Docket offers a connector, Docket MCP, that lets authorized users of a Docket customer access - and, where such features are enabled, act on - their organization's Docket data from AI assistants such as OpenAI's ChatGPT. Access requires signing in with existing Docket credentials; every request is limited to the user's own organization and role permissions and is recorded in an access log. Where the connector supports actions that create or change data (for example, updating a lead or booking record), those actions are performed only at the direction of the authorized user and within the same organization and role limits. For the website visitor and lead data described below, our customer determines the purposes of processing and Docket acts on the customer's behalf.
Depending on the user's request and permissions, a response may include:
1. Identifiers - internal IDs for visitors, leads, companies, conversations, meetings, and website agents.
2. Contact and professional details - names, business email addresses, job titles, and employers of website visitors and leads, and of meeting attendees.
3. Company and enrichment data - information about the companies associated with leads (such as industry, size, and location), including enrichment data obtained from third-party business-data providers and stored in Docket.
4. CRM matching identifiers - visitor tokens used to match a website visitor to the customer's own marketing and CRM systems (such as HubSpot or Marketo).
5. Sales workflow data - the team member a lead is assigned to, opportunity amount, and expected close date, where recorded.
6. Conversation content and analysis - the content of conversations between website visitors and the customer's website agents, including summaries, qualification status, engagement-based lead scores, identified pain points, products of interest, and next steps. Where the user's role permits and the user explicitly requests it, a response may include time-limited secure links to full transcripts and audio recordings (recordings contain the visitor's voice).
7. Marketing and activity data - campaign attribution (such as UTM parameters), referring pages, website journey and session data, and the consent state recorded for a visitor.
8. Meeting records - booking times, statuses (including rescheduled and cancelled), and attendee details.
9. Agent configuration and knowledge sources - website-agent settings and performance metrics. For authorized administrators who explicitly request them, responses may include agent prompts, embed configuration, and time-limited links to knowledge-source files.
10. Technical data - the signed-in user's identity, role, and access level; the organization's configured limits and the names and connection status of connected integrations; and pagination and request identifiers included in responses.
Docket's underlying customer data is retained for the duration of the customer's contract or until the customer requests deletion, whichever is earlier, as described in "Security and Retention." OAuth authorizations for the connector are retained until revoked or disconnected. MCP access logs are retained on the same basis, except where a longer period is required for security, audit, or legal purposes. Data transmitted to an AI assistant provider is retained by that provider under its own terms, privacy policy, and the user's account settings.
When a user submits a query, the data returned is transmitted to the AI assistant provider the user has chosen (for example, OpenAI when used within ChatGPT) and becomes subject to that provider's terms and privacy policy in addition to this one; controls over the provider's use of data, including for model training, are available in the user's settings with that provider. Docket does not sell personal data and does not use it for advertising. Users can disconnect the app at any time from their AI assistant's settings; organization administrators control who may use the connector.