Privacy notice
What DocuDriver collects, why, where it goes, how long it is kept, and what you can ask of us. Last updated 2026-09-18. 1 item marked for completion.
This notice explains what DocuDriver collects when an organisation uses the service, why, who can see it, how long it is kept, and what you can ask of us. It is written for the people who sign in and for the institutions that contract for the service. It is a draft awaiting legal review and will be dated and versioned once published.
Who we are
DocuDriver is operated by DocuDriver (the company details, registered address, and privacy contact will be completed here before the first contract). Questions about this notice go to the support address on the Help and support page.
For a workspace, the organisation that contracted for it is the controller of the data in it. DocuDriver processes that data on the organisation's instructions under a data processing agreement, and this notice describes how.
What DocuDriver is for, and what it never does
DocuDriver keeps the documentation behind analytics deliverables: report definitions, data model files, SQL, packages, notebooks, and Office documents. It builds a data dictionary from that documentation and answers questions about it. The documents describe systems; they are not the systems.
DocuDriver never connects to the databases those documents describe, never extracts rows of data from them, and never stores student, employee, or customer records. Extraction keeps structure and metadata only: table and column names, measures, relationships, and descriptions. This is a design rule, checked on every update, not a setting.
Because of that rule, DocuDriver does not receive education records in the sense of FERPA. If a document a person uploads happens to contain personal data (a screenshot of a report with names in it, for example), the retention rules and deletion described below apply to it, and the workspace's owner can remove it at any time.
What is collected
| Data | Why | Where it comes from |
|---|---|---|
| Account details: name, email address, password hash, two-factor secret (encrypted), profile picture if you add one | To sign you in and show who did what | You, or your organisation's directory when single sign-on or provisioning is on |
| Memberships and roles in each workspace | To decide what you may see and do | Your workspace owner or your organisation's directory |
| Uploaded documentation and the metadata extracted from it, dictionary entries, review decisions | The service itself | The people in your workspace |
| Questions asked of the assistant and the answers given, with the sources cited | So the answer can be shown again, reviewed, and audited | You, when you ask |
| Audit log: who did what and when in a workspace | Accountability; your organisation can read it at any time | Generated by the service |
| Sign-in trail: sign-ins, failed attempts, lockouts, two-factor changes, with the network address | To protect accounts from abuse and to show you where you are signed in | Generated by the service |
| Workspace configuration, including any model key or identity provider secret your organisation stores (encrypted) | To run the workspace the way your organisation configured it | Your workspace owner |
| Support requests | To answer them | You, when you write to us |
DocuDriver does not use cookies for advertising or tracking. One cookie holds your session; a second, when your organisation uses single sign-on, carries the sign-in through the identity provider and expires in minutes.
Where it is processed and by whom
Data is processed on servers operated for DocuDriver by the providers below. Each provider holds its own security attestation, and none receives more than it needs to run its part of the service.
When the assistant answers a question, the question and the documentation passages it is grounded on are sent to a model provider. By default that is the provider named in the AI use statement, under commercial terms that forbid training on the content. A workspace owner may instead connect the organisation's own model account, in which case those requests go to that account under the organisation's own agreement, and DocuDriver stores the key encrypted and never displays it again.
DocuDriver's own staff can read a workspace's audit log and configuration for support, cannot read secrets, cannot change a workspace's data, and every such look is written into that workspace's own audit log where its owner can see it.
How long it is kept
Uploaded documentation follows the retention rules the workspace sets: documents can be flagged for review, archived, or deleted after a period, deleted documents wait in a window during which they can be restored, and a legal hold freezes all of that. Owners see every step in the audit log.
The audit log is kept for the life of the workspace and cannot be edited or deleted, by DocuDriver or by the organisation; an owner can hide older rows from their own view, and that is recorded too.
The sign-in trail is kept for 400 days and then removed automatically.
Account details are kept while the account exists. Questions and answers are kept with the workspace.
At the end of a contract
The organisation can export its dictionary and its audit log at any time. When a contract ends, DocuDriver exports the workspace's data on request, deletes the workspace and every row belonging to it, purges its stored files, and confirms in writing, within thirty days of the request.
Your rights
You can see and change your own name, picture, and security settings on your Profile page, and see where you are signed in. For anything else about your data, ask your workspace owner first, because the organisation is the controller; if you would rather ask us directly, write to the support address and we will answer within thirty days. Where a law gives you rights of access, correction, or deletion, we will help the organisation honour them.
If something goes wrong
If DocuDriver learns of a breach affecting an organisation's data, it tells that organisation without undue delay and within 72 hours of confirming it, with what is known, what was affected, and what is being done. The incident response plan describes the steps in full.
Changes to this notice
The date at the top changes when the notice does. Material changes are announced to workspace owners before they take effect.