requires us to prohibit, and what happens if you break the rules.

Effective
26 July 2026
Version
1.0

This policy forms part of the terms of service and applies to everyone who uses DropTheDoc, including recipients who never create an account. It exists because a tool for getting documents signed is also a tool for getting documents signed under false pretences, and we would rather be explicit than discover the difference later.

1.The general rule

Use DropTheDoc for documents you have the right to send, addressed to people who are expecting them, for purposes that are lawful where you and they are located. Almost everything below follows from that.

2.Prohibited conduct

You must not:

  • Send a document you have no right to send, or that you are not authorised to send on behalf of the named sender.
  • Impersonate any person or organisation, or misrepresent your affiliation with one, including by configuring workspace branding to look like someone else.
  • Obtain a signature by deception, including by misrepresenting what a document is, hiding material terms, altering a document after a recipient has reviewed it, or placing fields in a way designed to mislead someone about what they are agreeing to.
  • Use the service for fraud, money laundering, terrorist financing, or to evade sanctions or export controls.
  • Upload or transmit malware, or any code designed to interrupt, destroy or limit the functionality of any computer resource.
  • Attempt to gain unauthorised access to any account, workspace, document or system, or to bypass authentication, authorisation, rate limiting or any other control.
  • Probe, scan, load test or penetration test the service without our prior written authorisation, other than good-faith research within the safe harbour on the security page.
  • Scrape, crawl or systematically extract data from the service, or use automated means to create accounts.
  • Resell, sublicense or provide the service to a third party as your own, unless we have agreed it in writing.
  • Reverse engineer, decompile or disassemble the service, except where applicable law expressly permits it despite this restriction.
  • Interfere with the service or place an unreasonable load on it, including through denial of service.
  • Remove, obscure or falsify any document identifier, audit record, certificate of completion or hash we generate, or present a document as signed through DropTheDoc when it was not.

3.Prohibited content

Rule 3(1)(b) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 requires us to inform users that they must not host, display, upload, modify, publish, transmit, store, update or share information that:

  1. Belongs to another person and to which the user does not have any right.
  2. Is obscene, pornographic, paedophilic, invasive of another's privacy including bodily privacy, insulting or harassing on the basis of gender, libellous, racially or ethnically objectionable, relating to or encouraging money laundering or gambling, or otherwise inconsistent with or contrary to the laws in force.
  3. Is harmful to a child.
  4. Infringes any patent, trademark, copyright or other proprietary rights.
  5. Violates any law for the time being in force.
  6. Deceives or misleads the addressee about the origin of the message, or knowingly and intentionally communicates any information that is patently false or misleading in nature but may reasonably be perceived as a fact.
  7. Impersonates another person.
  8. Threatens the unity, integrity, defence, security or sovereignty of India, friendly relations with foreign states, or public order, or causes incitement to the commission of any cognisable offence, or prevents investigation of any offence, or is insulting to any other nation.
  9. Contains a software virus or any other computer code, file or programme designed to interrupt, destroy or limit the functionality of any computer resource.
  10. Is patently false and untrue, and is written or published in any form with intent to mislead or harass a person, entity or agency for financial gain, or to cause injury to any person.

These categories apply in addition to everything else in this policy, and they apply wherever you are, not only in India.

4.Email and unsolicited messages

DropTheDoc sends email on your behalf, from our sending infrastructure, so your sending practices affect every other customer's deliverability. Treat this section as strictly enforced.

  • Send documents only to people who are expecting them or who have a genuine business relationship with you.
  • Do not use DropTheDoc for marketing, newsletters, promotional campaigns or bulk unsolicited email. It is not an email marketing tool and using it as one will get your account suspended.
  • Do not send to purchased, harvested, scraped or rented address lists.
  • Do not falsify sender information, headers or reply-to addresses.
  • Comply with the anti-spam law that applies to your recipients, including the CAN-SPAM Act in the United States, CASL in Canada, the GDPR and the ePrivacy rules in the EEA, the Privacy and Electronic Communications Regulations in the United Kingdom, the Spam Act 2003 in Australia, and the TRAI Telecom Commercial Communications Customer Preference Regulations in India.
  • Respect a recipient who tells you to stop. Do not resend a document to someone who has declined it or asked not to be contacted.

We monitor bounce rates, complaint rates and abuse reports, and we may throttle or suspend sending on an account that is generating them.

5.Documents that must not be sent

Some documents are excluded by statute

Certain document types cannot lawfully be executed electronically, including wills and testamentary dispositions, powers of attorney, trust deeds, negotiable instruments other than cheques, and contracts for the sale or conveyance of immovable property in India, plus the categories excluded by ESIGN section 103 in the United States. The full list is at e-sign disclosure clause 12. Sending one through DropTheDoc does not make it valid and may make it void.

You must also not use the service for a document whose contents you are legally prohibited from holding or transmitting, or that would require a licence or authorisation you do not hold.

6.Personal data in documents

You decide what goes into a document, so you carry the data protection obligations for it. Do not include special category or sensitive personal data, such as health records, biometric data, financial account credentials or government identifiers, unless you have a lawful basis and any consent the applicable law requires. Do not include another person's personal data without the right to process it. The full allocation of responsibility is in the privacy policy and the data processing addendum.

7.Fair use of resources

Plan limits apply as published. Beyond those, we ask that you do not use the service in a way that degrades it for others: unusually large files, extreme document volumes, or automated request patterns that behave like an attack. If your legitimate usage is going to be unusual, tell us at support@dropthedoc.xyz first and we will make room for it rather than throttle you by surprise.

8.Reporting a violation

If you receive a document through DropTheDoc that you believe is fraudulent, infringing, unlawful or otherwise in breach of this policy, report it to grievance@dropthedoc.xyz. Include the document identifier from the email or the signing page, the sender's address, and what is wrong with it.

The grievance redressal policy sets out how we acknowledge and resolve reports, and the timelines we work to. Do not sign a document you believe is fraudulent in order to obtain evidence. Report it instead.

9.What we do about violations

Our response is proportionate to what happened. Depending on severity we may:

  • Contact you to ask about it and give you a chance to put it right.
  • Throttle or block specific activity, such as sending.
  • Remove or disable access to specific content, including on receipt of a court order or a notification from an appropriate government agency, within the time the IT Rules, 2021 require.
  • Suspend the account while we investigate.
  • Terminate the account and the workspace.
  • Report the matter to law enforcement or a regulator where we are required to, or where there is a risk to someone's safety.

For serious violations, particularly fraud, malware and content that endangers a child, we act immediately and without prior notice. Otherwise we will normally contact you first. Suspension does not entitle you to a refund where it results from your breach, and does not relieve you of fees already incurred.

If you believe we have acted wrongly, appeal through the grievance redressal policy. We will look again.

Version history

  • Version 1.0 · 26 July 2026

    First publication.