Privacy Policy
Effective 1 October 2026
1. Who we are
1.1 This policy explains how [LEGAL_ENTITY], business ID [BUSINESS_ID], [ADDRESS] (“Doquill”, “we”, “us”) handles personal data when you visit doquill.com, use the Doquill web application or call the Doquill API (together, the “Service”).
1.2 We have not appointed a data protection officer. Questions and requests go to privacy@doquill.com.
1.3 We wear two hats. For the data we collect to run your account, bill you, secure the Service and understand how our website is used, we are the controller. For everything you put into the Service to generate documents, we are a processor acting on your instructions, and you are the controller. Sections 2 and 3 describe each in turn.
2. Data we hold as controller
2.1 The table below lists the personal data we collect on our own behalf, where it comes from, why we need it and how long we keep it.
| Data | Source | Why | Kept for |
|---|---|---|---|
| Email address, the subject identifier from Google, GitHub, Microsoft or your single sign-on provider if you sign in that way, and the public keys of any passkeys you register | You, at sign-up or sign-in | Creating and securing your account, signing you in, sending you service emails | Until your account is deleted |
| First name, last name and phone number, if you provide them | You, in your account settings. Your name may be prefilled from Google, Microsoft or your single sign-on provider when you first sign in with them | Addressing you in the Service and in support conversations, and contacting you about your account | Until you remove them or your account is deleted |
| Workspace name, your role in it, invitations you send or receive | You and your workspace owners | Running workspaces and access control | Until the workspace or membership is deleted |
| Stripe customer and subscription identifiers, subscription status, billing period dates | Stripe, when you subscribe | Billing and entitlement | Until your workspace is deleted; invoices for as long as accounting law requires |
| API key names, prefixes, hashes and creation times | You, when you create keys | Authenticating API requests, showing you which keys are in use | Until the key or workspace is deleted |
| Render events: workspace, API key, template, template version, event type, timestamp and error message | Generated when you render | Usage counting against plan limits, diagnostics | As long as needed for usage counting and diagnostics |
| Server logs and traces, including IP address, user agent, request path, timing, status and error details | Generated when you use the Service | Security, abuse prevention, troubleshooting | Logs 30 days, traces 14 days |
| Web application monitoring: pages you view, load and response times, errors and warnings raised in your browser, interactions with some controls, browser and device type, your account and active workspace identifiers, and a random session identifier | The web application, as you use it | Finding and fixing errors and performance problems | Errors and events 30 days, timings 14 days |
| Emails you send us and our replies | You | Support and legal correspondence | As long as needed to handle the matter, then for a reasonable period as a record |
| Support chat: your email address, name and account identifier, your workspaces with your role and plan in each, the messages you send, and the web application pages you view while the chat is loaded | You, and the web application when it loads the chat | Answering your support requests | As long as needed to handle the matter, then for a reasonable period as a record |
2.2 Card numbers and other payment details are entered directly into Stripe’s payment form. They never reach our servers. Stripe’s privacy notice explains how Stripe handles them.
3. Data we process for you
3.1 When you build templates, upload assets, save sample data, send render requests or store generated documents (together, “Your Content”, as defined in our Terms of Service), that content may contain personal data about your customers, employees or other people. You decide what goes in; we process it only to provide the Service to you and as described in the Terms of Service.
3.2 For this data you are the controller and we are the processor. We follow your instructions, given through your use of the Service, and we do not use this data for our own purposes. Our obligations under Article 28 of the GDPR are set out in our Data Processing Agreement, which forms part of the Terms of Service.
3.3 Retention follows your actions:
- Data in a synchronous render request, and the document generated from it, are not stored.
- Documents created by render jobs, and assets you upload, are kept until you delete them or your workspace is deleted.
- Data in a render job request is kept until the job finishes. The job’s status, including any error message, is kept for 30 days.
- Templates and sample data are kept until you delete them or your workspace is deleted.
3.4 Our logs record only which workspace, key and template were involved in a render, and any error message. Template content and request data are never written to logs.
4. Website and app analytics
4.1 We run our own instance of Plausible Analytics to understand how many people visit doquill.com and the web application, which pages they view and roughly where they come from. Plausible sets no cookies and does not track you across sites. Your IP address and browser details are used momentarily to derive a country and a device type and are not stored. Only aggregate numbers are kept.
4.2 Separately, the web application reports errors and performance measurements to our own monitoring system, which runs on our servers. These reports are linked to your account so we can investigate problems you run into. They are used only to keep the Service working and are never used for marketing. Section 2 lists what they contain and how long they are kept.
5. Cookies
5.1 The web application sets a session cookie and a CSRF protection cookie so that you stay signed in and your requests are protected against forgery. These are strictly necessary for the Service to work. The support chat in the web application sets its own cookies to keep your conversation connected to you across visits. It runs on our own servers, so these are first-party cookies too. To group the error and performance reports described in section 4.2, the web application keeps a random identifier in your browser’s session storage, which is cleared when you close the tab. We set no advertising, tracking or third-party cookies, and no consent banner is needed.
