Politique de confidentialité des données
At GrackleDocs, we are committed to safeguarding the privacy of our website visitors, product users, and the individuals whose information appears in the documents our customers entrust to us. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights and choices available to you.
Résumé en langage clair sur la protection de la vie privée
We care about your privacy and want to keep your personal information safe. This summary explains, in simple terms, what we do with your data. For full details, please read the complete Data Privacy Policy below.
- What we collect: Only what we need, like your name, work email, or billing details when you sign up or purchase our services, plus limited usage data that helps us improve our products. If you sign in with Google or Microsoft, we receive basic profile information from your identity provider instead of storing a password.
- Your documents are yours: When you use our software or services to check or remediate documents, we process those documents on your behalf and on your instructions. We do not use your document content to train AI models, and we do not sell, rent, or trade any personal information, ever.
- How we use it: To provide our document accessibility products and services, process payments, answer your questions, and improve our offerings. We send marketing emails only if you’ve agreed to receive them, and you can opt out at any time.
- Sharing your data: We share information only with service providers who help us run our business (such as cloud hosting and payment processors), and only under contracts that require them to protect it. Our current subprocessors are listed at trust.grackledocs.com.
- AI features: Some of our features use AI to automate accessibility tasks (for example, AutoTagging and Layout Detection). AI features run only when you choose to use them, temporary processing files are deleted after completion, and your content is never used to train AI models. Organizations can disable AI features entirely: see Section 9.
- Your choices: You can ask to see, correct, delete, or receive a copy of your information. Contact us and we’ll respond within the timelines required by law (30 days in most cases).
- Keeping it safe: We use strong safeguards, including encryption in transit and at rest, and we maintain SOC 2 Type II compliance. If a data breach ever affects you, we will notify you and the appropriate regulators promptly.
- Where your data lives: Our services run on Google Cloud Platform in North America. Where data crosses borders, we use legally recognized safeguards.
- Contact us: Our Security Officer can be reached at security@grackledocs.com or by mail at 92 Caplan Ave, Suite 508, Barrie, Ontario, L4N 9J2, Canada.
We may update this policy from time to time, and we’ll tell you about significant changes. Thank you for trusting GrackleDocs.
Politique de confidentialité des données
Last Updated: August 5, 2026
GrackleDocs Inc. (“GrackleDocs,” “we,” “us,” or “our”) is a Canadian company headquartered in Ontario, with operations in Australia and customers worldwide. This Data Privacy Policy describes our practices for collecting, using, disclosing, and protecting personal information in compliance with the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), the EU and UK General Data Protection Regulation (GDPR) where applicable, the Australian Privacy Act 1988, and applicable US state privacy laws.
This policy applies to our websites, our software products (including Grackle PDF, Grackle PDF Online, Grackle Office, Grackle Workspace, Grackle Check, Grackle GO, Grackle Scan, Grackle Stream, and the Grackle Dashboard), and our professional services (including PDF remediation, auditing, consulting, and training).
1. Our Two Roles: Controller and Processor
GrackleDocs handles personal information in two distinct capacities, and your rights and our obligations differ depending on which applies:
As a controller. When you visit our website, create an account, purchase our products, contact support, or subscribe to communications, GrackleDocs determines how and why your personal information is processed. Most of this policy describes our practices in this role.
As a processor (service provider). When you or your organization use our products or services to check, tag, or remediate documents, those documents may contain personal information about you or third parties. In this capacity, we process document content solely on behalf of and under the instructions of our customer: we do not use it for our own purposes. Our obligations in this role are governed by our Data Processing Agreement (DPA), available at trust.grackledocs.com, which incorporates the safeguards required by PIPEDA, Law 25, GDPR Article 28, and other applicable laws. If your personal information appears in a document processed through our services and you have questions about it, please contact the organization that submitted the document; we will support their response as required by law.
2. Information We Collect
Contact and account information. Name, work email address, phone number, organization, and mailing address, provided when you register, contact us, request a demo, or purchase products or services.
Authentication information. Most of our products use single sign-on (SSO). When you sign in through an identity provider such as Google, we receive basic profile information (name, email address, and a unique identifier) from that provider. We do not receive or store your password. Where password-based accounts exist, credentials are stored using industry-standard hashing.
Billing information. Payment details are collected and processed by PCI-compliant third-party payment processors; GrackleDocs does not store full payment card numbers.
License and usage information. For licensed products, we process entitlement data (license type, seat counts, activation status, usage against plan limits) to administer your subscription.
Document content (processor role). Documents you submit for checking, tagging, remediation, or conversion, including their content, structure, formatting, and metadata. See Sections 1 and 9.
