Privacy Policy

Docil.ai Privacy Policy

Last updated: 08/03/2026 Effective date: 08/03/2026 Version: 1.0


0. How to read this document

This Privacy Policy explains how Start and Power (“Start and Power”, “we”, “us”) handles personal data in connection with the Docil.ai service (the “Platform” or the “Service”).

The document is organized as follows:

  • Sections 1–13: apply to all users, regardless of where they are located.
  • Section 14 (Annex A): additional information for United States residents (California CCPA/CPRA and equivalent state laws).
  • Section 15 (Annex B): additional information for residents of the European Economic Area (EEA), the United Kingdom and Switzerland (GDPR / UK GDPR).

In the event of a conflict, the annex corresponding to your jurisdiction prevails over the general sections.

Contents

  1. How to read this document
  2. Identity of the data controller
  3. What data we collect
  4. Data isolation: dedicated container model
  5. What we use data for (purposes)
  6. Artificial intelligence: how your data is processed
  7. Legal basis for processing (GDPR)
  8. Sub-processors and third-party providers
  9. Data location, international transfers and retention
  10. Security
  11. Your rights
  12. Cookies and similar technologies
  13. Minors
  14. Changes to this policy

ANNEX A — Additional information for United States residents

  • A.1 Notice at Collection
  • A.2 Sale and sharing of personal information
  • A.3 Your rights if you reside in the U.S.
  • A.4 “Shine the Light” (California Civil Code §1798.83)
  • A.5 Do Not Track and Global Privacy Control
  • A.6 Notice to Nevada residents

ANNEX B — Additional information for the EEA, United Kingdom and Switzerland

  • B.1 Supervisory authority and right to lodge a complaint
  • B.2 Mandatory nature of the data
  • B.3 Data Processing Agreement (DPA)

Contact


1. Identity of the data controller

ItemDetails
Legal nameStart and Power LLC
Legal form and state of incorporationLLC incorporated in the State of Wyoming, United States
Registered address1621 Central Ave, Cheyenne, WY 82001, United States
Trade name / productDocil.ai
Websitehttps://docil.ai
Privacy emailprivacy@docil.ai
General emailhello@startandpower.com · hello@docil.ai
Data Protection Officer (DPO)We have not appointed a DPO, as the circumstances set out in Art. 37 GDPR do not apply. For any privacy matter, write to us at privacy@docil.ai.

Start and Power is a company incorporated in Wyoming, United States, and provides the Service primarily to U.S. customers. The Service infrastructure and customer data containers are hosted in the European Union (see Section 8).

Because we also offer the Service to individuals located in the European Economic Area, we are subject to the General Data Protection Regulation (GDPR) pursuant to its Art. 3(2), and we have appointed a representative in the Union under Art. 27, whose details appear above. EEA users may contact that representative in addition to contacting us.

1.1 Controller vs. processor

It is important to distinguish between two roles:

  • We are the CONTROLLER with respect to data arising from our contractual relationship with you: account data, billing data, support, technical logs and Platform usage data.
  • We are the PROCESSOR with respect to the data you enter into or connect to the Platform (“Customer Data”), including data coming from your connected sources (Stripe, HubSpot, Salesforce, Google Drive, Slack, etc.). You are the controller of that data and you decide on its purposes. We process it only in accordance with your instructions and under the Data Processing Agreement (DPA).

2. What data we collect

2.1 Account and registration data

  • First and last name.
  • Email address.
  • Password (stored exclusively as a hash; never in plain text and never recoverable).
  • Organization identifier (org_id) and role within the organization.
  • Language, time zone and account preferences.

2.2 Billing and payment data

Payments are processed through Stripe. We do not store card numbers or full payment instrument details; these are handled directly by Stripe as an independent controller under its own privacy policy.

We retain: Stripe customer identifier, plan and subscription status, invoice history, amount and currency, billing country and tax details necessary to issue invoices.

