Last updated: 1 September 2025
This page explains how Docoply complies with the UK GDPR and the EU GDPR when we provide our services and operate our website. It should be read together with our Privacy Policy, Data Processing Addendum (DPA), Sub-processors List, and Security page.
Controller: Educational Whiteboards Limited (trading as “Docoply”)
Company number: 14554635
Registered office: 124 City Road, London, England, EC1V 2NX
Primary privacy contact / DPO (or privacy lead): privacy@docoply.com
Supervisory authority (UK): Information Commissioner’s Office (ICO). You have the right to lodge a complaint with the ICO.
EU/EEA representative (if required under Art. 27 GDPR): Details will be published here if appointed.
When we are a Controller: We act as a data controller for data we collect about you when you visit our website, create an account, communicate with us, pay for subscriptions, and receive marketing (where permitted).
When we are a Processor: When customers upload or submit contracts and related documents to be analysed by Docoply, we process that personal data on the customer’s documented instructions and for their purposes. In those cases, the customer is the Controller and Docoply is the Processor under the DPA.
Our current sub-processors and their purposes are listed at /legal/sub-processors.
We rely on one or more of the following lawful bases (UK/EU GDPR Art. 6):
| Category | Purpose | Lawful basis |
|---|---|---|
| Account & service data | Provision of Docoply, customer support | Contract; Legitimate interests (support) |
| Uploaded contracts & attachments (customer content) | Contract analysis & report generation | Contract (Processor role under DPA) |
| Payments & billing | Subscription processing, fraud prevention | Contract; Legal obligation |
| Technical & security logs | Security monitoring, incident response | Legitimate interests; Legal obligation (where applicable) |
| Product analytics (derived, non-essential) | Improve features and UX | Consent (where required); Legitimate interests (strictly necessary analytics) |
| Marketing | Updates, news (opt-in) | Consent (or soft opt-in where permitted) |
Full details appear in our Privacy Policy.
Docoply uses AI models to parse contracts, identify risk patterns, and draft suggested clause rewrites. Outputs are intended to assist (not replace) professional judgement.
Under the UK/EU GDPR, you have the right to:
How to exercise your rights: Email privacy@docoply.com. We will respond within one month (extendable by up to two additional months for complex or numerous requests). We may request verification of identity.
If your data was provided to Docoply by your organisation (our customer) or analysed through our Processor role, please contact your organisation first. We will assist them as required by the DPA.
We use a consent management platform (CMP) to let you control non-essential cookies and similar technologies. You can change or withdraw your consent at any time via the site’s cookie banner or the “Cookie Settings” link.
We share personal data with service providers under contract (sub-processors) to help us operate the service (e.g., hosting, AI inference, analytics, payments, support). See the current list at /legal/sub-processors.
Where data is transferred outside the UK/EEA, we implement appropriate safeguards such as the UK/EU Standard Contractual Clauses (and the UK Addendum where applicable) and, where relevant, transfer risk assessments.
We do not sell personal data.
We apply administrative, technical, and physical measures proportionate to risk, including:
Further details appear on our Security page.
Retention may be extended where necessary to establish, exercise, or defend legal claims or comply with legal obligations.
If we become aware of a personal data breach, we will assess risk and, where required, notify the ICO within 72 hours and affected individuals without undue delay when there is a high risk to their rights and freedoms. Customers will be notified per the DPA.
We maintain Records of Processing Activities (Art. 30) for both our Controller and Processor roles. We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing — including significant changes to AI features, model providers, or data flows.
Docoply is designed for business use and is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, please contact us so we can delete it.
We may update this page to reflect changes in our practices or law. We will post the new date at the top, and where appropriate we will notify customers.
Questions or requests: privacy@docoply.com

AI-powered legal document analysis for startups and growing businesses. Identify legal risks before they become costly problems.
© 2025 Docoply. All rights reserved. | Built for UK startups navigating complex compliance requirements.