Docil.ai Privacy Policy
Last updated: 08/03/2026 Effective date: 08/03/2026 Version: 1.0
0. How to read this document
This Privacy Policy explains how Start and Power (“Start and Power”, “we”, “us”) handles personal data in connection with the Docil.ai service (the “Platform” or the “Service”).
The document is organized as follows:
- Sections 1–13: apply to all users, regardless of where they are located.
- Section 14 (Annex A): additional information for United States residents (California CCPA/CPRA and equivalent state laws).
- Section 15 (Annex B): additional information for residents of the European Economic Area (EEA), the United Kingdom and Switzerland (GDPR / UK GDPR).
In the event of a conflict, the annex corresponding to your jurisdiction prevails over the general sections.
Contents
- How to read this document
- Identity of the data controller
- What data we collect
- Data isolation: dedicated container model
- What we use data for (purposes)
- Artificial intelligence: how your data is processed
- Legal basis for processing (GDPR)
- Sub-processors and third-party providers
- Data location, international transfers and retention
- Security
- Your rights
- Cookies and similar technologies
- Minors
- Changes to this policy
ANNEX A — Additional information for United States residents
- A.1 Notice at Collection
- A.2 Sale and sharing of personal information
- A.3 Your rights if you reside in the U.S.
- A.4 “Shine the Light” (California Civil Code §1798.83)
- A.5 Do Not Track and Global Privacy Control
- A.6 Notice to Nevada residents
ANNEX B — Additional information for the EEA, United Kingdom and Switzerland
- B.1 Supervisory authority and right to lodge a complaint
- B.2 Mandatory nature of the data
- B.3 Data Processing Agreement (DPA)
Contacto
1. Identity of the data controller
| Item | Details |
|---|---|
| Legal name | Start and Power LLC |
| Legal form and state of incorporation | LLC incorporated in the State of Wyoming, United States |
| Registered address | 1621 Central Ave, Cheyenne, WY 82001, United States |
| Trade name / product | Docil.ai |
| Website | https://docil.ai |
| Privacy email | privacy@docil.ai |
| General email | hello@startandpower.com · hello@docil.ai |
| Data Protection Officer (DPO) | We have not appointed a DPO, as the circumstances set out in Art. 37 GDPR do not apply. For any privacy matter, write to us at privacy@docil.ai. |
Start and Power is a company incorporated in Wyoming, United States, and provides the Service primarily to U.S. customers. The Service infrastructure and customer data containers are hosted in the European Union (see Section 8).
Because we also offer the Service to individuals located in the European Economic Area, we are subject to the General Data Protection Regulation (GDPR) pursuant to its Art. 3(2), and we have appointed a representative in the Union under Art. 27, whose details appear above. EEA users may contact that representative in addition to contacting us.
1.1 Controller vs. processor
It is important to distinguish between two roles:
- We are the CONTROLLER with respect to data arising from our contractual relationship with you: account data, billing data, support, technical logs and Platform usage data.
- We are the PROCESSOR with respect to the data you enter into or connect to the Platform (“Customer Data”), including data coming from your connected sources (Stripe, HubSpot, Salesforce, Google Drive, Slack, etc.). You are the controller of that data and you decide on its purposes. We process it only in accordance with your instructions and under the Data Processing Agreement (DPA).
2. What data we collect
2.1 Account and registration data
- First and last name.
- Email address.
- Password (stored exclusively as a hash; never in plain text and never recoverable).
- Organization identifier (org_id) and role within the organization.
- Language, time zone and account preferences.
2.2 Billing and payment data
Payments are processed through Stripe. We do not store card numbers or full payment instrument details; these are handled directly by Stripe as an independent controller under its own privacy policy.
We retain: Stripe customer identifier, plan and subscription status, invoice history, amount and currency, billing country and tax details necessary to issue invoices.
