Privacy Policy

Effective date: 1 June 2025

1. Who We Are

Dockcert("we", "us") operates the trade document verification platform at dockcert.com. This policy explains what personal data we collect, why we collect it, and how it is used and protected.

2. Data We Collect

We collect the following categories of data:

Account data

Name, email address, password (hashed), organisation name, role. Collected when you create an account.

Document data

Trade documents you upload (PDFs, images), extracted structured data (fields, values, confidence scores), and AI-generated findings. Stored in your workspace and isolated by organisation.

Usage data

Pages visited, features used, shipments created, API calls, error events. Used to improve the Service and for billing purposes.

Billing data

Payment method details are handled by our payment processor (Stripe) and are not stored by Dockcert. We store subscription status and billing history.

Communications

Emails you send to us, feedback submitted in-app, and support conversations.

3. How We Use Your Data

  • To provide, operate, and improve the Service
  • To process your documents and return verification results
  • To send transactional emails (verification results, deadline alerts, team invites)
  • To enforce usage quotas and billing
  • To detect and prevent fraud and abuse
  • To comply with legal obligations (including record-keeping for reference lookups)
  • To respond to support requests

We do not sell your data. We do not use your documents to train AI models without explicit written consent.

4. Legal Basis for Processing (GDPR)

For users in the EEA and UK, our legal basis for processing is:

  • Contract performance — providing the Service you signed up for
  • Legitimate interests — fraud prevention, service improvement, security
  • Legal obligation — reference lookup record-keeping requirements
  • Consent — marketing emails (where applicable, with opt-out)

5. Data Sharing

We share data only with:

  • Supabase — database and authentication (EU data residency available)
  • Cloudflare R2 — document and report storage
  • Anthropic / Google — AI providers processing document content for extraction (no training on your data per their terms)
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Inngest — background job orchestration (event payloads contain shipment IDs, not document content)

All sub-processors are bound by data processing agreements. We do not share personal data with third parties for marketing purposes.

6. Data Retention

We retain account data for as long as your account is active. Document data and findings are retained for the duration of your subscription plus 12 months. Billing records are retained for 7 years for tax purposes. Upon account deletion, personal data is removed within 30 days; anonymised aggregate usage data may be retained indefinitely.

7. Security

We implement technical and organisational measures to protect your data, including encryption in transit (TLS 1.2+) and at rest, row-level security enforcing tenant isolation in the database, and regular access reviews. No system is completely secure; please notify us immediately at privacy@dockcert.com if you discover a security vulnerability.

8. Your Rights

You have the right to:

  • Access a copy of your personal data
  • Correct inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Object to or restrict processing
  • Data portability (export your data in machine-readable format)
  • Withdraw consent where processing is based on consent

To exercise these rights, email privacy@dockcert.com. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (in the UK: the ICO at ico.org.uk).

9. Cookies

We use session cookies to maintain your authenticated state. We do not use third-party advertising cookies. Analytics (PostHog) uses first-party cookies to understand how the Service is used. You may disable cookies in your browser, but this will prevent you from logging in.

10. International Transfers

Our infrastructure is primarily located in the EU and US. When data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses with sub-processors.

11. Changes to This Policy

We may update this policy. Material changes will be notified by email at least 14 days before they take effect. The current version is always available at dockcert.com/privacy.

12. Contact

Privacy enquiries: privacy@dockcert.com
General enquiries: support@dockcert.com