Privacy Policy

Last updated: September 2, 2026

We’re committed to safeguarding your privacy and ensuring the security of your personal information. This privacy policy outlines how we collect, use, and protect your data when you interact with our service.

Please take a moment to familiarize yourself with the details provided in this policy to understand how Docket handles your information. This policy describes how we collect, use, and protect your personal data.

If you have any questions or concerns regarding our data practices, please contact us at [email protected].



Thank you for choosing Docket.

Sources of personal data

1. When you sign up with Docket
    • When you sign up or leave your email ID with us through our website / web-app or other means.
2. By using our services
    • When you ask Docket questions in the Web App or Slack, we collect the following information
         I. Your e-mail ID
         ii. Questions you ask (we make sure it’s anonymized)
3. Files you upload
    • When you upload a file or link to your Knowledge Sources in Docket, Docket ingests and stores that data securely. 
    • We use ingested data in Slack to help our AI learn and answer your questions.
    • We use ingested data from your integrated apps, such as Intercom, Zendesk, Sharepoint, Google Drive, and more, to answer your questions.
    • Ingested data is deleted once you terminate your contract with Docket.

Usage of personal data

1. To respond to your enquiries, including requests for a demo submitted through our website. We use this information solely to respond to your request and to take steps prior to entering into a contract with you (GDPR Article 6(1)(b)). Demo request submissions are not used for marketing communications
2. To communicate product and company updates over email to existing customers with whom we have an active agreement, as part of performing our contract (Article 6(1)(b)) or based on our legitimate interests (Article 6(1)(f)). You can unsubscribe from these at any time.
3. Within the Docket platform, we use large-language-model providers (including OpenAI) to process conversations after removing personally identifiable information, and our agreements with these providers for such processing do not permit training on customer data. Separately, when an authorized user connects Docket MCP to an AI assistant, identified data is returned to that assistant at the user's direction, as described in "AI Assistant Apps" below.
4. To help our AI answer questions on Docket Web App and Docket Slack, and to help our AI learn and deliver accurate answers, as necessary to provide our services under our contract with your organization (Article 6(1)(b)).

AI Assistant Apps (Docket MCP)

Docket offers a connector, Docket MCP, that lets authorized users of a Docket customer access - and, where such features are enabled, act on - their organization's Docket data from AI assistants such as OpenAI's ChatGPT. Access requires signing in with existing Docket credentials; every request is limited to the user's own organization and role permissions and is recorded in an access log. Where the connector supports actions that create or change data (for example, updating a lead or booking record), those actions are performed only at the direction of the authorized user and within the same organization and role limits. For the website visitor and lead data described below, our customer determines the purposes of processing and Docket acts on the customer's behalf.

Depending on the user's request and permissions, a response may include:

1. Identifiers - internal IDs for visitors, leads, companies, conversations, meetings, and website agents.
2. Contact and professional details - names, business email addresses, job titles, and employers of website visitors and leads, and of meeting attendees.
3. Company and enrichment data - information about the companies associated with leads (such as industry, size, and location), including enrichment data obtained from third-party business-data providers and stored in Docket.
4. CRM matching identifiers - visitor tokens used to match a website visitor to the customer's own marketing and CRM systems (such as HubSpot or Marketo).
5. Sales workflow data - the team member a lead is assigned to, opportunity amount, and expected close date, where recorded.
6. Conversation content and analysis - the content of conversations between website visitors and the customer's website agents, including summaries, qualification status, engagement-based lead scores, identified pain points, products of interest, and next steps. Where the user's role permits and the user explicitly requests it, a response may include time-limited secure links to full transcripts and audio recordings (recordings contain the visitor's voice).
7. Marketing and activity data - campaign attribution (such as UTM parameters), referring pages, website journey and session data, and the consent state recorded for a visitor.
8. Meeting records - booking times, statuses (including rescheduled and cancelled), and attendee details.
9. Agent configuration and knowledge sources - website-agent settings and performance metrics. For authorized administrators who explicitly request them, responses may include agent prompts, embed configuration, and time-limited links to knowledge-source files.
10. Technical data - the signed-in user's identity, role, and access level; the organization's configured limits and the names and connection status of connected integrations; and pagination and request identifiers included in responses.

