Privacy Policy

How Doctagd collects, uses, stores, and processes personal data. Operated by Project Paced Ltd.

Last updated 21 September 2026

This Privacy Policy explains how Doctagd ("Doctagd", "we", "us", or "our") collects, uses, stores, and processes personal data.

Doctagd is a product operated by Project Paced Ltd.

Company Information

Project Paced Ltd,
International House,
64 Nile Street,
London,
N1 7SR,
United Kingdom


1. Scope

This Privacy Policy applies to:

  • the Doctagd website
  • the web application
  • API access
  • billing and account systems
  • support communications
  • related services

2. Information We Collect

Account Information

We may collect:

  • name
  • email address
  • login credentials
  • authentication records
  • password hashes
  • account preferences
  • API key metadata

Customer Content

We process Customer Content uploaded or generated through the Service, including:

  • spreadsheets
  • Word templates
  • generated documents
  • saved configurations
  • mappings
  • workflow metadata
  • API payloads
  • filenames
  • preview data
  • AI-assistance inputs, including selected field labels and settings, instructions, and clarification answers
  • AI-assistance outputs, including proposed mappings, joins, formatting rules, confidence bands, and clarification questions

Customer Content may contain personal data depending on what users upload.


Billing Information

We may collect or receive:

  • subscription status
  • billing plans
  • invoices
  • payment metadata
  • usage records
  • Stripe customer identifiers

Payment card information is processed by our payment processor and is not stored directly by Doctagd.


Technical and Usage Information

We may collect:

  • IP addresses
  • browser information
  • device information
  • timestamps
  • usage metrics
  • log records
  • API activity
  • rate-limit data
  • security telemetry

3. How We Use Information

We use information to:

  • provide document-generation functionality
  • authenticate users
  • secure the Service
  • operate the API
  • generate previews and downloads
  • save configurations
  • provide optional AI-assisted mapping and setup when a user explicitly requests it
  • process subscriptions and billing
  • meter document usage, configuration limits, and AI-assistance credits
  • prevent abuse and fraud
  • provide support
  • maintain and improve the Service
  • comply with legal obligations

4. Legal Bases for Processing

Where UK GDPR or GDPR applies, we rely on legal bases including:

  • performance of a contract
  • legitimate interests
  • compliance with legal obligations
  • consent where applicable

Our legitimate interests include:

  • operating and securing the Service
  • improving reliability and functionality
  • preventing abuse
  • supporting customers
  • enforcing our Terms

5. File Storage and Retention

Uploaded files may be stored temporarily in private cloud storage.

Session uploads and temporary processing artefacts may be automatically deleted after operational retention periods.

Saved configurations and associated templates may persist until deleted by users or removed in accordance with our policies.

Generated documents, previews, logs, and job metadata may be retained temporarily for operational, billing, support, security, or reliability purposes.

When Smart Mapping & Setup is used, Doctagd caches the proposal payload for 24 hours and retains provider-usage metadata for 90 days before scheduled deletion. Working suggestions may also remain in the user's browser session storage for up to 24 hours. The AI Usage Policy explains these controls in more detail.

Retention periods may vary depending on:

  • feature usage
  • billing status
  • legal obligations
  • security requirements
  • operational needs

6. Sharing and Disclosure

We do not sell Customer Content.

We may share data with third-party service providers that help operate the Service, including providers for:

  • hosting
  • storage
  • databases
  • billing
  • email delivery
  • authentication
  • bot protection
  • infrastructure
  • monitoring
  • optional AI-assisted mapping

We may also disclose information:

  • where required by law
  • to protect rights or security
  • to investigate abuse
  • during corporate transactions
  • with your consent or direction

7. Subprocessors and Service Providers

Doctagd uses third-party subprocessors and infrastructure providers.

Current providers are listed on the Subprocessors page.

Google processes account information as an independent provider when a user chooses Google sign-in. Have I Been Pwned receives a k-anonymised password-hash prefix for compromised-password screening; it does not receive the password or account identity.

Generated document content is sent to the conversion and rendering provider listed on the Subprocessors page when a user requests a rendered preview or a paid user chooses PDF export.

When a Pro or Business user explicitly submits a Smart Mapping request, selected mapping context and clipped spreadsheet samples are sent to TypeSafe and OpenAI. The full spreadsheet and Word template are not sent through this feature. Smart Mapping is optional, and ordinary previews and document generation do not call these AI providers.

The Subprocessors page is the current list of providers that process personal data on Doctagd's behalf.


8. International Transfers

The processing locations used by Doctagd's subprocessors are stated on the Subprocessors page. For transfers of personal data outside the United Kingdom or European Economic Area, Doctagd uses the safeguards required by applicable data protection law.


9. Optional AI-Assisted Processing

Smart Mapping provides suggestions that a user may accept or reject. It does not independently apply mapping changes or make solely automated decisions about individuals that produce legal or similarly significant effects. Users remain responsible for reviewing sample results, mappings, formatting, and generated documents.


10. Security

We use technical and organisational measures intended to help protect the Service and Customer Content, including:

  • authentication protections
  • private storage controls
  • access restrictions
  • encryption in transit
  • operational monitoring
  • credential protections

No system can guarantee absolute security.

Users are responsible for securing their own devices, credentials, integrations, and uploaded data.

See the Security overview for more detail.


11. Your Rights

Depending on applicable law, you may have rights including:

  • access
  • correction
  • deletion
  • restriction
  • objection
  • portability
  • withdrawal of consent
  • complaint to a supervisory authority

Requests may be subject to verification and applicable legal limitations.


12. Cookies and Similar Technologies

Doctagd may use cookies and similar technologies for:

  • authentication
  • session management
  • security
  • preferences
  • analytics
  • operational functionality

Additional details are provided in the separate Cookie Policy.


13. Children

The Service is not intended for children under 18.

We do not knowingly collect personal data from children.


14. Changes to This Policy

We may update this Privacy Policy periodically.

Updated versions will be posted with a revised "Last updated" date.

Continued use of the Service after updates become effective constitutes acceptance of the revised policy.


15. Contact

Questions regarding this Privacy Policy or privacy-related requests may be submitted through the contact page or official support channels.

See all legal documents or send questions through the contact page.