Scope and retention
bb-sign backs every signed document with integrity, signer identification and evidence, and keeps it for a fixed period. This page explains what the service covers, how long it keeps documents and how your organization can archive each envelope to keep it for as long as the law or your own rules require.
What bb-sign covers
Section titled “What bb-sign covers”- Integrity. Every signed document is sealed, and any later change is detected.
- Identification. The signer is identified by their email and, when the organization requires it, by a one-time code.
- Record of the agreement. What the signer saw and accepted is recorded with date and time.
- Consistent evidence. The audit chain lets you confirm that no record was inserted or removed.
- Probative value. The evidence (who, what, when and from where) can be viewed and downloaded.
- Traceability. Every relevant action on an envelope is recorded in its history.
bb-sign keeps documents for a fixed period set out in its terms. Once that period ends, keeping them is the responsibility of the organization that sent them.
Retention policy
Section titled “Retention policy”These are the service’s commitments, set out in the retention clause of the Terms and conditions (draft for Version 2).
| Item | Policy |
|---|---|
| Retention of signed documents and evidence | 365 days. A fixed period, the same for every organization. |
| Move to cold archive | At 90 days. A file in cold archive cannot be downloaded immediately. |
| Restore | On request. The restored copy stays available for 7 days. It usually takes a few hours, with no guaranteed time. |
| After the period | Retention is the customer’s responsibility (Ley 527 de 1999, article 12). |
How the policy is applied
Section titled “How the policy is applied”This table describes how the service currently behaves, as verified on the platform.
| Item | Current behaviour |
|---|---|
| Documents: move to infrequent-access storage | At 30 days. |
| Documents: move to cold archive | At 90 days. |
| Restore on request | Handled by Binary Bridges. To obtain a document that has moved to cold archive, request it from Binary Bridges; it cannot be downloaded from the application. |
| Envelope moves to “Archived” | 30 days after creation, a completed, cancelled or expired envelope moves to the “Archived” view. The record is kept. |
Outside production, the application’s Storage page shows testing defaults, not the production configuration. See Storage.
What Ley 527 de 1999 says
Section titled “What Ley 527 de 1999 says”Article 12 sets the conditions under which a retained data message satisfies a legal obligation to retain. The Spanish text is the authoritative one:
Artículo 12. Conservación de los mensajes de datos y documentos. Cuando la ley requiera que ciertos documentos, registros o informaciones sean conservados, ese requisito quedará satisfecho, siempre que se cumplan las siguientes condiciones:
- Que la información que contengan sea accesible para su posterior consulta.
- Que el mensaje de datos o el documento sea conservado en el formato en que se haya generado, enviado o recibido o en algún formato que permita demostrar que reproduce con exactitud la información generada, enviada o recibida, y
- Que se conserve, de haber alguna, toda información que permita determinar el origen, el destino del mensaje, la fecha y la hora en que fue enviado o recibido el mensaje o producido el documento.
No estará sujeta a la obligación de conservación, la información que tenga por única finalidad facilitar el envío o recepción de los mensajes de datos.
Los libros y papeles del comerciante podrán ser conservados en cualquier medio técnico que garantice su reproducción exacta.
In summary: the information must remain accessible for later consultation; it must be kept in the format in which it was generated, sent or received, or in one that demonstrably reproduces it exactly; and any information that identifies its origin, destination, date and time must be kept with it.
Article 13 allows that obligation to be met through third parties:
Artículo 13. Conservación de mensajes de datos y archivo de documentos a través de terceros. El cumplimiento de la obligación de conservar documentos, registros o informaciones en mensajes de datos, se podrá realizar directamente o a través de terceros, siempre y cuando se cumplan las condiciones enunciadas en el artículo anterior.
In other words, retention may be carried out directly or through a third party, provided the conditions of article 12 are met. bb-sign acts as that third party for the policy period. The sealed PDF you download meets the second condition, because it reproduces exactly what was signed, and its seal includes the name, email and date of every signature. To keep it for the years your obligation requires, store it in your organization’s archive.
