Privacy Policy

This Privacy Policy explains how Agreedock, trading as AgreeDock (“AgreeDock,” “we,” “us,” or “our”), collects, uses, shares, stores, and protects personal data when you use our website, applications, and related services.

It also explains AgreeDock’s role when businesses and individuals use the Service to create Forms and collect information or signatures from other people.

1. Who is responsible for your personal data?

AgreeDock is operated by:

Agreedock
Privacy contact: info@agreedock.com
Website: www.agreedock.com

For personal data concerning AgreeDock accounts, billing, website use, support, security, and our business operations, Agreedock is generally the data controller.

For personal data submitted through a Form created by an AgreeDock Customer, the Customer is generally the data controller and AgreeDock generally processes that information on the Customer’s behalf.

2. Scope of this Privacy Policy

This Privacy Policy applies when you:

  • visit the AgreeDock website;
  • create or use an AgreeDock account;
  • purchase or manage a Subscription;
  • communicate with our support team;
  • receive product or marketing communications from us;
  • complete a Form hosted through AgreeDock; or
  • otherwise interact with the Service.

This Privacy Policy does not govern the independent privacy practices of AgreeDock Customers, Stripe, or other third-party services.

3. AgreeDock’s different data-protection roles

AgreeDock may have different legal roles depending on the context.

AgreeDock as a controller

AgreeDock generally acts as a controller when we determine why and how personal data is processed, including when we process:

  • account-registration information;
  • billing and Subscription information;
  • communications with our team;
  • website and product-usage information;
  • security, fraud-prevention, and system logs;
  • marketing preferences; and
  • information needed to administer our business.

AgreeDock as a processor

AgreeDock generally acts as a processor when a Customer uses the Service to collect or store personal data through a Form.

In that context:

  • the Customer decides why the personal data is collected;
  • the Customer decides what information the Form requests;
  • the Customer determines the legal basis for processing;
  • AgreeDock processes the information under the Customer’s instructions; and
  • the Customer is primarily responsible for responding to privacy requests from Respondents.

4. Personal data we collect

The information we collect depends on how you interact with AgreeDock.

4.1 Account information

When you create or manage an account, we may collect:

  • first and last name;
  • email address;
  • telephone number, where provided;
  • business or organisation name;
  • account role and permissions;
  • country or billing location;
  • login and authentication information;
  • communication preferences; and
  • other information added to your account.

4.2 Subscription and billing information

When you purchase a paid plan, we may collect or receive:

  • billing name and address;
  • business name;
  • tax or VAT information;
  • selected plan;
  • billing period;
  • invoice information;
  • payment status;
  • transaction identifiers;
  • limited payment-method information; and
  • information concerning renewals, cancellations, failed payments, or refunds.

Payments are processed by Stripe or another payment provider identified during checkout. Payment-card details are provided to the payment provider and are processed according to that provider’s privacy practices.

Depending on the payment integration, AgreeDock may not receive or store complete payment-card details.

4.3 Customer Forms and Form submissions

Customers may create Forms containing:

  • text and contractual terms;
  • instructions, notices, or disclosures;
  • questions and selectable answers;
  • contact-information fields;
  • date fields;
  • checkboxes;
  • input fields;
  • signature fields; and
  • other Customer-selected content.

A Respondent completing a Form may provide:

  • first and last name;
  • email address;
  • telephone number;
  • organisation or position;
  • answers to questions;
  • acknowledgements and selections;
  • dates;
  • free-text responses;
  • signatures;
  • uploaded information, where supported;
  • submission timestamps;
  • technical information associated with the submission; and
  • any other information requested by the Customer.

The categories of personal data collected through a Form are determined by the Customer.

4.4 Technical and usage information

When you use the Service, we may automatically collect:

  • IP address;
  • device type;
  • browser type and version;
  • operating system;
  • approximate location derived from IP address;
  • language and time-zone settings;
  • pages and features accessed;
  • actions taken within the Service;
  • referring pages;
  • session and event timestamps;
  • error reports;
  • diagnostic information;
  • security events; and
  • cookie or similar-technology identifiers.

We use this information to operate, protect, understand, and improve the Service.

