Terms of service
The agreement between DocuDriver and the organizations and people who use it: what the service is, what you may and may not put in it, how AI models are involved, fees, and the limits of our responsibility. Last updated 2026-10-06. 2 items marked for completion.
These terms are the agreement under which DocuDriver is provided. They apply to the organization that contracts for a workspace (the Customer) and to every person who signs in (a User). By creating an account, accepting an invitation, signing in through your organization's identity provider, or clicking Accept where these terms are shown, you agree to them. If you are accepting for an organization, you confirm that you have the authority to do so. If you do not agree, do not use the service.
1. Definitions
Service means the DocuDriver software offered at docudriver.app and any workspace address under it, including the assistant, the data dictionary, retention tools, and every related page, interface, and command we provide.
Workspace means a sealed area of the Service that belongs to one Customer, holding its documents, dictionary, members, and settings.
Customer means the organization that contracts for one or more workspaces, whether on a paid plan, a trial, or a license key we issued.
User means any person who holds an account on the Service, including the Customer's owners, admins, editors, and viewers.
Customer Content means everything a Customer or its Users put into the Service: uploaded files, the text and metadata extracted from them, dictionary entries and definitions, questions asked of the assistant, settings, and anything else they create there.
Output means text the Service produces, including answers from the assistant, proposed dictionary entries, summaries, comparisons, and review findings.
Model Provider means a third party whose language model the Service calls to produce Output: the provider behind the model included in a plan, or a provider the Customer chooses by entering its own API key.
Plan means the subscription, trial, or license under which a workspace is provided, with its allowances for storage, questions, and workspaces.
2. The Service, and what it is not
DocuDriver keeps the documentation behind analytics and reporting work (report definitions, data model files, SQL, packages, notebooks, policies, procedures, and Office documents), builds a data dictionary from it, applies retention rules and legal holds to it, and answers questions about it with citations to the Customer's own documents.
The Service reads the documents you give it. It does not connect to the databases, warehouses, or systems those documents describe, does not extract rows of data from them, and is not a system of record for any data they hold. The documents describe systems; they are not the systems.
The Service is in beta. Features may change, be added, or be withdrawn, and we may suspend the Service for maintenance. We tell Customers of material changes through the Service or by email to workspace owners.
3. Accounts and access
Each User must have their own account. Accounts are not shared, and the Customer is responsible for every action taken under its Users' accounts, whether or not it authorized the action.
The Customer's owners decide who is a member of a workspace, what role they hold, and which collections each member may see, ask about, or download. These grants are the Customer's own access control decisions. We provide the tools; the Customer decides who sees what.
Users must keep their passwords and two-factor devices private, use the two-factor and single sign-on options the Customer requires, and tell the Customer's owner promptly if they believe an account has been compromised. Workspace owners may require two-factor authentication, set session timeouts, and deactivate or remove members at any time.
A User may hold accounts in more than one workspace. Nothing in one workspace is visible from another.
4. Customer Content and ownership
The Customer owns its Customer Content. We claim no rights in it beyond those needed to provide the Service.
The Customer grants us a non-exclusive, worldwide license to store, copy, extract, index, transmit, and display Customer Content as needed to provide the Service to the Customer and its Users, including sending relevant parts of it to a Model Provider as described in section 6, and to make backups. This license ends when the Customer Content is deleted from the Service and from our backups in the ordinary course.
We do not use Customer Content to train models, do not sell it, and do not use it for any purpose other than providing, securing, and supporting the Service.
The Customer confirms that it has the rights needed to put its Customer Content into the Service and to let the Service process it as these terms describe, including any rights of third parties whose material appears in it.
5. Content that must not be put into the Service
The Service is built for documentation about systems, not for the data inside those systems, and not for information about people. It is not designed, secured, or certified for sensitive or regulated data, and you must not put such data into it. In particular, do not upload, paste, or type into the Service:
- Personal information about individuals beyond the business names and work contact details of the people doing the work, such as lists or records of students, employees, patients, customers, or donors, or any file that contains such records.
- Education records in the sense of FERPA, or any record about an identifiable student.
- Health information of any kind, including anything covered by HIPAA.
- Payment card numbers, bank or financial account numbers, or any data covered by PCI DSS.
- Government identifiers such as Social Security, passport, driver's license, or national identity numbers.
- Passwords, API keys, tokens, private keys, connection strings with credentials, or any other secret, other than the Model Provider key you enter in the place the Service provides for it.
- Data subject to export control, or data you are forbidden by law or contract to disclose to a third party.
- Material you do not have the right to use.
