Privacy Policy
DOCAXO edits PDFs in your browser and runs the heavy tools on our own servers. This policy explains, in plain language, which personal data we process when you use it, why, for how long, and what you can do about it. It is written to meet the General Data Protection Regulation (GDPR) and the Dutch implementation act (UAVG).
Last updated: 13 September 2026
Who we are
The controller for the personal data described here is Van Melsen Marketing B.V., trading as DOCAXO, a private limited company established in the Netherlands.
- Controller
- Van Melsen Marketing B.V.
- Trading as
- DOCAXO
- Chamber of Commerce
- KvK 82776350
- VAT number
- NL862600339B01
- Website
- https://docaxo.com
- Privacy contact
- [email protected]
We have not appointed a data protection officer because we are not legally required to; the privacy contact above reaches the people responsible for data protection directly.
What this policy covers
This policy applies to the DOCAXO website at docaxo.com, the browser editor, the server tools (OCR, compress, convert, merge, split, redact, e-sign and the other tools listed on the tools page), encrypted cloud storage, accounts, billing, the public API and the emails we send to operate the service.
It does not cover third-party websites we link to, or what you do with documents after you download them. When you pay, Stripe acts as the merchant of record and also processes your payment data under its own privacy policy (see Subprocessors).
Data we process
You can use most of DOCAXO without an account. Browser tools render, edit and export your file entirely in the tab; nothing is uploaded until you start a server tool or save a file to your account. Depending on what you use, we process the following categories of data.
Account data
- Email address, optional display name, and a salted hash of your password (never the password itself).
- Email verification status and the verification, password-reset and account-deletion tokens we email you.
- If you sign in with Google or Apple: the account identifier and email address the provider shares with us. We do not receive your provider password.
- Session records (session id, creation time, last seen, rough device description) so you can review and revoke sessions.
- Your plan, trial status and preferences.
Files and content
- The files you upload for a server tool or save to your account, the results those tools produce (for example OCR text and coordinates, converted documents), and any signatures, form values or annotations you add.
- Documents may themselves contain personal data about you or third parties. You are responsible for having a lawful basis to process those documents; we process them only on your instruction, to provide the tool you selected.
- Anonymous sessions: files started without an account belong to a temporary anonymous account and are deleted after two hours unless you sign up and keep them.
Usage and billing data
- Which tools you ran, on how many pages, and when; credit reservations and settlements; storage used.
- Your Stripe customer id, subscription status, invoices and the last four digits and brand of your payment method as reported by Stripe. Full card numbers never reach our servers.
- Business details you enter at checkout (company name, VAT id, billing address), held by Stripe and mirrored on invoices.
Technical logs
- IP address, user agent, requested URL, response status, request id and timestamp for requests to our servers, plus error traces when something fails.
- Security events such as failed logins, rate-limit hits and abuse signals, used to protect the service.
API data
- A hash of each API key (the key itself is shown to you once and not stored), key scopes, rotation state, webhook endpoint URLs and delivery logs, and per-key usage for metering and rate limiting.
Support and correspondence
- Emails you send us, and our replies, so we can answer you and keep a record of what was agreed.
We do not buy data about you and do not build advertising profiles. The only analytics we use is Google Analytics, and only after you accept it in the cookie banner (see Cookies). OCR runs on GPU hardware we operate ourselves; your documents are not sent to third-party AI services.
Purposes and legal bases
Article 6 GDPR requires a legal basis for every purpose. The table below lists ours. Where we rely on legitimate interests (art. 6(1)(f)) we have weighed them against your interests and you may object (see Your rights).
