Privacy Policy

Documentero SaaS Service

Effective Date: 1 September 2023

Last Updated: 8 September 2026

Introduction

This Privacy Policy explains how Documentero (“we,” “us,” or “our”) collects, uses, and protects personal information when you use our Software-as-a-Service (SaaS) document generation service, including the web application at app.documentero.com, our REST API, shareable forms, and integrations (together, the “Service”), and when you visit our website.

Our Role: Controller and Processor

Documentero acts in two roles:

  • As a data controller for the personal data we need to run the Service and our website: account and login information, billing and subscription records, usage statistics and activity logs, security and abuse-prevention data, administrative support correspondence, and website analytics. This Privacy Policy describes that processing.
  • As a data processor for the content you place in the Service — your document templates, form configurations, the data you submit for document generation, generated documents, and data provided by people who fill in your shareable forms (“Customer Content”). You (our customer) are the controller of Customer Content, and we process it only to provide the Service to you, under our Data Processing Agreement.

If you have submitted a form published by a Documentero customer or received a document generated by a Documentero customer, that customer is responsible for the personal data involved. Please direct privacy requests to them. Customer Content shared with us solely to troubleshoot the Service is also processed on the customer's behalf.

Information We Collect

We collect and process the following types of data:

  1. User Account Information: When you create an account, we collect your name, email address, login credentials, preferred language, and company or workspace name. Account administrators may add team members, in which case we process the team member's name, email address, and role.

  2. Document Generation Data: When you use our service to generate documents through the application, API, shareable forms, or integrations, we temporarily process the data provided by you for the sole purpose of document generation. The content of this data is determined by you.

  3. Document Templates and Forms: We store document templates, form configurations, and related settings that you create and manage within your account.

  4. Shareable Form Submissions: If you publish a shareable form, people who fill it in may provide their name and email address (where you enable this option) and the form fields you have defined. We process this data on your behalf to generate the document and, where you have configured it, to send a confirmation or the generated document to the submitter and notifications to you.

  5. Activity Logs: We maintain logs of activities related to document generation, including which templates were used, when documents were generated, and which user performed the action.

  6. Billing Information: Payments are processed by our reseller and merchant of record, Paddle. We do not receive or store your card or payment instrument details. We store the subscription and transaction references needed to manage your plan.

  7. Technical and Security Data: When you sign up, log in, or use the API, we process technical data such as IP address, device and browser information, timestamps, and usage counts to secure the Service, enforce limits, and prevent fraud and abuse.

  8. Support Communications: When you contact us by email or through the in-app chat, we process the content of your messages and the contact details you provide.

  9. AI Feature Data: When you actively use an optional AI Feature, the template content, form configuration, prompts, and related context you submit for that action are processed as described under “AI-Assisted Features” below.

How We Use Your Data

We use your data for the following purposes:

  1. Account Management: To create and manage your user account and team, to verify your email address, and to let you reset your password.

  2. Document Generation: To process the data you provide via the application, API, shareable forms, or integrations to generate documents as per your instructions, to store and manage your templates and forms, to make generated documents available to you, and to deliver them where you instruct us to.

  3. Service Operation and Improvement: To maintain activity records, enforce usage limits, troubleshoot the Service, and analyse aggregated usage to improve it.

  4. Billing and Plan Enforcement: To manage your subscription, apply the limits of your plan, and notify you when you approach or reach those limits.

  5. Security and Abuse Prevention: To protect the Service and our users, including rate limiting, preventing fraudulent or duplicate account creation, and investigating misuse.

  6. Service Communications: To send you emails necessary to operate the Service, such as verification, password reset, usage limit alerts, billing receipts (sent by Paddle), and account deletion notices.

  7. Product Updates: To inform account holders about new features, changes to the Service, and related information. You may opt out of such communications at any time by contacting us at support@documentero.com or by using the unsubscribe option where provided.