Docket's underlying customer data is retained for the duration of the customer's contract or until the customer requests deletion, whichever is earlier, as described in "Security and Retention." OAuth authorizations for the connector are retained until revoked or disconnected. MCP access logs are retained on the same basis, except where a longer period is required for security, audit, or legal purposes. Data transmitted to an AI assistant provider is retained by that provider under its own terms, privacy policy, and the user's account settings.

When a user submits a query, the data returned is transmitted to the AI assistant provider the user has chosen (for example, OpenAI when used within ChatGPT) and becomes subject to that provider's terms and privacy policy in addition to this one; controls over the provider's use of data, including for model training, are available in the user's settings with that provider. Docket does not sell personal data and does not use it for advertising. Users can disconnect the app at any time from their AI assistant's settings; organization administrators control who may use the connector.

Sharing of personal data

1. We do not sell your personal information. We share personal data only: (a) with service providers that process it on our behalf under confidentiality and data-protection obligations (such as our cloud hosting, authentication, and AI model providers); (b) at the direction of our customers or their authorized users, such as when a user connects Docket to a third-party application (including AI assistants - see "AI Assistant Apps" below); and (c) where required by law.
2. Anonymized data is shared with our product and engineering teams so they can make Docket better for you.

Data subject rights

YOUR RIGHTS & PREFERENCES AS A DATA SUBJECT
Subject to the GDPR and applicable law’s limitations, the rights afforded to you as a data subject are:

1. RIGHT TO BE INFORMED: You have a right to be informed about the manner in which any of your personal data is collected or used, which we have endeavored to do by way of this Policy.
2. RIGHT OF ACCESS: You have a right to access the personal data you have provided by requesting us to provide you with the same.
3. RIGHT TO RECTIFICATION: You have a right to request we amend or update your personal data if it is inaccurate or incomplete.
4. RIGHT TO ERASURE: You have a right to request that we delete your personal data.
5. RIGHT TO RESTRICT: You have a right to request us to temporarily or permanently stop processing all or some of your personal data.
6. RIGHT TO OBJECT: You have a right, at any time, to object to our processing of your personal data under certain circumstances. You have an absolute right to object to us processing your personal data for the purposes of direct marketing.
7. RIGHT TO DATA PORTABILITY: You have a right to request us to provide you with a copy of your personal data in electronic format, and you can transmit that personal data to use another third-party’s product/service.
8. RIGHT NOT TO BE SUBJECT TO AUTOMATED DECISION-MAKING: You have a right not to be subject to a decision based solely on automated decision-making, including profiling.
9. RIGHT TO WITHDRAW CONSENT: Where processing is based on your consent, you have the right to withdraw it at any time. On our website, consent is the legal basis only for non-essential cookies and similar technologies (marketing, analytics, and personalization cookies), which you can manage or withdraw through our website's cookie banner. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Security and Retention

1. Access controls: Admins in Docket can choose which channels and apps Docket retrieves answers from, so you can maintain the confidentiality of knowledge in the web-app and specific channels.

2. Data separation: Docket is SOC 2 Type 1 and Type 2 certified. Our LLMs do not train on your data or share it with a third party.

3. Data privacy: We utilize AWS as our cloud service, which meets the highest data privacy and compliance standards. Read more here.

4. Ingestion API: Docket utilizes "conversations.history" and "conversations.replies" APIs to retrieve Slack conversations.

5. Data Breach: Docket will notify you in writing upon verification of a security breach of the Docket services that affects your data within 72 hours.

6. Docket stores data until termination of contract.

7. Disconnecting an integration (Slack, Teams, Google Drive etc.) will result in deletion of data within 48 hours. Customers can also write to [email protected] to get their data removed immediately.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee compliance with data protection regulations.

If you have any questions about how we handle your personal data, or if you wish to exercise your rights, please contact our DPO.

Email: [email protected]
Address: 567 University Ave, Palo Alto, CA 94301