This Privacy Policy provides full transparency regarding how DOCUCOGNITOAI, S.R.L. collects, processes, transfers, and safeguards your personal data under the EU General Data Protection Regulation (GDPR 2016/679), California Consumer Privacy Act (CCPA/CPRA), Brazilian LGPD, Canadian PIPEDA/Law 25, Dominican Law No. 172-13, and global AI SaaS industry standards.
01. Data Controller & Data Protection Officer (DPO)
The designated Data Controller responsible for processing your personal information is:
Corporate Entity: DOCUCOGNITOAI, S.R.L.
Tax ID (RNC): 1-33-45956-6
Registered Address: Bella Vista, Santo Domingo de Guzmán, National District, Dominican Republic
Support & Privacy Inquiries: support@docucognito.ai
Data Protection Officer (DPO): dpo@docucognito.ai
02. Categories of Personal Data Processed
We collect only the minimum data necessary to operate our cloud document automation platform:
Account & Identity Data
Name, email address, unique Firebase UID, OAuth profile picture (Google Sign-In), and phone numbers for multi-factor authentication.
Content, Form Submissions & Templates
Form definitions, respondent submissions, MS Word (.docx) templates, generated PDF/Word documents, and uploaded file attachments.
E-Signatures & Audit Trail Records
Drawn signature strokes, exact UTC timestamps, signer IP addresses, browser/OS user-agents, and SHA-256 cryptographic document checksums.
Billing & Technical Telemetry
Order IDs and subscription lifecycle events processed via Paddle.com; cookie consent choices and platform performance telemetry.
03. Lawful Bases for Processing (GDPR Article 6)
We process your personal data strictly under established legal bases:
- Contractual Performance (Art. 6.1.b GDPR): Necessary to provision accounts, process template merges, generate output files, and maintain core services.
- Explicit Consent (Art. 6.1.a GDPR): For optional analytics (GA4, Microsoft Clarity) and conversion pixels (Meta, Google Ads).
- Legal Obligation (Art. 6.1.c GDPR): Retaining tax and accounting transaction records required by statutory law.
- Legitimate Interests (Art. 6.1.f GDPR): Safeguarding infrastructure against bots, fraud, and cyber threats via Google reCAPTCHA Enterprise and Cloudflare.
04. Comprehensive List of Subprocessors & Service Providers
Under GDPR Article 13(1)(e) and Article 28, we disclose our complete list of authorized third-party subprocessors:
| Subprocessor | Role & Purpose | Location & Safeguards |
|---|---|---|
| Google Cloud Platform (GCP) Cloud Run, Firestore, GCS, Cloud Tasks, Secret Manager, KMS |
Application hosting, encrypted NoSQL database, AES-256 storage at rest, asynchronous document job queues, and cryptographic key management. | USA (us-central1) / EU-U.S. Data Privacy Framework & Standard Contractual Clauses (SCCs). |
| Google Vertex AI & Gemini Models Google LLC |
Generative AI inference for form generation and variable mapping. Strict Zero-Training guarantee on customer inputs. | USA / Google Cloud Enterprise DPA. |
| Paddle.com Paddle.com Inc. / Paddle Payments Ltd. |
Merchant of Record (MoR) for PCI-DSS Level 1 payment processing, global tax compliance (VAT/GST), invoicing, and customer billing support. | UK / USA / Full GDPR DPA. |
| Google reCAPTCHA Enterprise Google LLC |
Bot detection, fraud prevention, anti-scraping, and automated abuse mitigation. | Global / Google Privacy Policy & Terms. |
| Cloudflare, Inc. Cloudflare CDN & Bot Management |
Global CDN edge acceleration, DDoS mitigation, TLS 1.3 encryption, and web application firewall (WAF). | Global (Anycast Network) / SCCs & EU-U.S. DPF. |
| Resend Inc. Resend (smtp.resend.com) |
Transactional email delivery for system notices, form submission copies, and authentication alerts. | USA / Enterprise DPA / TLS encrypted transit. |
| Amazon Web Services (AWS SES) Amazon.com Services LLC |
High-availability redundant transactional email delivery infrastructure. | USA (us-east-2) / AWS GDPR DPA. |
| Microsoft Clarity Microsoft Corporation |
Session heatmaps and UX interaction analysis (enabled with consent only; sensitive fields strictly masked). | USA / Microsoft Privacy Statement. |
| Google Analytics 4 & Google Tag Manager Google LLC |
Aggregated website usage analytics (gated by Google Consent Mode v2; IP anonymization enabled). | USA / SCCs & EU-U.S. DPF. |
Note on local client-side libraries (Syncfusion, SkiaSharp, QRCoder): Word and PDF processing occurs inside an isolated WebAssembly sandbox in your browser or within memory in our Google Cloud container; files are not sent to external Syncfusion servers.
