Privacy Policy
Last Updated: 24th January 2026
This policy explains how DociShield collects, uses, stores and protects personal data across our platform and services.
1. Introduction
DociShield ("DociShield", "we", "us" or "our") provides a document workflow platform consisting of Secure Sharing, Contracts and Payments, Document Protection and Audit Trails. This Privacy Policy explains how we collect, use, store, share and protect personal data when you use our website, applications and related services (together, the "Services").
By using the Services you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, you should not use the Services. If you have any questions, please contact us.
2. What data we collect
We collect the following categories of personal data:
A. Account and identity data
When you create an account we collect your name, email address, business name, role, country and authentication credentials. We also collect billing details required to process subscription payments.
B. Document and content data
We process the documents you upload to the Services and the metadata associated with them, such as titles, recipients, protection settings, signature fields and payment requirements. We act as a processor of this content on your behalf.
C. Usage and device data
We collect information about how you interact with the Services, including pages viewed, features used, IP address, browser type, device identifiers, operating system and approximate location derived from your IP address.
D. Recipient and signer data
When you send documents through DociShield, we process recipient information necessary to deliver, secure and verify document transactions. This may include recipient names, email addresses, signature metadata, document activity, consent records, timestamps, IP addresses and related audit information. Further information about how recipient information is handled is provided in Section 10 – Document Recipients.
E. Support and communications data
When you contact us we collect the content of your message together with any information you choose to provide so that we can respond and improve the Services.
3. How we collect data
- Directly from you when you create an account, upload documents, configure protection settings or contact us.
- Automatically through cookies, server logs and analytics tools as you interact with the Services.
- From signers and recipients when they view, consent to or sign documents you have sent through Secure Sharing or Contracts and Payments.
- From integration partners such as our payment processor when you take payment through Contracts and Payments.
4. Purposes of processing
- To provide and operate the Services, including Secure Sharing, Contracts and Payments, Document Protection and Audit Trails.
- To authenticate users, manage subscriptions and process payments.
- To enforce the document protection rules you configure and to generate tamper-evident audit trails.
- To communicate with you about account activity, security events and product updates.
- To improve the Services, diagnose technical issues and protect against abuse, fraud and security threats.
- To comply with our legal, regulatory and contractual obligations.
- To record document activity and maintain verifiable audit trails that protect the integrity of document transactions.
5. Lawful basis for processing
Where the GDPR or equivalent legislation applies, we rely on the following lawful bases:
Depending on how the Services are used, DociShield acts either as a data controller or as a data processor on behalf of its customers.
- Performance of a contract: to deliver the Services you have requested.
- Legitimate interests: to secure the Services, prevent fraud, generate audit trails and improve our product, balanced against your rights and interests.
- Legal obligation: to comply with applicable laws, regulations and lawful requests.
- Consent: where you have explicitly opted in, for example to receive marketing communications.
6. Data sharing and disclosure
We do not sell your personal data. We share personal data only where necessary to provide the Services or to comply with the law:
- Service providers and sub-processors that host our infrastructure, deliver email, process payments (such as Stripe) and provide analytics, under written data processing terms.
- Recipients of documents you send through the Services, who will see the document content and the information you choose to include.
- Regulators, law enforcement and other authorities where required by law or to protect the rights, property or safety of DociShield, our customers or others.
- Successors in interest in the event of a merger, acquisition or restructuring, subject to equivalent privacy protections.
7. Cross-border data transfers
DociShield operates globally. Personal data may be transferred to and processed in countries other than the country in which it was collected. Where we transfer personal data outside your country we put in place appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, to ensure your data continues to be protected.
8. Data retention
We retain personal data only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce our agreements and preserve the integrity of completed document transactions. Certain audit records may be retained where reasonably necessary to establish, exercise or defend legal claims or satisfy applicable legal requirements.
9. Data security
We employ industry-standard technical and organizational measures to protect your data, including AES-256 encryption at rest, TLS 1.2 or higher in transit, role-based access controls, logging and monitoring. Document Protection rules you set are enforced technically at the platform layer.
No system can guarantee perfect security. If we become aware of a security incident affecting your personal data we will notify you in accordance with applicable law.
10. Document Recipients
When a DociShield customer sends you a document through the Services, we process certain personal data about you in order to deliver the document, facilitate the requested transaction, maintain the integrity of the document workflow and provide a verifiable audit trail.
Information we collect
Depending on how you interact with a document, we may collect:
- Your name and email address.
- Your IP address and approximate location derived from your IP address.
- Device, browser and operating system information.
- The dates and times you receive, open, view, acknowledge, sign, decline or complete a document.
- Signature metadata, consent records and authentication information where applicable.
- Payment-related events where payment forms part of the document workflow. Payment processing is performed by our payment provider and DociShield does not store full payment card details.
- Technical logs and audit information necessary to operate, secure and verify the transaction.
Why we collect this information
Recipient information is collected to:
- Deliver documents to their intended recipient.
- Verify document delivery and recipient activity.
- Maintain tamper-evident audit trails.
- Protect both senders and recipients by creating a verifiable record of the transaction.
- Detect and prevent fraud, misuse and unauthorised access.
- Comply with applicable legal and regulatory obligations.
Audit Trail
DociShield maintains an audit trail for documents processed through the platform.
Depending on the workflow, the audit trail may include recipient names, email addresses, timestamps, IP addresses, browser and device information, signature events, payment events and other document activity necessary to verify the integrity of the transaction.
The sender of the document may access this audit trail for documents they have sent to verify document activity, support compliance requirements and maintain transaction records.
Data retention
Recipient information forms part of the document history and audit trail associated with a transaction.
We retain this information only for as long as reasonably necessary to provide the Services, comply with applicable legal obligations, resolve disputes, enforce our agreements and preserve the integrity of completed document transactions.
Retention periods may vary depending on the customer's subscription, document settings and applicable legal requirements.
Your rights
Where DociShield processes recipient information on behalf of the document sender, that sender may be the controller of your personal data.
If you wish to exercise your privacy rights regarding information contained within a document transaction, you may contact either the document sender or DociShield using the contact details provided in this Privacy Policy. We will assist where required under applicable law.
11. User rights
Subject to applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data.
- Object to or restrict certain processing activities.
- Receive a portable copy of data you have provided to us.
- Withdraw any consent you have previously given.
Additional information relating specifically to the rights of document recipients is provided in Section 10 – Document Recipients.
To exercise any of these rights, please contact us. We will respond within the time frames required by applicable law.
13. Buyer data and seller responsibility
When you use Contracts and Payments to collect signatures and payment from your customers, you act as the controller of the personal data you collect from those customers and DociShield acts as a processor on your behalf.
You are responsible for ensuring you have the lawful basis to collect and process that personal data, for providing your own privacy notice to your customers and for handling any rights requests they make to you. We will assist where required by applicable law.
14. Children's Privacy
DociShield is designed for business and professional use and is not intended for children under the age required by applicable law to provide consent for the processing of personal data. We do not knowingly collect personal information directly from children through our Services. If we become aware that personal information has been collected in error, we will take reasonable steps to delete it.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Services or applicable law. When we make material changes we will update the "Last Updated" date at the top of this page and, where appropriate, notify you through the Services or by email.
16. Contact and complaints
If you have questions about this Privacy Policy or how DociShield processes personal data, please contact us using the contact details provided on our website.
You also have the right to lodge a complaint with your local data protection authority.
Questions about this policy? Contact us.
Contact us