The Service extracts structure and metadata from documents by design and keeps no rows of data, but a document can carry anything, and the Service cannot tell what is in a screenshot, a spreadsheet of records, a comment, or a question. The Customer and its Users are solely responsible for what they put into the Service, for reviewing documents before uploading them, and for removing anything that should not be there. Owners can delete any document; deleted files stay recoverable for the purge window the owner sets and are then removed from storage. We are not responsible for sensitive or regulated data that a Customer or User puts into the Service in breach of this section, for its processing by the Service or by a Model Provider, or for any loss, claim, fine, or obligation that results.
If you believe such data has been put into a workspace by mistake, delete it, release any hold on it, run the retention sweep, and tell us through the Help and support page so we can confirm its removal from backups.
6. How AI models are involved
The assistant, dictionary proposals, comparisons, reviews, and similar features work by sending material from your workspace to a Model Provider and showing you what it returns. This is how the product works, and you should assume it happens whenever you use those features. The material sent includes passages of your documents chosen for the question, dictionary definitions, the question itself, and, for a review or comparison, the sections being judged. The whole of a document is not sent at once, but any part of it may be, and over time most of it may be.
The model included in your Plan. Unless the Customer chooses otherwise, Output is produced by the Model Provider we select, under our agreement with that provider, which we name in the AI use statement. We choose providers that commit not to train on data sent through their API and that delete it after a short retention period, and we pass those commitments on to you only to the extent the provider gives them to us.
Your own key. A workspace owner may instead enter the Customer's own Model Provider account key under Workspace settings, Assistant model. From then on the material is sent to that provider under the Customer's own agreement with it, billed to the Customer's own account, and the Customer is responsible for that provider's handling of it. We store the key encrypted, use it only for the Customer's own questions, and never show it again.
In either case the Model Provider is a third party. We do not control how it processes what it receives beyond the terms of our or your agreement with it, and we are not responsible for its acts or omissions. The Customer decides what goes into its workspace knowing that its contents may be sent to a Model Provider, and section 5 applies with full force to that decision.
7. Output
Output is generated by a language model from the material it is given. It can be wrong, incomplete, out of date, or misleading, even when it cites a document, and it can describe a document's contents inaccurately. Output is information, not advice: it is not legal, financial, compliance, medical, or professional advice, and the Service is not a substitute for reading the documents or consulting a qualified person. The Customer and its Users are responsible for checking Output before relying on it, and for any decision made on the strength of it.
Approved dictionary entries are the Customer's own curated definitions. Approving an entry is the Customer's statement that the definition is right; the Service then cites it as authoritative.
8. Acceptable use
You must not use the Service to break any law; to store or distribute material that is unlawful, infringing, or harmful; to probe, scan, or test the security of the Service or interfere with its operation; to access another Customer's workspace or data, or attempt to; to reverse engineer, copy, or resell the Service; to send the Service's Output to a Model Provider in a way that breaches that provider's terms; or to upload malware or deliberately malformed files. We may remove content and suspend accounts that breach this section, and we tell the Customer's owners when we do.
9. Security, availability, and the Customer's responsibilities
We take reasonable technical and organizational measures to protect Customer Content, including encryption in transit and at rest, workspace isolation enforced in the database, envelope encryption of stored secrets, audit logging, and the controls described on our Trust and compliance page. We do not promise that the Service is free of defects or that unauthorized access will never occur.
The Customer is responsible for its own access decisions (members, roles, grants, hierarchy), for the strength and secrecy of its Users' credentials, for turning on the security options it needs, for the content it uploads, and for exporting anything it needs to keep before a workspace ends.
The Service is provided from infrastructure we select; the regions and subprocessors in use are listed in the privacy notice. We may change them with notice to workspace owners.
Support access. To resolve a support request, a named member of our support staff may sign in to a workspace as one of its Users. Every such session is limited in duration, requires a recorded reason, is announced to the workspace's owners by email when it starts and when it ends, and is written in full into the workspace's audit log: the session itself, every change made during it attributed to the staff member by name, and every document, dictionary entry, access record, member list, settings page, or export viewed. The record is kept for the life of the workspace and after it. A workspace owner may turn support access off at any time under Workspace settings, in which case our staff can only advise.
10. Fees and payment
Plans, prices, allowances, and add-ons are those shown in the Service at the time of purchase. Subscriptions are billed in advance for each period, monthly or yearly as chosen, and renew automatically until canceled. Cancelling stops the next renewal; the current period runs to its end and is not refunded. Question packs are one-time purchases, drawn on only after the Plan's monthly allowance, and do not expire; they are not refundable once bought.
Changing a Plan or adding a workspace in the middle of a period is charged at once for the difference and the new rate applies from the next period. Prices may change with at least thirty days' notice; a change takes effect at the next renewal.
Fees exclude taxes. The Customer is responsible for any sales, use, VAT, or similar tax, which we add where we are required to collect it. If a payment fails, we tell the Customer's owners and retry; if it remains unpaid after the grace period shown in the Service, the workspace becomes read-only until it is paid, and may be ended under section 11.
