- Electronic signature systems
- Industry-specific compliance (biotech & pharma)
- Document integrity and technical verification
- Security and phishing prevention
- Technical requirements and accessibility
- Sustainability (Green Biotech Commitment)
- International recognition and legal basis (EU, Austria & USA)
- Storage and data protection
- Central contact
- FAQ – Frequently asked questions
Electronic signature systems
Standard system DocuSign
For the majority of our business correspondence and standard contracts, acib uses the trust service provider DocuSign, a leading global provider of secure electronic signatures. We use the following procedures:
- Simple Electronic Signature (SES): This is our standard procedure. It offers a high level of user-friendliness and is fully recognised by law for most business transactions.
- Advanced Electronic Signature (AES): We use AES for increased security requirements or when a more unique proof of identity is required. This involves additional verification of the signatory’s identity, for example by means of a one-time password (OTP) sent to your mobile phone via SMS or by telephone authentication.
- Recognition and ‘Approve’ function: Signatures from acib usually contain a personal signature scan, accompanied by a grey acib logo or an official acib stamp. For simpler documents (e.g. internal approvals), we use the ‘Approve’ function (Approve) function. Legally and technically, this click is equivalent to a conventional signature and is fully documented in the audit trail.
- Verifiable delivery and acknowledgement: For documents that do not require a signature (e.g. guidelines), acib uses DocuSign as digital proof of delivery. The system logs precisely when a document was delivered, opened and acknowledged.
- E-forms: For certain administrative processes, we offer e-forms provided by DocuSign for contract requests via links. As a rule, we use a URL shortening system (short.acib.at) to make the links easier to recognise and use. Filling out the form triggers an e-signature process, and the document is signed via the DocuSign system.
Qualified Electronic Signature (QES) via ID Austria
- Highest standard: The QES is the only form of electronic signature that is 100% legally equivalent to a handwritten signature. acib expressly refers to this legal equivalence.
- Freedom of choice: acib expressly reserves the right to choose the signature procedure. Since a QES completely replaces a handwritten signature in legal terms, we reserve the right to use a QES instead of physical (‘wet ink’) signatures or to map the process digitally.
- Verification: The validity of these signatures can be verified at any time via the official RTR verification service at (https://www.signatur.rtr.at/de/vd/Pruefung.html).
Signed PDFs
In addition to Docusign or specialised trust service providers, we use and accept both the e-signature function of Adobe Acrobat (‘Fill & Sign’ / e-Sign) and certificate-based signatures created with signature certificates issued to acib email addresses for signing PDF documents
- Adobe E-Signature: When using e-signature in Adobe, a simple electronic signature (SES) is generated in accordance with the eIDAS Regulation: the signature is captured electronically and linked to meta information (e.g. timestamp, account e-mail address, IP address), but does not provide its own cryptographic link between identity and document.
- Certificate-based signatures: Certificate-based signatures in Adobe (‘digital signature’/certificate signature) use a personal signature certificate that has been issued to an acib email address and the associated domain and has been verified as part of a validation process (e.g. domain/email validation by the certification authority). The signature is permanently linked to the document using public key cryptography; changes to the document after signing are technically detectable, and the signature can be verified as valid in Adobe Acrobat. Depending on the certificate used and the trust level of the provider, such signatures achieve at least the level of a secure SES or, in some cases, an advanced signature (FES) and, in the event of a dispute, have greater evidential value than pure e-signatures without a certificate.
Regardless of the system used, we generally cannot accept mere scanned signatures or pure signature images (e.g. inserted PNG/JPEG signatures) as legally valid signatures. Such image signatures can be easily copied or altered, do not contain verifiable signature or certificate data and therefore provide only limited evidential value with regard to the identity of the signatory, the time of signing and the integrity of the document; for legally relevant agreements, a technically verifiable electronic or digital signature is therefore required.
