DocMaster Privacy Policy
Last updated: 24 September 2026
This Privacy Policy explains how SIA DocMaster, registration No. 40203699978, Ceriņu iela 5, Lielvārde, LV-5070, Latvia (“DocMaster“, “we“) handles personal data when you use DocMaster (the Excel add-in and the web portal), visit our website, or contact us.
Contact for privacy questions and requests: support@docmaster.ai.
1. Two roles
We are the controller for the personal data described in this policy: user accounts, billing details, usage and technical data, support correspondence and website visits.
We are the processor for the documents our customers upload, their file names and job names, and the results produced from them. Our customer (your employer or organisation) decides what to upload and why, and we process that data only on its behalf, under our Data Processing Agreement. If your personal data appears in a document a customer uploaded, please contact that customer first; we will help them respond.
2. What we collect and why
| Data | Examples | Why | Legal basis (GDPR) |
|---|---|---|---|
| Account data | name, email address, user ID, organisation and role, sign-in method (Microsoft, Google, or email with a password or one-time code), session information, invitations | To create and run your account, let you sign in, and let administrators manage their organisation | Performance of a contract (Art. 6(1)(b)); for users invited by their organisation, our and the organisation’s legitimate interest in providing the service it bought (Art. 6(1)(f)) |
| Billing data | company name and legal name, billing email, postal address, VAT number, plan and seats, invoices, payment status; card details are entered with and stored by Stripe (we never see or store the full card number) | To charge for the service, issue invoices and keep accounting records | Performance of a contract (Art. 6(1)(b)); legal obligation for accounting and tax records (Art. 6(1)(c)) |
| Usage data | which features you used, the jobs you ran (when, how many files and pages, how long they took), usage against plan limits | To provide the service and apply plan limits | Performance of a contract (Art. 6(1)(b)) |
| Product analytics | pseudonymous user and organisation IDs, pages and screens viewed, interactions (with on-screen text and form contents masked), error reports, IP address | To understand how the product is used, fix errors and improve it | Legitimate interests (Art. 6(1)(f)) |
| Technical and security logs | IP address, request URLs, user and organisation IDs, error codes, timestamps | To keep the service secure and working, and to investigate problems | Legitimate interests (Art. 6(1)(f)) |
| Support and sales correspondence | what you write to us and your contact details | To answer you and keep a record of our communication | Legitimate interests (Art. 6(1)(f)); performance of a contract (Art. 6(1)(b)) |
We do not use your personal data for automated decisions that have legal or similarly significant effects on you. We do not sell personal data.
3. Cookies and local storage
The DocMaster add-in and portal do not use advertising or tracking cookies, and do not show a cookie banner because they only use storage that is necessary for the service:
- Sign-in (Clerk). Clerk, our sign-in provider, sets cookies needed to keep you signed in securely.
- Our local storage. The add-in and portal keep your sign-in tokens, who is signed in, a copy of your settings and a few display preferences in your browser’s local storage. Signing out removes everything tied to your account.
- Product analytics (PostHog). Analytics runs in memory only: it stores nothing on your device and starts afresh on every page load.
- Payments (Stripe). You enter card details on Stripe’s own payment page, which sets the cookies Stripe needs to process payments and prevent fraud.
Our website (docmaster.ai) uses its own cookies, which you can accept or reject in the cookie banner shown on the site. The banner stores your choice in a cookie named cookieadmin_consent. If you accept, the website uses Google Analytics (cookies whose names start with _ga) to count visits and see which pages are read. If you accept marketing cookies, it also loads the LinkedIn Insight Tag (cookies such as li_sugr, bcookie and lidc) to measure visits that come from our LinkedIn posts and ads. If you reject them, neither Google Analytics nor LinkedIn is loaded. Website forms use Google reCAPTCHA to block spam. It runs on pages of the website and sends Google your IP address and browser details. The website’s fonts are served from our own server, so loading them sends nothing to Google. When you fill in a form on the website (for example contact, free trial, webinar or Audit Circle), we receive what you enter, keep it in the website’s system and may add your email address to our mailing tool (MailerLite) so that we can answer you and send what you asked for.
4. Who receives personal data
We share personal data only with service providers that help us run DocMaster, under contracts that require them to protect it: hosting (Microsoft Azure), document storage and AI processing (Google Cloud), sign-in (Clerk), payments (Stripe), product analytics (PostHog), and our email provider for correspondence with us. The service providers, with locations, are listed on our Subprocessors page.
We may also disclose personal data where the law requires it, or to protect our rights, for example to our legal advisers or in a dispute.
5. Transfers outside the EU
We host DocMaster in the European Union. Some providers (such as Clerk and Stripe) may process data in the United States. For those transfers we rely on the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses. Details are on the Subprocessors page.
6. How long we keep data
| Data | How long |
|---|---|
| Account data | While your account exists. Deleted within 30 days after you or your organisation ask us to delete it. |
| Billing records | As long as Latvian accounting and tax law requires. |
| Saved payment card | Stored by Stripe until you ask us to remove it. It stays on file after a cancellation, so that a later subscription can use it. |
| Usage data and job history | While your organisation’s subscription is active. Within 90 days after it ends, we delete file names and job names together with the documents; the rest of the job records (dates, counts, user and organisation IDs) stays as usage statistics. |
| Product analytics | Kept by our analytics provider (PostHog) for up to 7 years, including IP addresses. We delete a person’s analytics data on request. |
| Application and server logs (including IP addresses) | 30 days. |
| Document access audit logs | 400 days (they contain identifiers, not document contents). |
| Support and sales correspondence | Up to 3 years after our last contact. |
Documents uploaded to the service are kept as described in our Data Processing Agreement.
7. Your rights
You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict how we use it;
- receive your data in a portable format;
- object to processing based on our legitimate interests, including product analytics;
- withdraw consent at any time, where processing is based on consent.
To use these rights, write to support@docmaster.ai. We answer within one month.
You can also complain to the Latvian data protection authority, the Data State Inspectorate (Datu valsts inspekcija, www.dvi.gov.lv), or to the authority in your own EU country.
8. Security
We protect personal data with technical and organisational measures that include encryption in transit and at rest, restricted and logged access, and hosting in the EU. More detail is in Annex II of our Data Processing Agreement.
9. Changes
We may update this policy. The date at the top shows the latest version. We will tell customers’ administrators by email about significant changes.