1. Company and scope
The controller for this Policy is the company providing the Docxkeeper service, legally registered with the Companies Registration Department in Baghdad and based at Baghdad – Al-Mansour, Iraq. It is referred to in this Policy as “the company” or “the service provider.”
This Policy applies to the Docxkeeper website, download pages, contact requests, product-related accounts and services, and synchronization when a customer chooses to enable it. An approved written customer agreement may contain more specific provisions for that customer’s data and will govern within its scope where it conflicts with this Policy.
2. Privacy of your document files
Document files are at the heart of Docxkeeper. Their protection is designed so that the synchronization server does not store them in their original, readable form.
Docxkeeper encrypts protected document file content with AES-256-GCM before synchronization. The content is transferred as encrypted data, and the copy stored on the synchronization server remains encrypted.
The synchronization server does not store the raw decryption keys required to read document content, and the passphrase for the customer’s Recovery Kit is not uploaded to the server. As a result, document content cannot be read using the data held on the server alone.
Files are opened and decrypted on organization-authorized devices that possess the required keys, or through an authorized recovery process using recovery information retained by the customer.
3. Local work and synchronization
If synchronization is not enabled, document files and work data remain within the local Docxkeeper environment managed by the organization.
When synchronization is enabled, document files are sent to the synchronization service only after their content has been encrypted, and the server stores those files in encrypted form. Mentioning synchronization in this Policy does not mean it is enabled automatically for every customer or user.
4. Operational data needed for synchronization
When synchronization is enabled, the server processes the organizational and operational data needed for the enabled functions, such as organization, account, permission, device, activation, entitlement, synchronization-state, and support data.
This differs from document-file content and data covered by client-side encryption. Document-file content is transferred and stored in encrypted form, and any protected data covered by that encryption reaches the server as ciphertext rather than in readable form. Operational data needed to manage the service remains processable within the enabled function; this does not mean that the server possesses the keys needed to decrypt document-file content.
Authorized administrative or legal access to service data is governed by the relevant permissions, agreements, and applicable obligations.
5. Account and organization data
Where the relevant services are used, Docxkeeper may process the information needed to manage organizations, accounts, users, departments, permissions, registered devices, activation and entitlement status, synchronization, and support.
We use this information to operate the account and service, verify authorized access, apply the organization’s settings, and provide assistance when requested. Not every customer or user enables every connected service.
Docxkeeper may send limited operational and technical data to its servers as needed to manage licensing, devices, synchronization, support, and service reliability. These operational usage summaries do not include document content, file names, or details of records kept within the customer’s archive, and they are not used to create personal monitoring of the organization’s employees or to analyze the content of their work.
6. Contact and trial requests
When you contact us or request a trial or quotation, we use the information you provide—such as your name, organization name, email address, phone number, request type, and message—to respond and follow up on your request.
Submitting the contact form or acknowledging this Policy does not mean that you consent to unsolicited marketing messages. Optional fields may be left blank; required fields are needed to process the request.
7. Download requests and email verification
When you request Docxkeeper through the website, we ask for your full name, email address, and intended use. You may also provide a company, organization, or entity name. We send a link to verify that you control the email address; your name, intended use, and organization name are self-declared information and are not represented as independently verified.
We store the normalized email address, full name, intended use, organization name if supplied, language, first and latest request times, request count, email verification time, first and latest download-start times, and download count.
We also store the current marketing-consent state, when it was updated, the consent-text version, and when a positive consent was linked to the verified email. We do not treat a new or changed opt-in as valid for marketing until the matching request link is used and the email is verified; withdrawal takes effect immediately. Marketing consent is separate from downloading: you may decline or change it without losing access to the download request. The verification and download email is an operational message required to complete your request, not a marketing message.
The verification link is valid for 30 minutes and one use. We generate a cryptographically strong random token and store only its SHA-256 hash, together with creation, expiry, and consumption timestamps—not the raw token. This download-verification system does not store IP addresses or device or browser fingerprints. You can withdraw marketing consent through support@docxkeeper.com.