6. Why we process your data and on what basis
6.1 We rely on the following legal bases under the GDPR:
- Performance of a contract (Article 6(1)(b)): creating and operating your account and workspace, authenticating you, billing, providing support.
- Legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing abuse and fraud, monitoring performance, understanding how the Service is used so we can improve it, and defending our legal rights. We have assessed that these interests do not override your rights, given the limited data involved.
- Legal obligation (Article 6(1)(c)): keeping accounting and tax records, responding to lawful requests from authorities.
- Consent (Article 6(1)(a)): only for optional things we may introduce later, such as product newsletters. Where we ask for consent you can withdraw it at any time.
7. Who we share data with
7.1 We use the following providers to run the Service. Except for the sign-in providers, which handle your sign-in under their own privacy notices, each processes personal data only on our instructions and under a data processing agreement. Those that also process Your Content are listed on our sub-processors page.
| Provider | Purpose | Location of processing |
|---|---|---|
| UpCloud Oy | Hosting: servers, database and object storage where all Service data lives | Helsinki, Finland |
| Stripe Payments Europe, Ltd. and its affiliates | Payment processing and invoicing | Ireland, with transfers to the United States under Stripe’s data processing agreement and standard contractual clauses |
| Mailjet SAS | Sending transactional email such as sign-in codes, account recovery, invitations and billing notices | European Union |
| BunnyWay d.o.o. (bunny.net) | Content delivery network and DNS in front of our websites and API | Slovenia, with edge locations worldwide under standard contractual clauses |
| Google LLC, GitHub, Inc., Microsoft Corporation | Sign-in, only if you choose to sign in with that provider | Per the provider’s own privacy notice |
7.2 We may disclose personal data where the law requires it, for example in response to a valid request from a court or authority, or where necessary to protect our rights, our users or the public. We do not sell personal data and we do not share it with advertisers.
7.3 If Doquill is acquired or merges with another business, personal data may transfer to the new owner under the same commitments as this policy. We will tell you before that happens.
8. Where data is stored and international transfers
8.1 All Service data, including your account, workspace and Your Content, is stored on UpCloud infrastructure in Helsinki, Finland, within the European Economic Area.
8.2 Some providers listed in section 7 may process limited data outside the EEA, most notably Stripe for payment processing, bunny.net’s edge locations that pass requests through to our servers, and the sign-in providers if you use them. Those transfers rely on the European Commission’s standard contractual clauses or on an adequacy decision, together with the provider’s own safeguards.
9. How long we keep data
9.1 How long each category of data is kept is stated in sections 2 and 3. Account, workspace and content data stay for as long as you keep them in the Service. Render events are kept only as long as they are needed for usage counting and diagnostics. Server logs are kept for 30 days and traces for 14 days. Data deleted from our databases remains in database backups for up to 31 days before it is gone. Invoices and accounting records are kept for six years from the end of the financial year in which they were created, as the Finnish Accounting Act requires.
9.2 When you ask us to delete your workspace or account, we remove your data from our active systems within 30 days. Content you delete inside the Service is hidden immediately and permanently removed no later than when your workspace is deleted. Database backups are kept for up to 31 days, so copies in backups are gone no later than 31 days after that.
9.3 Until a self-service deletion feature is available in the web application, send account and workspace deletion requests to support@doquill.com from an email address associated with a workspace owner.
10. How we protect data
10.1 We take measures appropriate to the risk, including:
- TLS encryption for all traffic to and between our services.
- Databases stored on encrypted disk volumes, and object storage, including backups, encrypted at rest.
- A private network with per-service policies that only allow the connections each component needs.
- Document renderers that cannot reach the public internet or other workspaces.
- No passwords to leak: sign-in uses one-time codes sent to your email address, passkeys or a third-party identity provider. API keys are stored only as hashes.
- Access to production systems limited to the people who operate the Service, using individual credentials.
- Monitoring, logging and alerting for security-relevant events.
10.2 No system is perfectly secure. If we become aware of a personal data breach that is likely to put you at risk, we will tell you and the supervisory authority as the GDPR requires.
11. Your rights
11.1 Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data, subject to legal retention obligations;
- restrict processing in certain circumstances;
- receive your data in a portable format where processing is based on contract or consent;
- object to processing based on our legitimate interests; and
- withdraw consent at any time where processing is based on consent.
11.2 To exercise a right, email privacy@doquill.com. We may ask you to verify your identity, and we will respond within one month, or tell you if we need longer for a complex request.
11.3 If your data was put into the Service by one of our customers, the customer is the controller and you should direct your request to them. We will help the customer respond.
11.4 If you believe we have processed your data unlawfully, you can lodge a complaint with the Office of the Data Protection Ombudsman of Finland (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or with the supervisory authority in the country where you live or work.
12. Changes and contact
12.1 We may update this policy as the Service or the law changes. If a change materially affects how we handle your data, we will tell you by email or through the Service before it takes effect. The effective date at the top shows when the current version started to apply.
12.2 Contact us about anything in this policy:
[LEGAL_ENTITY], business ID [BUSINESS_ID], [ADDRESS].
- Privacy requests: privacy@doquill.com
- Everything else: support@doquill.com