2.3 Data from connected sources (Customer Data)
When you connect an integration, the Platform accesses — with your explicit authorization via OAuth or API key — the data of that service in order to analyze it. Currently available integrations:
| Integration | Types of data accessed |
|---|---|
| Stripe | Transactions, customers, invoices, subscriptions, balance, refunds, disputes |
| HubSpot | Contacts, companies, deals, activities, CRM properties |
| Salesforce | Accounts, contacts, leads, opportunities, custom objects |
| Google Ads | Campaigns, ad groups, performance metrics, spend, conversions |
| Google Analytics | Audience metrics, sessions, events, conversions, aggregated reports |
| Google Search Console | Search queries, impressions, clicks, positions, indexing coverage |
| Google Drive | Only the files you expressly select: their content and metadata. We do not access the rest of your drive |
| Slack | Messages from authorized channels, users, channels, shared files |
| Notion | Pages, databases, content blocks and their properties |
| Zendesk | Tickets, conversations, end users, organizations, macros and metrics |
| Google Sheets | Only the spreadsheets you expressly select: their content and metadata |
| Dropbox | File names, document content, folder structure, metadata |
| OneDrive | File names, document content, folder structure, metadata |
| SharePoint | Documents, lists, libraries, sites, metadata and permissions |
| Microsoft Teams | Messages from authorized channels, users, channels, shared files |
| Jira | Issues, projects, sprints, comments, assigned users, workflows |
| Confluence | Spaces, pages, documentation content, comments, metadata |
No integration is activated automatically: all of them require a connection action and your express consent. The same safeguards apply to all of them: authorization via OAuth or API key, least-privilege principle in the permissions requested, storage in your isolated and dedicated container, no human access on our part, and deletion when you disconnect the source or delete your account.
Custom integrations: if you need to connect an internal system or a tool specific to your industry, write to us at hello@docil.ai and we will build it. Any custom integration is equally subject to this policy and, where applicable, to the Data Processing Agreement entered into with you.
Important: the permissions granted are the minimum necessary (least-privilege principle) and you may revoke them at any time, either from the Platform or from the provider itself. See Section 3 to understand how this data is isolated and protected.
2.4 Data generated by artificial intelligence
Summaries, analyses, evidence, chat responses, reports, insights and any other content generated by the AI models from your data. These outputs are stored in your isolated container and are deleted together with it.
2.5 Technical and usage data
- IP address.
- Browser type and version, operating system, device type.
- Timestamps, pages visited, actions within the Platform.
- Session identifiers, authentication records and failed access attempts.
- Error and diagnostic logs.
2.6 Communications
The content of the messages you send us by email or through support forms, and the history of those conversations.
2.7 Special categories of data
We do not deliberately request or seek special categories of data (health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, sex life or sexual orientation).
We acknowledge, however, that your connected sources could incidentally contain such information within documents, tickets or messages. In that case, we act as a processor and it is you, as the controller, who must ensure that you have a valid legal basis for processing it before connecting that source. We recommend that you do not connect sources containing special categories of data if you do not have such a legal basis.
3. Data isolation: dedicated container model
This is a core design principle of Docil.ai and it shapes much of this policy:
- Dedicated container per user/organization. Data from your connected sources is stored and processed in a logically isolated container dedicated exclusively to your account. It is not mixed with other customers’ data.
- No human access on our part. Our staff does not access the content of your connected sources. The data is processed automatically by the Platform and by the AI models, not read by members of our team.
- Strict and limited exceptions. The only circumstances in which technical access to your environment could occur are (i) when you expressly request it in order to resolve a support incident, or (ii) when there is a binding legal obligation. Any such access is recorded in an audit log and, unless legally prohibited, you will be notified of it.
- Application-level isolation. All database queries and all API calls are mandatorily filtered by org_id, making it technically impossible for one organization to access another organization’s data.
- Deletion upon account removal. When you delete your profile, the entire container and all its content are destroyed. We only retain the billing and accounting data that we are legally required to keep (see Section 8).
4. What we use data for (purposes)
| Finalidade | Description |
|---|---|
| Provision of the Service | To provide you with AI-assisted business analysis of your connected data. |
| Source synchronization | To connect, synchronize and query the integrations you authorize. |
| Account management | Registration, authentication, management of users and roles within your organization. |
| Faturação | To manage subscriptions, payments, invoices, taxes and accounting compliance. |
| Suporte | To handle your queries, incidents and technical requests. |
| Security | To prevent fraud, abuse, unauthorized access and attacks; to safeguard the integrity of the Service. |
| Service improvement | To analyze aggregated, non-identifiable usage metrics in order to improve features and performance. |
| Communications | To send you operational and service notices (essential) and, if you consent, commercial communications. |
| Legal compliance | To respond to legal and tax obligations and to requests from competent authorities. |
4.1 What we do NOT do
- We do not sell your personal data or the data from your connected sources.
- We do not share your data with third parties for cross-site behavioral advertising purposes.