8. Technical data and service providers
The technical infrastructure supporting the website and service processes certain connection and request information needed for operation, security, fault diagnosis, and prevention of misuse.
The website uses an automated-abuse protection service before accepting certain requests.
The company uses hosting, email, DNS/CDN, protection, and other technical service providers needed to operate certain website and service functions. Those providers may process the information technically necessary to deliver their services, subject to their applicable commitments and policies.
The company may use aggregate statistics to understand how many times an application download is started and to improve the service. This counter is not used to store customer document content or create personal profiles about visitors.
Access by authorized personnel or contractors is limited to what is needed for support, operations, or protection of a lawful right within permitted limits.
Where an enforceable legal obligation applies, the company may disclose only the data it actually holds and only to the extent required by law. In protection modes where the company does not hold the decryption keys, what can be provided may be limited to operational data and encrypted content stored by the company; this does not mean that the company has the technical ability to decrypt customer content.
9. Why we use data
- Operate the website and provide the application download.
- Send the operational verification message, verify the email address, and carry out the requested download start.
- Send Docxkeeper news and offers only where separate marketing consent has been given.
- Manage accounts, activation, entitlements, devices, and services the organization chooses to use.
- Provide synchronization across registered devices when enabled.
- Respond to trial and quotation requests, inquiries, and support needs.
- Protect the website and service, prevent misuse, diagnose faults, and improve performance.
- Meet applicable contractual or legal obligations and establish, exercise, or defend rights.
- Use aggregate information to understand service operation and improve Docxkeeper.
10. Retention
We retain contact data for as long as needed to respond to and reasonably follow up on the request and maintain relevant operational or legal records. We then delete or minimize it unless applicable law, a dispute, or an enforceable agreement requires longer retention.
We retain download-request, verification, download-start, and consent records for as long as reasonably needed to operate downloads, manage consent and communications, protect the service, and meet applicable legal obligations, then delete or minimize them when no longer needed. A link becomes unusable after 30 minutes; its hashed verification record and timestamps may remain for operational and security records without retaining the raw token.
Retention of account, service, and encrypted synchronized document-file copies depends on service status, customer instructions, the approved agreement, and applicable operational, security, and legal requirements.
Aggregate statistics that do not identify an individual may be retained to measure and improve the service.
11. Protecting data
Docxkeeper uses technical and organizational measures appropriate to its current architecture and the nature of the data. These include encrypting document file content before synchronization, managing access, permissions, and registered devices, protecting website and service requests, and limiting operational access where needed.
These measures do not mean that Docxkeeper protects a customer device against compromise of the operating system itself. The customer is responsible for protecting Windows, controlling Administrator privileges, protecting against malware, spyware, and ransomware, and securing the physical device and local accounts.
To the maximum extent permitted by law, the company is not liable for data exposure or damage resulting from compromise of the customer environment or from software operating with device privileges outside the application boundary.
Organizations manage their users, devices, permissions, and recovery information through the product’s available controls and their internal procedures.
No technical measure, storage method, or electronic communication can be guaranteed to be completely secure.
12. Customer and user rights
Depending on the applicable circumstances and legal requirements, you may request information about personal data relating to you, ask for inaccurate data to be corrected, or request deletion, restriction, or objection to certain processing. Send requests to support@docxkeeper.com; we may request proportionate information to verify identity and authority before acting.
You may also withdraw marketing consent at any time through support@docxkeeper.com. Withdrawal does not affect your ability to request Docxkeeper or the operational messages required to complete a new download request.
Where an account is managed by an organization, some requests may need to be submitted through or coordinated with that organization’s authorized administrator to protect the organization and its users.
Organizations can manage their users, devices, departments, permissions, and service-data requests according to their agreement and available product capabilities.
13. Contact and updates
For privacy questions or requests, email support@docxkeeper.com or use the contact section of the website.
We may update this Policy when the product, service, or applicable requirements change. The revised version will be published with its effective date. An update to this page does not retroactively amend an enforceable written agreement except as provided by that agreement and applicable law.