2.3 Data from connected sources (Customer Data)

When you connect an integration, the Platform accesses — with your explicit authorization via OAuth or API key — the data of that service in order to analyze it. Currently available integrations:

IntegrationTypes of data accessed
StripeTransactions, customers, invoices, subscriptions, balance, refunds, disputes
HubSpotContacts, companies, deals, activities, CRM properties
SalesforceAccounts, contacts, leads, opportunities, custom objects
Google AdsCampaigns, ad groups, performance metrics, spend, conversions
Google AnalyticsAudience metrics, sessions, events, conversions, aggregated reports
Google Search ConsoleSearch queries, impressions, clicks, positions, indexing coverage
Google DriveOnly the files you expressly select: their content and metadata. We do not access the rest of your drive
SlackMessages from authorized channels, users, channels, shared files
NotionPages, databases, content blocks and their properties
ZendeskTickets, conversations, end users, organizations, macros and metrics
Google SheetsOnly the spreadsheets you expressly select: their content and metadata
DropboxFile names, document content, folder structure, metadata
OneDriveFile names, document content, folder structure, metadata
SharePointDocuments, lists, libraries, sites, metadata and permissions
Microsoft TeamsMessages from authorized channels, users, channels, shared files
JiraIssues, projects, sprints, comments, assigned users, workflows
ConfluenceSpaces, pages, documentation content, comments, metadata

No integration is activated automatically: all of them require a connection action and your express consent. The same safeguards apply to all of them: authorization via OAuth or API key, least-privilege principle in the permissions requested, storage in your isolated and dedicated container, no human access on our part, and deletion when you disconnect the source or delete your account.

Custom integrations: if you need to connect an internal system or a tool specific to your industry, write to us at hello@docil.ai and we will build it. Any custom integration is equally subject to this policy and, where applicable, to the Data Processing Agreement entered into with you.

Important: the permissions granted are the minimum necessary (least-privilege principle) and you may revoke them at any time, either from the Platform or from the provider itself. See Section 3 to understand how this data is isolated and protected.

2.4 Data generated by artificial intelligence

Summaries, analyses, evidence, chat responses, reports, insights and any other content generated by the AI models from your data. These outputs are stored in your isolated container and are deleted together with it.

2.5 Technical and usage data

  • IP address.
  • Browser type and version, operating system, device type.
  • Timestamps, pages visited, actions within the Platform.
  • Session identifiers, authentication records and failed access attempts.
  • Error and diagnostic logs.

2.6 Communications

The content of the messages you send us by email or through support forms, and the history of those conversations.

2.7 Special categories of data

We do not deliberately request or seek special categories of data (health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation).

We acknowledge, however, that your connected sources could incidentally contain such information within documents, tickets or messages. In that case, we act as a processor and it is you, as the controller, who must ensure that you have a valid legal basis for processing it before connecting that source. We recommend that you do not connect sources containing special categories of data if you do not have such a legal basis.


3. Data isolation: dedicated container model

This is a core design principle of Docil.ai and it shapes much of this policy:

  • Dedicated container per user/organization. Data from your connected sources is stored and processed in a logically isolated container dedicated exclusively to your account. It is not mixed with other customers’ data.
  • No human access on our part. Our staff does not access the content of your connected sources. The data is processed automatically by the Platform and by the AI models, not read by members of our team.
  • Strict and limited exceptions. The only circumstances in which technical access to your environment could occur are (i) when you expressly request it in order to resolve a support incident, or (ii) when there is a binding legal obligation. Any such access is recorded in an audit log and, unless legally prohibited, you will be notified of it.
  • Application-level isolation. All database queries and all API calls are mandatorily filtered by org_id, making it technically impossible for one organization to access another organization’s data.
  • Deletion upon account removal. When you delete your profile, the entire container and all its content are destroyed. We only retain the billing and accounting data that we are legally required to keep (see Section 8).