  8. Support: To respond to your questions and resolve issues.

  9. Legal Compliance: To comply with our legal obligations and respond to lawful requests.

Legal Bases for Processing

Where we act as a data controller, we rely on the following legal bases under the GDPR:

  • Performance of a contract (Article 6(1)(b)) — to provide the Service you have signed up for, including account management, subscription management, billing, and service communications.
  • Legitimate interests (Article 6(1)(f)) — to secure the Service and prevent abuse, to keep usage statistics, to inform account holders about the Service, and to analyse and improve aggregated Service usage where these interests are not overridden by your rights.
  • Consent (Article 6(1)(a)) — where required for analytics cookies or optional communications. You may withdraw consent at any time.
  • Legal obligation (Article 6(1)(c)) — for example to keep accounting records or respond to lawful requests from authorities.

Where we process Customer Content as a data processor, the legal basis is determined by our customer as the data controller.

Data Security

We use technical and organisational measures appropriate to the nature of the Service, including:

  • Secure Access: Access to your workspace is limited to authenticated users you authorise, according to their role.
  • Data Encryption: Data transmitted to and from our service is encrypted using HTTPS, and data is encrypted at rest within our hosting provider's infrastructure.
  • Protected Documents: Generated documents are provided through time-limited download links or the delivery methods you choose. Anyone who receives a valid download link may be able to access the document, so you should keep it confidential.
  • Data Minimisation in Logs: Our operational logs are designed to avoid recording the content of your documents or the full data you submit for generation.
  • Ongoing Security Practices: We maintain change-management, access-control, vulnerability-management, and incident-response practices appropriate to our size and risk profile.

No method of transmission or storage is completely secure. Please keep your account credentials and API keys confidential and rotate your API key if you suspect it has been exposed.

Data Retention

We retain your data as follows:

  1. Temporary Data: Data provided for document generation is processed for the duration of the generation request and is not retained as a separate dataset. Generated documents are deleted automatically, typically within 24 hours and at the latest within 72 hours; download links expire within 60 minutes.

  2. Document Templates and Forms: We store document templates and form configurations for as long as your account remains active or until you delete them.

  3. Activity Logs: Activity logs (as described in "Activity Logging" above) are retained for usage tracking, statistics, and auditing purposes for up to 12 months.

  4. Technical Logs: Technical infrastructure logs are retained for up to 60 days.

  5. Support Communications: Retained for as long as reasonably necessary to resolve the request, maintain an appropriate business record, or establish, exercise, or defend legal claims.

  6. Product Communications: Account contact details are retained until the account is deleted or you opt out, unless they must be retained for another lawful purpose.

  7. Analytics and Security Data: Retained only for as long as reasonably necessary for analytics, security, fraud prevention, or legal compliance, taking account of the settings and retention periods of the relevant provider.

  8. Account and Billing Information: Retained for as long as your account remains active. Billing records may be retained for longer where required by tax and accounting law; payment records held by Paddle are subject to Paddle's own retention periods.

  9. Account Deletion: You may request deletion of your account from within the application (an active paid subscription must first be cancelled). After confirmation, your account is deactivated and Customer Content is deleted from active systems within 30 days, except where we are required by law to retain information. Data retained in backups, where applicable, remains protected and is deleted through the applicable backup-rotation process.

Your Rights

Under GDPR, you have specific rights regarding your personal data. You can:

  • Access and review your data.
  • Correct inaccuracies in your data.
  • Request the deletion of your data (subject to legal requirements and our data retention policies).
  • Object to or restrict the processing of your data.
  • Receive a copy of your data in a structured format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with a supervisory authority, in particular in the EU member state of your residence or place of work. Our lead supervisory authority is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych, UODO) in Poland.

Many of these rights can be exercised directly in the application (for example by editing your profile, managing templates and forms, or requesting account deletion). To exercise these rights otherwise, or if you have any questions about your data or this Privacy Policy, please contact us at support@documentero.com. We may need to verify your identity before acting on a request. Where the request concerns Customer Content that we process on behalf of one of our customers, the request should be directed to that customer.

Service Providers and Other Recipients

We use the following providers to operate the Service. Providers acting as our processors are contractually required to protect personal data and process it only for the agreed purposes.

