Skip to content

Privacy

Privacy policy

What DocPilot and its mobile application do with your data, and how to exercise your rights. Last updated: September 25, 2026.

This English translation is provided for convenience only; the French version is the only legally binding version.

1. Who is responsible?

DocPilot publishes the DocPilot document management platform (website, web application, “DocPilot Mobile” mobile application and API).

For its users’ documents and accounts, each customer organisation is the data controller; DocPilot acts as a processor, within the limits of the contract between them. DocPilot is the data controller for website data (contact form) and for the technical operation of the service.

2. What data is processed?

  • Account: first name, last name, business e-mail address, organisation, role and permissions. The password is never stored in plain text.
  • Documents: uploaded files (PDFs, images, photos taken from the mobile application), e-mails received at the organisation’s intake address, recognised text (OCR), extracted information and record metadata.
  • Activity: approval decisions, comments, questions asked to the assistant, audit log (user, action, date).
  • Technical: IP address, request identifier, error logs, application version. On mobile, an installation identifier and, if notifications are enabled, a notification token.
  • Website: contact form fields (name, e-mail, company, message).

3. Mobile application

  • Camera: used only when you photograph a document. Photos are sent to your organisation and are not stored elsewhere on the phone.
  • Photos and files: the system picker is used; the application does not access your gallery or your files beyond what you select.
  • Notifications: when enabled, the notification token is sent to Firebase Cloud Messaging (Google) to deliver alerts.
  • Local storage: session tokens are kept in the phone’s secure storage; a read-only cache of recent approvals, documents and notifications is kept for offline viewing. This data is deleted on sign-out and on uninstallation.
  • No advertising SDK and no behavioural tracking tool is included.

4. Why?

  • To provide the service: intake, recognition, extraction, approval, search and viewing of documents.
  • To secure the service: authentication, organisation isolation, audit log, abuse prevention.
  • To respond to requests sent via the contact form.
  • To comply with DocPilot’s legal obligations.

This processing is based on the performance of the contract with the customer organisation, on DocPilot’s legitimate interest in securing its service, and on your request when you contact us.

5. Recognition and extraction by DocpilotAI

The text and information in a document are extracted by OCR engines and language models. Each organisation chooses the authorised engines and providers in its settings. Documents are not used to train models.

6. Who has access?

  • Members of your organisation, according to their rights (roles, departments).
  • DocPilot’s technical teams, for operations and support, under a duty of confidentiality.
  • Processors required for the service: hosting in the European Union, e-mail delivery, mobile notifications, OCR engines and models chosen by your organisation.

Data is neither sold nor transferred to third parties for commercial purposes.

7. How long?

  • Documents, records and audit logs: for the duration of the organisation’s contract, then deleted or returned at its request.
  • Accounts: for as long as the user is active in the organisation.
  • Technical logs: twelve months at most.
  • Contact form: twelve months at most after the last exchange.

8. Cookies

The website uses strictly necessary cookies (language, security, remembering your choice) which cannot be disabled.

With your consent, analytics cookies (Google Analytics, Microsoft Clarity for click maps and anonymised session replays) and marketing cookies (e.g. Metricool) may be set. Your choice is stored in a “dp_consent” cookie (13 months) shared with the app.docpilot-app.com area, which applies the same analytics (Google Analytics only, with no document content). You can accept, refuse or customise these categories at any time from the Cookies page.

Manage my cookie preferences

9. Your rights

You may request access to, rectification, erasure, restriction or portability of your data, and object to processing based on legitimate interest.

For data managed by your organisation, first contact its DocPilot administrator. You can also write to DocPilot at the address below; we respond within one month. You have the right to lodge a complaint with the CNIL (the French data protection authority).

10. Deleting your account and data

You can delete your account from the mobile application: Profile > Delete my account, then confirm with your password. Your personal information (name, e-mail, photo) is erased immediately and the account can no longer sign in. If you are the only member of your organisation, the organisation is closed and its subscription cancelled; otherwise, another administrator must be appointed before deletion.

Without access to the application, ask your organisation’s administrator for deletion or write to DocPilot stating your e-mail address and your organisation. Audit logs keep an anonymised reference to past actions, for the period set out in the section on retention.

Uninstalling the mobile application erases the local cache and session tokens, but not your account or your organisation’s documents.

11. Security

  • Encrypted communications (HTTPS) between the applications and the API.
  • Organisation isolation at database level.
  • Time-limited session tokens, renewed over a dedicated channel for mobile.
  • Audit log of important actions.

See the security measures in detail

12. GDPR approach

DocPilot describes concrete practices (EU hosting, data-subject rights, documented processors) without claiming absolute compliance or certification. A summary is available on the GDPR page.

See the GDPR page

13. Changes

This policy may change as the service evolves. The date of the last update appears at the top of the page; significant changes are notified to customer organisations.

14. Contact

For any question or request about your data: social@docpilot-app.com.