4. What we use data for (purposes)

PurposeDescription
Provision of the ServiceTo provide you with AI-assisted business analysis of your connected data.
Source synchronizationTo connect, synchronize and query the integrations you authorize.
Account managementRegistration, authentication, management of users and roles within your organization.
BillingTo manage subscriptions, payments, invoices, taxes and accounting compliance.
SupportTo handle your queries, incidents and technical requests.
SecurityTo prevent fraud, abuse, unauthorized access and attacks; to safeguard the integrity of the Service.
Service improvementTo analyze aggregated, non-identifiable usage metrics in order to improve features and performance.
CommunicationsTo send you operational and service notices (essential) and, if you consent, commercial communications.
Legal complianceTo respond to legal and tax obligations and to requests from competent authorities.

4.1 What we do NOT do

  • We do not sell your personal data or the data from your connected sources.
  • We do not share your data with third parties for cross-site behavioral advertising purposes.
  • We do not use your data or your content to train AI models, whether our own or third parties’. We work with AI providers under enterprise-grade contractual terms that expressly exclude the use of our data for training their models (see Section 5).
  • We do not carry out profiling or automated decision-making with legal or similarly significant effects on individuals.

5. Artificial intelligence: how your data is processed

In order to generate analyses, summaries and responses, the Platform sends fragments of your data to a large language model (LLM) provider.

  • AI provider: Google (Google Cloud Vertex AI / Gemini API), as a processor under enterprise terms.
  • No training: under the applicable enterprise terms, the data sent is not used to train or improve the provider’s models.
  • No extended retention: the provider does not retain request data beyond the time necessary to process it and, where applicable, for abuse monitoring, in accordance with its contractual terms.
  • Minimization: only the context strictly necessary to answer your query is sent, not the entirety of your container.
  • No automated decision-making: AI outputs are informational and intended to support decision-making. They do not produce legal effects nor do they significantly affect you in an automated manner within the meaning of Art. 22 GDPR.
  • Limitations: AI systems may produce inaccurate or incomplete results. You should not base critical decisions solely on them without human verification.

5.1 Use of data obtained through Google APIs (Limited Use)

Express statement: Docil.ai’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

English: Docil.ai’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Which Google APIs we use and what for

API / ServiceScope requestedWhat it is used for in the Docil.ai interface
Google Drivedrive.fileTo read exclusively the files you select through the Google picker, in order to index them and generate summaries, evidence and analysis chat responses
Google Sheetsdrive.fileTo read exclusively the spreadsheets you select, in order to incorporate their data into the business analysis
Google Adsadwords (read-only)To analyze campaigns, spend and advertising performance in the reports
Google Analyticsanalytics.readonlyTo analyze traffic, conversions and behavior in the reports
Google Search Consolewebmasters.readonlyTo analyze organic visibility, queries and positions in the reports
Google Sign-Inopenid, email, profileAuthentication and identification of your account

Per-file access, not access to your entire drive. For Drive and Sheets we deliberately use the drive.file scope, which is the most restrictive available. This means that:

  • Docil.ai cannot see, list or access the general content of your Google Drive.
  • Access is granted file by file, only for the documents you choose through the Google file picker (Google Picker), which is displayed within your own Google session.
  • If you do not select a file, that file is technically inaccessible to us. This is not a contractual promise: it is a limitation imposed by the Google API itself.
  • You may withdraw a file from the analysis at any time, which removes its content from your container.

We request only the minimum scopes indispensable for the functions described. All information obtained is used exclusively for user-facing features of the Docil.ai interface that you have requested.

Limited Use commitments. Information received from Google APIs is not used or transferred:

  • To display advertising of any kind, including personalized, retargeting or interest-based advertising.
  • To determine creditworthiness or for lending purposes.
  • To data brokers, information resellers or information service providers.
  • To train, fine-tune or improve generalized AI or machine learning models, whether our own or third parties’. The AI provider that processes this data is Google (Vertex AI / Gemini API) under enterprise terms that contractually exclude training on customer data.