Customers on an invoiced agreement or a license key we issued pay under that agreement, and the terms of the agreement govern fees where they differ from this section.
11. Term, termination, and what happens to the data
These terms apply for as long as the Customer has a workspace or a User has an account.
The Customer may cancel a subscription or end a workspace at any time from Account and billing or by asking us. We may end a workspace or an account on thirty days' notice, or at once if the Customer or a User breaches sections 5 or 8, fails to pay after the grace period, or if we are required to by law. Where we end the Service for convenience we refund any prepaid fees for the period after the end date.
At the end of a workspace the Customer may export its dictionary and audit log from the Service, and may ask us for a copy of its documents, for thirty days. After that the workspace and its content are deleted from the Service, and from backups in the ordinary cycle, which is no more than thirty further days. Sections 4 (license to the extent needed for deletion), 5, 6, 7, 12, 13, 14, 15, 16, and 17 survive the end of these terms.
12. Confidentiality
Each party will keep the other's confidential information private and use it only for these terms. Confidential information includes Customer Content, the Customer's configuration, and our non-public technical and business information, but not information that is public, already known to the receiving party, independently developed, or lawfully received from someone else. Either party may disclose confidential information when the law requires it, telling the other first where it may.
13. Intellectual property
We own the Service, its software, documentation, design, and all improvements, and every right in them not expressly granted here. The Customer may use the Service during the term for its internal business purposes under these terms, and for nothing else. If a Customer or User gives us a suggestion or feedback, we may use it without obligation.
14. Warranties and disclaimers
We warrant that we provide the Service with reasonable skill and care. Beyond that, the Service and all Output are provided as is and as available, and we disclaim every other warranty, express or implied, including merchantability, fitness for a particular purpose, non-infringement, accuracy, and uninterrupted or error-free operation. We do not warrant that Output is correct, that the dictionary is complete, that retention rules will meet any legal retention requirement of yours, or that the Service is suitable for any sensitive or regulated data (it is not; see section 5).
15. Limitation of liability
To the fullest extent the law allows, neither party is liable to the other for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill, however caused and under any theory, even if told of the possibility. Our total liability under these terms, for everything together, is limited to the fees the Customer paid us for the Service in the twelve months before the event giving rise to the claim, or one hundred US dollars where no fees were paid. These limits do not apply to a party's breach of section 12, to a Customer's breach of section 5 or 8, to its indemnity under section 16, or to liability that cannot be limited by law.
16. Indemnity
The Customer will defend and indemnify us against claims, losses, fines, and costs (including reasonable legal fees) arising from Customer Content, from a breach of sections 5 or 8, from the Customer's or its Users' use of the Service in breach of these terms or of the law, or from a Model Provider's claim arising from the Customer's use of its own key. We will defend and indemnify the Customer against a third party's claim that the Service itself, used as these terms allow, infringes that party's intellectual property, except where the claim arises from Customer Content or from a combination with something we did not supply.
17. General
Changes to these terms. We may update these terms. When we do, the new version is shown to every User at their next sign-in and must be accepted before the Service is used again; the version and the date of each acceptance are recorded. Continued use after accepting is agreement to the new version. If a Customer does not agree, it may end its workspace under section 11.
Governing law and disputes. These terms are governed by the laws of the State of Texas, without regard to its conflict of laws rules. The state and federal courts in Harris County, Texas have exclusive jurisdiction over any dispute, and each party submits to it, except that either party may seek injunctive relief in any court to protect its confidential information or intellectual property. Before starting proceedings, the parties will try in good faith to resolve the dispute by discussion between people with authority to settle it, for at least thirty days.
Notices. Notices to the Customer go to its workspace owners' email addresses. Notices to us go to the address on the Help and support page, or to the notices address above once completed.
Whole agreement. These terms, the privacy notice, the AI use statement, and any order, invoice, license agreement, or data processing agreement between us form the whole agreement about the Service and replace earlier discussions. Where a signed agreement between us and the Customer differs from these terms, the signed agreement governs for that Customer.
Assignment. The Customer may not assign these terms without our consent, which we will not withhold unreasonably. We may assign them to a successor to the Service on notice.
Severability and waiver. If a provision is unenforceable, the rest stand. A party's failure to enforce a provision is not a waiver of it.
Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, except for payment obligations.
Export and sanctions. The Customer must not use the Service in breach of export control or sanctions law, and confirms that it and its Users are not on any sanctions list.
18. Contact
Questions about these terms go to the support address on the Help and support page. The privacy notice explains what we collect and why; the AI use statement explains what the assistant does and never does; the Trust and compliance page lists our controls and evidence.