Privacy Policy
Last updated: 31 August 2026
1. Who we are
Northdocs ApS (“Northdocs”, “we”, “us”) provides an EU-native document redaction and pseudonymization service for law firms, municipalities, in-house counsel, and other professional teams. Cases / Redact is the primary product. Conversation Redact, Outbound Guard, and Prompt Guard are part of the same Service. This Privacy Policy explains how we process personal data when you visit our websites, create an account, or use the Service.
2. Data controller and processor
Account and billing data. Northdocs is the data controller for account registration, authentication events, organization membership, billing/subscription metadata, support tickets you open with us, and website telemetry needed to operate the marketing site and app.
Customer documents. For documents you upload and process through the Service (and detections, review state, outputs, related case metadata, Conversation Redact audio and transcripts, and Outbound Guard telemetry when deployed), your organization is the controller (or processor acting for a controller) and Northdocs is the processor under a Data Processing Addendum (DPA). Data Processing Addendum (DPA).
3. What we process
Depending on how you use Northdocs, we may process:
- Identity and contact data: name, email address, organization name, role/title.
- Authentication data via our identity provider (Clerk), including session and SSO assertions where configured.
- Billing and plan data: subscription tier, usage/page counts, invoices and payment references handled by Stripe (card numbers stay with Stripe; Northdocs does not store full card numbers).
- Customer content: uploaded files, extracted text, OCR output, detection spans, redaction/pseudonymization decisions, exports, share-link metadata, chat transcripts, and meeting audio you upload for Conversation Redact.
- Technical data: IP address, user agent, approximate security logs, workflow/job status, and diagnostic error reports.
- Support content: messages and attachments you send to support.
- Optional AI inputs: when AI detection is enabled for your organization, limited document text, detection values, Outlook compose snippets, clipboard text (Prompt Guard), or audio for speech-to-text may be sent to OVHcloud AI Endpoints. Administrators can disable AI under organization settings. See the Enterprise AI Policy.
- Outbound Guard telemetry (when deployed): mailbox, finding counts, destination class, intent labels, and domains. Message bodies and raw CPR are not stored.
- Prompt Guard: pasted text is processed to strip personal data. Raw pasted text is not stored for the product default; only anonymized counts are audited unless you enable optional history.
- Identity provider and payment processors: Clerk for authentication; Stripe for self-serve checkout and invoices.
4. Purposes and legal bases
We process personal data to:
- Provide, secure, and improve the Service (performance of contract / legitimate interests).
- Authenticate users and manage organizations and seats (performance of contract).
- Bill subscriptions and enforce plan limits (performance of contract / legal obligation).
- Process Customer documents solely on documented instructions (Art. 28 GDPR; see DPA).
- Detect abuse, prevent fraud, and maintain audit trails (legitimate interests / legal obligation).
- Respond to support and compliance requests (performance of contract / legitimate interests).
- Meet legal obligations, including bookkeeping and responding to lawful requests.
- Provide optional Outlook send-time protection (Outbound Guard) on documented instructions, including body-free accountability packs.
Where we rely on legitimate interests, we balance those interests against your rights. You may object as described in section 8.
5. Where data is stored and transferred
Documents and extracted data are stored and processed in the European Union by default on OVHcloud Frankfurt infrastructure. Organization administrators can view the configured data region under Settings → Organization. A United States residency option is not offered at this time.
Some subprocessors (notably Clerk for identity and Stripe for payments) may process data outside the EEA. Transactional email uses Scaleway TEM in the EU. Optional AI detection uses OVHcloud AI Endpoints in the EU. Where required, we use Standard Contractual Clauses and other appropriate safeguards. See our Subprocessors register and DPA. Subprocessors · Data Processing Addendum (DPA).
6. Retention
Documents and their extracted data are automatically deleted after your organization’s configured retention period (60 days by default, maximum 90 days; cases may shorten). Audit logs are kept longer for security and accountability, typically up to the period required for dispute resolution and legal compliance.
Account and billing records are retained for the life of the customer relationship and for statutory bookkeeping periods thereafter. Support tickets are retained as needed to resolve your request and improve the Service.
8. Your rights
Subject to applicable law (including the GDPR), you may request access, rectification, erasure, restriction, portability, and object to certain processing, and you may withdraw consent where processing is consent-based. You also have the right to lodge a complaint with a supervisory authority (in Denmark: Datatilsynet).
9. Security
We apply technical and organizational measures appropriate to the risk, including TLS, encryption at rest for document storage, tenant isolation, RBAC, audit logging, retention controls, and fail-closed export checks. More detail is in our Security Overview. Security Overview.
11. Children
The Service is directed at professional organizations and is not intended for children under 16. We do not knowingly collect account data from children.
12. Changes
We may update this policy from time to time. Material changes will be indicated by updating the “Last updated” date and, where appropriate, notifying organization administrators.