Human access. No member of our team reads your Google data. The only exceptions, aligned with Google’s policy, are: (a) that you give us your express consent to review a specific file or data point in the context of a support incident; (b) that it is necessary for security reasons, for example to investigate abuse or a failure; (c) that applicable law requires it; or (d) that the data is aggregated and used for internal operations in accordance with applicable privacy regulations.

Transfer to third parties. We do not transfer data from Google APIs to third parties, except to the infrastructure providers strictly necessary to provide you with the Service (EU hosting and Google AI processing), which act as processors under contract, or where required by law.

Storage. Data obtained from Google APIs is stored encrypted and in the isolated container dedicated to your organization, hosted in the European Union, in accordance with Section 3.

How to revoke access and delete your Google data. You may do so at any time and by any of the following means:

  • From Docil.ai, under Settings → Integrations → Disconnect. Upon disconnecting, the token is revoked and all data from that source is deleted from your container.
  • By withdrawing specific files from the analysis through the interface itself, which removes their content from your container without needing to disconnect the entire integration.
  • From your Google account, at myaccount.google.com/permissions, by withdrawing the access granted to Docil.ai.
  • By deleting your account under Settings → Delete account, which destroys the entire container.
  • By writing to us at privacy@docil.ai.

Deletion takes effect immediately in active systems and is completed in backups within a maximum of 30 days.

Changes in the use of Google data. If in the future we wish to access Google data of a type or for a purpose not described in this policy, we will update this document beforehand and will request your consent again before doing so.


6. Legal basis for processing (GDPR)

ProcessingLegal basis (Art. 6 GDPR)
Creating and managing your accountPerformance of the contract (Art. 6(1)(b))
Providing the Service and generating analysesPerformance of the contract (Art. 6(1)(b))
Connecting Stripe, Google, Slack, Notion and other sourcesExplicit consent (Art. 6(1)(a)), given during the OAuth/API flow. Revocable at any time
Billing and collectionPerformance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c))
Retention of invoices and accounting recordsLegal obligation (Art. 6(1)(c))
Security, fraud prevention and auditingLegitimate interest (Art. 6(1)(f))
Customer supportPerformance of the contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f))
Aggregated usage metrics to improve the productLegitimate interest (Art. 6(1)(f))
Analytics cookiesConsent (Art. 6(1)(a) and Art. 22 LSSI / ePrivacy Directive)
Commercial communicationsConsent (Art. 6(1)(a)) or legitimate interest for existing customers regarding similar products

Where we rely on legitimate interest, we have carried out the corresponding balancing test between our interest and your rights and freedoms. You may request a summary of that assessment by writing to privacy@docil.ai.


7. Sub-processors and third-party providers

We rely on the following providers. The up-to-date list is available at [LINK TO SUB-PROCESSORS PAGE].

ProviderFunctionData processedLocation
CONTABOHosting of the application and of the data containersAll Platform dataEuropean Union
Google Cloud (Vertex AI / Gemini)Processing by AI modelsContent fragments sent with each queryU.S. / EU
StripePayment processing and billingPayment, billing and customer identification dataU.S. / EU
Google LLCOAuth and integrations (Drive, Ads, Analytics, Search Console)Access tokens and data from the authorized APIsU.S. / EU
Google AnalyticsSite and application usage analyticsCookie identifiers, IP, browsing eventsU.S.
CONTABOSending of service emailsEmail, name, message contentEU
Start and Power LLCSupport ticket managementEmail, name, query contentU.S.

Each of these providers is bound by a data processing agreement with confidentiality and security obligations equivalent to our own. We will inform you with reasonable advance notice of the addition of any new sub-processor, and you may object on reasonable data protection grounds.

HubSpot, Salesforce, Slack, Notion, Zendesk, Dropbox, Microsoft (OneDrive, SharePoint, Teams), Atlassian (Jira, Confluence) and other connected sources are not our sub-processors: they are your systems, from which the Platform reads data with your authorization. Their processing is governed by the contracts you have with them.