4.5 Communications and support information

When you contact us, we may collect:

  • your name and contact details;
  • the content of your message;
  • account or Subscription information;
  • support history;
  • screenshots or attachments you provide; and
  • information needed to investigate and respond to your request.

Please avoid sending sensitive personal data to our support team unless it is necessary.

4.6 Marketing information

Where applicable, we may collect:

  • email-marketing preferences;
  • records of consent;
  • whether you opened or interacted with a message;
  • event or campaign registration information; and
  • information you provide in surveys or promotional activities.

5. How we obtain personal data

We collect personal data:

  • directly from you;
  • from the organisation that provides your account;
  • from a Customer that creates or sends you a Form;
  • when you complete a Form;
  • automatically through the Service;
  • from Stripe and other service providers;
  • from integration partners that you connect to AgreeDock; and
  • from public sources where permitted by law.

6. Why we process personal data

Where the GDPR or similar law applies, we rely on one or more of the following legal bases.

Providing the Service

We process account, usage, support, and billing information to:

  • create and administer accounts;
  • authenticate users;
  • provide requested features;
  • store and deliver Forms;
  • manage Subscriptions;
  • process payments;
  • provide customer support; and
  • communicate about the Service.

The legal basis is normally performance of a contract or taking steps at your request before entering into a contract.

Operating and improving AgreeDock

We may process technical, usage, support, and account information to:

  • understand how the Service is used;
  • diagnose errors;
  • improve usability and performance;
  • develop new features;
  • manage capacity;
  • conduct internal reporting; and
  • maintain business records.

The legal basis is normally our legitimate interest in operating and improving the Service. Where required, we will rely on consent.

Security and misuse prevention

We process account, technical, submission, and log information to:

  • prevent fraud;
  • detect unauthorised access;
  • investigate misuse;
  • protect Customers and Respondents;
  • enforce our Terms; and
  • maintain the security and integrity of the Service.

The legal basis is our legitimate interest in protecting the Service, our users, and our legal rights. Processing may also be necessary to comply with a legal obligation.

Payments, accounting, and legal compliance

We process billing, transaction, account, and communication information to:

  • collect fees;
  • create invoices;
  • maintain accounting records;
  • comply with tax obligations;
  • respond to lawful requests;
  • establish or defend legal claims; and
  • comply with applicable law.

The legal basis may be performance of a contract, compliance with a legal obligation, or our legitimate interests.

Service communications

We may send messages concerning:

  • account access;
  • Form activity;
  • security;
  • payment status;
  • Subscription changes;
  • product updates that materially affect the Service;
  • changes to legal documents; and
  • support requests.

These communications are normally necessary to perform our contract or operate the Service.

Marketing communications

We may send product news, offers, educational content, or other marketing communications where:

  • you have consented;
  • applicable law otherwise permits the communication; or
  • we have a legitimate interest that is not overridden by your rights.

You may unsubscribe at any time using the link in the message or by contacting us.

Consent

We rely on consent where legally required, including for certain:

  • non-essential cookies;
  • marketing communications;
  • optional tracking technologies; or
  • other processing specifically presented to you.

You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.

7. Data submitted through Customer Forms

When you complete a Customer’s Form, AgreeDock generally processes your information on behalf of that Customer.

The Customer is responsible for explaining:

  • who it is;
  • why it is collecting your information;
  • what legal basis it relies on;
  • how the information will be used;
  • who will receive it;
  • how long it will be stored; and
  • how you can exercise your rights.

AgreeDock does not determine whether a Customer’s questions are necessary or appropriate.

Privacy requests concerning a Customer Form should normally be sent directly to the Customer. Where you send such a request to AgreeDock, we may forward it to the relevant Customer or assist the Customer in responding.

We may independently process limited technical or security information associated with a Form submission where necessary to secure the Service, prevent abuse, comply with law, or establish legal claims.

8. Signatures

A signature collected through AgreeDock is personal data.

Depending on how the Service is configured, a signature may be accompanied by information such as:

  • the signer’s name;
  • the related Form;
  • the submission date and time;
  • technical submission information; and
  • acknowledgements provided by the signer.

