Privacy Policy
Document version: 2026-09-16
Effective date:
Last updated:
1. Operator and contact
DocuChat is a product and brand operated by Trouvaillesys, a sole proprietorship registered in India. The public contact for privacy requests is admin@docuchat.in. Further identity and GST information appears on the Contact & Imprint page.
For account, billing, security, support, and site operations, Trouvaillesys determines why and how personal data is processed. For Customer Content and visitor conversations submitted through customer chatbots, Trouvaillesys generally processes data to provide the Service for the customer, while retaining any independent duties imposed by law. The exact legal role may differ by processing activity and jurisdiction.
2. Scope
This policy covers the public marketing site, authenticated application, public API, support and service communications, billing, document and chatbot processing, and DocuChat widgets or embeds. An embedding customer may also have its own privacy notice and responsibilities for its website visitors.
3. Data categories
Depending on the features used, we may process:
- Account and profile data: name, email address, authentication identifier, organization and role information if provided, and account status.
- Authentication, security, and technical data: sign-in and session identifiers, IP address, browser or device information, timestamps, audit, abuse-prevention, error, and diagnostic records generated by the Service or its providers.
- Billing and tax data: Razorpay order and payment identifiers, amount, status, credit grant and balance records, invoice or receipt information, billing address, and a customer GSTIN where supplied. Payment-card processing is handled by the payment provider; DocuChat does not need full card details for ordinary top-ups.
- Customer Content: uploaded files, source URLs and extracted source material, chatbot settings and instructions, prompts, conversations, generated answers, citations, and retrieval context.
- Usage and service data: selected model and feature use, answered-message and credit metering, chatbot and API activity, widget session identifiers, operational events, and product-performance records.
- Support and communications: emails, support requests, grievance and rights-request correspondence, and identity-verification information when reasonably needed.
- Marketing-site consent data: the consent choice, policy version, and timestamp stored in browser local storage as described in the Cookie Policy.
4. Sources
We receive data from you, members of your organization, visitors who interact with a customer chatbot, the websites or files you direct us to process, and service providers involved in authentication, hosting, databases, payments, email, security, and selected AI functionality.
5. Purposes
We process data as reasonably needed to:
- create and authenticate accounts and manage account access;
- ingest sources, configure chatbots, retrieve context, generate answers, and provide APIs, widgets, analytics, and other requested features;
- meter answered messages and credit use, process top-ups, grant credits, reconcile payments, issue invoices, and meet tax obligations;
- secure, troubleshoot, maintain, and improve reliability and product performance;
- prevent fraud, abuse, unlawful use, and security incidents;
- respond to support, privacy, grievance, and legal requests;
- send account, authentication, security, billing, support, and other service communications; and
- establish, exercise, or defend legal rights and comply with law.
We do not currently send promotional marketing email. If that changes, we will provide any notice and choice required by applicable law.
6. Customer Content, model training, and operational metrics
DocuChat does not sell or rent personal data or Customer Content. DocuChat's policy is not to use Customer Content to train or improve DocuChat or general-purpose AI models. Customer Content may be processed by the selected model and service providers to deliver requested functionality. Because third-party handling depends on their current contracts, settings, retention, and terms, we do not give an absolute no-training assurance for every third-party system.
We may use aggregated or de-identified operational metrics that exclude Customer Content to measure usage, reliability, abuse, cost, and product performance, provided they are handled with appropriate privacy safeguards.
7. Personnel access
Authorized DocuChat personnel may access Customer Content only when reasonably necessary for requested support, service operation, security or abuse investigation, or legal compliance. Access by service providers is governed by their role in providing the selected services and their applicable terms and configurations.
8. Service providers and processing locations
Provider categories include cloud authentication, storage, compute and retrieval; managed database services; payment processing; transactional email; security and abuse prevention; and supported AI model services selected or configured for a chatbot.
Current architecture includes managed AWS services, including Cognito, S3, Lambda, Bedrock, and Amazon SES where applicable; MongoDB Atlas for database services; Google as an optional federated identity provider; Firecrawl when a customer directs DocuChat to extract a website; Razorpay for payments; and supported AI model services selected or configured for a chatbot. Model providers depend on current configuration and availability. Google Tag Manager and Google Analytics are not configured or active on the production marketing site as of this policy's effective date.
The MongoDB Atlas primary deployment is in Mumbai, India (AWS region ap-south-1). Other AWS resources, service providers, support access, or selected model processing may occur in India or other countries. The backup location is not currently known. We do not promise India-only processing, a single region, or data residency in any country.
Where data crosses borders, we handle it subject to applicable law and provider arrangements. Global availability does not mean every feature or transfer is lawful in every jurisdiction.
9. No launch DPA
DocuChat does not offer a separate data processing agreement at launch. If your organization or intended use requires a DPA or additional processor terms, do not submit affected data unless and until a suitable written arrangement is available.
10. Retention, deactivation, and deletion
We retain data only for as long as reasonably needed for the purposes above, including active service use, account reactivation, security, dispute handling, tax and accounting obligations, legal holds, and other legal requirements. Periods vary by record type and applicable law.
The current account lifecycle is designed to allow reactivation for up to 30 days after deactivation. That designed window is not a promise that every record will remain complete throughout it or that irreversible deletion occurs immediately afterward.
After a confirmed deletion request, account access may be disabled and account, chatbot, and document records may first be marked deleted. Scheduled cleanup may later remove selected authentication, storage, and retrieval resources. Provider copies, backups, logs, legal holds, tax records, security records, and other legally or operationally required records may remain for longer. We do not promise an immediate, exhaustive, or irreversible physical purge.
11. Rights and requests
Depending on applicable law, you may have rights to information about processing, access, correction, updating, erasure, consent withdrawal, grievance handling, nomination, portability, or other remedies. Rights and exceptions differ by jurisdiction.
Submit a request to admin@docuchat.in. We normally verify control through the registered account email and may request additional proof when reasonably necessary to protect the account or comply with law. We respond within the deadline required by applicable law; we do not promise a shorter voluntary deadline.
There is no self-service account-data export. Until such a feature exists, we will provide a manual export through the email process only where applicable law requires it, subject to verification, lawful scope, exceptions, and available records.
12. Sensitive and high-stakes data
Submit sensitive data only when you have lawful authority and have assessed the notices, consents, security measures, provider restrictions, sector rules, and cross-border consequences applicable to your use. DocuChat is not designed or certified as a credential vault or PCI card-data environment.
For high-stakes use, customers must independently review output with appropriately qualified people and must not use DocuChat as professional advice or as the sole basis for decisions affecting a person's rights, health, safety, finances, or access to essential opportunities.
13. Security and incidents
We seek to use safeguards appropriate to the nature of the Service, but no system is completely secure. This policy does not promise a specific security certification, uninterrupted availability, disaster-recovery capability, RPO, RTO, backup outcome, or service level. If a personal-data breach requires notice under applicable law, we will provide notice as and when that law requires.
14. Age
Account creation and credit purchases are limited to people aged 18 or older. Customers who make a chatbot available to visitors are responsible for any visitor-age notices, permissions, or restrictions required for their use, subject to duties that law places directly on Trouvaillesys.
15. Changes to this policy
For a material change, we will email the registered account address and provide any lead time required by applicable law. Continued use after the stated effective date constitutes acceptance where permitted; we will seek express consent or use another process where law requires it.
16. Grievances and contact
Privacy questions and rights requests: admin@docuchat.in. Grievance handling and escalation details are on the Grievance Officer page.
Document version: 2026-09-16
Effective date:
Last updated: