Privacy Policy
Last updated: December 11, 2025
Introduction
CraftCodely SRL ("we," "us," or "our") operates Docuyond, an AI-powered chatbot platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service at docuyond.com.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using Docuyond, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Personal Information
When you register for an account, we collect:
- Email address - Used for account authentication and communication
- Name - Used for personalization and identification
- Password - Encrypted and stored securely for account access
- Google OAuth data - If you sign up via Google (name, email, profile picture)
Widget Data
When you create and configure AI chatbots, we collect:
- Widget configuration - Name, description, appearance settings, domain restrictions
- Knowledge base content - Documents and text you upload to train your chatbot
- Chat conversations - Messages between your customers and the AI chatbot
- Support escalations - Customer questions that require human assistance
Payment Information
We use Stripe for payment processing. We store:
- Stripe customer ID - Links your widget to Stripe account
- Subscription status - Current plan and billing cycle information
We do not store credit card numbers or payment details. All payment information is handled securely by Stripe in accordance with PCI-DSS standards.
Technical Information
We automatically collect certain information when you use our service:
- Usage data - Features accessed, pages viewed, time spent
- Device information - Browser type, operating system, IP address
- Cookies - Session cookies for authentication and functionality
How We Use Your Information
We use your information for the following purposes:
- Service delivery - To provide and maintain the Docuyond platform
- AI chatbot functionality - To train and operate your custom AI chatbots
- Account management - To manage your account, subscriptions, and billing
- Communication - To send service updates, security alerts, and support responses
- Improvement - To analyze usage patterns and improve our service
- Legal compliance - To comply with legal obligations and enforce our Terms of Service
We process your data based on the following legal grounds:
- Contract performance - Processing necessary to provide our services
- Legitimate interests - Improving our service and preventing fraud
- Consent - When you provide explicit consent for specific processing
- Legal obligation - Complying with laws and regulations
Data Sharing and Third Parties
We do not sell, trade, or rent your personal information to third parties. We share data only with trusted service providers who assist in operating our platform:
- Cloudflare - Hosting provider for infrastructure, databases (D1), file storage (R2), and AI processing (Workers AI)
- Stripe - Payment processing and subscription management
- Google OAuth - Authentication service (only if you choose to sign in with Google)
- Resend - Transactional email delivery
All third-party providers are bound by data protection agreements and process data only as instructed. They do not use your data for their own purposes.
Data Storage and Security
Storage location: Your data is stored on Cloudflare's infrastructure, which may include servers located in the European Union and other regions.
Security measures: We implement industry-standard security practices:
- Encrypted passwords using bcrypt hashing
- HTTPS encryption for all data in transit
- Secure authentication with session tokens
- Regular security audits and updates
- Access controls and monitoring
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide you services. Specific retention periods:
- Account data - Retained until account deletion is requested
- Chat conversations - Retained for the lifetime of the widget or until deletion
- Payment records - Retained for 7 years to comply with tax and accounting regulations
- Backup data - May be retained for up to 30 days in secure backups
Your GDPR Rights
If you are located in the European Union, you have the following rights under GDPR:
- Right to access - Request a copy of your personal data
- Right to rectification - Correct inaccurate or incomplete data
- Right to erasure - Request deletion of your personal data (see Account Deletion below)
- Right to restriction - Request limitation of data processing
- Right to data portability - Receive your data in a machine-readable format
- Right to object - Object to certain types of data processing
- Right to withdraw consent - Withdraw consent for data processing at any time
To exercise any of these rights, contact us at support@docuyond.com. We will respond within 30 days.
Account Deletion
You can request account deletion at any time by emailing support@docuyond.com. Upon receiving your request, we will:
- Verify your identity to ensure security
- Delete your account and associated personal data immediately
- Remove all widgets, knowledge base content, and chat conversations
- Cancel any active subscriptions (no refunds for partial billing periods)
Please note that some data may remain in secure backups for up to 30 days before permanent deletion. Payment records will be retained for 7 years to comply with legal obligations.
Cookies and Tracking
We use cookies to:
- Maintain your logged-in session
- Remember your preferences
- Analyze site usage and performance
You can control cookies through your browser settings. Disabling cookies may limit certain functionality of our service.
Children's Privacy
Docuyond is a business tool intended for users aged 18 and older. We do not knowingly collect personal information from children under 18. If we discover that a child has provided us with personal data, we will delete it immediately.
International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Data processing agreements with third-party providers
- Compliance with GDPR requirements for international transfers
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Significant changes will be communicated via email. Continued use of our service after changes constitutes acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
CraftCodely SRL
Email: support@docuyond.com
Location: Romania
For GDPR-related inquiries or to exercise your data rights, email support@docuyond.com with "GDPR Request" in the subject line.