Archive every envelope on completion
Section titled “Archive every envelope on completion”The most reliable approach is automatic: when the envelope.completed event arrives, list the
envelope’s documents and download the signed copy of each one to your organization’s archive.
- Create a webhook subscribed to
envelope.completed. See Webhooks. - Verify the signature of every delivery before processing it. The envelope ID is in
data.envelope.id. - Call
GET /api/v1/envelopes/{id}/documentswith a credential that holdsdocument:downloadin the envelope’s workspace (auditor role or above). Without that permission,signedUrlcomes back empty. - Download every
signedUrl. The links are valid for 3,600 seconds; download them as you receive them, without storing them.
# After the envelope.completed webhook checks out, data.envelope.id is the envelope.ENVELOPE_ID="3f8c1c2e-7d0a-4f3b-9d2a-0a1b2c3d4e5f"mkdir -p "archive/$ENVELOPE_ID"
curl -sSf -H "Authorization: Bearer $TOKEN" \ "$BBSIGN_BASE_URL/api/v1/envelopes/$ENVELOPE_ID/documents" \ | jq -r '.[] | "\(.signedUrl // "MISSING")\t\(.filename)"' \ | while IFS=$'\t' read -r url filename; do if [ "$url" = "MISSING" ]; then echo "No signed copy for $filename: the credential needs document:download" >&2 exit 1 fi curl -sSf -o "archive/$ENVELOPE_ID/$filename" "$url" doneimport { createClient } from '@binarybridges/bb-sign-sdk'import { mkdir, writeFile } from 'node:fs/promises'
const client = createClient({ baseUrl: process.env.BBSIGN_BASE_URL, tokenUrl: process.env.BBSIGN_TOKEN_URL, clientId: process.env.BBSIGN_CLIENT_ID, clientSecret: process.env.BBSIGN_CLIENT_SECRET,})
// Call this from your webhook handler once the envelope.completed signature checks out.export async function archiveEnvelope(envelopeId) { const documents = await client.envelopes.listEnvelopeDocuments({ id: envelopeId }) await mkdir(`archive/${envelopeId}`, { recursive: true })
for (const document of documents) { if (!document.signedUrl) { throw new Error(`No signed copy for ${document.filename}: the credential needs document:download`) } const response = await fetch(document.signedUrl) if (!response.ok) { throw new Error(`Download of ${document.filename} failed: HTTP ${response.status}`) } await writeFile(`archive/${envelopeId}/${document.filename}`, Buffer.from(await response.arrayBuffer())) }}import co.binarybridges.sign.sdk.BbSignClient;import co.binarybridges.sign.sdk.generated.model.DocumentWithUrlsResponse;import java.net.URI;import java.net.http.HttpClient;import java.net.http.HttpRequest;import java.net.http.HttpResponse;import java.nio.file.Files;import java.nio.file.Path;import java.util.List;import java.util.UUID;
// Call this from your webhook handler once the envelope.completed signature checks out.void archiveEnvelope(BbSignClient client, UUID envelopeId) throws Exception { List<DocumentWithUrlsResponse> documents = client.execute(client.envelopes().listEnvelopeDocuments(envelopeId)); Path folder = Files.createDirectories(Path.of("archive", envelopeId.toString())); HttpClient http = HttpClient.newHttpClient();
for (DocumentWithUrlsResponse document : documents) { if (document.getSignedUrl() == null) { throw new IllegalStateException("No signed copy for " + document.getFilename() + ": the credential needs document:download"); } HttpRequest request = HttpRequest.newBuilder(URI.create(document.getSignedUrl())).GET().build(); HttpResponse<Path> response = http.send(request, HttpResponse.BodyHandlers.ofFile(folder.resolve(document.getFilename()))); if (response.statusCode() != 200) { throw new IllegalStateException("Download of " + document.getFilename() + " failed: HTTP " + response.statusCode()); } }}If you do not have an integration, download the signed documents from the envelope page. See Download signed documents.