Privacy Policy
1. Scope and roles
This policy explains how Doklavio handles personal data when someone visits the website, creates an account, uses the document editor, joins a team, contacts support or uses the API.
For account administration, security, billing and operation of the service, Doklavio acts as controller. When a customer uploads personal data to create documents, the customer normally decides why and how that data is used; Doklavio then acts as processor under the Data Processing Agreement.
2. Data we handle
- Account data: Google account identifier, name, email address, profile image and authentication records.
- Workspace data: templates, template names, layouts, uploaded assets, previews, sharing settings, team membership and invitation email addresses.
- Billing data: plan, subscription status, usage, Stripe customer and subscription identifiers. Payment-card details are handled by Stripe and are not stored by Doklavio.
- API data: API-key metadata, request identifiers, rate-limit and quota records, template selections and temporary generated output. Complete API secrets are shown once and are not stored.
- Support data: messages and any information voluntarily included in them.
- Technical data: IP address, device/browser details, timestamps, security events and diagnostic logs collected by the service or infrastructure providers.
- Browser data: the strictly necessary local-storage, session-storage and IndexedDB values described in the Cookie Policy.
3. Why data is used
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, templates, teams, subscriptions and requested PDFs | Performance of a contract or steps requested before a contract |
| Secure the service, prevent abuse and investigate incidents | Legitimate interests and, where applicable, legal obligations |
| Process payments, invoices and accounting records | Contract and legal obligations |
| Respond to support and privacy requests | Contract, legitimate interests or legal obligations |
| Send optional marketing | Consent, if this feature is introduced; Doklavio currently does not send marketing email |
4. Document data
CSV and JSON records loaded into the browser editor are used locally and are not saved with cloud templates. A template can contain personal data if the customer deliberately places it in the design or its assets. Images uploaded to the reusable team library are available to active members of that team, so customers must upload only assets they are authorised to share with those members. API input records are processed server-side in memory and are not persisted as input files. Generated API PDFs are stored privately for idempotent replay, become eligible for deletion after 24 hours and are removed by scheduled cleanup.
5. Service providers and transfers
Doklavio uses Google services, including Firebase, Google Cloud, Google Identity and reCAPTCHA Enterprise, for hosting, authentication, storage, security and processing. Stripe processes subscription payments. These providers may process data outside Latvia or the European Economic Area. Where a restricted transfer occurs, Doklavio uses an applicable transfer mechanism such as an adequacy decision or contractual safeguards.
Data may also be disclosed when required by law, to protect users or the service, or as part of a lawful business reorganisation. Personal data is not sold.
6. Retention
Account and workspace data is generally retained while the account exists. Account deletion removes the active account and associated workspace data, subject to technical completion and records that must be retained by law. Billing and transaction records may be kept for statutory accounting and tax periods. Security and diagnostic logs are retained for limited operational periods configured with the relevant provider. Support correspondence is retained only as long as reasonably needed. API-output retention is described above.
7. Your rights
Subject to the GDPR and applicable Latvian law, individuals may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where processing relies on consent. A person may also complain to the Latvian Data State Inspectorate or another competent supervisory authority.
Requests will require reasonable identity verification. Where Doklavio processes content only on a customer's instructions, the request may be referred to that customer as controller.
8. Security
Doklavio uses access controls, tenant isolation, encryption in transit, protected credentials, rate limits, private storage and an isolated document renderer. No service can guarantee absolute security. Users must protect account access and API keys and report suspected compromise promptly.
9. Children
Doklavio is intended for adults and business use and is not directed to children. Accounts must not be created by anyone under 18.
10. Contact and changes
Doklavio is based in Latvia. Legal operator and privacy contact details will be added here when registration is complete. Material changes will be dated and, where required, communicated before they take effect.