Skip to content

Data protection

GDPR and DocPilot practices

A summary of the practices actually in place for data protection — without any claim of absolute compliance. Last updated: September 24, 2026.

This English translation is provided for convenience only; the French version is the only legally binding version.

Scope of this page

This page summarises the practices actually in place in DocPilot (website, web application, mobile application and API) for the protection of personal data.

It does not constitute a certificate of legal compliance, a third-party audit or a regulatory guarantee. For details of the processing, see the privacy policy; for technical measures, see the Security page.

Who is responsible for what?

Two situations coexist, depending on the context:

  • Customer organisation: data controller for the documents, accounts and activities of its users in DocPilot. DocPilot then acts as a processor, within the limits of the contract.
  • DocPilot: data controller for website data (contact form) and for the technical operation of the service (authentication, logging, hosting).

Practices in place

The items below correspond to features or commitments already described in the product and the associated legal pages.

  • Website and applications hosted on cloud infrastructure in the European Union.
  • Multi-organisation isolation: each customer has a dedicated workspace; the active organisation is carried by the authentication session.
  • Role-based access control (RBAC) and scopes (department, domain, document grants) enforced server-side.
  • Write-only audit log for sensitive actions (authentication, documents, workflows, members, permissions).
  • Hashed passwords (Argon2id); client–API communications over HTTPS; files kept in private object storage and accessed via time-limited signed URLs.
  • Choice, per organisation, of authorised OCR / AI engines; DocPilot does not claim to train models on your documents.
  • Public privacy policy, documented processors required for the service, and a soft-deletion process for accounts, memberships and documents in line with the product.

Cookies and analytics

On the marketing website, a consent banner lets you accept or refuse non-essential cookies. Analytics scripts (Google Analytics, Microsoft Clarity, Metricool) are only loaded after acceptance; withdrawing consent stops these scripts and deletes their cookies.

Data-subject rights

Data subjects may request access to, rectification, erasure, restriction or portability of their data, and object to processing based on legitimate interest, under the conditions laid down by the GDPR.

  • For data managed in an organisation’s workspace: first contact that organisation’s DocPilot administrator.
  • A request can also be sent to DocPilot (contact below); a response is provided within one month.
  • Right to lodge a complaint with the CNIL (the French data protection authority).

Read the “Your rights” section of the privacy policy

What DocPilot does not claim

In the interest of transparency, DocPilot does not display absolute compliance without external proof.

  • No ISO, SOC 2 or HDS certification is claimed.
  • No generic regulatory guarantee (“100% GDPR compliant”) is displayed on this website.
  • Each customer remains responsible for its own processing and for how it uses the platform.

Useful documents and links

  • Privacy policy

    Purposes, data processed, retention periods, recipients and rights.

  • Terms of use

    Access to the service, documents, subscriptions and liability.

  • Security

    Authentication, permissions, isolation, storage and audit.

  • Contact

    Form or e-mail for a question or a request.

Contact

For a question about your personal data or our practices: social@docpilot-app.com, or via the contact form.