Effective Date: 1 September 2023
Last Updated: 8 September 2026
This Privacy Policy explains how Documentero (“we,” “us,” or “our”) collects, uses, and protects personal information when you use our Software-as-a-Service (SaaS) document generation service, including the web application at app.documentero.com, our REST API, shareable forms, and integrations (together, the “Service”), and when you visit our website.
Documentero acts in two roles:
If you have submitted a form published by a Documentero customer or received a document generated by a Documentero customer, that customer is responsible for the personal data involved. Please direct privacy requests to them. Customer Content shared with us solely to troubleshoot the Service is also processed on the customer's behalf.
We collect and process the following types of data:
User Account Information: When you create an account, we collect your name, email address, login credentials, preferred language, and company or workspace name. Account administrators may add team members, in which case we process the team member's name, email address, and role.
Document Generation Data: When you use our service to generate documents through the application, API, shareable forms, or integrations, we temporarily process the data provided by you for the sole purpose of document generation. The content of this data is determined by you.
Document Templates and Forms: We store document templates, form configurations, and related settings that you create and manage within your account.
Shareable Form Submissions: If you publish a shareable form, people who fill it in may provide their name and email address (where you enable this option) and the form fields you have defined. We process this data on your behalf to generate the document and, where you have configured it, to send a confirmation or the generated document to the submitter and notifications to you.
Activity Logs: We maintain logs of activities related to document generation, including which templates were used, when documents were generated, and which user performed the action.
Billing Information: Payments are processed by our reseller and merchant of record, Paddle. We do not receive or store your card or payment instrument details. We store the subscription and transaction references needed to manage your plan.
Technical and Security Data: When you sign up, log in, or use the API, we process technical data such as IP address, device and browser information, timestamps, and usage counts to secure the Service, enforce limits, and prevent fraud and abuse.
Support Communications: When you contact us by email or through the in-app chat, we process the content of your messages and the contact details you provide.
AI Feature Data: When you actively use an optional AI Feature, the template content, form configuration, prompts, and related context you submit for that action are processed as described under “AI-Assisted Features” below.
We use your data for the following purposes:
Account Management: To create and manage your user account and team, to verify your email address, and to let you reset your password.
Document Generation: To process the data you provide via the application, API, shareable forms, or integrations to generate documents as per your instructions, to store and manage your templates and forms, to make generated documents available to you, and to deliver them where you instruct us to.
Service Operation and Improvement: To maintain activity records, enforce usage limits, troubleshoot the Service, and analyse aggregated usage to improve it.
Billing and Plan Enforcement: To manage your subscription, apply the limits of your plan, and notify you when you approach or reach those limits.
Security and Abuse Prevention: To protect the Service and our users, including rate limiting, preventing fraudulent or duplicate account creation, and investigating misuse.
Service Communications: To send you emails necessary to operate the Service, such as verification, password reset, usage limit alerts, billing receipts (sent by Paddle), and account deletion notices.
Product Updates: To inform account holders about new features, changes to the Service, and related information. You may opt out of such communications at any time by contacting us at support@documentero.com or by using the unsubscribe option where provided.
Support: To respond to your questions and resolve issues.
Legal Compliance: To comply with our legal obligations and respond to lawful requests.
Where we act as a data controller, we rely on the following legal bases under the GDPR:
Where we process Customer Content as a data processor, the legal basis is determined by our customer as the data controller.
We use technical and organisational measures appropriate to the nature of the Service, including:
No method of transmission or storage is completely secure. Please keep your account credentials and API keys confidential and rotate your API key if you suspect it has been exposed.
We retain your data as follows:
Temporary Data: Data provided for document generation is processed for the duration of the generation request and is not retained as a separate dataset. Generated documents are deleted automatically, typically within 24 hours and at the latest within 72 hours; download links expire within 60 minutes.
Document Templates and Forms: We store document templates and form configurations for as long as your account remains active or until you delete them.
Activity Logs: Activity logs (as described in "Activity Logging" above) are retained for usage tracking, statistics, and auditing purposes for up to 12 months.
Technical Logs: Technical infrastructure logs are retained for up to 60 days.
Support Communications: Retained for as long as reasonably necessary to resolve the request, maintain an appropriate business record, or establish, exercise, or defend legal claims.
Product Communications: Account contact details are retained until the account is deleted or you opt out, unless they must be retained for another lawful purpose.
Analytics and Security Data: Retained only for as long as reasonably necessary for analytics, security, fraud prevention, or legal compliance, taking account of the settings and retention periods of the relevant provider.
