How DataDoc Ltd collects, uses, shares and protects personal information across our compliance automation platform.
Version: 3.0Last updated: May 2026Effective: May 2026
1. Scope and About This Policy
This Privacy Policy describes how DataDoc Ltd, trading as DataDoc and operated by Privacy Pad ("DataDoc", "we", "us", "our"), collects, uses, discloses and safeguards personal information when you visit our websites (datadoc.uk, privacypad.co.uk), use our compliance automation platform, or otherwise interact with us (collectively, the "Services").
This Policy does not apply to: (a) third-party applications, websites or services that integrate with the Services; or (b) Customer Data that you or your organisation upload into the platform for processing — that data is governed by the Data Processing Agreement ("DPA") between DataDoc and the customer organisation, in respect of which DataDoc acts as processor.
2. Our Role: Controller and Processor
• Controller: for personal information about website visitors, prospects, account holders, billing contacts and support correspondents.
• Processor: for Customer Data that customer organisations upload into the platform for compliance analysis. The customer remains the controller.
For UK GDPR purposes, DataDoc Ltd is established in the United Kingdom. We do not currently meet the threshold requiring appointment of a UK or EU Representative under Article 27, but will appoint one if our processing activities trigger that obligation.
3. Categories of Personal Data We Collect
Identity & contactName, work email, job title, employer, telephone (optional).
BillingBilling contact, VAT number, invoice address, last four digits of card, transaction history. Full card data is processed by Stripe (PCI DSS Level 1).
Customer Data (as processor)Documents, policies, vendor records, RFP content and other materials that you upload. May include personal data of your employees, customers or suppliers.
Support & communicationsMessages sent through the contact form, support tickets, survey responses, recorded preferences.
MarketingEmail engagement (opens, clicks), inferred interests, consent records.
We do not knowingly request special category data (UK/EU GDPR Art. 9) or sensitive personal information (CPRA) and ask that you do not upload such data unless required for a specific compliance use case and a lawful basis exists.
4. How We Collect Personal Data
• Directly from you when you sign up, contact us, upload content, or configure the platform.
• Automatically through cookies, server logs and product analytics when you use the Services (see our Cookie Policy).
• From your organisation when an administrator invites you, assigns roles, or uploads data about you.
• From third parties such as authentication providers (Google OAuth), payment processors (Stripe), and enrichment/marketing partners (limited to publicly available business contact data).
5. Purposes and Lawful Bases (UK / EU GDPR Art. 6)
Provide and operate the ServicesPerformance of a contract
Authenticate users and protect accountsLegitimate interests (security)
Process payments and manage subscriptionsPerformance of a contract; legal obligation
Provide customer supportPerformance of a contract; legitimate interests
Improve product features and develop new onesLegitimate interests (using aggregated/de-identified data wherever possible)
Detect, investigate and prevent fraud, abuse and security incidentsLegitimate interests; legal obligation
Comply with tax, accounting and other legal obligationsLegal obligation
Send service announcements (security, billing, material changes)Performance of a contract; legitimate interests
Send marketing communicationsConsent (or soft opt-in for existing customers under PECR)
Defend legal claimsLegitimate interests; establishment, exercise or defence of legal claims
6. Artificial Intelligence and Automated Processing
The platform uses Advanced AI to analyse uploaded documents, generate policy drafts, assess vendor risk, draft RFP responses and provide recommendations. We have implemented the following safeguards:
• Customer Data and prompts are not used to train third-party foundation models.
• AI outputs are decision-support, not a substitute for human professional judgement; human review is always required before acting.
• We do not carry out solely-automated decision-making producing legal or similarly significant effects within the meaning of UK/EU GDPR Art. 22.
• You may request a human explanation of any AI-generated finding via the in-product "Ask Why" feature or by contacting us.
• Inference processing is carried out via the Lovable AI Gateway and contracted model providers under appropriate confidentiality and data-protection terms.
7. Recipients and Sub-processors
We do not sell or rent personal information. We share personal data only with categories of recipient listed below. All sub-processors are bound by written terms imposing UK/EU GDPR-equivalent obligations.
Web analytics providerAggregate site analytics; no cross-site trackingEU
An up-to-date sub-processor list is available on request from info@privacypad.co.uk. Customers on a paid plan will be notified by email at least 30 days in advance of any new sub-processor that processes Customer Data, with the right to object on reasonable grounds.
We may also disclose information to: (i) professional advisers (lawyers, auditors, insurers); (ii) competent authorities where required by law, court order or to protect rights, property or safety; and (iii) an acquirer or successor in the event of a merger, acquisition, financing or sale of assets, subject to standard confidentiality protections.
