DocAccessible is generally the controller of website, account, billing, contact, and support data. For personal data inside Customer Content, we generally act as the customer's processor or service provider under the Data Processing Addendum.
1. Scope and who is responsible
This policy applies to docaccessible.com, the signed-in application, hosted document pages, APIs, Exchange, website monitoring, support, sales, and manual remediation inquiries. “DocAccessible,” “we,” and “us” mean the organization operating the service. A customer remains responsible for its own notices, permissions, and instructions for personal data it uploads or asks us to process.
2. Data we collect and why
Account and workspace data
We collect name, work email, hashed password credentials, email-verification status, workspace membership, roles, preferences, sessions, and account security events. We use this data to create and secure accounts, authorize access, provide collaboration, prevent abuse, and communicate about the service.
Customer Content and workflow data
We process uploaded PDFs, DOCX files, images, extracted text and structure, metadata, accessibility findings, generated outputs, comments, review decisions, feedback, case evidence, connected-site PDF URLs, scan results, and delivery records. We use this content to provide the features you request, maintain version history and audit evidence, secure file delivery, troubleshoot problems, and follow customer instructions.
Billing and transaction data
We receive plan, customer, subscription, invoice, payment-status, refund, and transaction identifiers from Dodo Payments. Dodo collects payment-card details directly; DocAccessible does not store full card numbers or security codes. We use transaction data to provide paid access, reconcile billing, prevent fraud, and meet financial and legal obligations.
Contact, sales, and support data
The contact form collects the details you choose to provide, including name, email, organization, phone, response preference, topic, document type, estimated page count, timeline, and message. It also records consent time, source page, delivery status, and a one-way hash derived from network data for abuse prevention. We do not store the raw network address with the contact request. Authorized administrators can view requests in a private inbox.
Device, log, and security data
Servers and security controls process request time, route, response status, browser and device information, approximate network data, request identifiers, rate-limit events, and diagnostic errors. We use this data to operate, secure, debug, and measure the service. Telemetry is configured to exclude customer documents, private URLs, credentials, and default personal-information capture.
Optional analytics
Google Analytics loads only after you select “Allow analytics” and only when it is configured. We use it for aggregate page performance, referral source, checker completion, signup, and contact-form completion. We disable Google signals and ad-personalization signals and do not intentionally send document content, form fields, names, or email addresses. See the Cookie Policy.
3. How AI-assisted processing works
When AI features are configured, eligible source PDFs, images, and extracted block inventories may be sent to Anthropic to propose image descriptions, interpret structure, or compare source fidelity. Files over configured size, page, or block limits are not sent for the document-level comparison. Results are advisory and do not make legal or accessibility decisions about a person.
We do not use Customer Content to train our own models. Anthropic states that commercial API inputs and outputs are not used for model training by default; its provider terms and retention commitments apply to its processing. A private document can still be sent to configured processors needed to perform the requested private service.
4. Sources of personal data
We receive data directly from you; from a workspace owner, teammate, customer, requester, vendor, or reviewer who invites or names you; from your use of the service; from public web pages connected for same-domain PDF discovery; and from service providers such as Dodo Payments. Customers determine the contents of uploaded documents and may include information about other people.
5. Legal reasons for processing
Depending on the context and applicable law, we process data to perform a contract or take requested pre-contract steps; pursue legitimate interests in operating, securing, supporting, and improving the service; comply with legal obligations; protect vital or legal interests; and, for optional analytics or where otherwise required, based on consent. You may withdraw consent without affecting processing already completed.
6. When we disclose data
- Service providers. Infrastructure, private storage, email, AI, payments, error monitoring, analytics, malware scanning, and validation providers receive only the data needed for their function. See Subprocessors.
- Your organization and recipients. Workspace members, invited vendors, reviewers, requesters, and delivery recipients receive data according to permissions and links configured by the customer.
- Public or shared publication. Content becomes available through public, unlisted, protected, intake, vendor, or delivery routes only when an authorized user creates or uses that route.
- Legal and safety. We may preserve or disclose information when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or establish and defend legal claims.
- Business change. Data may transfer in a merger, financing, acquisition, reorganization, or sale, subject to confidentiality and notice where required.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not use Customer Content for advertising.
7. International processing
DocAccessible and its providers may process data outside your country. Where applicable law requires a transfer safeguard, we use an approved contractual mechanism or other lawful basis. Business customers can request applicable transfer documentation through the DPA. We do not claim a fixed data-residency location unless it is confirmed in a signed order.
8. Retention and deletion
We keep personal data only while needed for the purposes described here, including the customer's active account, version and evidence history, security, billing, dispute resolution, and legal requirements. Customers can delete individual documents and can permanently delete eligible accounts in settings. Account deletion removes owned workspace content, credentials, sessions, keys, and active service records; storage deletion is queued and retried if a provider is temporarily unavailable. Required non-identifying tombstones or redacted audit and payment events may remain where needed to preserve collaboration integrity, fraud evidence, or legal records. Backup copies age out under the controlled backup rotation and are not restored for ordinary product use.
Share, vendor, invitation, reset, and delivery links expire according to their configured lifetime. Support and contact records are kept only as long as needed to resolve the inquiry, maintain a response record, prevent abuse, and meet legal obligations. A signed order may define a customer-specific schedule.
9. Security
We use technical and organizational safeguards described in the Security Overview. No internet service is risk-free. Customers should avoid uploading unnecessary sensitive information, restrict workspace membership, protect delivery links and API keys, and report suspected incidents promptly.
10. Your privacy choices and rights
Depending on your location, you may have rights to access, know, correct, delete, restrict or object to processing, withdraw consent, receive a portable copy, or complain to a data-protection authority. California residents may also request categories and specific pieces of information, correction, deletion, and non-discriminatory treatment. Because we do not sell or share personal information for cross-context behavioral advertising, there is no sale or advertising-sharing opt-out to exercise. We will honor legally valid browser signals where they apply to a practice we use.
Use the privacy request form. We may need to verify identity and authority. If your information is controlled by a DocAccessible customer, we may direct the request to that customer or assist it as processor. You may use an authorized agent where law permits. We will not discriminate against you for exercising a privacy right.
11. Children
The service is not directed to children and accounts require users to be at least 18. We do not knowingly collect personal data directly from children under 13. If you believe a child has created an account or submitted personal data without appropriate authorization, contact us so we can investigate and delete it as required. Schools and other customers remain responsible for the authority and notices required for student information they upload.
12. Changes and contact
We may update this policy as the service, providers, or law changes. The effective date shows the latest revision, and material changes may receive additional notice. For questions or complaints, use the privacy contact route. You may also lodge a complaint with the privacy regulator responsible for your location.