Privacy Policy
Effective 26 July 2026
This explains what Datavanta Labs Limited does with personal data in doc2api. It covers two different relationships, and the difference matters:
- Your account. For the data we hold about you as a customer — your email, your workspace, your usage — we are the controller, and this policy is our notice to you.
- Your documents. For the personal data inside the documents you upload and the forms people fill in, you are the controller and we act on your instructions as a processor. Our Data Processing Addendum governs that, and the people filling your forms should be looking at your privacy notice, not this one.
1.What we collect
Account data. Your email address, an authentication record, your organisation and plan, and the API keys issued to your templates.
Document data. The files you upload, the field positions and rules you configure, and the values submitted through your forms or your API calls. A drawn signature arrives as an image and is stamped onto the document; in the submission record we store, we replace that image with a short placeholder rather than keeping the picture.
Usage data. Counts we need for metering and abuse prevention — documents produced per month, templates created, rate-limit counters keyed to your workspace or IP address — plus records of webhook deliveries, including the body we sent to your endpoint and the response we got back.
Technical data. Ordinary server and platform logs (IP address, user agent, request path, timestamps) and error reports. Our error monitoring is configured not to collect personal data with reports.
Cookies. Only essential ones: a session cookie once you sign in, and a signed cookie identifying a trial workspace so your work survives a page reload. We set no advertising or cross-site tracking cookies, so there is no consent banner to click.
2.Why we use it
- To provide the Service — store your templates, fill and render documents, run your forms, deliver your webhooks.
- To operate accounts and authenticate you, and to send transactional email such as sign-in and account notices.
- To meter usage against your plan and enforce quotas and rate limits.
- To keep the Service secure — detecting abuse, investigating incidents, blocking attacks.
- To fix problems, using error reports and logs.
- To comply with legal obligations, and to establish or defend legal claims.
Our lawful bases, where the GDPR or a similar law applies, are performance of a contract (providing the Service you signed up for), our legitimate interests (security, abuse prevention, product reliability), and legal obligation. We do not rely on consent for any of the above, and we do not use your data for advertising or profiling.
3.How long we keep it
| Data | Kept for |
|---|---|
| Templates and their uploaded documents | Until you delete them, or you close your account |
| Submission records (the field values) | By plan: Free 1 day, Starter 7 days, Pro 90 days, Business until you delete it |
| Trial workspaces and everything in them | 24 hours from creation, unless you sign up — then they move into your account |
| PDFs linked from a webhook delivery | 24 hours, then deleted from our storage |
| Webhook delivery records | Kept while a delivery is being retried, then pruned |
| Account record | While your account is open, then removed on closure |
| Server and error logs | A short rolling window kept by our hosting and monitoring providers |
Deleting a template removes its stored file as well as its rows. Retention runs on a schedule, so a record may persist a few hours past its window before the sweep removes it. Backups age out on their own cycle.
5.Where data is processed
Our providers operate internationally, so data may be processed outside your country, including outside the European Economic Area and the United Kingdom. Where we transfer personal data from those regions we rely on the appropriate safeguards — typically the European Commission’s Standard Contractual Clauses in our agreements with the provider. You can ask us which region your workspace’s data sits in.
6.How we protect it
These are the measures actually in place, not aspirations:
- Uploaded documents live in private storage — never public buckets — and are reachable only through an authenticated request or a short-lived signed URL.
- Every workspace is isolated, and each request is checked against the workspace that owns the template.
- Each template has separate keys for filling, browser embedding and administration, so the key you expose in a browser cannot fill documents or change configuration. Any key can be rotated instantly, which immediately invalidates the old one.
- Embedding can be locked to your own domains, enforced both by a frame-ancestors policy and by rejecting the publishable key from other origins.
- Webhook deliveries are signed with a per-endpoint secret so you can verify they came from us, and outbound webhook URLs are checked so the Service cannot be pointed at private or internal network addresses.
- Rate limits and per-plan quotas bound both abuse and cost.
- Traffic is encrypted in transit; our error monitoring is configured not to collect personal data.
No system is perfectly secure. If you find a vulnerability, please tell us at security@doc2api.co before disclosing it publicly, and we will work with you on a fix.
7.Your rights
Depending on where you live you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in a portable form, object to or restrict certain processing, and complain to your data protection authority. Email privacy@doc2api.co and we will respond within the time the applicable law allows — one month under the GDPR.
If your request concerns personal data inside a customer’s documents — for example you filled in a form on someone’s website — we are the processor, not the controller. Please contact that organisation; if you contact us, we will point you to them, and we will help them respond.
You can delete a template or your whole account yourself from the dashboard at any time.
8.Data we are not built for
Do not put payment card numbers into a document, and do not use the Service for health information subject to HIPAA — we do not offer a Business Associate Agreement. If your forms collect special category data under the GDPR (health, biometrics, and the rest), you are responsible for having a lawful basis and for telling the people involved.
9.Children
The Service is for organisations and developers, and is not directed at children. We do not knowingly collect personal data from children for our own purposes. A form you build may collect data about a child — a parent completing a consent form, for instance — and that remains yours to justify and disclose.
10.Changes and contact
We will update this policy as the Service changes, and will bump the effective date at the top. Where a change materially affects you we will give notice by email or in the dashboard.
Contact us at privacy@doc2api.co about anything in this policy, or legal@doc2api.co about the Terms of Service.
Datavanta Labs Limited