Privacy Notice
Effective date: 2026-08-09 00:00
Last updated: 2026-08-09 00:00
This Notice explains how personal data is processed when you visit a Documira marketing website, contact us, create an account, authenticate, use the Documira application or purchase a subscription.
1. Controller and contact
For account administration, contracting, website operation, support, security and business analytics, the controller is Documira.
Privacy and data-rights requests may be sent to documira.contact [at] gmail.com. Ordinary product support should be requested through the website contact form. No data protection officer has been appointed.
2. When Documira is a processor
Professional Customers generally determine why and how personal data included in their templates, variables, project records, uploaded images and generated documents is used. For that Customer Content, the Customer is the controller and Documira acts as processor under the DPA.
This Privacy Notice covers Documira’s processing as controller. Data subjects whose information was placed in Documira by a Customer should normally contact that Customer first. Documira will assist the Customer as required by the DPA.
3. Data we process
Depending on how you interact with Documira, we process:
- Website and device data: requested page, date and time, IP address, browser and device information, security/CDN logs, referrer and consent choice.
- Attribution and analytics data: source, audience segment and UTM campaign parameters; consented page views and analytics identifiers.
- Contact data: name, email address, message and normal request metadata submitted through Formspree.
- Account and organization data: email, password hash, first and last name where supplied, organization name, language, account status, login timestamps and membership.
- Social-login data: provider, provider user ID, email, verification status and profile information returned by Google or Meta according to the permissions displayed by that provider. OAuth access tokens are not intentionally retained by Documira.
- Customer Content: project titles and descriptions, variable definitions and values, record data, templates, formatting, uploaded images, generated or saved documents, filenames and related metadata.
- Service and support data: settings, actions needed to provide the Service, support correspondence, transactional-email delivery status and provider message identifiers.
- Trial and billing data: plan, trial and subscription status, dates, Dodo customer/subscription/payment/checkout identifiers, order amount and currency, payment status and transaction/webhook records. Documira does not directly collect full card numbers.
Please do not submit CNP, equivalent national identifiers, identity documents, payment-card details, passwords, special-category data, criminal-offence data or other data prohibited by the Terms.
4. Purposes and legal bases
We process personal data for the following purposes:
| Purpose | Main data | GDPR legal basis |
|---|---|---|
| Provide accounts, trials and subscriptions | Account, organization, service and billing status | Contract; steps requested before contract |
| Authenticate users, including optional social login | Account, session and provider profile data | Contract; legitimate interest in usable authentication |
| Process payments and administer subscriptions | Account, order and billing-reference data | Contract; legal obligations; legitimate interest in reconciliation and fraud prevention |
| Send transactional messages | Email, organization, trial and service status | Contract; legitimate interest in service communications |
| Answer contact and support requests | Name, email, message and account context | Steps requested before contract; contract; legitimate interest in responding |
| Secure, troubleshoot and prevent abuse | Logs, account, device, content and transaction events | Legitimate interest in protecting users, systems and legal rights; legal obligations where applicable |
| Measure marketing-site use | Consented analytics and campaign data | Consent for non-essential browser storage and analytics |
| Establish, exercise or defend claims and comply with law | Relevant account, content, support, billing and log data | Legal obligations; legitimate interest in legal protection |
Where information is required to create an account or provide a requested function, failure to provide it may prevent us from providing that function. Analytics consent is optional and refusal does not prevent ordinary website use.
Documira processes Customer Content as processor on the Customer’s documented instructions. The Customer, not Documira, determines the Article 6 and, where applicable, Article 9 legal basis for that content. Documira acts as controller only for limited associated activities and metadata such as account administration, billing, security and legal compliance.
5. Sources
We receive data directly from you and your organization, from your browser or use of the Service, from Google or Meta when you choose social login, from Dodo Payments concerning payment and subscription events, and from service providers that deliver hosting, security, forms and transactional email.