Account and Billing Information: Retained for as long as your account remains active. Billing records may be retained for longer where required by tax and accounting law; payment records held by Paddle are subject to Paddle's own retention periods.
Account Deletion: You may request deletion of your account from within the application (an active paid subscription must first be cancelled). After confirmation, your account is deactivated and Customer Content is deleted from active systems within 30 days, except where we are required by law to retain information. Data retained in backups, where applicable, remains protected and is deleted through the applicable backup-rotation process.
Under GDPR, you have specific rights regarding your personal data. You can:
Many of these rights can be exercised directly in the application (for example by editing your profile, managing templates and forms, or requesting account deletion). To exercise these rights otherwise, or if you have any questions about your data or this Privacy Policy, please contact us at support@documentero.com. We may need to verify your identity before acting on a request. Where the request concerns Customer Content that we process on behalf of one of our customers, the request should be directed to that customer.
We use the following providers to operate the Service. Providers acting as our processors are contractually required to protect personal data and process it only for the agreed purposes.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Google Cloud | Hosting, authentication, data storage, computing, and technical logging | Account information, templates and forms, temporary generation data and generated documents, activity and technical logs | European Union regions selected by Documentero |
| Brevo | Sending transactional emails (account emails, notifications, and generated documents where you instruct us to send them) and managing our account contact list | Recipient email addresses, message content and attachments; account holder name, email, and language | European Union |
| OpenAI (optional) | Providing optional AI-assisted features (content generation, template editing, document-to-template conversion, form configuration). OpenAI acts as our subprocessor in AI Credits mode and under your own OpenAI agreement in Bring Your Own Key mode. | Template content, form configuration, prompts, and related context you submit when you actively use an AI Feature. No data is sent to OpenAI when AI Features are set to “Disabled”. | United States (transfers under EU Standard Contractual Clauses; API data is not used to train OpenAI's models) |
| Tidio | In-application live chat for support | Chat messages and any details you share in a conversation; technical data collected by the chat widget | European Economic Area (provider entity established in the United States; transfers under Standard Contractual Clauses / EU-U.S. Data Privacy Framework) |
| Google Analytics | Understanding how our website and application are used, in order to improve them | IP address, device and browser information, pages visited, and interactions | European Union / United States (Google LLC is certified under the EU-U.S. Data Privacy Framework) |
Paddle acts as our reseller and merchant of record and processes your payment details (name, email, billing address, tax identifiers, and payment method) as an independent data controller under its own privacy policy. We do not receive your card details.
This list reflects the providers used as of the “Last Updated” date above.
We configure the Google Cloud resources used to host account data, templates, and documents in European Union regions. Some providers listed above may process personal data outside the European Economic Area, in particular in the United States. Where this is the case, we rely on appropriate safeguards under Chapter V GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision (including the EU-U.S. Data Privacy Framework where the recipient is certified). Transfers that result from your own choices — such as using a third-party integration platform, your own AI provider key, or sending generated documents to recipients outside the EEA — are made on your instruction.
Documentero offers optional AI-assisted features (such as content generation, AI-assisted template editing, document-to-template conversion, and form auto-configuration) powered by OpenAI. AI behavior is controlled by an account-level setting with three modes:
Data submitted to OpenAI is used only to perform the requested action and is subject to OpenAI's data processing terms. Under OpenAI's current API terms, API data is not used to train its models. OpenAI processes data in the United States (see “International Data Transfers”). Please do not include personal data in AI prompts beyond what is necessary for the requested action.
You may connect the Service to third-party automation platforms and compatible clients.
Integrations connect to Documentero using your API key and act on your instructions. The data you send to Documentero through an integration is processed in the same way as data you submit directly. The integration platform itself is not a Documentero subprocessor; the data shared with it is subject to the privacy policies and data processing practices of the integrated service. We encourage you to review the privacy policies of the integrated services to understand how they handle your data.
You control which integrations you use and can revoke their access by regenerating your API key.
Our website and application use cookies and similar technologies (such as local storage) for the following purposes:
You can control cookies through your browser settings. Disabling essential cookies may prevent you from using parts of the Service.
The Service is intended for business use and is not directed at children. You must be at least 16 years old to create an account. Customers that collect personal data through shareable forms are responsible for determining whether their forms may be used by children and for obtaining any consent or authorisation required by law. If you believe a child has provided personal data directly to Documentero, please contact us.
If you have questions, concerns, or a request concerning how we process personal data, please do not hesitate to contact us at support@documentero.com.
We may update this Privacy Policy to reflect changes in our data practices, our subprocessors, or legal requirements. The version currently published on this page, identified by its “Last Updated” date, is the current version. We encourage you to review this policy periodically.