Privacy Policy

Last updated: March 4, 2026

DOKit, LLC ("DOKit," "we," "our," or "us") is committed to protecting your privacy and ensuring you have a positive experience when using our document processing platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our platform, or engage with our services.

Please read this Privacy Policy carefully. By accessing or using DOKit, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our services.

1. Information We Collect

We collect information in several ways depending on how you interact with our services:

1.1 Information You Provide Directly

Account Registration: When you create an account, we collect your name, email address, phone number (optional), company name, job title, and billing information (processed through our payment processor).

Profile Information: Information you add to your profile, such as a profile photo, department, or role within your organization.

Communications: When you contact us for support, request a demo, or communicate with us via email, phone, or chat, we collect the content of those communications along with your contact information.

Survey and Feedback: Information you provide when responding to surveys, questionnaires, or feedback requests.

1.2 Customer Data (Documents and Content)

Uploaded Documents: Documents, files, images, and other content you upload to DOKit for processing. This may include sensitive information depending on your use case.

Processed Output: The extracted data, structured information, summaries, and analysis results generated from your documents.

Workflow Configurations: Custom templates, extraction schemas, rules, and workflow configurations you create within the platform.

1.3 Information Collected Automatically

Device Information: Hardware model, operating system version, unique device identifiers, browser type and version, and mobile network information.

Log Data: IP address, access times, pages viewed, links clicked, and the page you visited before navigating to our services.

Usage Data: Features used, documents processed, processing statistics, error logs, and performance data.

Location Information: General location based on IP address (country/region level only).

1.4 Information from Third Parties

Single Sign-On Providers: If you authenticate using a third-party service (e.g., Google, Microsoft), we receive basic profile information from that service.

Integration Partners: If you connect DOKit to other services, we may receive data from those integrations as necessary to provide the requested functionality.

2. How We Use Your Information

We use the information we collect for the following purposes:

2.1 Providing and Improving Our Services

  • To create and manage your account
  • To process your documents and deliver extraction results
  • To provide customer support and respond to inquiries
  • To personalize your experience and remember your preferences
  • To analyze usage patterns and improve our platform
  • To develop new features and services
  • To monitor and maintain the security and integrity of our services

2.2 Communications

  • To send transactional emails (account verification, password reset, processing notifications)
  • To send service announcements and updates
  • To send marketing communications (with your consent, where required)
  • To respond to your comments, questions, and requests

2.3 Legal and Safety

  • To comply with applicable laws and regulations
  • To enforce our Terms of Service and other agreements
  • To protect the rights, privacy, safety, or property of DOKit, our users, or others
  • To detect, prevent, or address fraud, security, or technical issues

3. How We Share Your Information

We do not sell your personal information. We may share information in the following circumstances:

3.1 Service Providers

We engage third-party companies and individuals to perform services on our behalf, such as:

  • Cloud Infrastructure: Amazon Web Services (AWS) for hosting, storage, and computing. AWS has signed a Business Associate Agreement (BAA) with us for HIPAA compliance.
  • AI Processing: OpenAI for document analysis and extraction. OpenAI operates under a HIPAA-compliant agreement and does not use customer data for training.
  • Payment Processing: Stripe for processing payments. Stripe is PCI-DSS compliant and processes payment information directly.
  • Email Services: For transactional and marketing emails.
  • Analytics: To understand how our services are used (anonymized/aggregated data only).

All service providers are contractually obligated to protect your information and use it only for the purposes we specify.

3.2 Business Transfers

If DOKit is involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

3.3 Legal Requirements

We may disclose information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas, government requests). We will attempt to notify you before disclosing your information unless prohibited by law.

3.4 With Your Consent

We may share information with third parties when you have given us explicit consent to do so.

3.5 Aggregated or De-identified Data

We may share aggregated or de-identified information that cannot reasonably be used to identify you for research, analysis, or other purposes.

