Privacy Policy
Your privacy matters. This policy explains what data we collect, why we collect it, and how we protect it — in plain language.
Last updated: May 21, 2026
Our commitment to you
DocumintQ is built on a foundation of trust. We process millions of sensitive documents for legal, financial, and enterprise teams. We take our responsibility seriously: your files are yours, your data is never sold, and we maintain SOC 2 Type II certification to back it up.
1. Information We Collect
Account Information
When you register for DocumintQ, we collect your name, email address, company name (optional), and a hashed password. We never store plaintext passwords.
Files You Upload
PDF files and documents you upload for processing are stored temporarily on our servers using AES-256 encryption. Files are used solely to deliver the requested operation (merge, split, convert, sign, etc.) and are automatically purged from our servers within 24 hours of processing, unless you explicitly save them to your DocumintQ workspace.
Usage Data
We collect information about how you interact with our platform — including the tools used, credit consumption, session timestamps, browser type, IP address, and device type. This data is used to improve our service and ensure platform stability.
Payment Information
Credit card and billing details are handled exclusively by our PCI-DSS compliant payment processor. DocumintQ does not store raw card numbers or CVV codes on our servers.
2. How We Use Your Information
- ✓To provide, operate, and maintain the DocumintQ platform and its 70+ PDF tools.
- ✓To process your file operations and deliver results accurately.
- ✓To manage your account, credit balance, and subscription.
- ✓To send transactional emails (receipts, password resets, usage alerts).
- ✓To detect and prevent fraud, abuse, or unauthorized access.
- ✓To improve our AI-powered features such as Smart OCR and Auto-Tagging.
- ✓To comply with legal obligations and respond to lawful requests.
- ✓To send product updates and promotional content — you may opt out at any time.
3. File Processing & Storage
Temporary Processing
Files uploaded for one-time operations (merge, compress, convert, etc.) are processed in isolated, encrypted environments. They are not read by human staff, not used to train AI models, and not shared with third parties. Files are deleted automatically within 24 hours.
Workspace Storage
Files saved to your DocumintQ workspace are stored with AES-256 encryption at rest and TLS 1.3 in transit. You retain full ownership of your files. You can delete them at any time from your dashboard, and deletion is permanent and irreversible.
Team & Collaboration Features
When you share files or folders with team members, those users gain access only to the specific assets you share. Audit trails record all access and modification events for compliance purposes.
4. Data Security
DocumintQ maintains a comprehensive information security program that includes AES-256 file encryption, TLS 1.3 for all data in transit, SOC 2 Type II compliance, regular third-party penetration testing, role-based access controls (RBAC), multi-factor authentication (MFA) support, and continuous anomaly detection. Despite these measures, no system is completely immune to risk. We encourage you to use a strong, unique password and enable MFA on your account.
5. GDPR & Your Rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):
- ✓Right of Access — request a copy of the personal data we hold about you.
- ✓Right to Rectification — request correction of inaccurate or incomplete data.
- ✓Right to Erasure (“Right to be Forgotten”) — request deletion of your personal data, subject to legal retention obligations.
- ✓Right to Restriction — request that we limit the processing of your data.
- ✓Right to Data Portability — receive your data in a structured, machine-readable format.
- ✓Right to Object — object to processing based on legitimate interests or direct marketing.
- ✓Right to Withdraw Consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at privacy@documintq.com. We will respond within 30 days.
7. Third-Party Services
DocumintQ integrates with carefully vetted third-party services to deliver its features. These include payment processors, cloud infrastructure providers, and email delivery services. All third-party processors are bound by data processing agreements (DPAs) and are prohibited from using your data for any purpose beyond delivering the contracted service. We do not sell, rent, or broker your personal data.
8. Data Retention
- ✓Temporarily uploaded files: deleted within 24 hours of processing.
- ✓Workspace files: retained until you delete them or close your account.
- ✓Account data: retained for the duration of your account, plus up to 90 days after closure for backup/audit purposes.
- ✓Billing records: retained for 7 years to comply with financial regulations.
- ✓Usage logs: retained for 12 months for security and abuse prevention.
9. Children's Privacy
DocumintQ is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact privacy@documintq.com and we will promptly delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date at the top of this page and, for material changes, notify you via email or an in-app notice. Your continued use of DocumintQ after such changes constitutes acceptance of the updated policy.
11. Contact Us
For privacy-related questions, data requests, or to report a concern:
Have questions about this policy? Contact our privacy team