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the editor, server tools, storage and API you request | Account data, files and content, usage data, API data | Performance of a contract — art. 6(1)(b) |
| Creating and securing your account, verifying your email, resetting passwords | Account data, technical logs | Performance of a contract — art. 6(1)(b); legitimate interest in security — art. 6(1)(f) |
| Billing, invoicing, VAT handling and fraud prevention | Usage and billing data, account data | Performance of a contract — art. 6(1)(b); legal obligation (tax and accounting law) — art. 6(1)(c) |
| Enforcing plan limits, rate limits and our acceptable-use rules | Usage data, technical logs, API data | Legitimate interest in running a fair and reliable service — art. 6(1)(f) |
| Keeping the service secure and available; detecting and investigating abuse | Technical logs, security events | Legitimate interest — art. 6(1)(f); legal obligation to secure personal data — art. 32 |
| Sending transactional emails (verification, receipts, security notices, deletion confirmations) | Email address, account data | Performance of a contract — art. 6(1)(b) |
| Sending product news or offers | Email address | Consent — art. 6(1)(a); only with a separate opt-in, withdrawable at any time |
| Measuring which pages and tools are used (Google Analytics) | Pseudonymous client id, pages visited, device type, truncated IP | Consent — art. 6(1)(a); only after you accept analytics cookies, withdrawable via “Cookie settings” |
| Answering support requests and legal claims | Correspondence, account data | Performance of a contract — art. 6(1)(b); legitimate interest — art. 6(1)(f) |
| Complying with legal obligations and requests from authorities | Whatever the obligation requires | Legal obligation — art. 6(1)(c) |
We do not use your data for automated decision-making with legal or similarly significant effects, and we do not use your documents to train machine-learning models.
How long we keep data
We keep personal data only as long as needed for the purpose it was collected for, or as long as the law requires. The main retention periods are fixed and enforced automatically by a lifecycle sweeper.
| Data | Retention |
|---|---|
| Unsaved anonymous files and job results | Deleted automatically 2 hours after upload or completion. |
| Files saved to an account | Kept until you delete them, or until your account is deleted. |
| API input files and results | Expire automatically after the period shown as expires_at on the file (currently 2 hours), or earlier when you delete them. |
| Account data | Kept while your account exists. When you request deletion, the account is deactivated immediately (sessions and API keys revoked) and permanently erased after a 30-day grace period during which you can cancel the deletion by contacting us. |
| Files in a deleted account | Purged with the account at the end of the 30-day grace period. |
| Invoices and payment records | 7 years from the end of the financial year, as required by Dutch tax law (Algemene wet inzake rijksbelastingen art. 52). |
| Usage and credit ledger | Kept for the duration of the account plus the period needed to substantiate invoices (see above), then deleted or anonymised. |
| Technical request logs | Up to 30 days, unless a specific log entry is needed for an ongoing security investigation. |
| Security event logs (failed logins, abuse signals) | Up to 12 months. |
| Email verification, reset and deletion tokens | Until used or expired (verification links are valid for 48 hours, reset links for 2 hours). |
| Support correspondence | Up to 2 years after the last message, unless needed longer for a dispute. |
Backups of our database are encrypted and rotated on a short schedule; data that has been deleted from the live system disappears from backups when those backups expire.
Subprocessors and recipients
DOCAXO runs on servers we own and operate in a data centre in the Netherlands. We use a small number of third parties to deliver parts of the service. Each processes personal data either as our processor under a data processing agreement, or as an independent controller where indicated.
| Party | Role | Data | Location |
|---|---|---|---|
| Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. | Merchant of record for all paid plans via Stripe Managed Payments. Stripe sells you the subscription or Day Pass, collects payment, calculates and remits VAT and issues invoices. Independent controller for payment data; processor for the account details we pass to it. | Email address, name, billing address, VAT id, payment details, purchase and usage records | EU (Ireland); some processing in the United States |
| Cloudflare, Inc. | CDN, reverse proxy, TLS termination and DDoS protection in front of our servers; Cloudflare Email Service for transactional email. Processor. | IP address, request metadata, TLS handshake data; recipient address and content of transactional emails | Global edge network with EU data localisation where available; United States |
| Google LLC / Apple Inc. | Optional sign-in providers. Only used if you choose “Continue with Google” or “Continue with Apple”. Independent controllers for the sign-in itself. | Account identifier and email address exchanged during sign-in | United States / EU |
| Google Ireland Ltd. (Google Analytics 4) | Aggregated usage statistics (which pages and tools are used), only after you accept analytics cookies. Google Signals, advertising features and data sharing are switched off; IP addresses are truncated. Processor. | Pseudonymous client id, pages visited, tool used, device/browser type, truncated IP | EU; some processing in the United States |
Other than these parties, we disclose personal data only when the law requires it (for example a binding order from a Dutch court or authority), to defend our legal rights, or with your explicit instruction (for example when you create a share link to a file). We never sell personal data.
If we add or replace a subprocessor we will update this page before the change takes effect and, for changes that affect files or account data, notify account holders by email.