- We do not use your data or your content to train AI models, whether our own or third parties’. We work with AI providers under enterprise-grade contractual terms that expressly exclude the use of our data for training their models (see Section 5).
- We do not carry out profiling or automated decision-making with legal or similarly significant effects on individuals.
5. Artificial intelligence: how your data is processed
In order to generate analyses, summaries and responses, the Platform sends fragments of your data to a large language model (LLM) provider.
- AI provider: Google (Google Cloud Vertex AI / Gemini API), as a processor under enterprise terms.
- No training: under the applicable enterprise terms, the data sent is not used to train or improve the provider’s models.
- No extended retention: the provider does not retain request data beyond the time necessary to process it and, where applicable, for abuse monitoring, in accordance with its contractual terms.
- Minimization: only the context strictly necessary to answer your query is sent, not the entirety of your container.
- No automated decision-making: AI outputs are informational and intended to support decision-making. They do not produce legal effects nor do they significantly affect you in an automated manner within the meaning of Art. 22 GDPR.
- Limitations: AI systems may produce inaccurate or incomplete results. You should not base critical decisions solely on them without human verification.
5.1 Use of data obtained through Google APIs (Limited Use)
Express statement: Docil.ai’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
English: Docil.ai’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Which Google APIs we use and what for
| API / Service | Scope requested | What it is used for in the Docil.ai interface |
|---|---|---|
| Google Drive | drive.file | To read exclusively the files you select through the Google picker, in order to index them and generate summaries, evidence and analysis chat responses |
| Google Sheets | drive.file | To read exclusively the spreadsheets you select, in order to incorporate their data into the business analysis |
| Google Ads | adwords (read-only) | To analyze campaigns, spend and advertising performance in the reports |
| Google Analytics | analytics.readonly | To analyze traffic, conversions and behavior in the reports |
| Google Search Console | webmasters.readonly | To analyze organic visibility, queries and positions in the reports |
| Google Sign-In | openid, email, profile | Authentication and identification of your account |
Per-file access, not access to your entire drive. For Drive and Sheets we deliberately use the drive.file scope, which is the most restrictive available. This means that:
- Docil.ai cannot see, list or access the general content of your Google Drive.
- Access is granted file by file, only for the documents you choose through the Google file picker (Google Picker), which is displayed within your own Google session.
- If you do not select a file, that file is technically inaccessible to us. This is not a contractual promise: it is a limitation imposed by the Google API itself.
- You may withdraw a file from the analysis at any time, which removes its content from your container.
We request only the minimum scopes indispensable for the functions described. All information obtained is used exclusively for user-facing features of the Docil.ai interface that you have requested.
Limited Use commitments. Information received from Google APIs is not used or transferred:
- To display advertising of any kind, including personalized, retargeting or interest-based advertising.
- To determine creditworthiness or for lending purposes.
- To data brokers, information resellers or information service providers.
- To train, fine-tune or improve generalized AI or machine learning models, whether our own or third parties’. The AI provider that processes this data is Google (Vertex AI / Gemini API) under enterprise terms that contractually exclude training on customer data.
Human access. No member of our team reads your Google data. The only exceptions, aligned with Google’s policy, are: (a) that you give us your express consent to review a specific file or data point in the context of a support incident; (b) that it is necessary for security reasons, for example to investigate abuse or a failure; (c) that applicable law requires it; or (d) that the data is aggregated and used for internal operations in accordance with applicable privacy regulations.
Transfer to third parties. We do not transfer data from Google APIs to third parties, except to the infrastructure providers strictly necessary to provide you with the Service (EU hosting and Google AI processing), which act as processors under contract, or where required by law.
Storage. Data obtained from Google APIs is stored encrypted and in the isolated container dedicated to your organization, hosted in the European Union, in accordance with Section 3.
How to revoke access and delete your Google data. You may do so at any time and by any of the following means:
- From Docil.ai, under Settings → Integrations → Disconnect. Upon disconnecting, the token is revoked and all data from that source is deleted from your container.
- By withdrawing specific files from the analysis through the interface itself, which removes their content from your container without needing to disconnect the entire integration.
- From your Google account, at myaccount.google.com/permissions, by withdrawing the access granted to Docil.ai.
- By deleting your account under Settings → Delete account, which destroys the entire container.
- By writing to us at privacy@docil.ai.
Deletion takes effect immediately in active systems and is completed in backups within a maximum of 30 days.