Provider Purpose Data involved Location
Google Cloud Hosting, authentication, data storage, computing, and technical logging Account information, templates and forms, temporary generation data and generated documents, activity and technical logs European Union regions selected by Documentero
Brevo Sending transactional emails (account emails, notifications, and generated documents where you instruct us to send them) and managing our account contact list Recipient email addresses, message content and attachments; account holder name, email, and language European Union
OpenAI (optional) Providing optional AI-assisted features (content generation, template editing, document-to-template conversion, form configuration). OpenAI acts as our subprocessor in AI Credits mode and under your own OpenAI agreement in Bring Your Own Key mode. Template content, form configuration, prompts, and related context you submit when you actively use an AI Feature. No data is sent to OpenAI when AI Features are set to “Disabled”. United States (transfers under EU Standard Contractual Clauses; API data is not used to train OpenAI's models)
Tidio In-application live chat for support Chat messages and any details you share in a conversation; technical data collected by the chat widget European Economic Area (provider entity established in the United States; transfers under Standard Contractual Clauses / EU-U.S. Data Privacy Framework)
Google Analytics Understanding how our website and application are used, in order to improve them IP address, device and browser information, pages visited, and interactions European Union / United States (Google LLC is certified under the EU-U.S. Data Privacy Framework)

Paddle acts as our reseller and merchant of record and processes your payment details (name, email, billing address, tax identifiers, and payment method) as an independent data controller under its own privacy policy. We do not receive your card details.

This list reflects the providers used as of the “Last Updated” date above.

International Data Transfers

We configure the Google Cloud resources used to host account data, templates, and documents in European Union regions. Some providers listed above may process personal data outside the European Economic Area, in particular in the United States. Where this is the case, we rely on appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision (including the EU-U.S. Data Privacy Framework where the recipient is certified). Transfers that result from your own choices — such as using a third-party integration platform, your own AI provider key, or sending generated documents to recipients outside the EEA — are made on your instruction.

AI-Assisted Features

Documentero offers optional AI-assisted features (such as content generation, AI-assisted template editing, document-to-template conversion, and form auto-configuration) powered by OpenAI. AI behavior is controlled by an account-level setting with three modes:

  • Disabled: AI Features are turned off. No template, document, or form data is sent to OpenAI or any other AI provider.
  • AI Credits: When you use an AI Feature, the data you submit for the requested action is sent to OpenAI for processing using AI credits provided by Documentero.
  • Bring Your Own Key: AI requests are processed through OpenAI using your own API key, under your own OpenAI account and terms. Documentero stores your key in protected server-side storage and transmits the requests on your behalf.

Data submitted to OpenAI is used only to perform the requested action and is subject to OpenAI's data processing terms. Under OpenAI's current API terms, API data is not used to train its models. OpenAI processes data in the United States (see “International Data Transfers”). Please do not include personal data in AI prompts beyond what is necessary for the requested action.

Third-Party Integrations

You may connect the Service to third-party automation platforms and compatible clients.

Integrations connect to Documentero using your API key and act on your instructions. The data you send to Documentero through an integration is processed in the same way as data you submit directly. The integration platform itself is not a Documentero subprocessor; the data shared with it is subject to the privacy policies and data processing practices of the integrated service. We encourage you to review the privacy policies of the integrated services to understand how they handle your data.

You control which integrations you use and can revoke their access by regenerating your API key.

Cookies and Similar Technologies

Our website and application use cookies and similar technologies (such as local storage) for the following purposes:

  • Essential: To keep you signed in, remember your preferences, and secure the Service. These are necessary for the Service to work.
  • Analytics: Google Analytics helps us understand how our website and application are used. You can opt out using the Google Analytics opt-out browser add-on.
  • Support chat: The Tidio chat widget in the application sets cookies to maintain your conversation.
  • Billing: Paddle uses technologies necessary to operate checkout and manage payment transactions.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using parts of the Service.

Children

The Service is intended for business use and is not directed at children. You must be at least 16 years old to create an account. Customers that collect personal data through shareable forms are responsible for determining whether their forms may be used by children and for obtaining any consent or authorisation required by law. If you believe a child has provided personal data directly to Documentero, please contact us.

Questions and Contact Information

If you have questions, concerns, or a request concerning how we process personal data, please do not hesitate to contact us at support@documentero.com.

Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in our data practices, our subprocessors, or legal requirements. The version currently published on this page, identified by its “Last Updated” date, is the current version. We encourage you to review this policy periodically.