Updated at July 30, 2024
At Docxster, we prioritise the privacy and security of your personal data. In today’s digital age, safeguarding your information is more important than ever. Our commitment to data privacy protection is reflected in our rigorous adherence to the General Data Protection Regulation (GDPR) and other applicable data protection laws. This Privacy Policy outlines our practices for collecting, using, and protecting your personal data. We aim to provide you with transparency and control over your information, ensuring that you can use our cloud-based SaaS platform with confidence. Your trust in our data handling practices is paramount to us. We are dedicated to maintaining the highest standards of data privacy, and we continuously review and improve our policies and procedures to meet and exceed regulatory requirements. By using Docxster, registering an account, or engaging with our services, you consent to the terms outlined in this Privacy Policy and can be assured of our unwavering commitment to your privacy.
This Privacy Policy applies to all personal data collected, processed, and stored by Docxster through our website and services. It covers the data we gather from users of the respective Organization and also the data processed from the documents uploaded by the client.
Docxster is dedicated to upholding GDPR standards. We have established and publicly available privacy policies and procedures to ensure lawful data collection and processing practices.
We process personal data based on the following legal grounds.
Our legitimate interests include:
We collect the following types of personal data:
We collect the following types of personal data:
We obtain explicit consent from users for processing their personal data, including during sign-up. You can withdraw your consent at any time by contacting us at dpo@docxster.com.
We have a consent management system to ensure that consent preferences are respected and implemented effectively.
We enter into SCCs with client organizations to ensure data protection when processing personal data on their behalf. This agreement outlines the responsibilities and safeguards for both parties. Additionally, we have a Data Processing Agreement (DPA) also in place with the client organization.
We implement robust security measures to protect your personal data:
We have procedures in place to detect and respond to data breaches. This includes monitoring our systems for unusual activities and potential security threats.
Our incident management policy includes steps for managing information security incidents, including detecting breaches, notifying affected individuals, and taking remedial actions.
Our incident management policy includes steps for managing information security incidents, including detecting breaches, notifying affected individuals, and taking remedial actions.
To exercise your rights, please email us. We will handle your requests in accordance with GDPR requirements and respond promptly. The contact details of Data Protection Committee is given: dpo@docxster.com.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Docxster processes or stores all personal data in fully vetted, DPA compliant vendors. We do store all conversation and personal data for up to 6 years unless your account is deleted. In which case, we dispose of all data in accordance with our Terms of Service and Privacy Policy, but we will not hold it longer than 60 days.
We maintain a retention matrix that specifies:
Sometimes, we might partner with other companies (sub-processors) to deliver our services effectively. We carefully choose these partners and ensure they comply with GDPR just like we do. You can find more details about our sub-processors on our dedicated Sub-processors page. These sub-processors may be based outside Europe.
If your data needs to travel outside Europe (EEA), we take extra precautions. We use Standard Contractual Clauses (SCCs) approved by the European Commission. These clauses guarantee the same level of protection for your data as it receives within Europe. These include legal agreements and security measures to ensure data is handled securely.
We also obtain explicit consent from individuals for transferring their data outside the EEA if necessary.
We have appointed a three-member committee to oversee our data protection practices and ensure compliance with data protection laws. The Data Protection Committee operates independently and possesses expertise in data protection and privacy regulations.
The Data Protection Committee's responsibilities include:
Docxster's platform does not specifically target children under the age of 18 or vulnerable groups. However, it is crucial to ensure that the platform's data protection measures are robust enough to safeguard all users, including potentially vulnerable individuals.
We may change our Service and policies, and we may need to make changes to this Privacy Policy so thatthey accurately reflect our Service and policies. Unless otherwise required by law, we will notify you (for example, through our Service) before we make changes to this Privacy Policy and give you an opportunity to review them before they go into effect. We review and update this Privacy Policy annually or as needed to reflect changes in our practices or regulatory requirements.
Then, if you continue to use the Service, you will be bound by the updated Privacy Policy. If you do not want to agree to this or any updated Privacy Policy, you can delete your account.
For any questions or concerns regarding this Privacy Policy or our data protection practices, please contact:
We conduct thorough due diligence on our vendors to ensure they comply with data protection regulations. Our contracts with third parties define the scope of data sharing, usage, and security measures.
Our Business Continuity Policy includes measures for the backup and restoration of personal data to ensure ongoing protection.
We adhere to the principle of data minimization, collecting only the data necessary for our services. We have mechanisms in place to ensure we collect and process minimal data. We Use techniques like data masking for any sensitive data that is collected. We also engage with stakeholders, including data subjects, to ensure transparency about what data is collected and why.
We conduct Privacy Risk Assessments to identify and mitigate privacy risks as part of our ongoing risk management processes.
We provide regular training to our employees on data protection practices and the procedures for reporting breaches
We have established procedures to ensure that employees know how to report breaches and that our response mechanisms are effective in detecting and managing privacy breaches.
Docxster is dedicated to maintaining the highest standards of data protection and privacy. We regularly review and update our policies to ensure compliance with GDPR and other applicable regulations. For any questions or concerns with regards to our privacy policies, please contact our team at support@docxster.com.