Changes in the use of Google data. If in the future we wish to access Google data of a type or for a purpose not described in this policy, we will update this document beforehand and will request your consent again before doing so.
6. Legal basis for processing (GDPR)
| Processing | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and managing your account | Performance of the contract (Art. 6(1)(b)) |
| Providing the Service and generating analyses | Performance of the contract (Art. 6(1)(b)) |
| Connecting Stripe, Google, Slack, Notion and other sources | Explicit consent (Art. 6(1)(a)), given during the OAuth/API flow. Revocable at any time |
| Billing and collection | Performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Retention of invoices and accounting records | Legal obligation (Art. 6(1)(c)) |
| Security, fraud prevention and auditing | Legitimate interest (Art. 6(1)(f)) |
| Apoio ao cliente | Performance of the contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) |
| Aggregated usage metrics to improve the product | Legitimate interest (Art. 6(1)(f)) |
| Analytics cookies | Consent (Art. 6(1)(a) and Art. 22 LSSI / ePrivacy Directive) |
| Commercial communications | Consent (Art. 6(1)(a)) or legitimate interest for existing customers regarding similar products |
Where we rely on legitimate interest, we have carried out the corresponding balancing test between our interest and your rights and freedoms. You may request a summary of that assessment by writing to privacy@docil.ai.
7. Sub-processors and third-party providers
We rely on the following providers. The up-to-date list is available at [LINK TO SUB-PROCESSORS PAGE].
| Provider | Function | Data processed | Location |
|---|---|---|---|
| CONTABO | Hosting of the application and of the data containers | All Platform data | European Union |
| Google Cloud (Vertex AI / Gemini) | Processing by AI models | Content fragments sent with each query | U.S. / EU |
| Stripe | Payment processing and billing | Payment, billing and customer identification data | U.S. / EU |
| Google LLC | OAuth and integrations (Drive, Ads, Analytics, Search Console) | Access tokens and data from the authorized APIs | U.S. / EU |
| Google Analytics | Site and application usage analytics | Cookie identifiers, IP, browsing events | U.S. |
| CONTABO | Sending of service emails | Email, name, message content | EU |
| Start and Power LLC | Support ticket management | Email, name, query content | U.S. |
Each of these providers is bound by a data processing agreement with confidentiality and security obligations equivalent to our own. We will inform you with reasonable advance notice of the addition of any new sub-processor, and you may object on reasonable data protection grounds.
HubSpot, Salesforce, Slack, Notion, Zendesk, Dropbox, Microsoft (OneDrive, SharePoint, Teams), Atlassian (Jira, Confluence) and other connected sources are not our sub-processors: they are your systems, from which the Platform reads data with your authorization. Their processing is governed by the contracts you have with them.
8. Data location, international transfers and retention
8.1 Location
Docil.ai’s infrastructure — servers, databases and customer containers — is hosted in the European Union (Germany).
8.2 International transfers
Two types of transfer outside the European Economic Area occur:
a) Access from the United States by Start and Power. Although the data resides on EU servers, Start and Power is a U.S. company and its administrative, billing and support staff access certain data (account data, billing, tickets and operational metadata) from the United States. Remember that, in accordance with Section 3, this access never extends to the content of your connected sources, which remains in your isolated container in the EU with no human access on our part.
b) Providers established outside the EEA, such as Stripe or Google.
Both cases are covered by one or more of the following mechanisms under Chapter V of the GDPR:
- Standard Contractual Clauses (SCCs) approved by the European Commission through Implementing Decision (EU) 2021/914, supplemented by any additional technical and organizational measures found necessary following the corresponding Transfer Impact Assessment.
- EU-U.S. Data Privacy Framework, where the importing entity is certified.
- For the United Kingdom: UK International Data Transfer Addendum; for Switzerland: the Swiss extension of the DPF or adapted SCCs.
You may request a copy of these safeguards by writing to privacy@docil.ai.
8.3 Retention periods
| Category | Period |
|---|---|
| Account data | For as long as the account is active |
| Container of data from connected sources | For as long as the source is connected. Deleted immediately upon disconnecting the source or deleting the account, with effective destruction within a maximum of 30 days including backups |
| AI-generated outputs | Together with the container |
| OAuth tokens | Until the connection is revoked or the account is deleted |
| Billing and accounting data | 7 years from the last transaction (the usual period under IRS requirements and applicable U.S. state accounting rules) |
| Technical and security logs | [12] months |
| Support tickets | [24] months from closure |
| Backups | [30]-day rotation; deleted data disappears from backups once the cycle completes |
| Consent data and evidence of consent | For as long as it is valid + [3] years |
Once these periods have elapsed, the data is securely deleted or irreversibly anonymized.