AgreeDock does not use signature images to identify individuals through biometric matching unless this is expressly introduced, explained, and supported by an appropriate legal basis.

Customers must not use signature information for unrelated purposes without a lawful basis.

9. Sensitive and special-category data

Customers control the content of their Forms and may request information that is sensitive or specially protected.

AgreeDock does not require Customers to collect such information as part of the ordinary operation of the Service.

Customers are responsible for determining whether they may lawfully collect information concerning:

  • health;
  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • genetics;
  • biometric identification;
  • sex life or sexual orientation;
  • criminal allegations or convictions;
  • government identification;
  • financial accounts; or
  • children.

We may restrict the collection of particular information where we believe the Service does not provide safeguards suitable for the proposed processing.

10. How we share personal data

We may share personal data in the following circumstances.

With Customers and their Authorised Users

Form submissions are made available to the Customer that created the Form and to people the Customer authorises to access its account.

The Customer controls access permissions within its organisation.

With service providers

We use service providers that help us operate AgreeDock, including providers of:

  • cloud hosting and data storage;
  • content delivery and networking;
  • authentication;
  • email delivery;
  • customer support;
  • system monitoring;
  • error reporting;
  • analytics;
  • security and fraud prevention;
  • backups; and
  • payment processing.

These providers may process personal data only to provide their contracted services or for other purposes permitted by applicable law.

With Stripe

Stripe processes payment and billing information when you purchase an AgreeDock Subscription.

Stripe may act as an independent controller for certain processing, including compliance, fraud prevention, and payment-network activities. Stripe’s handling of personal data is governed by its own privacy documentation.

With professional advisers

We may share information with lawyers, accountants, auditors, insurers, and other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations.

For legal and safety reasons

We may disclose information where we reasonably believe disclosure is necessary to:

  • comply with law, court orders, or lawful government requests;
  • protect the rights, safety, and property of AgreeDock, our users, or others;
  • investigate fraud, security incidents, or violations;
  • enforce agreements; or
  • establish, exercise, or defend legal claims.

Corporate transactions

Personal data may be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, insolvency, or sale of all or part of our business.

Where required, we will provide notice and continue to protect personal data in accordance with applicable law.

At your direction

We may share information where you instruct us to do so, including when you enable an integration or export information to another service.

11. International data transfers

AgreeDock is established in Lithuania, within the European Economic Area.

Some service providers may process personal data outside Lithuania or outside the EEA.

Where personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:

  • European Commission standard contractual clauses;
  • supplementary contractual, technical, or organisational safeguards; or
  • another lawful transfer mechanism.

Customers should review our Data Processing Addendum and subprocessor information for details relevant to Customer-controlled data.

12. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, meet legal obligations, resolve disputes, and enforce agreements.

Retention depends on the category of information.

Account information

We generally retain account information while the account is active and for [30 DAYS] after account closure, unless a longer period is required for legal, security, fraud-prevention, or dispute-resolution purposes.

Customer Forms and submissions

Customer Content is generally retained until:

  • the Customer deletes it;
  • the Customer closes its account;
  • the applicable plan or retention setting requires deletion; or
  • the Customer instructs us to return or delete the information.

Following deletion from active systems, information may remain in encrypted or access-restricted backups for up to [90 DAYS] before being overwritten, unless retention is required by law.

Customers are responsible for establishing appropriate retention periods for their Forms.

Billing and transaction records

Invoices, transaction records, tax information, and related records may be retained for the period required by accounting, tax, anti-fraud, and other applicable laws.

Technical and security logs

Technical, diagnostic, and security logs are generally retained for up to [12 MONTHS], unless a longer period is required to investigate an incident or establish legal claims.

Support communications

Support records may be retained for up to 24 months after the request is resolved, unless they are needed for an active account, dispute, security investigation, or legal requirement.

Marketing information

Marketing preferences and consent records are retained while relevant and for a reasonable period afterwards to demonstrate compliance. Suppression records may be retained to ensure that a person who opted out is not contacted again.

13. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, or access.

