Privacy Policy & Global Legal Consent
At DocFlexa Inc. ("DocFlexa", "we", "us", or "our"), we respect your fundamental right to privacy. This Privacy Policy details how we collect, process, store, and safeguard personal data across all jurisdictions worldwide, and outlines your legal consent when using our services.
1Scope & Data Controller
This Privacy Policy applies to all individuals and organizations accessing or using the DocFlexa web application, mobile experiences, APIs, and associated cloud services. DocFlexa Inc. acts as the Data Controller under the General Data Protection Regulation (EU/UK GDPR) and applicable international data protection statutes.
2Information We Collect & Process
We collect information in three categories:
A. Account & Identity Data (Provided Directly by You)
Full name, display name, email address, hashed passwords, organization metadata, business phone number, and optional tax identification details for verified business entities.
B. Document Metadata & Form Schemas
Template structures, custom field definitions, validation rules, item titles, category tags, purchase dates, warranty expiration timestamps, and scheduled reminder preferences.
C. Connected Storage & OAuth Access Tokens
Encrypted OAuth tokens required to communicate with third-party storage providers (Google Drive, Microsoft OneDrive, Dropbox, AWS S3, Azure Blob) solely to upload, fetch, or sync your document attachments.
3How We Use Information & Legal Bases (GDPR Article 6)
We process personal data strictly under lawful legal bases:
- Contractual Necessity: To provide the DocFlexa platform, execute document indexing, render forms, authenticate users, and manage subscriptions.
- Legitimate Interests: To prevent fraud, detect malicious honeypot bots, safeguard system security, and provide sub-second search indexing.
- Legal Consent: To send automated reminder emails before warranty expirations and process cloud storage synchronization via OAuth tokens.
- Legal Compliance: To satisfy tax, invoicing, and regulatory recordkeeping obligations worldwide.
4Google API & Third-Party Storage Disclosure
GOOGLE USER DATA & DRIVE SCOPES POLICY COMPLIANCE:
DocFlexa's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- We only request Drive access scopes required to create and retrieve DocFlexa document files authorized by you.
- We do not transfer your Google data to third parties, data brokers, or advertising networks.
- Humans do not read your private Google Drive files unless specifically authorized by you for customer support debugging.
5Global Data Subject Rights (EU/UK GDPR, CCPA/CPRA, LGPD)
Regardless of your country of residence, DocFlexa grants all users comprehensive global data rights:
Right to Access & Portability
Export all your templates and document records as JSON schemas or zipped backups at any time via Account Settings.
Right to Erasure (Right to be Forgotten)
Permanently delete your account and all associated database records directly through the self-serve settings interface.
Right to Rectification
Update, correct, or amend profile, organization, and billing metadata instantly.
No Sale / Sharing of Personal Information
DocFlexa does NOT sell or share personal information under the California Consumer Privacy Act (CCPA/CPRA).
To exercise any statutory data right or submit a formal inquiry, email our Data Protection Officer at dpo@docflexa.com.
6Security Architecture & Encryption Standards
We implement enterprise-grade technical and organizational safeguards:
- In-Transit Encryption: All client-server traffic is encrypted using Transport Layer Security (TLS 1.3).
- At-Rest Encryption: Database records and OAuth secret keys are encrypted using AES-256 standards with ASP.NET Core Data Protection.
- Tenant Isolation: Strict multi-tenant row-level access controls prevent unauthorized cross-organization data leakage.
- Automated Threat Prevention: Continuous automated rate limiting, bot honeypots, and SQL injection sanitization.
7Cookies, Storage & Tracking Technologies
DocFlexa uses strictly necessary and functional cookies/local storage:
docs9_logged_in/docflexa_logged_in: Session authentication indicator.theme: Dark/light mode interface preference.docflexa_gemini_api_key: Client-side storage of user-provided Google Gemini API key (never transmitted to DocFlexa servers).
We do not employ third-party tracking pixels or behavioral cross-site advertising cookies.
8Children's Privacy Protection
DocFlexa is not intended for use by children under the age of 16 (or under the minimum digital consent age in your jurisdiction). We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact privacy@docflexa.com for immediate deletion.
9Data Protection Officer (DPO) & Contact Details
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact our Data Protection Officer:
DocFlexa Inc. — Data Protection Office
Email: privacy@docflexa.com
DPO Direct: dpo@docflexa.com
Security Response: security@docflexa.com