8. Data location, international transfers and retention

8.1 Location

Docil.ai’s infrastructure — servers, databases and customer containers — is hosted in the European Union (Germany).

8.2 International transfers

Two types of transfer outside the European Economic Area occur:

a) Access from the United States by Start and Power. Although the data resides on EU servers, Start and Power is a U.S. company and its administrative, billing and support staff access certain data (account data, billing, tickets and operational metadata) from the United States. Remember that, in accordance with Section 3, this access never extends to the content of your connected sources, which remains in your isolated container in the EU with no human access on our part.

b) Providers established outside the EEA, such as Stripe or Google.

Both cases are covered by one or more of the following mechanisms under Chapter V of the GDPR:

  • Standard Contractual Clauses (SCCs) approved by the European Commission through Implementing Decision (EU) 2021/914, supplemented by any additional technical and organizational measures found necessary following the corresponding Transfer Impact Assessment.
  • EU-U.S. Data Privacy Framework, where the importing entity is certified.
  • For the United Kingdom: UK International Data Transfer Addendum; for Switzerland: the Swiss extension of the DPF or adapted SCCs.

You may request a copy of these safeguards by writing to privacy@docil.ai.

8.3 Retention periods

CategoryPeriod
Account dataFor as long as the account is active
Container of data from connected sourcesFor as long as the source is connected. Deleted immediately upon disconnecting the source or deleting the account, with effective destruction within a maximum of 30 days including backups
AI-generated outputsTogether with the container
OAuth tokensUntil the connection is revoked or the account is deleted
Billing and accounting data7 years from the last transaction (the usual period under IRS requirements and applicable U.S. state accounting rules)
Technical and security logs[12] months
Support tickets[24] months from closure
Backups[30]-day rotation; deleted data disappears from backups once the cycle completes
Consent data and evidence of consentFor as long as it is valid + [3] years

Once these periods have elapsed, the data is securely deleted or irreversibly anonymized.


9. Security

We apply appropriate technical and organizational measures in accordance with Art. 32 GDPR:

  • Encryption in transit: all communications via HTTPS/TLS 1.2 or higher.
  • Encryption at rest: sensitive data, credentials and integration tokens are encrypted at rest using AES-256 with an application key (APP_ENCRYPTION_KEY) managed securely and separately from the database.
  • Passwords: stored exclusively as hashes using a resistant algorithm and a unique salt.
  • Multi-tenant isolation: strict segregation by org_id across the entire data and API layer, in addition to the dedicated container described in Section 3.
  • Access control: least-privilege principle, strengthened authentication for technical staff and audit logging of administrative access.
  • Least privilege in OAuth: we request only the scopes indispensable for the contracted functionality.
  • Encrypted backups and periodic restoration testing.
  • Security updates and patches applied on an ongoing basis.

9.1 Security breach notification

In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it, provided it is likely to result in a risk to your rights and freedoms. If the risk is high, we will also communicate it to you without undue delay. Where we act as a processor, we will inform the controlling customer without undue delay.

No security measure is infallible. It is your responsibility to keep your credentials confidential and to notify us immediately of any unauthorized use of your account.


10. Your rights

Regardless of where you reside, you may exercise the following rights:

  • Access: obtain confirmation as to whether we process your data and a copy of it.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”): request the deletion of your data.
  • Restriction: request that we restrict processing in certain circumstances.
  • Portability: receive your data in a structured, commonly used and machine-readable format, or request its transmission to another controller.
  • Objection: object to processing based on legitimate interest and, in all cases, to direct marketing.
  • Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
  • Not to be subject to automated decisions with legal or similarly significant effects.

10.1 How to exercise them

Write to privacy@docil.ai indicating the right you wish to exercise. You can also manage the following directly from the Platform:

  • Disconnect any source under Settings → Integrations.
  • Download your data under Settings → Export.
  • Delete your account and your container under Settings → Delete account.

We will respond within one month, extendable by two further months in complex cases, informing you of the extension. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests. We may ask you for additional information to verify your identity.

