Skip to main content

DOCUMENT HANDLING POLICY

Effective Date: 1/30/2024 Last Reviewed: 06/25/2026

1. Purpose

This policy outlines the procedures for securely storing, accessing, sharing, retaining, and disposing of documents processed through NotaryEveryday. As a platform facilitating notarization workflows for title companies and signing services, we prioritize compliance with data privacy laws (e.g., GLBA, GDPR, CCPA) and the secure handling of sensitive documents using AWS S3 and presigned URLs.

2. Scope

This policy applies to:

  • All employees, contractors, and third parties interacting with NotaryEveryday’s systems.

  • Documents uploaded, processed, or shared via the platform (e.g., loan agreements, deeds, titles).

  • AWS S3 buckets and presigned URL mechanisms used for temporary document access.

3. Roles & Responsibilities

Role

Responsibilities

Engineering Team

Manage AWS S3 infrastructure, encryption, access controls, and presigned URL logic.

Customer Support

Assist users with document access requests (no direct access to S3 buckets).

Compliance Officer

Audit adherence to this policy and regulatory requirements.

Data Protection Officer (DPO)

Ensure GDPR/CCPA compliance and oversee incident response.

4. Document Storage

4.1 AWS S3 Configuration

  • All documents are stored in encrypted S3 buckets using AES-256 server-side encryption.

  • Buckets are private by default; public access is explicitly blocked.

  • Versioning is enabled to track document changes.

  • Access logs are enabled and stored in a separate S3 bucket for auditing.

4.2 Data Classification

  • Confidential: Loan agreements, titles, deeds, personal identifiable information (PII).

  • Internal: Non-sensitive operational documents.

  • Public: Marketing materials (not stored in S3).

5. Document Access Controls

5.1 Presigned URLs

  • Documents are accessed via time-limited presigned URLs (valid for 15–30 minutes).

  • URLs are generated programmatically only for authorized users (title companies/signing services).

  • Expired URLs are invalidated immediately; no direct S3 object access is permitted.

5.2 IAM & Authentication

  • AWS IAM policies enforce least-privilege access to S3 buckets.

  • Multi-factor authentication (MFA) is required for administrative AWS accounts.

6. Secure Document Sharing

  • Title Companies/Signing Services: Presigned URLs are shared via secure email or through the NotaryEveryday platform.

  • Recipients are notified of URL expiration times.

  • Prohibited: Sharing documents via unsecured channels (e.g., public links, email attachments).

7. Retention & Disposal

  • Retention: Documents are retained for 7 years post-transaction to comply with legal/regulatory requirements.

  • Disposal: S3 objects are permanently deleted using AWS S3 Lifecycle Policies. Version history and delete markers are purged.

8. Security Measures

  • Encryption: Data encrypted at rest (AES-256) and in transit (TLS 1.2+).

  • Audits: Quarterly access log reviews and vulnerability scans.

  • Incident Response: Breaches are reported to the DPO within 1 hour, followed by root-cause analysis and user notification if PII is exposed.

9. Compliance & Training

  • Employees complete annual security training covering phishing, PII handling, and AWS best practices.

  • Third-party vendors (e.g., AWS) must comply with NotaryEveryday’s Data Processing Agreements (DPAs).

10. Policy Review

This policy is reviewed annually or after significant infrastructure/regulatory changes.

Approved By: Noel Serrato (CEO / CTO)

Contact: 602-500-1434 | noel@notaryeveryday.com

Did this answer your question?