DocuPipe Privacy Notice for EEA/EU, UK, and Swiss Residents

Effective Date: Jul 28, 2025

Hoss, Inc. (“DocuPipe”, “we”, “us”, or “our”) provides software services for document parsing, data extraction, and customer relationship management. This Privacy Notice is intended for residents of the European Economic Area (EEA), the European Union (EU), the United Kingdom (UK), and Switzerland, and supplements our general Privacy Notice.

This Notice describes how we collect, use, disclose, and retain personal data in accordance with the General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection. It applies to both:

  • Personal information you provide when registering or using your DocuPipe account (where DocuPipe acts as a data controller), and
  • Documents and extracted content you upload to our platform for processing (where DocuPipe acts as a data processor on your behalf).

1. Roles and Responsibilities

DocuPipe is the controller of your account-related personal information (e.g., name, email, IP address, login activity) for the purposes of providing access to the DocuPipe platform, securing your account, and communicating with you.

However, when you upload documents to our platform and initiate data extraction workflows, DocuPipe acts solely as a processor on your behalf. You, the customer, are the controller of any extracted data or document content. We process such content strictly according to your instructions and do not access, use, retain, or disclose it except as necessary to provide our services or comply with applicable law.

2. Legal Basis for Processing

We process your personal information based on the following lawful bases under applicable data protection laws:

  • Performance of a contract: To provide you with access to and operation of your DocuPipe account and services.
  • Legal obligation: To comply with legal and regulatory requirements.
  • Legitimate interests: To maintain and improve the security, reliability, and functionality of our platform.
  • Consent: Where required (e.g., for certain cookies or optional communications).

3. Your Document Content and Extracted Data

When you upload documents and initiate data extraction, DocuPipe processes that content exclusively on your behalf as a processor. All extracted data, including structured or unstructured financial information, remains under your sole ownership and control. DocuPipe does not access, analyze, share, or use that content for any marketing, profiling, training, or product development purposes.

You, as the customer, are empowered through your account with administrative control to manage, export, restrict, or permanently delete extracted document data at any time. DocuPipe will act on your instructions accordingly, unless retention is required by law.

4. International Transfers

If we transfer your personal data outside the EEA, UK, or Switzerland (for example, to our cloud infrastructure providers in the United States), we do so pursuant to lawful transfer mechanisms such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission or UK authorities
  • An adequacy decision by the relevant data protection authority
  • Binding corporate rules or other approved safeguards

5. Your Rights

Subject to applicable law, you have the following rights regarding your personal data processed by DocuPipe as a controller:

  • The right to access and obtain a copy of your personal data
  • The right to rectify inaccurate or incomplete data
  • The right to request deletion (“right to be forgotten”)
  • The right to restrict or object to processing in certain circumstances
  • The right to data portability
  • The right to withdraw consent at any time (where processing is based on consent)
  • The right to lodge a complaint with your local data protection authority

For document content and extracted data where DocuPipe acts as a processor, you, the customer, are responsible for responding to any applicable data subject rights requests. DocuPipe will assist you in fulfilling those requests if needed, as required by Article 28 of the GDPR.

6. Disclosures to Third Parties

We may disclose your personal information (not including document content) to service providers and subprocessors that help us operate our platform, such as hosting providers, payment processors, and support vendors. All such third parties are bound by contractual obligations to protect your data in accordance with this Notice and applicable law.

We will not disclose, share, or transfer your uploaded documents or extracted content to any third party, except:

  • As explicitly instructed by you
  • As required by law, court order, or regulatory demand

7. Government and Legal Requests

If we receive a legally binding request from a public authority for access to your personal data, we will:

  • Promptly notify you, unless prohibited by law
  • Challenge the request if we believe it lacks legal basis or is overbroad
  • Disclose only the minimum amount of data required to comply with the request

We maintain a record of all such requests and will make them available to the competent supervisory authority upon request.

8. Retention

We retain your account-related personal information for as long as necessary to provide services, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data at any time.

Uploaded documents and extracted data are retained solely under your control. You may permanently delete such content via your account interface. DocuPipe does not retain or replicate extracted data for internal purposes.

9. Contact Information

If you have questions or requests related to your personal data, contact us at:

© 2025 Hoss Inc. All rights reserved.TermsPrivacy