Privacy policy

Effective date: July 4, 2026

PaperlessZen™ is a document management system built by Rigason™. Our whole product exists because institutions trust us with documents that matter, so we hold ourselves to a simple standard on privacy: collect little, be clear about what we collect, and never treat your information as ours.

This policy covers two different situations, and it is worth being plain about the difference.

  1. This website. If you are reading our pages, filling in the contact form, or booking a demo, Rigason™ decides what is collected and why. This policy is the full story.
  2. The PaperlessZen product. If your institution stores documents in PaperlessZen, those documents belong to your institution. We hold them as a custodian on your institution’s behalf, under the agreement we sign with them. Your institution decides who can see what; we enforce those decisions.

What we collect on this website

We collect very little here.

  • Contact and demo requests. If you write to us or ask for a demo, we receive what you send: typically your name, work email address, organization, and your message. We use it to reply and to prepare for the conversation you asked for. That is all.
  • Email correspondence. If you email us at hello@paperlesszen.com, we keep the correspondence so we have the context of our conversation with you.
  • Server logs and basic usage data. Like nearly every website, our hosting infrastructure records standard technical information such as IP address, browser type, and the pages requested. We use this to keep the site running and secure. If we use analytics to understand which pages are useful, it is for that purpose alone, not to build profiles of individuals.

We do not run advertising on this site, we do not sell personal information, and we do not buy lists or enrich your details from data brokers.

What we collect in the product

When an institution uses PaperlessZen, three kinds of information pass through our hands.

  • Account information. Names, work email addresses, and roles for the people your institution authorizes to use the system. We use this to provide access and to record who did what.
  • Documents and their contents. The agreements, minutes, contracts, and records your institution stores. These are your institution’s documents. We read them to make them searchable and to surface what they promise, for your institution’s use and no one else’s. We never rewrite a document, and we do not use your documents to advertise, to profile people, or for any purpose your agreement with us does not name.
  • Activity records. PaperlessZen keeps an audit trail of views, shares, and downloads. That trail exists so your institution can answer who accessed a document and when. It is a feature your institution relies on, and it necessarily records the actions of individual users.

If you are a donor, a signer, or another outside party who received a secure link from an institution that uses PaperlessZen, here is what that means for you: the institution shared a document with you through a single-use link, the link expires, and the institution can see that it was viewed. We process that on the institution’s behalf. Questions about why you were sent a document, or requests about information an institution holds about you, should go to that institution first. We will help them answer.

How long we keep things

Website inquiries and correspondence are kept as long as we have a reason to keep them, which is usually as long as we are talking with you or your institution, and then a reasonable period after. Documents in the product are kept exactly as long as your institution’s retention rules say, which is the point of the product. When a customer leaves, we help them export their archive, and we remove their data in accordance with their agreement with us.

How we protect it

The controls we use to protect documents, permission-gated access, expiring links, revocable shares, deployment into the customer’s own cloud, and a complete audit trail, are described plainly on our security page. We are in early beta and we would rather be clear than impressive: your security team is welcome to ask us exactly what is in place, and we will tell them what exists now and what is planned.

Your choices

  • You can ask us what information we hold about you, ask us to correct it, or ask us to delete it. Write to hello@paperlesszen.com and we will respond.
  • If your information lives inside a customer’s archive, we will point you to that institution, because the documents are theirs to govern, and we will support them in responding to you.
  • Marketing from us is easy to stop. We send little, and if you ask us to stop writing, we stop.

This site is intended for institutions and the people who work with them, not for children, and we do not knowingly collect information from children.

Changes to this policy

If we change this policy, we will change the effective date at the top and, for changes that matter, we will say so plainly rather than hoping nobody notices. Material changes that affect our customers are communicated to them directly.

Contact

Rigason™ is the company behind PaperlessZen™. For anything in this policy, write to hello@paperlesszen.com. A person reads it.