Privacy Policy

Last Updated: August 31, 2026 | Version 2.9.2

Global Privacy & Data Protection Policy Version 2.9.2 · Last Updated: August 28, 2026

This Privacy Policy provides full transparency regarding how DOCUCOGNITOAI, S.R.L. collects, processes, transfers, and safeguards your personal data under the EU General Data Protection Regulation (GDPR 2016/679), California Consumer Privacy Act (CCPA/CPRA), Brazilian LGPD, Canadian PIPEDA/Law 25, Dominican Law No. 172-13, and global AI SaaS industry standards.

01. Data Controller & Data Protection Officer (DPO)

The designated Data Controller responsible for processing your personal information is:

Corporate Entity: DOCUCOGNITOAI, S.R.L.

Tax ID (RNC): 1-33-45956-6

Registered Address: Bella Vista, Santo Domingo de Guzmán, National District, Dominican Republic

Support & Privacy Inquiries: support@docucognito.ai

Data Protection Officer (DPO): dpo@docucognito.ai

02. Categories of Personal Data Processed

We collect only the minimum data necessary to operate our cloud document automation platform:

Account & Identity Data

Name, email address, unique Firebase UID, OAuth profile picture (Google Sign-In), and phone numbers for multi-factor authentication.

Content, Form Submissions & Templates

Form definitions, respondent submissions, MS Word (.docx) templates, generated PDF/Word documents, and uploaded file attachments.

E-Signatures & Audit Trail Records

Drawn signature strokes, exact UTC timestamps, signer IP addresses, browser/OS user-agents, and SHA-256 cryptographic document checksums.

Billing & Technical Telemetry

Order IDs and subscription lifecycle events processed via Paddle.com; cookie consent choices and platform performance telemetry.

03. Lawful Bases for Processing (GDPR Article 6)

We process your personal data strictly under established legal bases:

  • Contractual Performance (Art. 6.1.b GDPR): Necessary to provision accounts, process template merges, generate output files, and maintain core services.
  • Explicit Consent (Art. 6.1.a GDPR): For optional analytics (GA4, Microsoft Clarity) and conversion pixels (Meta, Google Ads).
  • Legal Obligation (Art. 6.1.c GDPR): Retaining tax and accounting transaction records required by statutory law.
  • Legitimate Interests (Art. 6.1.f GDPR): Safeguarding infrastructure against bots, fraud, and cyber threats via Google reCAPTCHA Enterprise and Cloudflare.

04. Comprehensive List of Subprocessors & Service Providers

Under GDPR Article 13(1)(e) and Article 28, we disclose our complete list of authorized third-party subprocessors:

Subprocessor Role & Purpose Location & Safeguards
Google Cloud Platform (GCP)
Cloud Run, Firestore, GCS, Cloud Tasks, Secret Manager, KMS
Application hosting, encrypted NoSQL database, AES-256 storage at rest, asynchronous document job queues, and cryptographic key management. USA (us-central1) / EU-U.S. Data Privacy Framework & Standard Contractual Clauses (SCCs).
Google Vertex AI & Gemini Models
Google LLC
Generative AI inference for form generation and variable mapping. Strict Zero-Training guarantee on customer inputs. USA / Google Cloud Enterprise DPA.
Paddle.com
Paddle.com Inc. / Paddle Payments Ltd.
Merchant of Record (MoR) for PCI-DSS Level 1 payment processing, global tax compliance (VAT/GST), invoicing, and customer billing support. UK / USA / Full GDPR DPA.
Google reCAPTCHA Enterprise
Google LLC
Bot detection, fraud prevention, anti-scraping, and automated abuse mitigation. Global / Google Privacy Policy & Terms.
Cloudflare, Inc.
Cloudflare CDN & Bot Management
Global CDN edge acceleration, DDoS mitigation, TLS 1.3 encryption, and web application firewall (WAF). Global (Anycast Network) / SCCs & EU-U.S. DPF.
Resend Inc.
Resend (smtp.resend.com)
Transactional email delivery for system notices, form submission copies, and authentication alerts. USA / Enterprise DPA / TLS encrypted transit.
Amazon Web Services (AWS SES)
Amazon.com Services LLC
High-availability redundant transactional email delivery infrastructure. USA (us-east-2) / AWS GDPR DPA.
Microsoft Clarity
Microsoft Corporation
Session heatmaps and UX interaction analysis (enabled with consent only; sensitive fields strictly masked). USA / Microsoft Privacy Statement.
Google Analytics 4 & Google Tag Manager
Google LLC
Aggregated website usage analytics (gated by Google Consent Mode v2; IP anonymization enabled). USA / SCCs & EU-U.S. DPF.

