This Privacy Policy explains what personal data DocuBot processes, for what purpose, who we share it with, and how you can exercise your rights, in accordance with Argentina's Personal Data Protection Law No. 25.326 and, to the extent applicable due to having visitors in the European Union, the principles of the General Data Protection Regulation (GDPR).
1. Data controller
[FULL NAME], National ID/Tax ID [NUMBER], with address at [ADDRESS], Argentina, is the controller of the personal data described in this policy. Contact: hola@docubot.dev.
The Agency for Access to Public Information, as the Enforcement Authority under Law 25.326, has the power to handle complaints and claims filed in relation to non-compliance with personal data protection regulations.
2. Who this policy applies to
This policy covers two distinct profiles of people:
- Customers: those who create a DocuBot account to generate a chatbot from their own documents.
- End visitors: the people who use the chat widget embedded on a Customer's site, without having a DocuBot account.
For end visitors, the Customer who installed the widget on their site acts as the controller with respect to their own users, and DocuBot acts as the data processor. The detail of this role is in our Data Processing Agreement.
3. What data we collect
From Customers (account holders)
- Account data: email and password (stored as a hash, never in plain text).
- Configuration data: collection name, allowed origins for the widget, bot personality settings (prompt, color, greeting), configured usage limits.
- Session cookie: an authentication token (JWT) in a technical, httpOnly, and secure cookie, needed to keep the session active. See the detail in the Cookie Policy.
- Service usage data: upload history, message statistics, and approximate cost of dashboard usage.
From the documents you upload
- The content of the files you upload (extracted to text), the filename and path of each document, and a hash of its content to detect changes.
We only process the files you choose to upload. We do not access any other files or storage on your device beyond what you select for upload.
From end visitors (widget users)
- The content of the messages they write in the chat and the responses generated.
- The rating (👍/👎) they give a response, if they use it.
- A chat session identifier, not linked to an identity unless the visitor themselves reveals it in their message.
We do not require end visitors to register to use the widget. If a visitor voluntarily writes personal data within their message (for example, their email so they can be contacted), that data is stored as part of the conversation and is treated as described in this policy.
4. What we use the data for
- Creating and maintaining your account and authenticating you.
- Processing and indexing the documents you upload, to generate the chatbot.
- Generating chatbot responses from the indexed content, in response to visitor questions.
- Showing you in the dashboard the conversation history, usage analytics, and estimated cost of the Service.
- Sending you operational communications necessary for the Service (for example, notice that an upload has finished processing, password reset, changes to these legal documents).
- Preventing abuse, fraud, or misuse of the Service, and protecting its security.
- Complying with legal obligations when applicable.
We do not use your data for advertising nor do we sell it to third parties.
5. Legal basis
We process your data because it is necessary to provide the Service you contracted (performance of a contract), because you have given your consent by creating the account or by voluntarily using the widget, or because we have a legitimate interest in maintaining the security and operation of the Service, provided that interest does not override your rights.
6. Who we share the data with
We do not share your data except with the following third parties, strictly to operate the Service:
| Provider | Purpose | What data it sees |
|---|---|---|
| OpenAI (or another compatible language model provider, configurable) | Generate the chat response from the relevant content found | The content fragment from your documents relevant to the question, and the text of the visitor's question. No credentials or account data are sent. |
| Hosting and infrastructure provider (database and servers) | Host the application and the database | All stored information, encrypted in transit |
Embeddings (vector representation of content used to search for relevant information) are generated with a model that runs on our own infrastructure; they are not sent to an external provider for that step.
We may disclose information if a competent authority legally requires it of us, or to protect our rights, those of our users, or those of third parties.
7. International transfers
Some of our providers (such as OpenAI) process data on servers outside Argentina, including the United States. When this occurs, we contractually require those providers to maintain an adequate level of data protection, in line with their own privacy and security commitments.
8. How long we keep the data
- Account data: while your account is active. Upon deletion, it is erased within a reasonable period, except where legally required to be retained.
- Uploaded documents and conversations: while the collection exists in your account. Deleting a collection cascades to erase all of its documents, conversation history, and configuration, immediately and irreversibly.
- Backups: may persist for a limited period after deletion, solely for disaster recovery, and are overwritten in the normal rotation cycle.
9. Security
We apply reasonable technical and organizational measures to protect the data, including:
- Passwords stored as a hash, never in plain text.
- Session via httpOnly and secure cookie, not accessible by browser JavaScript.
- Authentication required to access any collection data or its conversations.
- Validation of the widget request's origin to prevent unauthorized access.
- Limits on file size and count to protect the Service's infrastructure from abuse.
No system is 100% secure. If we detect a security breach affecting personal data, we will notify affected Customers and, when applicable, the competent authority, within the timeframes required by applicable regulations.
10. Your rights (access, rectification, erasure, objection)
As the owner of your data, under Law 25.326, you have the right to:
- Access: know what data we hold about you.
- Rectification: correct inaccurate or outdated data.
- Cancellation/Erasure: request that we delete your data when applicable.
- Objection: object to a specific processing of your data.
You can exercise these rights by writing to hola@docubot.dev from the email associated with your account. We will respond within a reasonable time and, in any case, within the timeframes established by applicable law. If you are not satisfied with the response, you can file a complaint with the Agency for Access to Public Information (www.argentina.gob.ar/aaip).
Most of these rights you can also exercise yourself from the dashboard: by editing your settings, or by deleting a collection (which cascades to erase all of its documents and associated conversations).
11. If you are a visitor to a site with the DocuBot widget
If you are chatting with a DocuBot widget on a third party's site, that third party (the Customer) is who decides what content to index and how to configure the bot, and is your primary point of contact for questions about your data, unless you want to ask us something specific about the technical operation of the Service, in which case you can write to us directly.
12. Minors
The Service is not directed at children under 13 and we do not deliberately collect account data from minors of that age. If an end visitor using a widget turns out to be a minor, the same protections in this policy apply; the Customer is responsible for ensuring the widget's use on their site is appropriate for their audience.
13. Changes to this policy
We may update this Privacy Policy. If the change is significant, we will notify you by email or via a notice in the dashboard before it takes effect. The "Last updated" date at the top of this page reflects the version in force.
14. Contact
For any question about this Privacy Policy or your personal data, write to us at hola@docubot.dev.