4. Data Security

We implement comprehensive security measures to protect your information:

  • Encryption: AES-256 encryption at rest for all stored data; TLS 1.3 encryption for all data in transit
  • Infrastructure: AWS infrastructure deployed in private VPC subnets with no direct public internet access
  • Access Controls: Role-based access control (RBAC), principle of least privilege, multi-factor authentication
  • Monitoring: Continuous security monitoring, intrusion detection, and logging
  • Key Management: AWS Key Management Service (KMS) with automatic key rotation
  • Employee Training: Regular security awareness training for all employees
  • Incident Response: Documented incident response procedures and breach notification protocols

While we implement these safeguards, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continually work to protect your information.

5. Data Retention

We retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Account Information: Retained while your account is active and for a reasonable period afterward for legal and business purposes
  • Customer Data (Documents): Retained according to your configured retention settings (7-90 days by default). Zero-retention mode available for sensitive workflows where documents are deleted immediately after processing.
  • Processing Output: Retained according to your configured settings or until you delete it
  • Audit Logs: Retained for compliance purposes (typically 1-7 years depending on regulatory requirements)
  • Billing Records: Retained for 7 years for tax and accounting purposes

You may request deletion of your data at any time, subject to legal retention requirements. Upon account termination, we will delete or anonymize your data within 30 days unless legally required to retain it.

6. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information:

6.1 Access and Portability

You have the right to request a copy of the personal information we hold about you. You can export your data from the platform at any time.

6.2 Correction

You have the right to request correction of inaccurate personal information. You can update most information directly in your account settings.

6.3 Deletion

You have the right to request deletion of your personal information, subject to certain legal exceptions. You can delete your account and associated data through the platform or by contacting us.

6.4 Opt-Out of Marketing

You can opt out of marketing communications at any time by clicking the "unsubscribe" link in any marketing email or by updating your preferences in your account settings. Note that you cannot opt out of transactional communications related to your account.

6.5 Restriction and Objection

You may have the right to restrict or object to certain processing of your personal information.

6.6 Exercising Your Rights

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or sooner if required by law). We may need to verify your identity before processing your request.

7. HIPAA Compliance

DOKit is designed to support HIPAA compliance for customers who process protected health information (PHI):

  • Business Associate Agreement (BAA): We offer BAAs to all customers who process PHI. You must sign a BAA before uploading PHI to DOKit.
  • Technical Safeguards: Encryption, access controls, audit logging, and automatic logoff
  • Administrative Safeguards: Workforce training, security management processes, and contingency planning
  • Physical Safeguards: AWS data centers maintain comprehensive physical security controls
  • Subcontractors: Our subcontractors who may access PHI (AWS, OpenAI) have signed BAAs with us

Contact [email protected] to request a BAA.

8. International Data Transfers

DOKit is based in the United States, and your information is processed and stored in the United States. If you are located outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

By using DOKit, you consent to the transfer of your information to the United States. We take steps to ensure that your information receives an adequate level of protection in the jurisdictions in which we process it.

9. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect and track information and improve our services:

  • Essential Cookies: Required for the platform to function (authentication, security, preferences). These cannot be disabled.
  • Analytics Cookies: Help us understand how users interact with our services. These are optional and can be disabled.
  • Marketing Cookies: Used to deliver relevant advertisements. These are optional and can be disabled.

You can control cookies through your browser settings. Note that disabling certain cookies may affect the functionality of our services.

10. Children's Privacy

DOKit is not intended for use by children under 16 years of age. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe we have collected information from a child under 16, please contact us at [email protected].

11. Third-Party Links

Our services may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party sites you visit.

12. California Privacy Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected, the sources of that information, our purposes for collecting it, and the categories of third parties with whom we share it.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
  • Right to Opt-Out: We do not sell personal information, so this right does not apply.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact us at [email protected] or call us at [phone number to be added].

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last updated" date at the top of this policy
  • Notify you by email (for account holders) or by posting a prominent notice on our website
  • Where required by law, obtain your consent to the changes

We encourage you to review this Privacy Policy periodically to stay informed about our data practices.

14. Contact Us

If you have questions, concerns, or complaints about this Privacy Policy or our data practices, please contact us:

DOKit, LLC

Email: [email protected]

For HIPAA/BAA inquiries: [email protected]

For security concerns: [email protected]

We will respond to all inquiries within 30 days.