GDPR Compliance

Your Data
Your Rights

DocuPro is fully compliant with the EU General Data Protection Regulation (GDPR). Here's how we protect your privacy.

Fully GDPR Compliant

Transparency

Clear about what data we collect and why

Security

Encrypted storage and secure processing

Your Control

Access, modify, or delete your data anytime

EU Rights

Full compliance with GDPR requirements

Your GDPR
Rights

Six fundamental rights guaranteed under GDPR

Right to Access

Request a copy of all personal data we hold about you, including documents, account info, and usage logs.

Export your data from account settings or contact us

Right to Rectification

Correct any inaccurate or incomplete personal data we have stored about you.

Update your profile in account settings

Right to Erasure

Request deletion of your personal data ("right to be forgotten"). We'll delete all data within 30 days.

Delete your account from settings or contact us

Right to Restrict Processing

Request that we limit how we process your data while you contest its accuracy or lawfulness.

Contact our privacy team to request restriction

Right to Data Portability

Receive your personal data in a structured, machine-readable format to transfer to another service.

Export as JSON/CSV from account settings

Right to Object

Object to processing of your personal data for direct marketing, research, or other purposes.

Opt out via email preferences or contact us

How We Process
Your Data

Transparent about our data collection and usage practices

Legal Basis for Processing

Contract Performance

We process your data to provide DocuPro services (document creation, storage, e-signatures) as outlined in our Terms of Service.

Legitimate Interests

We analyze usage patterns to improve our platform, prevent fraud, and ensure security - balancing our interests with your rights.

Consent

For marketing emails and non-essential cookies, we obtain your explicit consent, which you can withdraw anytime.

Legal Obligations

We may process data to comply with legal requirements (tax laws, court orders, regulatory requests).

Data We Collect

Account Information

Name, email address, password (hashed), profile picture, and OAuth provider data (Google).

Document Data

Documents you create, templates you use, recipient information, and signatures.

Usage Data

IP address, browser type, device information, login timestamps, and feature usage analytics.

Payment Data

Billing information processed by Paddle (we do not store credit card details).

How We Use Your Data

Service Delivery

Store and process documents, send emails, enable e-signatures, and manage your account.

Platform Improvement

Analyze usage to fix bugs, develop features, and optimize performance.

Communication

Send service-related emails (signature requests, account updates) and marketing emails (with consent).

Security & Fraud Prevention

Monitor for suspicious activity, prevent abuse, and protect against unauthorized access.

International Data
Transfers

How we protect your data when it crosses borders

Data Transfer Safeguards

When we transfer personal data outside the EU/EEA, we ensure adequate protection using Standard Contractual Clauses (SCCs), EU-US Data Privacy Framework, or other approved mechanisms. All third-party processors are GDPR-compliant.

Supabase (Database)

US-based cloud provider with EU data centers available

Standard Contractual Clauses (SCCs), EU-US Data Privacy Framework

Resend (Email)

Email delivery service for document notifications

Standard Contractual Clauses, GDPR-compliant processors

Paddle (Payments)

Payment processor for subscriptions

PCI-DSS certified, GDPR-compliant data handling

How to Exercise
Your Rights

Simple steps to access, modify, or delete your data

1

Self-Service Options

Most actions can be done directly in your account settings: update profile, export data, delete account, or manage email preferences.

2

Contact Our Privacy Team

For complex requests (data restriction, objection to processing), email privacy@docupro.com with your request and account details.

3

We Respond Within 30 Days

We'll verify your identity and respond to your request within 30 days (extendable to 60 days for complex requests).

Questions About GDPR?

Our Data Protection Officer is here to help with any GDPR questions or requests.

Contact Privacy Team