Last update: September 30, 2026
This policy explains what personal data DocsAutomator processes, why, on which legal basis, where, and for how long. It also explains your rights and how to use them.
Contents
- 1. Who we are
- 2. Two roles: controller and processor
- 3. Our principles
- 4. What we process, why, and on which legal basis
- 5. Customer content we process as a processor
- 6. Retention periods
- 7. AI features
- 8. AI assistants connected through MCP
- 9. Sub-processors and other recipients
- 10. Cookies and similar technologies
- 11. International transfers
- 12. How we protect data
- 13. Your rights
- 14. Google API data
- 15. Data Processing Agreement
- 16. Changes to this policy
1. Who we are
DocsAutomator UG (haftungsbeschränkt), Pappelallee 78/79, 10439 Berlin, Germany ("DocsAutomator", "we") operates docsautomator.co, its subdomains and web applications, the DocsAutomator API and the DocsAutomator MCP server.
We have not appointed a data protection officer, because the law does not require one for a company of our size.
2. Two roles: controller and processor
We are the controller for the data we need to run our business: your account, billing, support, product emails, security logs and our website. This policy describes that processing in full.
We are a processor for our customers for the content they process with DocsAutomator: the records that fill templates, the templates, the generated documents, the people who sign documents, and the content of conversations with the DocsAutomator Agent. Our customer decides what goes into DocsAutomator and why, and is the controller for it. We process this content only to provide the service, under our Data Processing Agreement (DPA). If your data was in a document that a DocsAutomator customer created or sent, please contact that customer first; we will help them answer you.
3. Our principles
- We collect only what we need to run DocsAutomator.
- We process the content of your documents only to provide the service to you. We do not sell it, use it for advertising, or use it to train AI models.
- You control what we store: you choose which data sources DocsAutomator connects to, and you can set generated documents to expire and delete them at any time.
- We never sell personal data.
4. What we process, why, and on which legal basis
The legal bases are those of Article 6(1) of the General Data Protection Regulation (GDPR): (a) consent, (b) performance of a contract, (c) legal obligation, and (f) legitimate interests.
| Data | Purpose | Legal basis | How long we keep it |
|---|
| Account data: name, email address, password (stored only as a one-way hash), workspace and team membership, sign-up date, last login | Create and secure your account, let you log in, manage teams | (b) contract | Until you delete your account. Other data linked to your account is deleted on request within 30 days (see section 13). |
| Billing data: plan, subscription status, Stripe customer ID. Stripe holds the card details and billing address; we never see full card numbers. | Take payments, issue invoices, meet tax law | (b) contract; (c) legal obligation for invoices and accounting records | For the life of the subscription. Invoices and accounting records are kept for the periods set by German commercial and tax law. |
| Connection data: access and refresh tokens and the granted scopes for Google Drive and Google Docs, Gmail, Microsoft 365, Airtable, Notion, ClickUp and SmartSuite | Read your templates and records and save or send documents, only when you ask for it | (b) contract | Until you disconnect the integration or delete your account |
| Automation settings: automation names, template links, field mappings, email and output settings | Run your automations | (b) contract | Until you delete the automation or your account |
| Transactional emails: your email address, and the content of product, security and billing emails | Run the service and keep you informed about your account | (b) contract | Delivery logs are kept by Postmark for a limited period |
| Marketing emails and newsletters: email address, name | Send product news | (a) consent, or for existing customers (f) legitimate interest in direct marketing for similar services. You can unsubscribe at any time. | Until you unsubscribe |
| Support conversations: messages, name, email, workspace ID | Answer your questions | (b) contract; (f) legitimate interest when you are not a customer | As long as we need them to handle your request, and afterwards for our records |
| Security and error logs: IP address, browser, time, error details | Keep the service secure and working, find and fix errors | (f) legitimate interest in a secure, working service | Error logs 60 days; hosting logs for the limited period set by our hosting provider |
| Product usage events: which features were used and when, linked to your account | Understand how the product is used and improve it | (f) legitimate interest in improving the product | 24 months (see section 6) |
| Onboarding survey answers | Tailor onboarding | (b) contract; (f) legitimate interest | Until you delete your account |