These measures may include:

  • encryption in transit;
  • access controls;
  • authentication measures;
  • infrastructure monitoring;
  • logging;
  • backups;
  • vulnerability management;
  • restricted staff access;
  • confidentiality obligations; and
  • incident-response procedures.

Security measures are reviewed based on the nature, scope, context, and risks of the processing.

No system is completely secure. Customers should use appropriate account controls, limit internal access, and maintain independent copies of records where necessary.

14. Personal-data breaches

Where AgreeDock becomes aware of a personal-data breach, we will investigate and take reasonable steps to contain and address it.

Where AgreeDock acts as a processor, we will notify the affected Customer without undue delay where required by applicable data-protection law.

Where AgreeDock acts as a controller, we will notify the appropriate supervisory authority and affected individuals where legally required.

15. Your data-protection rights

Depending on your location and the circumstances, you may have the right to:

  • receive information about how your personal data is used;
  • access your personal data;
  • correct inaccurate or incomplete personal data;
  • request deletion of personal data;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive certain personal data in a structured, commonly used, machine-readable format;
  • withdraw consent;
  • object to direct marketing; and
  • lodge a complaint with a supervisory authority.

These rights may be subject to legal conditions, limitations, and exceptions.

To exercise a right concerning data AgreeDock controls, contact info@agreedock.com.

We may request information needed to verify your identity and locate the relevant data.

We normally respond within one month, although the period may be extended where permitted for complex or numerous requests.

16. Rights concerning Customer Forms

When your request concerns information submitted through a Customer’s Form, the Customer is normally responsible for handling the request.

You should contact the Customer identified in the Form or in the Customer’s privacy notice.

AgreeDock may:

  • refer you to the Customer;
  • forward your request to the Customer;
  • assist the Customer with its response; or
  • act directly where required by law.

AgreeDock cannot normally delete a Customer-controlled record solely at a Respondent’s request without instructions from the Customer, unless AgreeDock is legally required to do so.

17. Complaints

Please contact us first at info@agreedock.com so that we can try to resolve your concern.

You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate.

You may also contact the data-protection authority in the EU or EEA country where you live, work, or believe an infringement occurred.

18. Cookies and similar technologies

AgreeDock may use cookies, local storage, pixels, software development kits, and similar technologies.

These technologies may be used for:

  • authentication;
  • account security;
  • remembering preferences;
  • maintaining sessions;
  • preventing fraud;
  • understanding product performance;
  • analytics; and
  • marketing, where permitted.

Strictly necessary technologies may be used without consent where permitted by law.

Non-essential analytics or marketing technologies will be used only where we have an appropriate legal basis, including consent where required.

Additional information should be provided in the AgreeDock Cookie Policy or cookie-preference interface.

You may adjust cookie preferences through our consent interface and through your browser settings.

19. Marketing choices

You may opt out of marketing emails by:

  • selecting the unsubscribe link in a message;
  • changing available account preferences; or
  • contacting info@agreedock.com

Opting out of marketing does not prevent us from sending necessary account, billing, security, legal, or Service-related communications.

20. Automated decision-making

AgreeDock does not currently use personal data to make decisions that produce legal or similarly significant effects based solely on automated processing.

If this changes, we will provide the information and safeguards required by applicable law.

21. Children

AgreeDock accounts are not intended for children who cannot legally enter into a contract.

Customers may create Forms intended to be completed for or concerning minors only where they have determined that the processing is lawful and have obtained parental or guardian authorisation where required.

Customers should avoid collecting information from children unless it is necessary and appropriate for the relevant purpose.

If you believe a child has provided personal data to AgreeDock unlawfully, contact info@agreedock.com

22. Third-party links and services

The Service may contain links to or integrations with third-party websites and services.

We are not responsible for the privacy practices of third parties. You should review their privacy policies before providing information or enabling an integration.

23. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to:

  • the Service;
  • our data practices;
  • our providers;
  • legal requirements; or
  • security and operational practices.

We will update the effective date when changes are made.

Where changes materially affect your rights or how we use personal data, we will provide additional notice where appropriate, such as an email, website notice, or in-product notification.

24. Contact us

For privacy questions or requests, contact:

Agreedock
Privacy email: info@agreedock.com
Website: www.agreedock.com