Legal

Privacy Policy

Effective date: 18 July 2026

1. Who we are

DocIQ is operated by NeoFlow IT Services ("we", "us", "our"). DocIQ is an AI-powered document intelligence platform for procurement teams. Our registered contact is hello@dociq.ai.

This policy applies to the DocIQ application at dociq.neoflow.inand any related APIs or services.

2. Data we collect

Account information

Email address, full name, organisation name, and role — collected when you register.

Documents you upload

PDFs, Excel sheets, scanned images, and ZIP packages you upload for processing. These are stored encrypted on our self-hosted servers (Hetzner VPS, India region).

Usage and audit logs

Actions within the application (uploads, comparisons, exports) logged with timestamps for audit trail purposes. IP address and user-agent are recorded at login.

Payment information

We do not store payment card details. Billing is handled by third-party payment processors.

3. How we use your data

  • To provide the DocIQ service — extract, compare, and analyse your documents
  • To authenticate your account and enforce role-based access controls
  • To generate audit logs for your organisation's compliance requirements
  • To send service-related notifications (extraction complete, comparison ready)
  • To investigate errors and improve system reliability

We do not use your documents or extracted data for advertising, profiling, or sale to third parties.

4. AI processing and third-party services

To extract data from your documents, the text content is sent to third-party AI APIs including OpenRouter (which routes to models including DeepSeek and Anthropic Claude) and Ollama (local, on-server).

Document content sent to OpenRouter and its upstream providers is transmitted over encrypted connections. We do not authorise these providers to use your document content for model training. You should review their respective data processing agreements for their specific guarantees.

Extracted results (comparison matrices, ESG scores, bid recommendations) are stored exclusively on our self-hosted infrastructure and are not shared with any third party.

5. Data storage and security

  • All data is stored on self-hosted servers hosted in Europe (Hetzner). We do not use AWS, Google Cloud, or Azure.
  • Data is encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Access is restricted by role (Viewer / Editor / Admin) and tenant isolation
  • All administrative actions are recorded in an immutable audit log

6. Data retention

Document files and extracted data are retained for the duration of your subscription and for 30 days after account deletion or subscription cancellation, after which they are permanently deleted.

Audit logs are retained for 90 days for compliance purposes. Account metadata (email, organisation) is retained for 7 years to comply with applicable tax and regulatory requirements.

7. Your rights

Under the Digital Personal Data Protection Act 2023 (India) and applicable law, you have the right to:

  • Access — request a copy of your personal data (available via account settings export)
  • Correction — request correction of inaccurate data
  • Erasure — request deletion of your account and personal data (DPDP Art. 17 / GDPR Art. 17)
  • Data portability — export your data in a machine-readable format (GDPR Art. 20)

To exercise any of these rights, email privacy@dociq.ai. We will respond within 30 days.

8. Cookies

We use session cookies for authentication and preference cookies for theme settings. We do not use advertising or tracking cookies. See our Cookie Policy for details.

9. Changes to this policy

We will notify you by email and in-app notice at least 14 days before making material changes to this policy. Continued use after that period constitutes acceptance.

10. Contact

Privacy enquiries: privacy@dociq.ai
General: hello@dociq.ai