| Partner referral data: if you arrive through a partner link, a Dub cookie (90 days) and, when you sign up, your name and email go to Dub | Credit and pay the partner who referred you | (f) legitimate interest in crediting our partners | Cookie 90 days |
| Internal notifications: when you sign up, change your plan, buy the e-signing add-on, or delete your workspace or account, we post a message with your email address (and for plan changes, your workspace and data sources) to our internal Slack | Let our team follow new sign-ups and account changes | (f) legitimate interest in running our business | As long as the Slack messages are kept in our workspace |
| Onboarding follow-up: a few hours after you sign up, we look up your email address with Apollo.io to find publicly available professional information (name, job title, company, company size, industry, location and LinkedIn profile). We combine it with your onboarding answers and your first steps in DocsAutomator, including your first messages to the DocsAutomator Agent, to decide whether a personal onboarding email could help you. Anthropic's Claude writes a draft of that email. A person on our team reviews every draft and decides whether to send it. | Help new users get started | (f) legitimate interest in helping new users succeed. You can object at any time (section 13). | Until you object or ask us to delete it |
| Website visits | Count visits | (f) legitimate interest. Plausible stores no cookies and no personal data. | Aggregated only |
| Customer content (see section 5) | Provide the service to our customer | We act as processor under Article 28 GDPR. The customer determines the legal basis. | See sections 5 and 6 |
5. Customer content we process as a processor
Record data. DocsAutomator reads the fields of the record you generate from (for example an Airtable record, a Notion page or a Google Sheets row), or receives them through the API, Zapier, Make, n8n or another automation platform, and uses them to fill your template.
Templates. Google Docs templates stay in your Google Drive; we store only the link. Word and PDF templates are stored in our file storage (Cloudflare R2, EU).
Generated documents. Documents can be saved to your own Google Drive or OneDrive. PDF and Word files are also stored in our file storage (Cloudflare R2, EU), so that we can show them in the app, send them by email and give you a download link. Anyone who has a document's download link can open it, so share links only with the people who should see the document. You decide how long we keep these files: each automation has an expiry setting from 5 minutes to 1 year, or no expiry (the default). You can also delete any document. Preview documents are deleted after 7 days. Deleted documents stay in the trash for 30 days and are then permanently deleted.
Run history. For each generation we keep a log so you can review and repeat runs. For runs started through the API or an automation platform, the log includes the data sent with the request. For runs from Airtable, Notion, Google Sheets, Google Forms, ClickUp and SmartSuite, it includes the record ID, not the record values. The log also includes email recipients and subjects. See section 6 for how long we keep it.
Emails you send through DocsAutomator. Recipients, subject and content. They are sent through Postmark, or through your own Gmail or Microsoft account if you connect it.
Electronic signing and acceptance. For each signer or recipient we process the name and email address, the signature, typed name and other field values, the time stamps of each step, the IP address, browser and device information, the approximate location (country, region and city) derived from the IP address, and the consent to sign electronically. We look up the location on our own servers with the DB-IP database; the IP address is not sent to any third party for this. From this data we create an audit trail and a certificate of completion, which are evidence that the document was signed.
Images in your records are processed so they fit the document. When we use Cloudinary for this, the images are deleted there within 30 minutes.
Temporary copies. While a document is generated, the job data sits in our job queue. It is deleted within 24 hours after the job finishes, or 7 days if the job fails.
6. Retention periods
We keep the following data for these periods:
- Run history: the content of each log entry (the data sent with the request) is deleted after 90 days. After that we keep only the metadata: date, automation, status, document name and error messages. Log entries of runs that started a signing or acceptance session are kept with the signing records.
- DocsAutomator Agent conversations: you can delete a conversation at any time. We delete conversations automatically 12 months after the last message. Files attached to a conversation are deleted 90 days after the last message.
- Prompts and files sent before sign-up: if you type a prompt or attach a file in the chat on our website before you create an account, we keep them for up to 1 day and then delete them.
- Signing and acceptance records and audit trails: 10 years after the signing session, so that the signature can be proven.
- Product usage events: 24 months.
- Generated documents, error logs and temporary copies: as described in sections 4 and 5.