Integrated wet ink workflow (hybrid forms)
Company-specific/multiple signature system environments
In practice, it sometimes happens that contractual partners use their own electronic signature systems, while we use DocuSign or Adobe and/or certificate-based signatures (e.g. certificates at name@acib.at) for our signatures. In such cases, we generally accept mixed signature environments, provided that the systems used by our partners meet the requirements of the eIDAS Regulation for simple, advanced or qualified electronic signatures and enable sufficient technical verification (e.g. audit trail, verifiability of the signature, immutability of the document).
For particularly high-risk or formal transactions, we reserve the right to require a uniform signature level (e.g. FES/QES).
Industry-specific compliance (biotech & pharma)
- FDA 21 CFR Part 11: For partners in the pharmaceutical and medical technology sectors, we ensure that our electronic records and signatures comply with the requirements of the US Food and Drug Administration (FDA) where necessary. This includes the traceability, immutability and security of digital documents.
- Audit trail guarantee: Each document is supplemented by a detailed completion certificate that documents all process steps without gaps and thus meets the requirements for GxP-compliant documentation.
Document integrity and technical verification
- Cryptographic seal: Once a document has been signed, it is digitally sealed. Any subsequent changes to the text will result in the immediate loss of validity. The official RTR verification tools can be used to verify the current signature status and document integrity: (https://www.signatur.rtr.at/de/vd/Pruefung.html)
- Long-term validation (LTV): Our documents contain all the information necessary to verify the validity of the signature even years later, regardless of the platform.
Important note: Subsequent merging, editing or combining of signed PDFs breaks the digital seal. Documents must therefore always remain as a closed unit.
Security and phishing prevention
- No request for access data: acib will never ask you for your personal passwords. The only exception is for documents that require integrated payment processing (e.g. via Stripe within DocuSign); in these cases, payment details are entered directly via the payment service provider’s secure interface.
- Identity verification for AES: Only AES signatures require you to enter a one-time password (OTP), which you will receive via text message or phone call. This is solely for the purpose of verifying your identity for this specific transaction.
- Data storage: acib uses DocuSign’s European data ring with data centres in the EU (Germany, France, Netherlands) to ensure the highest GDPR standards.
- Scepticism regarding third-party requests: If you receive any unannounced or suspicious requests, please contact us at legal@acib.at <legal@acib.at>.</legal@acib.at>
Technical requirements and accessibility
- No installation required: You do not need any special software or plug-ins. Signing takes place directly in your standard web browser (Chrome, Firefox, Safari, Edge).
- Mobile signature: Our documents can be conveniently viewed and signed on smartphones or tablets.
- Language support: The DocuSign user interface automatically adapts to the language of your browser to enable barrier-free processing in your native language.
Sustainability (Green Biotech Commitment)
International recognition and legal basis (EU, Austria & USA)
- EU (eIDAS Regulation) & Austria (SVG): Regulation (EU) No. 910/2014 forms the EU framework, which is supplemented in Austria by the Signature and Trust Services Act (SVG).
- USA (ESIGN Act): The Electronic Signatures in Global and National Commerce Act ensures legal validity in the USA.
- USA (UETA): The Uniform Electronic Transactions Act establishes the equivalence of electronic and physical transactions.
Storage and data protection
- Digital original: The electronically signed PDF document constitutes the legal original. Partners are responsible for downloading this document from the respective signature system (e.g. DocuSign, Adobe) immediately after completing the signature process and archiving it in their own systems.
- Storage: In the DocuSign environment used by acib, documents are only retained for a limited period of time (currently six months, for example) and are then automatically deleted. acib archives documents exclusively for its own internal purposes and does not assume any permanent archiving, storage or forwarding function for contractual partners; as a rule, documents are not resent after the defined storage period has expired. In individual cases, this is possible upon request and in return for reimbursement of costs.
- Data protection: Information on the processing of personal data in connection with electronic signatures and on the storage period can be found at Link to DSE E-Signature
FAQ – Frequently asked questions
These FAQs are intended as general guidance on the use of electronic signatures at acib and do not replace individual legal advice in specific cases. In the case of special legal or formal requirements (e.g. statutory written form, international circumstances, high liability risk), it is recommended that you consult with the legal department or external legal advisors in advance.