9. Security
We apply appropriate technical and organizational measures in accordance with Art. 32 GDPR:
- Encryption in transit: all communications via HTTPS/TLS 1.2 or higher.
- Encryption at rest: sensitive data, credentials and integration tokens are encrypted at rest using AES-256 with an application key (APP_ENCRYPTION_KEY) managed securely and separately from the database.
- Passwords: stored exclusively as hashes using a resistant algorithm and a unique salt.
- Multi-tenant isolation: strict segregation by org_id across the entire data and API layer, in addition to the dedicated container described in Section 3.
- Access control: least-privilege principle, strengthened authentication for technical staff and audit logging of administrative access.
- Least privilege in OAuth: we request only the scopes indispensable for the contracted functionality.
- Encrypted backups and periodic restoration testing.
- Security updates and patches applied on an ongoing basis.
9.1 Security breach notification
In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it, provided it is likely to result in a risk to your rights and freedoms. If the risk is high, we will also communicate it to you without undue delay. Where we act as a processor, we will inform the controlling customer without undue delay.
No security measure is infallible. It is your responsibility to keep your credentials confidential and to notify us immediately of any unauthorized use of your account.
10. Your rights
Regardless of where you reside, you may exercise the following rights:
- Access: obtain confirmation as to whether we process your data and a copy of it.
- Rectification: correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): request the deletion of your data.
- Restriction: request that we restrict processing in certain circumstances.
- Portability: receive your data in a structured, commonly used and machine-readable format, or request its transmission to another controller.
- Objection: object to processing based on legitimate interest and, in all cases, to direct marketing.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
- Not to be subject to automated decisions with legal or similarly significant effects.
10.1 How to exercise them
Write to privacy@docil.ai indicating the right you wish to exercise. You can also manage the following directly from the Platform:
- Disconnect any source under Settings → Integrations.
- Download your data under Settings → Export.
- Delete your account and your container under Settings → Delete account.
We will respond within one month, extendable by two further months in complex cases, informing you of the extension. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests. We may ask you for additional information to verify your identity.
10.2 If your data is in a customer’s system
If your personal data has reached Docil.ai because one of our customers connected a source that includes you, you must direct your request to that customer, who is the controller. If you write to us, we will redirect you to them and will provide them with the necessary assistance.
11. Cookies and similar technologies
Docil.ai uses:
| Type | Finalidade | Legal basis | Duration |
|---|---|---|---|
| Strictly necessary cookies (session, authentication, security, CSRF, load balancing) | To enable the basic functioning of the Service | Necessary — no consent required | Session / [30] days |
| Preference cookies | To remember language, theme and settings | Consent | [12] months |
| Analytics cookies (Analytics 4) | To measure use of the site and the application in order to improve them | Consent | [14] months |
We do not use advertising cookies, third-party tracking pixels or cross-site behavioral advertising technologies.
Consent management: in the EEA, the United Kingdom and Switzerland, non-necessary cookies are only installed after your express consent through our cookie banner. You may change or withdraw your choice at any time from Cookie settings. You may also block or delete cookies from your browser settings, although this may affect the functioning of the Service.
Browser privacy signals: we honor the Global Privacy Control (GPC) signal when we detect it, treating it as a valid opt-out request for sale/sharing under applicable U.S. law.
12. Minors
The Service is intended exclusively for businesses and professionals. It is not intended for individuals under 18 years of age and we do not knowingly collect data from minors.
If we become aware that we have collected personal data from a person under 18 without the corresponding legal authorization, we will delete that information without delay. If you believe a minor has provided us with data, write to us at privacy@docil.ai.
We comply with the U.S. COPPA (Children’s Online Privacy Protection Act): we do not direct the Service to children under 13 nor do we knowingly collect their data.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in the Service, in our practices or in applicable regulations.
- The current version will always be published at https://docil.ai/privacy with its last-updated date.
- If the changes are substantial, we will notify you by email and/or through a prominent notice on the Platform at least 30 days before they take effect.
- Where required by law, we will request your consent again.
- We will maintain an accessible history of previous versions.
ANNEX A — Additional information for United States residents
This annex applies to residents of California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland and other states with consumer privacy legislation in force.