We are rolling out the automatic deletion for run history content and the deletion of Agent conversations in the week of September 28, 2026. Until the rollout is complete, run history content and Agent conversations are kept without a time limit, and product usage events are kept for 12 months.
7. AI features
DocsAutomator uses the Claude AI models made by Anthropic. The DocsAutomator Agent runs on AWS Bedrock in the EU. Some smaller features call Anthropic directly.
| Feature | When it runs | What is sent to the AI model | Provider and location |
|---|
| DocsAutomator Agent (the in-app assistant) | When you chat with it | Your messages and attached files, your workspace and automation settings, and the data the Agent reads or sends when you ask it to: sample records from your data source, template text, recipient names and emails, run errors | Amazon Web Services Bedrock, in the EU (primary region Frankfurt, Germany; other EU regions for capacity). In exceptional cases, as a backup, Anthropic directly (USA). |
| AI template generation and editing | When you ask the Agent or the app to create or change a template | Your instructions, logos and reference images, and the text of the template being edited | AWS Bedrock in the EU, or Anthropic directly (USA). Color extraction from a logo and title suggestions use Anthropic directly (USA). |
| Smart field mapping | When you click it | Placeholder names and field names. For Google Sheets with line items across several sheets, up to 3 example values per column. | Anthropic (USA) |
| AI fill and line item suggestions in the preview | When you click them | Placeholder names, the text you type into the context box, and up to 3 values you already entered | Anthropic (USA) |
| AI sample data | When you click it | Document type and field names | Anthropic (USA) |
| Line item group calculations | Automatically, when a total or number format cannot be read with regular rules | The single field value that could not be read | Anthropic (USA) |
Retention and training. AWS Bedrock does not store prompts or outputs and does not use them to train models. Anthropic does not use data sent through its commercial API to train models, and keeps it only for a limited period under its commercial terms. We do not use your content to train AI models.
Your Agent conversations. We store them in our database so you can continue them. See section 6 for how long we keep them. We may read Agent conversations to fix errors and improve the Agent. Access is limited to the people who need it for this.
Legal basis: (b) contract, because you choose to use the feature.
8. AI assistants connected through MCP
You can connect an AI assistant, such as Claude or ChatGPT, to DocsAutomator through our MCP server (mcp.docsautomator.co). The assistant signs in with OAuth or with your API key, and can only do what the permissions you grant allow (read, or read and write).
When the assistant uses a DocsAutomator tool, the result goes to the assistant: for example automation settings, sample records from your data source, template text, signing status with signer emails, and document links. That data is then processed by the assistant's provider under your agreement with that provider, not under this policy. Signing status results leave out the personal signing link tokens and the signers' IP addresses, and no tool returns your DocsAutomator API key.
For each tool call we log the tool name, the connected app and the time. We do not log the content of the call. Documents generated through MCP appear in your run history like any other run. Access tokens expire after 1 hour and refresh tokens after at most 90 days. You can revoke access at any time by disconnecting DocsAutomator in your assistant or by creating a new API key.
9. Sub-processors and other recipients
We use the following service providers. Each one processes data only on our instructions.