General questions about electronic signatures
Yes, electronic signatures are generally legally valid under the eIDAS Regulation and cannot be rejected solely on the grounds that they are electronic or not handwritten. The decisive factor is that all parties are recognisably in agreement with the electronic processing (e.g. by using the electronic signature process), the signature meets the requirements for authentication, integrity and traceability, and that no specific legal form (e.g. mandatory written form with qualified signature) precludes this; a separate, prior ‘e-signature agreement’ is not usually required for this, but can be helpful for clarification and in the event of a dispute.
The legally relevant original document is the electronically signed PDF that is sealed by an encryption process and clearly certified. Only this original can be used to verify the authenticity of the signature. In addition, an audit trail and a signature history confirmation (certificate) can be downloaded via DocuSign, which serve to document the electronic signature processes. Paper printouts of signed documents are only copies in the legal sense and can serve as evidence, but cannot be verified. PDFs that have been altered after signing (merging, removing pages, etc.) violate the digital seal and invalidate the signatures.
The signature image printed in a document is for information and convention purposes only and has no legal significance. The electronic signature is created through the signing process and the electronic sealing of the document. The act of signing itself consists of confirming the signature, for example by clicking the ‘Finish’ button. Documents are valid even without a signature image
Each contracting party is responsible for downloading the electronically signed documents intended for them from the respective signature system (e.g. DocuSign, Adobe) and to archive them in their own systems in accordance with the statutory retention requirements. acib archives the documents exclusively for its own internal purposes and does not assume any permanent archiving, storage or forwarding function for contractual partners; after expiry of the storage period defined in the signature system (e.g. six months), acib does not generally provide the document again
A paper printout of an electronically signed PDF is generally only a copy of the electronic original. The legally binding version is the electronic, signed PDF document, as only this contains the technical signature information (e.g. certificate, time stamp, verifiability of integrity). Printouts can be used as evidence or working copies, but they do not replace the original electronic file; for complete verifiability and auditability, the electronically signed PDF should therefore always be retained.
The original electronic signature technically refers to the original electronic document; only this document contains the signature and certificate information that enables verification of identity, time and integrity. If an electronically signed document is simply printed out and then scanned back in, a new file is created without the original signature data; such a scan is generally only legally valid as a copy or simple electronic signature with significantly less evidential value and does not replace the electronically signed original.
Many funding agencies and authorities now accept electronically signed documents, but in some cases only at certain signature levels (e.g. advanced or qualified electronic signatures) or via specific submission portals; the relevant funding guidelines or official requirements are decisive. If documents have to be submitted in paper form, it is advisable to keep the electronically signed original as well and, if necessary, to indicate that the paper printout originates from an electronically signed document; in case of doubt, clarify in advance with the responsible funding agency which form of signature and submission is accepted. Note: From a purely legal perspective, according to the eIDAS Regulation, a qualified electronic signature (QES) may not be rejected by authorities and courts in the EU solely on the grounds that it is electronic; it has the same legal status as a handwritten signature on paper.
In this case, the electronic signature will usually still be technically assigned to your email address or user, even if another person actually performs the signing process. In the event of a dispute, this makes it difficult to clearly assign the declaration and weakens the evidential value of the signature; in addition, questions may arise regarding the authorisation of the person signing (power of attorney, internal responsibility). For this reason, signature requests must not be forwarded by email; if another person is to sign, the delegation/“Assign to Someone Else” function of the respective signature system must always be used, or the process must be restarted with the correct recipient data.
Thanks to long-term validation (LTV), the signature remains mathematically verifiable and legally valid even after the issuer’s certificates have expired. The document is permanently authentic.
Electronic signatures (especially certificate-based signatures) protect the integrity of the document: Any change after signing will cause the signature verification to display an error or mark the signature as invalid. For this reason, signed documents may no longer be changed in terms of content; if adjustments are necessary, a new, corrected version must be created and electronically signed again.
