Privacy Policy

What we collect, why, where it lives, and how to exercise your rights. Last updated July 10, 2026.

1. Who we are

Docman (docman.online) is a document delivery platform operated from the Netherlands. Freelancers and agencies ("account holders") use Docman to deliver files to their clients through a private, secure portal, with payment collected before the files unlock. This policy explains what personal data we process, why, and what rights you have. It applies to visitors of this website, account holders, and the clients who receive files through a Docman portal. For anything privacy-related, contact mail@docman.online.

2. Two roles: controller and processor

For the personal data of account holders — your name, email address, company and billing details, subscription status — Docman is the data controller. For the data account holders bring into the platform — their clients’ names and email addresses, and the documents they upload — Docman acts as a processor: the account holder decides what is delivered to whom, and we store and deliver it on their behalf. If you are a client receiving files and have questions about why your data is in a portal, your first point of contact is the business that invited you; we will assist them with any request.

3. What we collect

  • Account data — email address, password hash, company name, billing address, and VAT details of account holders
  • Client data — names and email addresses of the clients an account holder invites to their portal
  • Documents — the files account holders upload for delivery, stored encrypted in our private storage
  • Payment data — handled by Stripe; card numbers never touch Docman’s servers. We store payment status, amounts, and Stripe reference IDs
  • Access and audit logs — who downloaded or was denied access to which document and when, kept so account holders have a verifiable delivery record
  • Email delivery data — sends, bounces, and delivery status for the notifications and sign-in links we send via Postmark

4. What we don’t do

  • No advertising, no selling of personal data, no sharing with data brokers
  • No tracking cookies or analytics scripts on this website — it sets no cookies at all
  • The app itself uses only strictly necessary cookies: short-lived session cookies that keep you signed in
  • We never look inside the documents you deliver except when required to investigate an abuse report or comply with a legal obligation

5. Why we process data (legal bases)

We process account and client data to provide the service you signed up for (performance of a contract, Art. 6(1)(b) GDPR). Audit logs, abuse prevention, and platform security rest on our legitimate interest in running a safe, verifiable delivery platform (Art. 6(1)(f)). Invoices and payment records are kept to meet tax and bookkeeping obligations (Art. 6(1)(c)). Where we rely on consent — for example optional product updates — you can withdraw it at any time.

6. Where your data lives

Documents are stored in a private Cloudflare R2 bucket, encrypted at rest with AES-256 and in transit with TLS. Our database runs on Neon PostgreSQL in the EU. Every tenant’s data is isolated at the database level with row-level security. Our subprocessors are Cloudflare (hosting, storage, delivery), Neon (database), Stripe (payments and payouts), and Postmark (transactional email). Each processes data under a data processing agreement with appropriate safeguards, including EU Standard Contractual Clauses where transfers outside the EEA occur.

7. How long we keep it

Delivered documents are automatically deleted after a retention window that depends on the account holder’s plan — 14 days (Free), 30 days (Basic), or 90 days (Pro) after the last download (or after upload, if never downloaded). A deletion record is kept so account holders can prove what was removed and when. Account data is kept for as long as the account exists and removed when it is closed, except invoices and payment records, which we retain for the statutory period under Dutch tax law (currently 7 years). Access logs are kept for the life of the related project.

8. Your rights

Under the GDPR you can request access to, correction of, or deletion of your personal data, ask us to restrict or object to processing, and receive your data in a portable format. Write to mail@docman.online and we will respond within one month. If you believe we handle your data unlawfully, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.

9. Security

Access to documents requires authentication — clients sign in through single-use magic links, and every download is checked against payment status and access grants before a single byte is served. Files are encrypted at rest and in transit, tenants are isolated with enforced row-level security, and all access attempts, including denied ones, are logged. Found a vulnerability? Report it to mail@docman.online and we will respond promptly.

10. Changes to this policy

We may update this policy as the product and the legal landscape evolve. Material changes are announced to account holders by email. The date at the top always reflects the latest revision.

Contact

Privacy questions and data requests: mail@docman.online
Abuse and copyright notices: abuse@docman.online