Effective Date: [01-16-2026]
Last Updated: [01-16-2026]
Docstrail (“Docstrail”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, and security of information entrusted to us by users of our platform. This Privacy Policy describes in detail how we collect, use, store, process, disclose, and protect information when you access or use the Docstrail website, mobile applications, APIs, and related services (collectively, the “Services”).
By accessing or using the Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
1. Scope and Applicability
This Privacy Policy applies to:
- All visitors, registered users, customers, and organizations using Docstrail
- All information collected through our Services, communications, integrations, and support channels
This policy should be read together with our Terms of Service and any applicable Data Processing Agreement (DPA).
2. Definitions
- Personal Data / Personal Information: Any information that identifies or can reasonably be linked to an individual.
- Sensitive Personal Data: Information requiring higher protection, such as financial, biometric, or government-issued identifiers.
- Processing: Any operation performed on data, including collection, storage, use, analysis, disclosure, or deletion.
- Controller / Processor: As defined under applicable data protection laws.
3. Information We Collect
3.1 Information You Provide Directly
We may collect the following information when you register, use, or communicate with us:
- Full name
- Email address
- Phone number
- Company or organization name
- Job title or role
- Billing and payment information
- Account login credentials
- Communication content (emails, chat messages, support tickets)
3.2 Uploaded Documents and Content
Docstrail enables users to upload, store, manage, share, and process documents. This may include:
- Documents, files, images, PDFs, and metadata
- User-generated annotations, tags, comments, and version history
- Extracted data generated through OCR, AI, or automation features
All uploaded content remains the property of the user or their organization.
3.3 Automatically Collected Information
When you use the Services, we may automatically collect:
- IP address
- Device identifiers
- Browser type and version
- Operating system
- Log files and timestamps
- Referring URLs
- Usage activity, clicks, page views, and session duration
3.4 Cookies and Similar Technologies
We use cookies, web beacons, pixels, local storage, and similar technologies to:
- Authenticate users
- Maintain sessions
- Analyze performance and usage
- Improve security and functionality
You may control cookies through browser settings; however, disabling cookies may impact functionality.
4. Legal Basis for Processing
We process personal data based on one or more of the following legal grounds:
- Performance of a contract
- Compliance with legal obligations
- Legitimate business interests
- User consent, where required by law
5. How We Use Information
We use collected information for the following purposes:
- Providing, operating, and maintaining the Services
- Creating and managing user accounts
- Document storage, processing, indexing, and retrieval
- AI-based automation, search, and analysis (where enabled)
- Billing, invoicing, and payment processing
- Customer support and technical assistance
- Product improvement, analytics, and research
- Security monitoring, fraud prevention, and abuse detection
- Legal compliance and enforcement of rights
6. AI, Automation, and Data Processing
Where applicable, Docstrail may use artificial intelligence, machine learning, or automated systems to process documents and extract structured information. Such processing:
- Is performed solely to deliver platform functionality
- Does not involve selling or training public AI models using customer data
- Is governed by strict access controls and security safeguards
7. Data Sharing and Disclosure
We do not sell personal data. We may share information only as follows:
7.1 Service Providers
Trusted third-party vendors assisting with:
- Cloud hosting and storage
- Email and communication services
- Analytics and monitoring
- Payment processing
All providers are bound by contractual confidentiality and data protection obligations.
7.2 Legal and Regulatory Disclosure
We may disclose information if required to:
- Comply with applicable laws or regulations
- Respond to lawful requests from authorities
- Protect the rights, safety, and property of Docstrail or others
7.3 Business Transfers
In the event of a merger, acquisition, restructuring, or asset sale, information may be transferred subject to continued confidentiality protections.
8. Data Storage and International Transfers
Data may be stored and processed in multiple geographic locations depending on infrastructure and service providers. Where data is transferred across borders, we implement appropriate safeguards in compliance with applicable laws.
9. Data Retention
We retain personal data and documents only for as long as:
- Necessary to provide the Services
- Required by contractual obligations
- Mandated by applicable laws
Upon account termination, data may be deleted or anonymized subject to retention requirements.
10. Data Security Measures
We implement industry-standard security measures, including:
- Encryption at rest and in transit
- Role-based access controls
- Audit logs and monitoring
- Secure infrastructure and network protections
Despite these measures, no system can guarantee absolute security.
11. User Rights
Depending on applicable laws (including GDPR, DPDP Act, CCPA), users may have the right to:
- Access personal data
- Rectify inaccurate data
- Request erasure
- Restrict or object to processing
- Data portability
- Withdraw consent
Requests may be submitted using the contact details below.
12. Children’s Privacy
The Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors.
13. Third-Party Integrations and Links
Docstrail may integrate with or link to third-party services. We are not responsible for their privacy practices, and users should review their respective policies.
14. Compliance with Laws
Docstrail endeavors to comply with applicable data protection and privacy laws, including but not limited to:
- General Data Protection Regulation (GDPR)
- India Digital Personal Data Protection Act (DPDP Act)
- Other applicable regional privacy regulations
15. Changes to This Privacy Policy
We may update this Privacy Policy periodically. Updates will be posted on the Services with a revised effective date. Continued use constitutes acceptance of the updated policy.
16. Contact Information
For questions, requests, or concerns regarding this Privacy Policy or data practices, contact:
Docstrail
Email: support@docstrail.com
Address: Thackery Ln, Naperville, Illinois, 60564, USA
