Privacy Policy

Last updated: Draft (pending review)

Draft template — not yet reviewed by legal counsel. Do not rely on this text until it is finalized.

This Privacy Policy explains what personal data doxio processes, why, and the rights you have under the GDPR.

1. Who we are

doxio is operated by Matěj Tomeček, a sole trader registered under the Czech Trade Licensing Act (IČO 22186603), with a registered place of business at Fabiánka I 178, Kudlov, 760 01 Zlín, Czech Republic — contact hello@doxio.pro. We are the controller for account data and a processor for the document content you upload on behalf of your organization.

2. Data we collect

Account data (name, email, organization), billing data handled by our payment processor, the documents and signatures you create, and technical logs including IP addresses captured in the audit trail.

3. How we use it

To provide and secure the service, deliver one-time codes and notifications, process payments, and maintain a tamper-evident audit trail. Our legal bases are contract performance and legitimate interest in securing the service.

4. Sharing and sub-processors

We share data only with the sub-processors listed on our Sub-processors page (hosting, payments, email) under appropriate data-processing terms. We do not sell personal data.

5. Your rights

You have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. Contact us using the details on the Contact page to exercise these rights.

6. Data retention

We keep account and document data for as long as your account is active. When you delete your account or organization, a 30-day grace period applies during which the deletion can be cancelled; after it, your document files, unsigned documents, client records and account data are permanently erased. For documents that were signed, we retain a reduced set of signing evidence — the signer's name and e-mail address, the IP address and browser identifier used to sign, and the share recipient's name and e-mail address — together with the tamper-evident audit log, for 7 years from that date, so the signature can be evidenced if disputed; after the 7-year period this evidence is permanently erased as well. Secrets are stored only as hashes and access is least-privilege.

7. Your rights as a data subject

Under the GDPR you have the right to access your personal data, to have inaccurate data rectified, to have your data erased, to restrict or object to processing, and to data portability. Account owners and admins can export their organization's data (including documents and the audit log) as a ZIP from the account settings, and can schedule account or organization deletion there. For any other request, contact us using the details on the Contact page; we respond within the statutory time limits.

8. Recipients and signers

People who receive or sign a document are not account holders, so they cannot self-serve a data request through the app. If you are a signer and wish to access or erase your personal data, contact our data protection contact (DPO) using the details on the Contact page, or ask the organization that sent you the document (the controller of that content). We will assist the controller in honouring valid requests, subject to the audit-retention obligations above.