Legal
Privacy Policy
Last updated: 2026-06-17. Questions: hello@docsiv.com. These documents are provided as drafts for integration; have qualified counsel review before reliance.
Introduction
Docsiv (“we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal information in connection with the Docsiv website and services (the “Service”).
This policy applies to visitors to our marketing site, account holders, workspace users, and people who interact with a workspace through a Docsiv client portal or shared document (for example signers and commenters). If you access Docsiv through a client or employer, that organization’s administrator may control certain settings; this policy describes Docsiv’s own practices.
For cookie-specific information, see our Cookie Policy. For our role as a processor when customers use the Service to handle their end users’ data, see our Data Processing Agreement and Subprocessors list.
Who we are
Controller: Docsiv
Contact: hello@docsiv.com
Privacy inquiries: hello@docsiv.com
We handle privacy requests and notices by email at the addresses above.
Personal information we collect
Depending on how you use the Service, we may collect:
- Account and profile: name, email address, password (stored hashed by our authentication provider), avatar, organization or workspace name, handle, role, and preferences (such as theme).
- Authentication: if you sign in with a magic link we process your email address; if you use “Sign in with Google” or another social login, we receive identifiers from that provider as described in their sign-in notice. We use cookies/tokens to keep you signed in.
- Billing and transactions: billing contact details, plan and subscription status, seat counts, AI credit balances, billing country, and limited payment metadata processed by our payment provider. We do not store full card numbers.
- Customer Content you provide: documents, spreadsheets, presentations, designs, whiteboards, invoices, templates, comments, reactions, voice notes, uploaded files, images, audio, prompts, and reference materials you choose to submit, plus any personal data you choose to include inside that content.
- Client and recipient information: when you manage clients or share documents, we process details you enter or that recipients provide, such as client name, email, phone, website, address, and business details, and the identities of people you invite to view, comment on, or sign documents.
- Electronic signature data: for signing workflows we process signer name and email, the signature image or typed signature, consent to use electronic records, verification codes, and an audit trail (timestamps, IP address, and events) used to produce a completion certificate.
- Usage, analytics, and device data: log-derived data such as IP address, approximate location from IP, browser type, device identifiers, pages or features used, timestamps, and diagnostic events. For documents shared through tracked links or portals, we record view and engagement events (such as opens and time viewed) and surface them to the workspace.
- Integrations: if you connect Google Drive, we process an encrypted access token and the content of files you choose to import.
- Support and communications: messages you send us, survey responses, and chat or support thread records.
- Marketing (if applicable): mailing lists, lifecycle onboarding emails, and campaign engagement where you opt in or we have a lawful basis under applicable law.
We do not knowingly collect personal information from children under 16 for the Service. If you believe we have, contact us and we will delete it.
How we use personal information
We use personal information to:
- Provide, operate, secure, and improve the Service, including document creation, editing, AI-assisted features, collaboration, sharing, electronic signatures, invoicing, and analytics.
- Create and manage accounts and workspaces; authenticate users and portal visitors.
- Process payments, manage subscriptions and AI credits, and collect amounts due.
- Generate, store, and deliver electronic signature audit trails and completion certificates.
- Provide document engagement analytics to the workspace that owns a document.
- Provide customer support and respond to requests.
- Send transactional messages (verification, security notices, receipts, signing requests and reminders, comment notifications and digests).
- Send optional product, lifecycle, or marketing communications where permitted; you may opt out via the unsubscribe link or account settings.
- Detect, prevent, and respond to fraud, abuse, security incidents, and technical issues.
- Comply with law, enforce our Terms of Service, and protect rights and safety.
- Analyze usage, including product analytics and performance telemetry, to understand reliability and feature usage (see Cookie Policy).
Lawful bases (GDPR and similar)
Where GDPR or UK GDPR applies, we rely on one or more of:
- Contract: processing necessary to provide the Service you request.
- Legitimate interests: securing the Service, improving features, and analytics that are not overridden by your rights (you may object where applicable).
- Consent: where required, for optional cookies, certain analytics, or marketing.
- Legal obligation: compliance with law, including tax record-keeping and responses to valid legal process.
AI and automated processing
Several features use AI models to generate or transform content, including document generation, in-editor assistance and rewrites, spreadsheet and layout generation, image generation and editing, audio transcription, design critique, layout analysis, and client portal chat.
Personal data you include in prompts, documents, reference materials, images, or audio may be processed by AI systems to generate output. AI requests are routed through OpenRouter or the Vercel AI Gateway to a model provider configured for each feature (for example Anthropic, Google, or OpenAI); the specific provider depends on the configured model. Those providers process the content under their roles as subprocessors as described at Subprocessors, and short-lived prompt caching may be used to improve performance.
AI output may be inaccurate or incomplete, and we do not make legal or other significant decisions about you solely by automated means. You should avoid submitting data you are not permitted to share, and you are responsible for reviewing AI output before relying on it.
Sharing and disclosures
We share personal information with:
- Service providers (subprocessors) that help us operate the Service (hosting, database, authentication, file storage, email delivery, real-time collaboration, payments, analytics, and AI inference and routing). They are bound by contractual obligations. See Subprocessors.
- Other workspace and portal participants as a result of how a workspace uses the Service. For example, if you sign or comment on a document, your name, email, and related activity are visible to the workspace that owns it.
- Professional advisors (lawyers, auditors) under confidentiality.
- Authorities when required by law or to protect rights, safety, or the Service.
- Corporate transactions such as a merger or acquisition, subject to appropriate safeguards.
We do not sell personal information as defined by U.S. state privacy laws, and we do not share it for cross-context behavioral advertising except as disclosed if our practices change with notice.
International transfers
We may process data in the United States and other countries where we or our subprocessors operate. Where required, we use appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms. Contact hello@docsiv.com for more information or a copy of relevant safeguards.
Retention
We retain personal information for as long as needed to provide the Service, comply with law, resolve disputes, and enforce agreements. Documents you delete are held in trash for a limited period and then purged. Signing audit trails and completion certificates are retained to preserve the integrity of signed records. Billing records may be retained longer to meet tax and accounting obligations. Backups may persist for a limited period after deletion. When you close an account or workspace, we delete or de-identify associated personal data within a reasonable period, subject to legal retention requirements.
Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit, database-level access isolation between workspaces (row-level security), access controls, monitoring, and vendor due diligence. No method of transmission or storage is fully secure; we encourage strong passwords and careful configuration of sharing and workspace permissions.
Your rights and choices
Depending on your location, you may have rights to access, correct, delete, port, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights, contact hello@docsiv.com. We may verify your request as permitted by law. Authorized agents may submit requests where applicable law allows. If we process your personal data on behalf of a Docsiv customer (for example because you are that customer’s client, commenter, or signer), we will refer your request to that customer and assist them as their processor.
California residents (CPRA): You may request to know, delete, and correct certain personal information and to opt out of sale/sharing if applicable. We do not sell personal information and do not discriminate for exercising privacy rights.
Cookies and analytics
We use strictly necessary cookies for sign-in and security and, with your consent where required, product analytics to understand usage and performance. You can manage analytics through the cookie preferences available on our site. See our Cookie Policy for details.
Links and third-party sites
Our Service may link to or embed third-party websites and content (for example videos, design embeds, or stock images you choose to use). Their practices are governed by their own policies.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the “Last updated” date. Material changes may require additional notice where required.
Contact
Questions: hello@docsiv.com