Note on local client-side libraries (Syncfusion, SkiaSharp, QRCoder): Word and PDF processing occurs inside an isolated WebAssembly sandbox in your browser or within memory in our Google Cloud container; files are not sent to external Syncfusion servers.

05. AI Data Processing & Zero-Model-Training Guarantee

Zero Data Retention & Zero Public AI Training Guarantee

We guarantee that:

  • No user prompts, uploaded document files, template variable values, or form responses are ever used to train, retrain, or fine-tune public foundation models from Google or any third party.
  • All AI interactions occur over private, encrypted enterprise Vertex AI API endpoints with strict customer data isolation.
  • AI Transparency (EU AI Act): In compliance with Article 50 of the European Union Artificial Intelligence Act, we explicitly inform users that certain generative features (e.g., magic form builder) are powered by AI systems. These systems are designed with no risk of subliminal manipulation and ensure human-in-the-loop oversight before finalizing any document.

06. International Data Transfers & Cross-Border Safeguards

DocuCognito primary services operate in Google Cloud data centers located in the United States (us-central1). For users across the EEA, UK, Switzerland, Canada, Latin America, and APAC, cross-border transfers are legally protected by:

  • Standard Contractual Clauses (SCCs): European Commission approved clauses under Implementing Decision (EU) 2021/914.
  • EU-U.S. Data Privacy Framework (DPF): Participation in the EU-U.S. DPF, UK Extension to the DPF, and Swiss-U.S. DPF frameworks.

07. Data Retention, Backup Purge & Immutable Consent Records

We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected:

  • Active Data: Stored while your account remains open.
  • Account Deletion & Right to Erasure: When you request account deletion via the in-app profile modal or via email, your forms, templates, workspaces, and files are immediately purged from production databases. Encrypted backups are permanently erased within a 30-day rotating retention window.
  • Consent Records: Electronic logs recording policy version, timestamp, IP address, and anonymous identifiers are maintained to demonstrate compliance under GDPR Article 7.

08. Global Data Subject Rights (GDPR, CCPA/CPRA, LGPD, PIPEDA)

Regardless of your geographic location, you enjoy comprehensive privacy rights:

Right of Access & Portability

Obtain a copy of your personal data in structured, machine-readable format (JSON/CSV).

Right to Rectification & Erasure

Correct inaccurate data or request full deletion of your account and documents.

Restriction & Objection

Object to or restrict specific processing activities (e.g. analytics or marketing).

Do Not Sell or Share (CCPA/CPRA)

DocuCognito NEVER sells or shares personal data with third parties for monetary gain.

Global Privacy Control (GPC) & DNT Signal Recognition: Our platform automatically honors GPC and Do Not Track signals transmitted by your browser, automatically denying marketing and targeting cookies.

Right to Lodge a Complaint with a DPA: You have the right to file a complaint with the Data Protection Authority in your habitual residence (e.g., AEPD in Spain, ICO in the UK, CNIL in France, FTC in the US, or statutory DPAs worldwide).

To exercise any privacy right, contact our team at support@docucognito.ai or our DPO at dpo@docucognito.ai.

09. Security Measures & Technical Safeguards

We enforce enterprise-grade security standards:

  • Encryption: TLS 1.3 with strict HSTS in transit; AES-256 encryption at rest in Google Cloud Storage and Firestore.
  • Cryptographic Key Management (Cloud KMS): Centralized key management isolating encryption keys from application code.
  • Access Governance: Multi-factor authentication, least-privilege IAM policies, and continuous audit logging.

10. Children's Privacy (COPPA & Global Standards)

DocuCognito is strictly intended for enterprise professionals aged 18 and older. We do not knowingly collect personal data from children under 18. If we discover that a minor has provided personal information without verified parental consent, we will permanently purge the data immediately.