GDPR, retention and data residency
How Northdocs handles storage, retention and EU data residency.
Northdocs runs on OVHcloud Frankfurt with EU data residency by default. US residency is not offered. Organization settings show the configured EU region.
Retention
Document retention (Settings → General, default 60 days, maximum 90 days) permanently deletes documents by upload age: files, detections, and extracted page text, in any status. It applies to existing documents if you shorten the window (enforced on the next daily cleanup, not only to new uploads). Cases themselves are not deleted by age. Manual deletes go to Trash for 7 days first; that is separate from age-based retention.
Encryption and audit
Enterprise organizations can optionally enable per-document envelope encryption under Settings → Organization, and optionally wrap the organization key with Azure Key Vault BYOK.
All key actions are recorded in an audit log. Firm and above can export the audit log as CSV.
Download the Data Processing Addendum (DPA) at /dpa. Organization admins can accept it electronically or upload a signed PDF under Settings > Compliance.
Subprocessors and AI
Third-party suppliers (subprocessors) are listed at /subprocessors. Optional AI features via OVHcloud AI Endpoints (detection, Magic Redact, identity linking, Prompt Guard names, Outbound Guard names, Conversation Redact speech-to-text, and related assists) can be disabled in organization settings. When disabled, document content, Outlook snippets, clipboard text, and audio are not sent to any AI provider. Conversation Redact audio then needs a WebVTT or SubRip sidecar.
Outbound Guard telemetry (when deployed) stores mailbox, finding counts, destination class, and domains. It does not store message bodies or raw CPR.
See also /privacy, /cookies, /security, and /terms for the full policy set aimed at legal and public-sector buyers.
Related articles
Still need a hand?