| Provider | Company | Purpose | Data | Location |
|---|
| Render | Render Services, Inc. | Application servers, background jobs, job queue, PDF conversion | All service data in transit and during processing | Frankfurt, Germany |
| MongoDB Atlas | MongoDB Limited | Database | Account, settings, run history, signing records, Agent conversations | Ireland, EU |
| Cloudflare | Cloudflare, Inc. | File storage (R2), document links, DNS, network security, content delivery, website hosting | Templates, uploaded templates and generated documents (stored in the EU); IP addresses and requests passing through its network | Files stored in the EU; the network is global |
| Hetzner | Hetzner Online GmbH | Hosting of the Word template editor (Collabora Online) | Word templates while you edit them | Germany |
| Amazon Web Services (Bedrock) | Amazon Web Services EMEA SARL | AI model for the Agent and template generation | See section 7 | EU |
| Anthropic | Anthropic, PBC | AI model for the features listed in section 7, and drafts of onboarding emails (section 4) | See sections 4 and 7 | USA |
| Google | Google LLC / Google Cloud EMEA Ltd | Storage of documents generated before our move to Cloudflare (Firebase Storage); Google Drive, Docs and Gmail when you connect them | Older generated documents; your Google content that you choose to use | USA and EU |
| Microsoft | Microsoft Corporation / Microsoft Ireland Operations Ltd | OneDrive, Outlook and Word-to-PDF rendering when you connect a Microsoft account | Generated documents, email content | Region of your own Microsoft 365 tenant |
| Postmark | AC PM LLC | Sending emails: product emails, documents sent by email, signing invitations and notifications | Recipient addresses, email content, attachments | USA |
| Cloudinary | Cloudinary Ltd. | Image processing for documents | Images from your records, deleted within 30 minutes | USA |
| Stripe | Stripe, Inc. / Stripe Payments Europe Ltd | Payments | Billing data, email | USA and EU |
| Intercom | Intercom, Inc. | Support chat and emails | Name, email, user and workspace ID, messages | USA |
| Sentry | Functional Software, Inc. | Error monitoring for the web app | Technical error reports; configured not to send personal data by default | USA |
| Dub | Dub Technologies, Inc. | Partner referral tracking | Referral cookie; name and email at sign-up | USA |
| Apollo.io | Apollo.io, Inc. | Professional information about new users (section 4) | Email address of new users | USA |
| Slack | Slack Technologies, LLC | Internal team notifications (section 4) | Email address, workspace and data sources | USA |
| Plausible | Plausible Insights OÜ | Website statistics without cookies | No personal data | EU |
We tell customers who signed our DPA about new sub-processors in advance, as the DPA describes.
10. Cookies and similar technologies
- A session cookie keeps you logged in. It is necessary for the app to work.
- The support chat (Intercom) sets cookies to remember your conversation. It loads only after you open the chat.
- A partner cookie from Dub (90 days) credits the partner who referred you. It is set only if you arrive through a partner link.
- The booking calendar (Cal.com) and the icon library (Font Awesome) load from their providers, which receive your IP address.
We count website visits with Plausible, which sets no cookies and does not track you across websites.
11. International transfers
Some providers in section 9 are in the USA or can access data from there. For these transfers we rely on the EU-U.S. Data Privacy Framework where the provider is certified under it, and otherwise on the EU Standard Contractual Clauses. Our database and the documents we store stay in the EU.
12. How we protect data
- All connections to DocsAutomator use HTTPS (TLS).
- The whole database and its backups are encrypted at rest with AES-256. Stored files are encrypted at rest with AES-256.
- On top of that, we encrypt the Google, Gmail and Microsoft access tokens inside the application before we store them. Passwords are stored only as one-way hashes.
- Backups run every 6 hours and are kept for 35 days.
- Only the people who need it to run and support DocsAutomator can access personal data. They are bound to confidentiality.
- If a breach affects your personal data, we inform you and, where required, the supervisory authority, without undue delay.
13. Your rights
Under the GDPR you have these rights:
- Access: you can ask which personal data we hold about you and get a copy.
- Rectification: you can have incorrect data corrected.
- Erasure: you can ask us to delete your data. You can delete documents, automations, your workspace and your account in the app. To have all remaining data deleted, such as run history, signing records and Agent conversations, write to us; we complete the deletion within 30 days. We may keep data that the law requires us to keep, such as invoices.
- Restriction: you can ask us to limit how we use your data.
- Portability: you can receive the data you gave us in a common machine-readable format.
- Objection: you can object at any time to processing based on legitimate interest, including the onboarding follow-up and direct marketing.
- Withdrawal of consent: you can withdraw consent at any time. This does not affect processing that happened before.
- Complaint: you can complain to a data protection authority. Ours is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
DocsAutomator makes no decisions about you based solely on automated processing that have legal or similarly significant effects.
14. Google API data
DocsAutomator's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to develop, improve or train generalized AI or machine learning models.
15. Data Processing Agreement
Customers who need a Data Processing Agreement can read and sign ours on our
DPA page.
16. Changes to this policy
We update this policy when our processing changes. The date at the top shows the latest version. We tell customers about important changes by email.