Usage data. Information about how you interact with our websites and products, including IP address, browser type, device details, pages visited, feature usage, and session duration. Where feasible, this data is aggregated or anonymized.
Cookies and similar technologies. We use cookies and similar technologies to operate our website, remember preferences, and analyze usage. Non-essential cookies are set only with your consent, which you can give, refuse, or withdraw through our cookie preference banner or your browser settings.
Information from third parties. We may receive information from identity providers (as described above), business partners, resellers, or marketplace platforms (such as the Google Workspace Marketplace), only as permitted by law and, where required, with your consent.
3. How We Use Your Information and Our Legal Bases
We use personal information for the following purposes. Where GDPR applies, the legal basis for each is noted:
- Providing and maintaining our products and services, including account administration, license management, and document processing you request (performance of a contract).
- Processing transactions and issuing billing communications (performance of a contract; legal obligation).
- Customer support and service communications, including responding to inquiries and notifying you of service changes (performance of a contract; legitimate interests).
- Improving our products and websites, including analyzing aggregated usage patterns and diagnosing errors (legitimate interests).
- Sécurité, including detecting, preventing, and investigating fraud, abuse, and security incidents (legitimate interests; legal obligation).
- Marketing communications, such as newsletters and product announcements, sent only with your consent where required by law (e.g., under Canada’s Anti-Spam Legislation and GDPR), and always with an easy way to unsubscribe (consent).
- Legal compliance, including responding to lawful requests and meeting our obligations under applicable privacy, tax, and corporate laws (legal obligation).
We do not use personal information for automated decision-making that produces legal or similarly significant effects about individuals.
4. How We Share Your Information
We do not sell, rent, or trade personal information. We disclose it only in the following circumstances:
- Service providers and subprocessors. We engage vetted third parties for cloud hosting (Google Cloud Platform), payment processing, analytics, and customer support. Each is bound by a written agreement requiring confidentiality, security safeguards, and use of the data only to provide services to us.
- Business transfers. In a merger, acquisition, financing, or sale of assets, personal information may be transferred with appropriate safeguards and, where required by law, prior notice.
- Legal requirements. We disclose information where required by applicable law, regulation, or valid legal process. Where legally permitted, we will notify the affected customer before disclosing customer content in response to a government or court request.
- Protection of rights. We may share information as necessary to protect the rights, safety, or property of GrackleDocs, our users, or the public, including to prevent fraud.
5. International Data Transfers
Our services are hosted on Google Cloud Platform in North America. Information may be transferred to, stored in, or processed in countries other than the one in which you reside, including Canada, the United States, and Australia.
Where we transfer personal information internationally, we implement legally recognized safeguards appropriate to the originating jurisdiction:
- From the EU/EEA and the UK: transfers rely on adequacy decisions (Canada holds an EU adequacy decision for PIPEDA-covered processing) or the European Commission’s Standard Contractual Clauses and the UK Addendum/IDTA, supplemented by technical measures such as encryption.
- From Quebec: before communicating personal information outside Quebec, we conduct a privacy impact assessment to confirm the information will receive adequate protection, as required by Law 25.
- From Australia: we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.
Details of our transfer mechanisms are available on request from our Privacy Officer or in our DPA.
6. Your Rights and Choices
Depending on where you live, you may have some or all of the following rights regarding personal information for which GrackleDocs is the controller:
- Accès : request a copy of the personal information we hold about you.
- Correction : request that inaccurate or incomplete information be corrected.
- Deletion: request deletion of your personal information, subject to legal retention requirements.
- Portability: receive your information in a structured, commonly used format (available under GDPR and Quebec Law 25).
- Withdrawal of consent: withdraw consent at any time where processing is based on consent, without affecting prior processing.
- Objection and restriction: object to or request restriction of certain processing (where GDPR applies).
- Marketing opt-out: unsubscribe from marketing communications at any time via the link in any email or by contacting us.
- Cookies : manage preferences through our cookie banner or browser settings.
To exercise any of these rights, contact our Privacy Officer using the details in Section 14. We will verify your identity and respond within 30 days (or sooner where local law requires). We will not discriminate against you for exercising your rights. If we act as a processor for the information in question, we will refer your request to the relevant customer and support their response.
Residents of certain US states may also have rights under state privacy laws (such as the California Consumer Privacy Act). Because we do not sell or share personal information for cross-context behavioral advertising, no opt-out of sale or sharing is necessary; other applicable rights may be exercised as described above.