05. AI Data Processing & Zero-Model-Training Guarantee
Zero Data Retention & Zero Public AI Training Guarantee
We guarantee that:
- No user prompts, uploaded document files, template variable values, or form responses are ever used to train, retrain, or fine-tune public foundation models from Google or any third party.
- All AI interactions occur over private, encrypted enterprise Vertex AI API endpoints with strict customer data isolation.
- AI Transparency (EU AI Act): In compliance with Article 50 of the European Union Artificial Intelligence Act, we explicitly inform users that certain generative features (e.g., magic form builder) are powered by AI systems. These systems are designed with no risk of subliminal manipulation and ensure human-in-the-loop oversight before finalizing any document.
06. International Data Transfers & Cross-Border Safeguards
DocuCognito primary services operate in Google Cloud data centers located in the United States (us-central1). For users across the EEA, UK, Switzerland, Canada, Latin America, and APAC, cross-border transfers are legally protected by:
- Standard Contractual Clauses (SCCs): European Commission approved clauses under Implementing Decision (EU) 2021/914.
- EU-U.S. Data Privacy Framework (DPF): Participation in the EU-U.S. DPF, UK Extension to the DPF, and Swiss-U.S. DPF frameworks.
07. Data Retention, Backup Purge & Immutable Consent Records
We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected:
- Active Data: Stored while your account remains open.
- Account Deletion & Right to Erasure: When you request account deletion via the in-app profile modal or via email, your forms, templates, workspaces, and files are immediately purged from production databases. Encrypted backups are permanently erased within a 30-day rotating retention window.
- Consent Records: Electronic logs recording policy version, timestamp, IP address, and anonymous identifiers are maintained to demonstrate compliance under GDPR Article 7.
08. Global Data Subject Rights (GDPR, CCPA/CPRA, LGPD, PIPEDA)
Regardless of your geographic location, you enjoy comprehensive privacy rights:
Right of Access & Portability
Obtain a copy of your personal data in structured, machine-readable format (JSON/CSV).
Right to Rectification & Erasure
Correct inaccurate data or request full deletion of your account and documents.
Restriction & Objection
Object to or restrict specific processing activities (e.g. analytics or marketing).
Do Not Sell or Share (CCPA/CPRA)
DocuCognito NEVER sells or shares personal data with third parties for monetary gain.
Global Privacy Control (GPC) & DNT Signal Recognition: Our platform automatically honors GPC and Do Not Track signals transmitted by your browser, automatically denying marketing and targeting cookies.
Right to Lodge a Complaint with a DPA: You have the right to file a complaint with the Data Protection Authority in your habitual residence (e.g., AEPD in Spain, ICO in the UK, CNIL in France, FTC in the US, or statutory DPAs worldwide).
To exercise any privacy right, contact our team at support@docucognito.ai or our DPO at dpo@docucognito.ai.
09. Security Measures & Technical Safeguards
We enforce enterprise-grade security standards:
- Encryption: TLS 1.3 with strict HSTS in transit; AES-256 encryption at rest in Google Cloud Storage and Firestore.
- Cryptographic Key Management (Cloud KMS): Centralized key management isolating encryption keys from application code.
- Access Governance: Multi-factor authentication, least-privilege IAM policies, and continuous audit logging.
10. Children's Privacy (COPPA & Global Standards)
DocuCognito is strictly intended for enterprise professionals aged 18 and older. We do not knowingly collect personal data from children under 18. If we discover that a minor has provided personal information without verified parental consent, we will permanently purge the data immediately.