This policy explains how pmdox ("we", "us", "our") handles personal data when you use the Service. It applies to users worldwide and is written to meet, at minimum, the requirements of the EU/UK GDPR; you will find region-specific additions at the end.
1. Who we are
pmdox operates the Service. Contact for privacy questions and data-subject requests: info@pmdox.com.
pmdox's legal entity is established in Alberta, Canada. As we actively offer services to users in the European Union and the United Kingdom, we are in the process of appointing an Article 27 GDPR representative for the EU and a UK representative under the UK GDPR. Their contact details will be published here upon appointment. In the meantime, all data-subject requests and privacy inquiries can be directed to info@pmdox.com and will be handled within the statutory timeframes.
2. Data we collect
- Account data: name, email, password hash, role, optional organisation and industry.
- Project content: projects, documents, RAID items, stakeholders, budgets, prompts, doxChat messages, doxAssist drafts, doxScan integrity results, and files you upload for extraction.
- Billing data: if you subscribe to a paid plan, your name, billing email, billing address, plan, invoice history, and Stripe customer/subscription IDs. Card numbers are entered directly into Stripe — pmdox never sees or stores them.
- Communication data: notification and email preferences, unsubscribe tokens, and delivery/bounce metadata for transactional and digest emails we send you.
- Support data: messages you send via the help or feedback forms.
- Technical data: IP address (for rate limiting and abuse prevention), basic device/browser info, error reports.
- Usage data: aggregate, non-personal traffic statistics (page visits, referrer, country) derived from server-side request logs by our hosting platform. No cookies, browser identifiers, or personal data are used for this purpose, and nothing is shared with third parties for advertising.
3. How we use it and our legal bases
- To provide and improve the Service — performance of a contract.
- To authenticate you and secure your account — performance of a contract.
- To send transactional emails such as verification, security alerts, account notices, billing receipts, and the weekly project digest — performance of a contract.
- To send optional notification emails you have enabled in Settings — consent, which you can withdraw at any time from Settings → Notifications or via the unsubscribe link in each email.
- To process subscription payments and manage your plan through Stripe — performance of a contract and compliance with tax/accounting law.
- To respond to support requests — our legitimate interest in supporting users.
- To prevent fraud, abuse, and security incidents — our legitimate interest in keeping the Service safe.
- To understand aggregate platform usage via server-side traffic logs — no personal data is collected or shared for this purpose.
- To comply with legal obligations.
We do not sell or share your personal data for cross-context behavioural advertising, and we do not use your project content to train AI models.
4. Sub-processors
We rely on a small number of vetted third-party providers to operate the Service — including Lovable Cloud (Supabase on AWS) for database, authentication, and storage; Google AI Studio (Gemini) for LLM inference powering doxAssist, doxChat, doxScan, upload extraction, and questionnaire assist; Stripe for subscription billing; Lovable Email (Resend) for transactional, notification, and digest emails; Google Analytics 4 for opt-in product analytics; and Cloudflare for CDN, edge runtime, and DDoS protection. The full current list, with locations and transfer mechanisms, is published at /subprocessors. Primary storage of your account and project data is in the EU (Ireland).
5. International transfers
Some sub-processors (e.g. Google AI Studio, Stripe, Google Analytics, Cloudflare) may process data outside the EEA / UK / Switzerland. We rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss addendum, and — where the provider is certified — the EU–US Data Privacy Framework, as appropriate safeguards.
6. Retention
Account and project data is retained while your account is active. Deleting your account from Settings removes projects, documents, and AI memory within 30 days. Backups are purged within 90 days. Billing records (invoices, Stripe customer references) may be retained as required by tax law (typically 7 years). Server-side traffic logs are retained for 90 days and contain no personal identifiers.
7. Security
We protect data with row-level security in our database, encrypted transport (TLS 1.2+), encrypted storage at rest, least-privilege access for staff, and isolated per-project workspaces. No system is perfectly secure; please report suspected issues to info@pmdox.com.
8. AI processing
pmdox uses Google AI Studio (Gemini) as its sole large-language-model provider to generate project documents (doxAssist), power project chat (doxChat), run integrity checks (doxScan), extract content from your uploads, and assist questionnaire completion. We send only the prompt and the project context needed for the requested artifact. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects (GDPR Article 22 / Québec Law 25 §12.1). See our AI Disclosure for details on what is sent and how outputs should be reviewed.
9. Children
The Service is not directed to children under 16. If you believe a child has provided personal data to us, contact info@pmdox.com and we will delete it.
10. Your rights
Regardless of where you live, you can ask us to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Export your data in a portable format.
- Restrict or object to certain processing.
- Withdraw consent for analytics (use the cookie settings link below).
- Lodge a complaint with your local data-protection authority.
Most of these can be exercised in-app from Settings, or by emailing info@pmdox.com. We respond within 30 days (GDPR), 45 days (CCPA/CPRA), 15 days (LGPD), or sooner where local law requires it.
11. Region-specific notices
European Economic Area, United Kingdom, Switzerland
Our legal bases are listed in §3. You have the right to lodge a complaint with your local supervisory authority — see the EDPB list of national DPAs, the UK ICO, or the Swiss FDPIC.
California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other US states
Under the CCPA/CPRA and equivalent state laws, you have the right to know, delete, correct, and limit use of sensitive personal information; the right to opt out of "sale" or "sharing" of personal information (we do not sell or share, but you can still opt out of analytics via the cookie settings link in §10); and the right to be free of discrimination for exercising these rights. An authorised agent may act on your behalf with written authorisation. Categories of personal information we collect under CCPA are listed in §2.
Canada (PIPEDA) and Québec (Law 25)
pmdox is subject to the Personal Information Protection Act (PIPA) of Alberta and the federal Personal Information Protection and Electronic Documents Act (PIPEDA). Our privacy officer is reachable at info@pmdox.com. We may transfer personal information outside Canada (see §5). We do not make decisions about you based exclusively on automated processing of your personal information.
Brazil (LGPD)
Our legal bases mirror Article 7 of the LGPD: execution of contract, legitimate interest, legal obligation, and — for analytics — consent. You may contact the Brazilian National Data Protection Authority (ANPD) at gov.br/anpd.
India (DPDP Act 2023)
You may withdraw consent for analytics at any time using the cookie settings link in §10, contact our grievance officer at info@pmdox.com, and exercise your rights as a Data Principal. We will respond within statutory timelines.
UAE (PDPL), KSA (PDPL), Qatar (PDPPL)
Your account data is stored in the EU (Ireland). By using the Service you acknowledge that personal data may be transferred outside your country to jurisdictions assessed as adequate under your local law. Contact info@pmdox.com to exercise your rights.
Singapore (PDPA), Japan (APPI), South Korea (PIPA), Australia (Privacy Act)
Our local-law obligations are honoured through the global rights in §10. Korea PIPA: we do not use Google Signals or ad-personalisation signals. APPI: cross-border transfers are described in §5. Australia: you may complain to the OAIC.
South Africa (POPIA), Nigeria (NDPA), Kenya (DPA)
Our processing is lawful, fair, and limited to the purposes in §3. You may contact the Information Regulator (ZA), the Nigeria Data Protection Commission (NG), or the Office of the Data Protection Commissioner (KE).
12. Changes
Material changes will be notified by email or in-app at least 14 days in advance.