7. Data Security
We maintain technical, organizational, and physical safeguards designed to protect personal information against unauthorized access, use, alteration, or disclosure, including encryption in transit and at rest, role-based access controls, continuous cloud security posture monitoring, and employee confidentiality obligations. GrackleDocs maintains SOC 2 Type II compliance, and our security practices are documented in our Trust Center at trust.grackledocs.com.
If a breach of security safeguards creates a real risk of significant harm (or meets an equivalent threshold under applicable law), we will notify affected individuals and the appropriate regulators, including the Office of the Privacy Commissioner of Canada, Quebec’s Commission d’accès à l’information, EU/UK supervisory authorities, and US state authorities, as applicable, without undue delay and within legally required timeframes, and we will take prompt steps to contain and remediate the incident.
8. Data Retention
We retain personal information only as long as necessary for the purposes described in this policy, to meet legal obligations, resolve disputes, and enforce agreements. As a guideline:
- Account and license data: retained for the life of the customer relationship plus 7 years for legal and audit purposes.
- Customer document content: processed transiently where possible; temporary AI processing files are deleted automatically upon completion, and stored documents are retained only per product functionality and customer configuration, then deleted or returned in accordance with our DPA upon contract termination.
- Billing records: retained permanently as is accounting best practices.
- Marketing data: retained until you unsubscribe or after 12 months of inactivity.
When retention periods expire or you validly request deletion, we securely delete or irreversibly anonymize the information.
9. AI Features and Data Processing
Some GrackleDocs products include AI-powered features, such as Layout Detection, AutoTagging, and automated document structure analysis.
When AI processing occurs. AI features process your document content, structure, formatting, and metadata only when you actively use them. Temporary processing files are deleted automatically after the operation completes.
No training on your content. We do not use your document content to train AI models, ours or anyone else’s, and we do not permit our AI subprocessors to retain or use your content for model training. We may use aggregated, anonymized operational metrics (such as success rates and error patterns) that contain no document content, personal information, or customer-proprietary information to evaluate and improve feature quality.
Opting out. Organization administrators can disable AI-powered features for their users via by contacting support at support@grackledocs.com, and individual users can simply choose not to invoke AI features. Core accessibility functionality remains available without AI processing.
Transparency. Outputs of AI features (such as automatically generated tags) are suggestions subject to your review and remain under your control. We monitor our obligations under emerging AI regulation, including the EU Artificial Intelligence Act, and will update our practices and disclosures as those requirements take effect.
10. Children’s and Student Privacy
Our websites and services are intended for professional and institutional use and are not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information directly from children. If you believe a child has provided us personal information, contact our Privacy Officer and we will promptly delete it.
When we serve educational institutions, student personal information, including personal information contained in education records, is processed solely as a service provider on the institution’s behalf. In this context we:
- Process education records only as directed by the institution, consistent with the Loi sur les droits et la protection de la famille en matière d'éducation (FERPA) “school official” provisions, applicable state student privacy laws (such as California’s SOPIPA and New York Education Law §2-d), and equivalent laws in other jurisdictions;
- Apply the security safeguards described in Section 7 to all student data;
- Support the institution in responding to parental or eligible-student requests for access to or correction of education records.
11. Third-Party Links
Our websites and products may link to third-party sites and services. We are not responsible for their privacy practices and encourage you to review their policies before providing personal information.
12. Complaints
If you have a concern about our privacy practices, please contact our Privacy Officer first: we take complaints seriously and will work to resolve them promptly. If you are not satisfied, you may lodge a complaint with the supervisory authority in your jurisdiction, including:
Office of the Privacy Commissioner of Canada: 30 Victoria Street, Gatineau, Quebec K1A 1H3 · 1-800-282-1376 · www.priv.gc.ca
Commission d’accès à l’information du Québec (for Quebec residents) www.cai.gouv.qc.ca
EU/EEA and UK residents may contact their local data protection authority or the UK Information Commissioner’s Office; Australian residents may contact the Office of the Australian Information Commissioner.
13. Changes to This Privacy Policy
We may update this policy to reflect changes in our practices, products, or legal requirements. The “Last Updated” date shows the latest revision. We will provide prominent notice of material changes via our website or email and, where required by law, obtain your consent before applying them.
14. Contact Us: Security Officer
GrackleDocs has designated a Security Officer (the “person in charge of the protection of personal information” for the purposes of Quebec Law 25) who is accountable for our compliance with this policy and applicable privacy laws:
Security Officer, GrackleDocs Inc.
Courriel : security@grackledocs.com
Adresse : 92 Caplan Ave, Suite 508, Barrie, Ontario, L4N 9J2, Canada
Phone: +1 905-318-6800