Questions about the signature process at acib:
Yes. If you use the ‘Decline to sign’ function in DocuSign, Adobe or a comparable system, the entire signature process (envelope/agreement) is usually cancelled for all parties involved and marked as ‘declined’ or ‘void’; Further signatures are then no longer possible, and the process must be restarted if necessary. The rejection is logged, and the sender and any other parties involved are automatically informed. Depending on the system, a reason for rejection may (or must) be specified for the sender’s clarification.
acib may reject electronic signature requests if the signature process has not been agreed in advance (e.g. unannounced start of an external DocuSign/Adobe workflow), if the content of the document does not correspond to the agreed or internally approved version (e.g. unclarified changes, missing attachments, incorrect contract version) or if there are doubts about the authenticity or seriousness of the request (e.g. suspicion of phishing, unusual sender address). In these cases, the signature process is terminated using the ‘Reject’ function and the sender is informed with a brief note (e.g. ‘Contract version not approved / signature process not agreed’); resubmission is only possible after clarification with the responsible specialist or legal department at acib.
Electronic signature requests from contractual partners must not be sent ‘unannounced’ to individual persons at acib. Before an external signature process is initiated, it must be agreed with acib which persons are authorised to sign and in which order they are to sign; this is usually coordinated by the legal department (legal@acib.at) or the responsible contact person at acib. Signature requests that are sent without prior coordination or to unauthorised persons may be rejected or left unanswered. Acib must ensure that the intended signature fields are correctly created in the electronic document (e.g. two signature fields for Acib) and that the signature process reflects the internal signing rules.
Before sending an electronic signature request, it must be ensured that the content of the contract has been approved internally, that the correct and complete version of the document is being used, that the persons authorised to sign and any review steps (e.g. legal department) have been determined, and that the required signature level (e.g. SES/ FES/QES) has been defined. Only when these points have been clarified should the electronic signature process be started in order to avoid multiple runs, rejections or incorrect contract versions.
In this case, the signature request must not be forwarded informally. Instead, the signature process must be adjusted (e.g. via the delegation function in the signature system or by restarting the process with the correct recipients). Changes to the persons authorised to sign must be coordinated with the responsible specialist or legal department so that the electronic signature process continues to reflect the valid signing rules of acib.
In this case, the signature request must not simply be forwarded by email. Before starting the electronic signature process, please inform us which additional persons or departments need to review or approve the document in advance (e.g. legal department, specialist department, external partners). We map these review steps in the electronic workflow (e.g. as pure reviewers without signature or as additional signatories) so that all parties involved are included in the correct order and no unofficial forwarding of signature requests is necessary.
Please check your spam folder for messages from docusign.net. If you cannot find the email there, contact your administrator regarding emails in quarantine or contact your contact person at acib to resend the email or check the email address.
No. DocuSign does not store any biometric profiles (such as pressure or speed) for a standard SES/AES. Only the graphic image of the signature and the technical metadata are stored in the audit trail (IP, timestamp, email).
No. The document is finalised. If changes are necessary, please do not sign, but contact us at legal@acib.at.
No. Once you click ‘Finish’, the declaration of intent is legally documented.
Use the ‘Assign to someone else’ function in DocuSign. Do not forward the email manually.
This is the certificate of completion with the complete audit trail. It serves as essential proof of legal validity in the event of a dispute.
Security is significantly higher because documents are stored in encrypted form on servers and are not sent as unprotected attachments via the internet.
Carefully check the sender, content and links in every DocuSign email before clicking on ‘View document’ or similar buttons. A genuine DocuSign message usually comes from an address on the domains @docusign.net or @docusign.com and does not contain a file attachment, but rather a link to an HTTPS address on an official DocuSign domain (e.g. https://na2.docusign.net/…). Look out for subtle spelling mistakes or additional characters in the domain (e.g. docusgin.net, docu‑sign.net) as well as unusual senders such as private email accounts or foreign domains; these are typical signs of phishing.
In addition, technical authentication features (SPF, DKIM, DMARC) should be correct: Emails that purport to come from @docusign.net but fail DMARC checks or were obviously sent from unauthorised servers are most likely fake and should not be clicked on; such messages should be immediately marked as spam/phishing and, if possible, forwarded to the appropriate authorities (e.g. IT security, DocuSign Safety Centre).