GDPR — General Data Protection Regulation
Última atualização: 05 de abril de 2026
Doc.ai is committed to complying with the General Data Protection Regulation (EU) 2016/679 (GDPR), which governs the processing of personal data of individuals in the European Economic Area (EEA). This document describes how we apply GDPR principles to our operations.
1. Data Controller
Controller: Doc.ai Tecnologia Ltda.
Data Protection Officer (DPO): Available at dpo@docai.com.br
The DPO is responsible for overseeing the data protection strategy, ensuring compliance, and serving as the contact point for data subjects and supervisory authorities.
2. Legal Bases for Processing (Art. 6 GDPR)
We process personal data under the following legal bases:
- Performance of a contract (Art. 6(1)(b)): Data necessary to provide Doc.ai platform services, including document generation, template management, and digital signature processing;
- Consent (Art. 6(1)(a)): For marketing communications and optional features;
- Legitimate interests (Art. 6(1)(f)): For platform improvements, analytics, fraud prevention, and security;
- Legal obligation (Art. 6(1)(c)): To comply with tax, accounting, and regulatory requirements;
- Vital interests (Art. 6(1)(d)): When necessary to protect the vital interests of the data subject.
3. GDPR Principles (Art. 5)
- Lawfulness, Fairness and Transparency: We process data lawfully and transparently;
- Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes;
- Data Minimisation: We collect only what is necessary for the intended purposes;
- Accuracy: We take reasonable steps to keep personal data accurate and up-to-date;
- Storage Limitation: Data is retained only as long as necessary for its purpose;
- Integrity and Confidentiality: We implement appropriate security measures;
- Accountability: We demonstrate compliance with GDPR requirements.
4. Data Subject Rights (Chapter III GDPR)
As a data subject under GDPR, you have the following rights:
- Right of Access (Art. 15): You can request a copy of your personal data;
- Right to Rectification (Art. 16): You can request correction of inaccurate data;
- Right to Erasure / "Right to be Forgotten" (Art. 17): You can request deletion of your data under certain conditions;
- Right to Restriction (Art. 18): You can request limitation of processing;
- Right to Data Portability (Art. 20): You can request your data in a structured, machine-readable format;
- Right to Object (Art. 21): You can object to processing based on legitimate interests;
- Right not to be subject to Automated Decision-making (Art. 22): You can request human review of automated decisions;
- Right to Withdraw Consent (Art. 7(3)): You can withdraw consent at any time.
To exercise your rights, send a request to dpo@docai.com.br. We will respond within 30 days as required by GDPR. If we need an extension, we will inform you within the initial 30-day period.
5. Data Processed
| Category | Data | Purpose | Legal Basis | Retention |
|---|---|---|---|---|
| Account | Name, email | Authentication & identification | Contract | Account lifetime + 5 years |
| Company | Name, tax ID, address | Billing & invoicing | Legal obligation | 5 years after contract end |
| Payment | Card data (via Stripe) | Payment processing | Contract | Managed by Stripe |
| Documents | Templates & document content | Service delivery | Contract | Account lifetime + 30 days |
| Technical | IP, access logs, browser | Security & analytics | Legitimate interest | 90 days |
6. International Data Transfers
Some of our service providers (such as Stripe, cloud infrastructure providers, and digital signature services) may process data outside the EEA. In these cases, we ensure that data is transferred based on:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (Art. 46(2)(c));
- Adequacy decisions by the European Commission where applicable (Art. 45);
- Binding Corporate Rules where applicable (Art. 47).
7. Data Protection by Design and Default (Art. 25)
Doc.ai implements data protection principles from the design stage of our platform:
- Data minimisation in all collection points;
- Pseudonymisation and encryption where appropriate;
- Default privacy settings (minimal data exposure);
- Access controls based on the principle of least privilege;
- Regular privacy impact assessments.
8. Data Protection Impact Assessment (DPIA) — Art. 35
Doc.ai conducts Data Protection Impact Assessments for processing operations that are likely to result in high risk to the rights and freedoms of data subjects, particularly when using new technologies or processing special categories of data at scale.
9. Data Breach Notification (Art. 33-34)
In the event of a personal data breach, Doc.ai will:
- Notify the relevant Supervisory Authority within 72 hours of becoming aware of the breach (Art. 33);
- Communicate the breach to affected data subjects without undue delay when the breach is likely to result in high risk (Art. 34);
- Document all breaches, including their effects and the remedial action taken.
10. Sub-processors
We engage the following categories of sub-processors:
- Stripe — Payment processing (PCI DSS compliant);
- Clicksign / ZapSign / Autentique / DocuSign — Digital signature services;
- Google — Cloud infrastructure and Drive integration;
- Cloud hosting providers — Data storage and computing.
All sub-processors are bound by Data Processing Agreements (DPAs) that ensure GDPR compliance.
11. Cookie Policy
We use cookies in accordance with the ePrivacy Directive and GDPR:
- Essential cookies: Required for platform functionality (authentication, session management). These cannot be disabled;
- Analytical cookies: Used to understand platform usage and improve the service. These require your consent.
We do not use third-party advertising or tracking cookies. You can manage your cookie preferences through the cookie consent banner displayed on first visit.
12. Contact & Supervisory Authority
To exercise your rights, ask questions, or file a complaint regarding data processing:
- DPO Email: dpo@docai.com.br
- General Privacy: privacidade@docai.com.br
- Supervisory Authority: You have the right to lodge a complaint with your local Data Protection Authority (DPA). For EU residents, you can find your local DPA at edpb.europa.eu
13. Changes to This Policy
This GDPR compliance document may be updated periodically. Significant changes will be communicated to affected data subjects via email or through the platform. The "Last Updated" date at the top of this page indicates the most recent revision.