10.2 If your data is in a customer’s system

If your personal data has reached Docil.ai because one of our customers connected a source that includes you, you must direct your request to that customer, who is the controller. If you write to us, we will redirect you to them and will provide them with the necessary assistance.


11. Cookies and similar technologies

Docil.ai uses:

TypePurposeLegal basisDuration
Strictly necessary cookies (session, authentication, security, CSRF, load balancing)To enable the basic functioning of the ServiceNecessary — no consent requiredSession / [30] days
Preference cookiesTo remember language, theme and settingsConsent[12] months
Analytics cookies (Analytics 4)To measure use of the site and the application in order to improve themConsent[14] months

We do not use advertising cookies, third-party tracking pixels or cross-site behavioral advertising technologies.

Consent management: in the EEA, the United Kingdom and Switzerland, non-necessary cookies are only installed after your express consent through our cookie banner. You may change or withdraw your choice at any time from Cookie settings. You may also block or delete cookies from your browser settings, although this may affect the functioning of the Service.

Browser privacy signals: we honor the Global Privacy Control (GPC) signal when we detect it, treating it as a valid opt-out request for sale/sharing under applicable U.S. law.


12. Minors

The Service is intended exclusively for businesses and professionals. It is not intended for individuals under 18 years of age and we do not knowingly collect data from minors.

If we become aware that we have collected personal data from a person under 18 without the corresponding legal authorization, we will delete that information without delay. If you believe a minor has provided us with data, write to us at privacy@docil.ai.

We comply with the U.S. COPPA (Children’s Online Privacy Protection Act): we do not direct the Service to children under 13 nor do we knowingly collect their data.


13. Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, in our practices or in applicable regulations.

  • The current version will always be published at https://docil.ai/privacy with its last-updated date.
  • If the changes are substantial, we will notify you by email and/or through a prominent notice on the Platform at least 30 days before they take effect.
  • Where required by law, we will request your consent again.
  • We will maintain an accessible history of previous versions.

ANNEX A — Additional information for United States residents

This annex applies to residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with consumer privacy legislation in force.

Note on applicability. Start and Power may not currently meet the revenue or volume thresholds that trigger the mandatory application of some of these laws (for example, those in §1798.140(d) CCPA). Even so, we have chosen to voluntarily apply these standards to all of our U.S. users. Likewise, although several of these laws exclude data processed in purely B2B contexts, we do not apply that exclusion: we handle requests from our professional users in the same way as those from any consumer.

A.1 Notice at Collection

In the past twelve (12) months we have collected the following categories of personal information:

Category (CCPA §1798.140)Specific examplesDo we collect it?SourcePurposeDisclosed for business purposes?
A. IdentifiersName, email, IP, account ID, org_idYesYou, your deviceAccount, service, securityYes — hosting, email, support
B. Customer records (Cal. Civ. Code §1798.80)Name, billing dataYesYou, StripeBillingYes — Stripe
C. Protected characteristicsNoNo
D. Commercial informationSubscription history, transactionsYesYou, StripeBilling, supportYes — Stripe
E. Biometric informationNoNo
F. Internet or network activityUsage logs, pages visited, eventsYesYour deviceSecurity, product improvementYes — analytics, hosting
G. GeolocationApproximate location derived from IP (country/city level)YesYour deviceSecurity, tax complianceYes — hosting
H. Sensory informationNoNo
I. Professional or employment informationJob title, company, role in the organizationYesYouAccount, supportYes — support
J. Education information (FERPA)NoNo
K. InferencesAI-generated insights about your businessYesGenerated by the PlatformProvision of the ServiceNo
L. Sensitive personal informationAccount access credentials and integration tokensYesYouAuthentication and provision of the ServiceYes — hosting

Limited use of sensitive information: we use sensitive personal information exclusively for the purposes permitted by §7027(m) of the CCPA Regulations — providing the requested Service, ensuring security and preventing fraud. We do not use it to infer characteristics about you. Consequently, we are not required to offer a specific right to limit its use, although we will honor any request to that effect.