6. Recipients and service providers
Authorized access is limited to the Provider and vendors that need data for their services. Current categories include:
| Recipient | Purpose | Relevant location or role |
|---|---|---|
| Hosting provider | Server hosting for the application, database, private media and operational services | Germany; processor |
| Cloudflare | Static website delivery, DNS/CDN, proxying and security of public application traffic | Global network; processor under the applicable account terms |
| Formspree | Marketing-site contact forms | United States; processor/service provider |
| Brevo | Transactional account and service email | Email processor; provider terms determine processing locations |
| Optional Google login; Google Analytics after consent | Separate-controller aspects for login; analytics service provider | |
| Meta | Optional Facebook login | Separate-controller aspects under Meta’s terms |
| PostHog | Basic marketing analytics after consent, configured for EU hosting | EU-hosted analytics processor |
| Dodo Payments | Hosted checkout, Merchant-of-Record, tax, invoice, subscription and payment functions | Independent controller for its payment, tax and Merchant-of-Record functions under the checkout documents |
We do not sell personal data. We do not disclose Customer Content to third parties for their independent advertising.
7. International transfers
Core application data is hosted on the hosting provider servers in Germany. Cloudflare’s network and some providers, including Formspree, Google, Meta and Dodo, may process data outside the European Economic Area.
Where a recipient is outside the EEA and no adequacy decision applies, transfers are based on an applicable safeguard such as the European Commission’s Standard Contractual Clauses and supplementary measures provided under the relevant vendor agreement. Copies or information about applicable safeguards may be requested through the legal contact email, subject to protection of confidential information.
8. Retention
We retain data only for as long as needed for the relevant purpose:
- Active account and Customer Content: for the account term.
- Expired or closed workspace: restricted for 30 days for viewing and requesting available export assistance, then manually deleted from production unless legal retention applies.
- Backups: made approximately every seven days and retained for up to 30 days; deletion reaches backups as they expire.
- Contact and support correspondence: until the request is resolved and for a limited follow-up or legal-claims period, taking account of its nature.
- Consent choice: 180 days, unless withdrawn sooner.
- Marketing attribution: for the browser session on the websites; signup attribution associated with an organization may be retained with the account for acquisition records.
- Analytics: according to the configured GA and PostHog settings described in the Cookie Policy; provider-side aggregate reports may be retained for the configured analytics period.
- Authentication, security and operational logs: for the period reasonably needed to investigate incidents, operate the Service and protect legal rights, then rotated or deleted.
- Billing and transaction records: for the subscription term and any longer period required for accounting, tax, anti-fraud or legal-claims obligations. Dodo retains its own records under its notice.
If data is needed for a dispute, legal hold or statutory obligation, the relevant portion may be retained until that need ends.
9. Security
Measures include organization-scoped application access controls, password hashing, CSRF protections, restricted and validated uploads, sanitization of document HTML, signed billing webhooks, limited administrative access and periodic encrypted backups. The Provider is the only infrastructure administrator. Public traffic is delivered through HTTPS and Cloudflare-proxied services.
Customer Content is not represented as encrypted at rest, and the Service does not promise high availability or guaranteed recovery. No system is completely secure. Please report suspected incidents through the legal contact email and do not send passwords through the contact form.
10. Your rights
Subject to GDPR conditions and exceptions, you may request:
- access to your personal data and a copy;
- rectification of inaccurate data;
- erasure;
- restriction of processing;
- portability of data you provided where processing is automated and based on contract or consent;
- objection to processing based on legitimate interests; and
- withdrawal of consent at any time, without affecting earlier lawful processing.
You may exercise these rights through documira.contact [at] gmail.com. We may need information to verify identity and authority. If Documira processes the data only for a Customer, we may refer the request to that Customer.
You may lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or another competent EEA supervisory authority, particularly in the country where you live or work or where an alleged infringement occurred.
11. Automated decisions
Documira does not use personal data to make decisions producing legal or similarly significant effects solely by automated means. Analytics may create aggregated or pseudonymous usage reports but is not used for such decisions.
12. Cookies and browser storage
The websites use necessary storage for consent and, with consent, analytics and campaign attribution. The application uses authentication, security, language, timezone, trial and attribution storage. Details and controls are in the Cookie Policy.
13. Changes
We may update this Notice to reflect changes in law, vendors or the Service. Material changes will be highlighted on the website or communicated through an appropriate service channel. The date above identifies the current version.
14. Contact
Use documira.contact [at] gmail.com for privacy requests. Use the website contact form for ordinary product support.