International transfers
Your files and account data are stored and processed in the Netherlands. Some of our subprocessors are headquartered in the United States and may process limited data there:
- Stripe and Cloudflare are certified under the EU-US Data Privacy Framework and additionally rely on the European Commission’s Standard Contractual Clauses (2021/914) for transfers outside the EEA.
- Google and Apple sign-in transfers are governed by those providers’ own DPF certifications and Standard Contractual Clauses.
Document contents are not transferred outside the EEA by us: server tools and OCR run on our own hardware in the Netherlands, and Cloudflare only proxies the encrypted connection between your browser and our servers.
Security
We treat your documents as confidential and apply the following technical and organisational measures.
- Encryption at rest. Every stored file is encrypted with its own AES-256-GCM data key; that key is wrapped by a master key held separately from the object store (envelope encryption). Losing a copy of the storage does not expose file contents.
- Encryption in transit. All connections use TLS 1.2 or newer with HSTS. Plain HTTP is redirected.
- Isolated processing. Server tools run in sandboxed workers without outbound network access. OCR runs on GPU hardware we operate; no third-party AI or OCR service receives your documents.
- Access controls. Production access is limited to named staff with multi-factor authentication and is logged. Staff do not open customer files unless you ask us to for support.
- Credentials. Passwords are hashed with Argon2. API keys are stored only as hashes. Session cookies are
HttpOnly,SecureandSameSite. - Automatic deletion. The retention periods above are enforced by a sweeper, not by manual housekeeping.
- Incident response. If a personal data breach is likely to result in a risk to you, we notify the Autoriteit Persoonsgegevens within 72 hours and inform affected users without undue delay, as articles 33 and 34 GDPR require.
No system is perfectly secure. Choose a strong, unique password, keep your API keys secret and revoke sessions you do not recognise from the account page.
Your rights
Under the GDPR you have the following rights. Most of them you can exercise yourself from the account page.
- Access and export (art. 15, 20). Download everything we hold about you as JSON from Account → Export my data, or call
GET /v1/account/exportwith your session or API key. The export includes your account record, sessions, API key metadata, usage ledger, file metadata and billing summary, in a machine-readable format you can take elsewhere. - Rectification (art. 16). Change your display name on the account page, or ask us to correct anything else, including your email address.
- Erasure (art. 17). Delete individual files at any time, or delete your whole account from the account page. Deletion takes effect immediately for access and is permanent after 30 days. Invoice records we are legally required to keep are excluded.
- Restriction (art. 18) and objection (art. 21). You may ask us to stop processing that relies on legitimate interests, and we will do so unless we have compelling grounds to continue. You can always object to marketing.
- Withdraw consent (art. 7(3)). Where we rely on consent (marketing email, analytics cookies) you can withdraw it at any time via the unsubscribe link, the “Cookie settings” link in the footer, or by emailing us; this does not affect earlier processing.
- Not to be subject to automated decisions (art. 22). We do not make such decisions.
To exercise a right that is not self-service, email [email protected] from the address on your account. We respond within one month; for complex requests we may extend this by two further months and will tell you why. Requests are free unless they are manifestly unfounded or excessive.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens (Postbus 93374, 2509 AJ Den Haag). If you live in another EU member state you may complain to your local authority instead. We would appreciate the chance to resolve the matter with you first.
Email and marketing
We send transactional email to operate the service: verification links, password resets, receipts and invoices, security notices, trial and subscription changes, and account-deletion confirmations. These are part of the contract and cannot be opted out of while you hold an account.
We do not send marketing or product-news email unless you give a separate, specific opt-in. If you do opt in, every message contains an unsubscribe link and withdrawing is immediate.
Children
DOCAXO is not directed at children. You must be at least 16 years old to create an account, which is the age of digital consent in the Netherlands (art. 8 GDPR, art. 5 UAVG). If we learn that we hold account data for someone younger, we delete the account. If you believe a child has provided us with personal data, contact [email protected].
Changes to this policy
We may update this policy when the service or the law changes. The date at the top shows the current version. For changes that materially affect how we process your data — a new subprocessor with access to files, a new purpose, a longer retention period — we notify account holders by email at least 14 days before the change takes effect. Continued use after that date means you have taken note of the new version; where the law requires consent, we will ask for it.
Contact
Questions, requests and complaints about personal data: [email protected].
Van Melsen Marketing B.V. · KvK 82776350 · VAT NL862600339B01 · the Netherlands. For questions about the terms under which we provide the service, see the Terms of Service or write to [email protected].