Docoply (“we”, “us”, “our”) provides contract-review tools at docoply.com.
Role under data protection law: we act as controller for site/app telemetry, accounts, billing, support and marketing; and as processor for documents you upload for analysis, processing them only on your instructions under our Customer Agreement and DPA.
This Policy covers our website and product experiences, including trials, paid customers, authorised users, support and sales communications. It excludes third-party sites/services we don’t operate, and employee/candidate data (see our separate notice).
Territorial scope: we follow UK GDPR and PECR, and—where applicable—EU GDPR for individuals in the EEA.
We handle the following categories (details and examples are provided in the app or on request):
Special-category data: not intended; if such data appears within uploaded documents, we process it only to provide the service on your instructions and with safeguards.
We rely on Contract (to provide the service), Legitimate Interests (operate, secure, improve), Consent (marketing and non-essential cookies), and Legal Obligations (tax/records). When you upload documents, your organisation is the controller and chooses the lawful basis; we process only as instructed under the DPA.
We use cookies and similar technologies to run the site, understand usage, and—if you allow—measure and improve advertising. Non-essential cookies do not run until you consent.
Consent Mode v2: our banner sets separate choices for Analytics and Advertising; we signal these via analytics_storage, ad_storage, ad_user_data, ad_personalization. You can change choices anytime via “Manage Cookies”.
See our Cookie Policy for up-to-date cookie tables and lifetimes.
Some providers may process data outside the UK/EEA. Where transfers occur, we use approved safeguards (e.g., SCCs with UK Addendum/IDTA) plus technical and organisational measures. Transfer impact assessments are performed as appropriate.
Measures include encryption in transit, hardened cloud infrastructure, least-privilege access, MFA for staff, event logging, vendor due diligence, and vulnerability management. If you believe you’ve found a security issue, email privacy@docoply.com.
You may have rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent (for consent-based processing) and to complain to the ICO/EEA authority. To exercise rights, email privacy@docoply.com. We may need to verify your identity; authorised agents may be asked for proof.
Applies to accounts & profiles, usage/device logs, product analytics (with consent), communications/support, payments/billing, vendor/public-source data. See Sections above for purposes, bases, retention and transfers.
For documents you upload for analysis, we process only on your documented instructions under our Customer Agreement and DPA (subject-matter, duration, types of data and data subjects are described in the DPA). You should direct data-subject requests to your organisation; we’ll assist per the DPA.
Our services are intended for business users and are not directed to children. If you believe a child has provided data, contact privacy@docoply.com so we can delete it.
We’ll post updates here and, for material changes (e.g., new non-essential cookies or new marketing uses), notify you in advance via in-app/banner, email to the account/billing/admin contact, and/or a prominent site notice. Each version shows a “Last updated” date. Material changes take effect on the date stated in the notice.

AI-powered legal document analysis for startups and growing businesses. Identify legal risks before they become costly problems.
© 2025 Docoply. All rights reserved. | Built for UK startups navigating complex compliance requirements.