Privacy Notice

Effective date: 2026-08-09 00:00

Last updated: 2026-08-09 00:00

This Notice explains how personal data is processed when you visit a Documira marketing website, contact us, create an account, authenticate, use the Documira application or purchase a subscription.

1. Controller and contact

For account administration, contracting, website operation, support, security and business analytics, the controller is Documira.

Privacy and data-rights requests may be sent to documira.contact [at] gmail.com. Ordinary product support should be requested through the website contact form. No data protection officer has been appointed.

2. When Documira is a processor

Professional Customers generally determine why and how personal data included in their templates, variables, project records, uploaded images and generated documents is used. For that Customer Content, the Customer is the controller and Documira acts as processor under the DPA.

This Privacy Notice covers Documira’s processing as controller. Data subjects whose information was placed in Documira by a Customer should normally contact that Customer first. Documira will assist the Customer as required by the DPA.

3. Data we process

Depending on how you interact with Documira, we process:

Please do not submit CNP, equivalent national identifiers, identity documents, payment-card details, passwords, special-category data, criminal-offence data or other data prohibited by the Terms.

We process personal data for the following purposes:

PurposeMain dataGDPR legal basis
Provide accounts, trials and subscriptionsAccount, organization, service and billing statusContract; steps requested before contract
Authenticate users, including optional social loginAccount, session and provider profile dataContract; legitimate interest in usable authentication
Process payments and administer subscriptionsAccount, order and billing-reference dataContract; legal obligations; legitimate interest in reconciliation and fraud prevention
Send transactional messagesEmail, organization, trial and service statusContract; legitimate interest in service communications
Answer contact and support requestsName, email, message and account contextSteps requested before contract; contract; legitimate interest in responding
Secure, troubleshoot and prevent abuseLogs, account, device, content and transaction eventsLegitimate interest in protecting users, systems and legal rights; legal obligations where applicable
Measure marketing-site useConsented analytics and campaign dataConsent for non-essential browser storage and analytics
Establish, exercise or defend claims and comply with lawRelevant account, content, support, billing and log dataLegal obligations; legitimate interest in legal protection

Where information is required to create an account or provide a requested function, failure to provide it may prevent us from providing that function. Analytics consent is optional and refusal does not prevent ordinary website use.

Documira processes Customer Content as processor on the Customer’s documented instructions. The Customer, not Documira, determines the Article 6 and, where applicable, Article 9 legal basis for that content. Documira acts as controller only for limited associated activities and metadata such as account administration, billing, security and legal compliance.

5. Sources

We receive data directly from you and your organization, from your browser or use of the Service, from Google or Meta when you choose social login, from Dodo Payments concerning payment and subscription events, and from service providers that deliver hosting, security, forms and transactional email.

6. Recipients and service providers

Authorized access is limited to the Provider and vendors that need data for their services. Current categories include:

RecipientPurposeRelevant location or role
Hosting providerServer hosting for the application, database, private media and operational servicesGermany; processor
CloudflareStatic website delivery, DNS/CDN, proxying and security of public application trafficGlobal network; processor under the applicable account terms
FormspreeMarketing-site contact formsUnited States; processor/service provider
BrevoTransactional account and service emailEmail processor; provider terms determine processing locations
GoogleOptional Google login; Google Analytics after consentSeparate-controller aspects for login; analytics service provider
MetaOptional Facebook loginSeparate-controller aspects under Meta’s terms
PostHogBasic marketing analytics after consent, configured for EU hostingEU-hosted analytics processor
Dodo PaymentsHosted checkout, Merchant-of-Record, tax, invoice, subscription and payment functionsIndependent controller for its payment, tax and Merchant-of-Record functions under the checkout documents

We do not sell personal data. We do not disclose Customer Content to third parties for their independent advertising.

7. International transfers

Core application data is hosted on the hosting provider servers in Germany. Cloudflare’s network and some providers, including Formspree, Google, Meta and Dodo, may process data outside the European Economic Area.

Where a recipient is outside the EEA and no adequacy decision applies, transfers are based on an applicable safeguard such as the European Commission’s Standard Contractual Clauses and supplementary measures provided under the relevant vendor agreement. Copies or information about applicable safeguards may be requested through the legal contact email, subject to protection of confidential information.

8. Retention

We retain data only for as long as needed for the relevant purpose:

If data is needed for a dispute, legal hold or statutory obligation, the relevant portion may be retained until that need ends.

9. Security

Measures include organization-scoped application access controls, password hashing, CSRF protections, restricted and validated uploads, sanitization of document HTML, signed billing webhooks, limited administrative access and periodic encrypted backups. The Provider is the only infrastructure administrator. Public traffic is delivered through HTTPS and Cloudflare-proxied services.

Customer Content is not represented as encrypted at rest, and the Service does not promise high availability or guaranteed recovery. No system is completely secure. Please report suspected incidents through the legal contact email and do not send passwords through the contact form.

10. Your rights

Subject to GDPR conditions and exceptions, you may request:

You may exercise these rights through documira.contact [at] gmail.com. We may need information to verify identity and authority. If Documira processes the data only for a Customer, we may refer the request to that Customer.

You may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or another competent EEA supervisory authority, particularly in the country where you live or work or where an alleged infringement occurred.

11. Automated decisions

Documira does not use personal data to make decisions producing legal or similarly significant effects solely by automated means. Analytics may create aggregated or pseudonymous usage reports but is not used for such decisions.

12. Cookies and browser storage

The websites use necessary storage for consent and, with consent, analytics and campaign attribution. The application uses authentication, security, language, timezone, trial and attribution storage. Details and controls are in the Cookie Policy.

13. Changes

We may update this Notice to reflect changes in law, vendors or the Service. Material changes will be highlighted on the website or communicated through an appropriate service channel. The date above identifies the current version.

14. Contact

Use documira.contact [at] gmail.com for privacy requests. Use the website contact form for ordinary product support.