A.2 Sale and sharing of personal information

We do NOT sell personal information. We do NOT share personal information for cross-context behavioral advertising. Nor have we done so in the preceding twelve months. We do not sell or share the personal information of minors under 16, nor do we have knowledge of processing it.

A.3 Your rights if you reside in the U.S.

  • Right to know / access: request the categories and specific pieces of personal information we have collected, their sources, the purpose and the third parties to whom it is disclosed.
  • Right to deletion: request the deletion of your personal information, subject to applicable legal exceptions.
  • Right to correction: correct inaccurate information.
  • Right to opt out of sale, sharing and targeted advertising. Not applicable in practice, since we do not carry out any of these activities.
  • Right to limit the use of sensitive information.
  • Right to data portability.
  • Right to non-discrimination: we will not deny you service, charge you different prices, or provide you a lower quality of service for exercising your rights.
  • Right to opt out of profiling in decisions with legal or similarly significant effects (Colorado, Connecticut, Virginia). We do not carry out this type of profiling.
  • Right to appeal (Virginia, Colorado, Connecticut, Texas, Montana, Oregon): if we deny your request, you may appeal by writing to privacy@docil.ai with the subject line “Privacy appeal”. We will respond within 45–60 days. If we uphold the denial, we will inform you of how to complain to your state’s Attorney General.

How to exercise them: write to privacy@docil.ai or use the form. We will verify your identity through the email address associated with the account and, if necessary, additional information. We will respond within 45 calendar days, extendable by another 45 with prior notice.

Authorized agent: you may designate an authorized agent to exercise your rights. They must provide written proof of your authorization, and we may ask you to confirm that designation directly.

A.4 “Shine the Light” (California Civil Code §1798.83)

We do not disclose personal information to third parties for their own direct marketing purposes.

A.5 Do Not Track and Global Privacy Control

There is no uniform standard for “Do Not Track” signals, so we do not respond to them differently. We do recognize and honor the Global Privacy Control (GPC) signal as a valid opt-out request.

A.6 Notice to Nevada residents

Nevada residents may request to opt out of the sale of certain personal information. We do not sell personal information within the meaning of Nevada law, but you may direct your request to privacy@docil.ai.


ANNEX B — Additional information for the EEA, United Kingdom and Switzerland

B.1 Supervisory authority and right to lodge a complaint

Start and Power has no establishment in the European Union, so the one-stop-shop mechanism under Art. 56 GDPR does not apply. This means you may complain directly to the supervisory authority in your country.

If you believe that the processing of your data infringes the regulations, you have the right to lodge a complaint with the competent authority. We would be grateful if you first contacted us at privacy@docil.ai or our EU representative (Section 1) so that we can try to resolve the matter.

  • EU/EEA Member States: the authority of your country of residence, your place of work, or the place where the alleged infringement occurred. The full directory is available at edpb.europa.eu.
  • Spain: Agencia Española de Protección de Datos (AEPD) — C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es
  • United Kingdom: Information Commissioner’s Office (ICO) — www.ico.org.uk
  • Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — www.edoeb.admin.ch

B.2 Mandatory nature of the data

The data marked as mandatory in the forms is necessary for the performance of the contract. If you do not provide it, we will not be able to provide you with the Service. Connecting data sources is always voluntary, although without it the analysis functionality is not available.

B.3 Data Processing Agreement (DPA)

If you are a business customer and need a signed DPA in accordance with Art. 28 GDPR, with the Standard Contractual Clauses incorporated, write to us at privacy@docil.ai.


Contact

Start and Power LLC 1621 Central Ave, Cheyenne, WY 82001, United States

Privacy and exercise of rights: privacy@docil.ai General: hello@startandpower.com · hello@docil.ai Web: https://docil.ai

EU Representative (Art. 27 GDPR): Stella and Pow OU