8. International Transfers
DataDoc is established in the United Kingdom and primarily processes data within the UK and European Economic Area. Where personal data is transferred outside the UK / EEA, we rely on:
• UK and EU adequacy decisions where available;
• The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;
• The EU Standard Contractual Clauses (Commission Decision 2021/914);
• The UK–US Data Bridge and EU–US Data Privacy Framework where the recipient is certified;
• Supplementary technical measures (encryption in transit and at rest, key management, access controls) where necessary following a transfer impact assessment.
A copy of the relevant transfer mechanism is available on request.
9. Retention
• Account data: for the life of the account, plus 30 days after closure (90 days for inactive trial accounts).
• Customer Data uploaded for analysis: retained per the customer organisation's configured retention; default 24 months from upload, or until deletion is requested.
• Billing records: 7 years to comply with UK tax law.
• Audit and security logs: 12 months.
• Backups: rolling 90-day window; deleted records expire from backups within that window.
• Marketing preferences and suppression lists: retained indefinitely to honour opt-outs.
You may request earlier deletion at any time by emailing info@privacypad.co.uk, subject to legal hold or overriding legitimate interests.
10. Security
We implement appropriate technical and organisational measures aligned with SOC 2 Type II and ISO 27001:2022:
• AES-256 encryption at rest; TLS 1.2+ in transit.
• Role-based access control, least privilege and multi-factor authentication for staff with access to production systems.
• Row-Level Security on every customer-tenanted database table.
• Continuous logging, monitoring and intrusion detection.
• Annual third-party penetration testing and quarterly vulnerability scanning.
• Documented incident response, business continuity and disaster recovery procedures, tested annually.
• Background checks and confidentiality agreements for personnel.
No system is completely secure. We cannot guarantee that data transmitted over the internet will not be intercepted, but we work hard to minimise risk.
11. Personal Data Breach Notification
We will notify the UK Information Commissioner's Office (and other competent supervisory authorities where applicable) of any reportable personal data breach without undue delay and, where feasible, within 72 hours of becoming aware, in line with UK GDPR Art. 33. Where a breach is likely to result in a high risk to the rights and freedoms of individuals, we will also notify affected data subjects and customer controllers without undue delay (Art. 34).
12. Your Rights
Depending on your location, you have rights to:
• Access a copy of the personal data we hold about you;
• Rectify inaccurate or incomplete data;
• Erase data ("right to be forgotten") where conditions are met;
• Restrict or object to processing based on legitimate interests, including profiling and direct marketing;
• Data portability in a structured, machine-readable format;
• Withdraw consent at any time where processing is based on consent;
• Lodge a complaint with a supervisory authority (UK: ICO at ico.org.uk).
We respond to verified rights requests within one calendar month, extendable by up to two further months for complex or numerous requests. We may need to verify your identity before responding. Requests are free of charge unless manifestly unfounded or excessive.
If you are exercising rights in respect of Customer Data uploaded by an organisation, please contact that organisation; we will assist them in responding as their processor.
United States — California Residents (CCPA / CPRA)
In the past 12 months we have collected the categories of personal information described in section 3 for the business purposes in section 5. We have not "sold" or "shared" personal information for cross-context behavioural advertising and we honour the Global Privacy Control (GPC) signal as an opt-out request.
California residents have rights to know, access, delete, correct, opt-out of sale/share, limit the use of sensitive personal information, designate an authorised agent and freedom from retaliation. To exercise these rights, email info@privacypad.co.uk with the subject line "California Privacy Request".
Other US States
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA) and other states with comprehensive privacy laws have similar rights. We extend the access, correction, deletion, portability and opt-out rights described above to all such residents.
13. Marketing and Electronic Communications (PECR)
We send marketing emails to corporate subscribers either with prior consent or under the "soft opt-in" permitted by the Privacy and Electronic Communications Regulations (PECR), where you are an existing customer or have previously expressed interest in similar products. Every marketing email contains a one-click unsubscribe link, and you may withdraw consent at any time without affecting the lawfulness of prior processing.
14. Cookies and Similar Technologies
We use strictly necessary cookies and, with your consent, analytics and preference cookies. We honour Do-Not-Track and Global Privacy Control signals. Full details, including a category-by-category breakdown and consent management, are in our Cookie Policy.
15. Children's Privacy
The Services are intended for business use by individuals aged 18 and over. We do not knowingly collect personal information from children under 16 (or under 13 where applicable, e.g. COPPA in the US). If we become aware that we have inadvertently collected such data, we will delete it promptly.
16. Accessibility and Languages
This Policy is published in English. Alternative formats (large print, screen-reader optimised) are available on request to info@privacypad.co.uk.
17. Changes to This Policy
We may update this Policy from time to time. The "Last updated" and "Version" markers above will reflect the most recent revision. Material changes will be communicated by email and/or in-product notice at least 30 days before they take effect.
Version history:
• v3.0 — May 2026 — Added sub-processor list, AI processing disclosure, expanded US state rights, retention table, breach notification SLA.
• v2.0 — February 2026 — Restructured for UK GDPR, added CCPA section.