Privacy Policy
Last updated: 8 August 2026
This policy explains what personal data DocAI processes, why, and the choices you have. DocAI reads documents you upload (using OCR and AI) and turns them into structured, reviewable data. Because you decide what to upload, your documents may contain personal data about you or about other people. Please read sections 4 and 7 carefully.
1. Who we are
DocAI ("the Service") is operated by SYNAIRO SPΓΕKA Z OGRANICZONΔ ODPOWIEDZIALNOΕCIΔ, ul. ZΕota 75A/7, 00-819 Warszawa, Poland ("we", "us"). We act as the controller for the personal data we process to run the Service. Where you upload documents, you decide what they contain; we process that content to provide the Service to you. Contact: privacy@synairo.com. Full company registration details (KRS, NIP) are on our Legal Notice page.
We have not appointed a Data Protection Officer. Privacy and data-protection enquiries can be sent directly to privacy@synairo.com.
2. The data we process
- Account data: your email address, name, and authentication identifiers, managed by our authentication provider, Clerk. DocAI does not store your password.
- Authentication and session data: session tokens and cookies used to keep you signed in and to protect against cross-site request forgery.
- Uploaded documents: the files you upload and everything they contain.
- OCR text and AI results: the text read from your documents, the extracted fields, document type, confidence scores, summaries, and any corrections you make. These are stored only when you save an analysis (see sections 4 and 6).
- Workspace and team data: organisation names, membership, roles, and invitation records (including invited email addresses).
- Sharing data: your share settings and, for public or exported share views, an access log containing the viewer's IP address, browser user-agent, and time of access, used to secure the feature and detect abuse.
- Usage data: per-account analysis, page, and token counters and timestamps, used for service delivery, usage limits, abuse prevention, and (where you have a paid plan) billing.
- Anonymous rate limiting: for pages that can be opened without an account, such as a share link someone sent you, we store a truncated cryptographic hash derived from your IP address, plus a daily counter, to limit request rates and detect abuse. We do not store the raw IP address for this purpose. Analysing a document always requires an account, so this counter never meters document processing.
- API and automation data. If you use the API, we store a hash of your API key (never the key itself) and any webhook endpoints you register together with their delivery logs.
- Technical logs: request identifiers, timestamps, status codes, and error events. Error diagnostics are configured to exclude request bodies and cookies, so your document contents are not sent to our error-monitoring provider.
- Cookies and preferences: your cookie choices, language, and theme. Only strictly necessary cookies are active by default (see section 12).
We do not use web analytics, advertising, or tracking technologies, and we do not sell your personal data.
3. Legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)): providing the analysis you request, account management, workspaces, saved history, and paid plans.
- Legitimate interests (Art. 6(1)(f)): service security, abuse prevention, rate limiting, and error diagnostics.
- Consent (Art. 6(1)(a)): optional cookies, and any future analytics or marketing (neither is active today).
- Legal obligations (Art. 6(1)(c)): accounting and tax records for paid plans.
Where you upload documents containing special categories of personal data (Art. 9) or criminal-offence data (Art. 10), you are responsible for ensuring there is a lawful basis for that processing. See section 7.
4. Your uploaded documents
- You choose which documents to upload, and you are responsible for having the right to process them.
- Uploaded documents may contain personal data, confidential business data, and sometimes special-category data. Only upload documents you are authorised to process.
- When you save an analysis, we store the result and (where document storage is enabled) the uploaded file itself, so you can reopen, share, and export it. Stored files are removed when you delete the record. This is not immediate deletion after analysis.
- You can delete any saved record, or all of your saved documents, at any time (see section 11 and the Data Retention page).
5. AI, OCR, and LLM processing
- OCR converts your document pages into machine-readable text and layout, using an optical-character-recognition service we operate.
- AI analysis sends up to the first three pages of each document to an AI provider to extract, classify, and validate fields, produce a short summary, and locate the source text for each value.
