Legal

Customer data policy

Effective October 1, 2026Docksy Labs

The operating rules for customer records, document processing, AI, retention, and export.

Ownership and authority

Customers retain ownership of their content. A workspace owner must have authority to upload or connect each record and is responsible for assigning its permitted data class. Paxo does not treat a document, AI output, email domain, or provider login as business authorization.

Storage and originals

Customer workspaces covered by this policy use the United States data region. Uploaded files enter quarantine, receive a full-content malware and structural safety check, and are not available to users or downstream processors until that check succeeds. A clean original is preserved separately with immutable-write evidence. Previews, OCR, and extracted text remain traceable to the exact original version and hash.

Default retention

Unless a signed order or workspace policy specifies a longer period, active customer records and their immutable originals are retained for 365 days from their most recent governed record event. An immutable original cannot be shortened below the platform's 30-day protection floor. At the end of the applicable period, Paxo schedules eligible data for deletion unless a documented legal hold, unresolved reconciliation, security incident, or other binding obligation requires continued retention.

Disconnecting an integration stops new synchronization but does not silently delete records already accepted into the workspace. Workspace export and deletion requests remain subject to the same retention and hold rules.

AI and document processing

Paxo sends only the authorized, bounded evidence required for the feature a user invokes. AI responses are requested without provider-side response storage where the provider supports it. Customer content is not used to train shared models without a separate explicit agreement. AI may answer with citations or prepare a proposal; it cannot approve or execute a business command.

Connected providers

A workspace owner chooses each provider and reviews the exact read operations before synchronization starts. Credentials are isolated from customer records. Disconnect and provider revocation stop new work; ambiguous financial or external effects enter reconciliation instead of being replayed blindly.

Access, export, and deletion

Tenant and role checks apply on every customer request and worker operation. Workspace owners can request a portable export and deletion of eligible records. Audit evidence may be retained when required to prove access, approval, security, reconciliation, or deletion, but it must not contain provider credentials or unnecessary document content.

Contact

Questions or customer-data requests can be sent to privacy@docksy.io. Material policy changes receive a new version and require fresh acceptance where applicable.