1. Overview
Documentgate ("we", "us", "our") is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices you have. By using our Service, you agree to the collection and use of information in accordance with this policy.
2. Data We Collect
- Full name and email address provided at registration
- Profile photo (if uploaded)
- Password (stored as a bcrypt hash — we never store plaintext passwords)
- Account preferences and settings
- Resume content, work history, education, and skills you enter
- Cover letter drafts and final copies
- Portfolio content, project descriptions, and uploaded media
- AI-generated drafts created using our tools
- IP address and approximate location (country/city)
- Browser type, operating system, and device identifiers
- Pages visited, features used, and session duration
- Referring URL and exit pages
- Error logs and performance data
- Billing address and email for invoicing
- Payment method details (processed by our payment provider — we do not store card numbers)
- Subscription status and transaction history
3. How We Use Your Data
- To create and maintain your account and provide the Service
- To power AI-assisted writing features using your document content
- To process payments and manage your subscription
- To send transactional emails (e.g. password resets, magic links, receipts)
- To send product updates and tips (you can opt out at any time)
- To monitor and improve Service performance and security
- To comply with legal obligations and enforce our Terms
- To detect and prevent fraud, abuse, and other harmful activities
4. Legal Basis for Processing
Processing necessary to provide the Service you signed up for.
Security monitoring, fraud prevention, product analytics, and service improvement.
Marketing emails and non-essential cookies — you can withdraw consent at any time.
Compliance with applicable laws, regulations, and valid legal processes.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you close your account, we delete your personal data within 30 days, except where we are required to retain it for legal, statutory, or legitimate business purposes (such as tax records, which may be kept for up to 7 years). Anonymised or aggregated data may be retained indefinitely.
8. Security
We implement industry-standard security measures including TLS encryption in transit, encryption at rest for sensitive fields, bcrypt password hashing, regular vulnerability assessments, and access controls limiting data access to authorised personnel only. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but are committed to best-practice protections.
9. International Transfers
Your data may be processed in countries other than your own. Where we transfer personal data outside of the EEA or UK, we ensure appropriate safeguards are in place — including Standard Contractual Clauses approved by the relevant regulatory authority — to protect your data to an equivalent standard.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — request that we limit how we process your data
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests or for direct marketing
- Withdraw consent — at any time, where processing is based on consent
- Lodge a complaint — with your local data protection authority
To exercise any of these rights, contact us at privacy@documentgate.com. We will respond within 30 days.
11. Children's Privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us immediately and we will delete it promptly.
12. Third-Party Links
The Service may contain links to third-party websites. This Privacy Policy applies only to Documentgate. We are not responsible for the privacy practices of third-party sites and encourage you to read their privacy policies.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by email or by posting a prominent notice on the Service. The "Effective Date" at the top of this page indicates when it was last updated. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
14. Contact & DPO
For any privacy-related questions, concerns, or requests, contact our privacy team at privacy@documentgate.com. For users in the EEA, our Data Protection Officer can be reached at the same address. We aim to respond to all privacy requests within 30 days.