- AI output can be wrong. Extracted values are suggestions for you to review and confirm, not certified data. The Service does not make automated decisions that produce legal or similarly significant effects about you.
- The AI provider is either OpenAI (United States) or OVH AI Endpoints (European Union), as configured by us. Document content is sent to the active provider to produce your result. See our subprocessors list.
- We do not use your documents or extracted data to train AI models. Content processed by a third-party AI provider is handled under that provider's terms; refer to the provider's own documentation for its data-handling and training practices.
6. Workspaces, teams, and sharing
- Workspaces let you collaborate with colleagues. Roles are owner, admin, member, and viewer. Documents you move into a workspace can be viewed by that workspace's members; documents you keep private remain visible only to you.
- Invitations are sent to an email address and expire. Accepting an invitation requires signing in with a verified email that matches the invitation.
- Share links are temporary and revocable. You choose which fields are shared and whether each is shown in full, masked, or hidden; filtering is enforced on the server. Links expire (you choose 1β365 days; default 7) and expired or revoked links stop working.
- A sensitive-data scan can flag likely sensitive values (such as emails, phone numbers, bank/IBAN numbers, tax or national ID numbers, and dates of birth) before you share, so you can redact them.
- Team-only shares are restricted to authenticated workspace members and issue no public link.
7. What to consider before uploading
DocAI can process many document types, including invoices, purchase orders, delivery notes, receipts, forms, contracts, CVs/rΓ©sumΓ©s, bank statements, and identity documents. Some of these can contain sensitive or special-category personal data. The Service is not specifically designed or certified for health, biometric, or other special-category data (GDPR Art. 9); if you process such data you remain responsible for its lawfulness. Use the field-masking and redaction tools to limit what is stored in shared results.
8. Recipients and processors
We share data with service providers strictly to operate the Service, for authentication, AI/OCR processing, hosting and storage, error monitoring, email delivery, and (for paid plans) payments. The current list, with each provider's role and location, is on our Subprocessors page. We may also disclose data to professional advisers or public authorities where required by law.
9. International transfers
Some of our providers are located outside the European Economic Area (EEA), in particular in the United States; others operate in the EU. Where personal data is transferred outside the EEA, we rely on an appropriate safeguard, an adequacy decision (such as the EUβUS Data Privacy Framework, where the provider is certified) or Standard Contractual Clauses. Details for a specific provider are available on request.
10. Data retention
In short: saved analyses and any stored uploaded files are kept until you delete them. There is no time-based automatic deletion by default; your storage is instead bounded by your plan. Account data is kept until your account is deleted. Usage and billing records are kept as long as needed for billing integrity and legal obligations. Technical and security logs are short-lived. Full details are on the Data Retention page.
11. Your rights
You have the right to access, rectify, erase, restrict, or port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You can delete individual saved records, or all of your saved documents, from within the app. For account deletion or any other request, contact privacy@synairo.com. You may also lodge a complaint with your supervisory authority. In Poland, this is the President of the Personal Data Protection Office (Prezes UODO).
12. Cookies and similar technologies
Only strictly necessary cookies are active by default, for authentication, session security, and remembering your cookie choice. We also store your language and theme preferences. The optional "analytics" and "marketing" categories in our cookie settings are currently not active. No such technologies are deployed. You can review and change your choices at any time via Cookie settings in the menu.
13. Security
Data is encrypted in transit. The production database is encrypted at rest by our hosting provider. Stored document objects and their metadata are encrypted at rest with AES-256-GCM using keys managed by our object-storage provider. Access to stored data is restricted to your account and to workspaces you belong to; API keys and share/invitation links are stored only as cryptographic hashes. No online service can guarantee absolute security. More detail is on the Security page.
14. Children
DocAI is intended for business use by adults and is not directed to children. We do not knowingly collect personal data from children.
15. Automated decision-making
DocAI performs automated extraction and classification and presents the results for your review. It does not make automated decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22. A human (you) reviews and decides how to use the output.
16. Changes
We will post any changes to this policy on this page and update the date above. Material changes will be announced in the application.