Note on applicability. Start and Power may not currently meet the revenue or volume thresholds that trigger the mandatory application of some of these laws (for example, those in §1798.140(d) CCPA). Even so, we have chosen to voluntarily apply these standards to all of our U.S. users. Likewise, although several of these laws exclude data processed in purely B2B contexts, we do not apply that exclusion: we handle requests from our professional users in the same way as those from any consumer.
A.1 Notice at Collection
In the past twelve (12) months we have collected the following categories of personal information:
| Category (CCPA §1798.140) | Specific examples | Do we collect it? | Source | Finalidade | Disclosed for business purposes? |
|---|---|---|---|---|---|
| A. Identifiers | Name, email, IP, account ID, org_id | Yes | You, your device | Account, service, security | Yes — hosting, email, support |
| B. Customer records (Cal. Civ. Code §1798.80) | Name, billing data | Yes | You, Stripe | Faturação | Yes — Stripe |
| C. Protected characteristics | — | No | — | — | No |
| D. Commercial information | Subscription history, transactions | Yes | You, Stripe | Billing, support | Yes — Stripe |
| E. Biometric information | — | No | — | — | No |
| F. Internet or network activity | Usage logs, pages visited, events | Yes | Your device | Security, product improvement | Yes — analytics, hosting |
| G. Geolocation | Approximate location derived from IP (country/city level) | Yes | Your device | Security, tax compliance | Yes — hosting |
| H. Sensory information | — | No | — | — | No |
| I. Professional or employment information | Job title, company, role in the organization | Yes | You | Account, support | Yes — support |
| J. Education information (FERPA) | — | No | — | — | No |
| K. Inferences | AI-generated insights about your business | Yes | Generated by the Platform | Provision of the Service | No |
| L. Sensitive personal information | Account access credentials and integration tokens | Yes | You | Authentication and provision of the Service | Yes — hosting |
Limited use of sensitive information: we use sensitive personal information exclusively for the purposes permitted by §7027(m) of the CCPA Regulations — providing the requested Service, ensuring security and preventing fraud. We do not use it to infer characteristics about you. Consequently, we are not required to offer a specific right to limit its use, although we will honor any request to that effect.
A.2 Sale and sharing of personal information
We do NOT sell personal information. We do NOT share personal information for cross-context behavioral advertising. Nor have we done so in the preceding twelve months. We do not sell or share the personal information of minors under 16, nor do we have knowledge of processing it.
A.3 Your rights if you reside in the U.S.
- Right to know / access: request the categories and specific pieces of personal information we have collected, their sources, the purpose and the third parties to whom it is disclosed.
- Right to deletion: request the deletion of your personal information, subject to applicable legal exceptions.
- Right to correction: correct inaccurate information.
- Right to opt out of sale, sharing and targeted advertising. Not applicable in practice, since we do not carry out any of these activities.
- Right to limit the use of sensitive information.
- Right to data portability.
- Right to non-discrimination: we will not deny you service, charge you different prices, or provide you a lower quality of service for exercising your rights.
- Right to opt out of profiling in decisions with legal or similarly significant effects (Colorado, Connecticut, Virginia). We do not carry out this type of profiling.
- Right to appeal (Virginia, Colorado, Connecticut, Texas, Montana, Oregon): if we deny your request, you may appeal by writing to privacy@docil.ai with the subject line “Privacy appeal”. We will respond within 45–60 days. If we uphold the denial, we will inform you of how to complain to your state’s Attorney General.
How to exercise them: write to privacy@docil.ai or use the form. We will verify your identity through the email address associated with the account and, if necessary, additional information. We will respond within 45 calendar days, extendable by another 45 with prior notice.
Authorized agent: you may designate an authorized agent to exercise your rights. They must provide written proof of your authorization, and we may ask you to confirm that designation directly.
A.4 “Shine the Light” (California Civil Code §1798.83)
We do not disclose personal information to third parties for their own direct marketing purposes.
A.5 Do Not Track and Global Privacy Control
There is no uniform standard for “Do Not Track” signals, so we do not respond to them differently. We do recognize and honor the Global Privacy Control (GPC) signal as a valid opt-out request.
A.6 Notice to Nevada residents
Nevada residents may request to opt out of the sale of certain personal information. We do not sell personal information within the meaning of Nevada law, but you may direct your request to privacy@docil.ai.
ANNEX B — Additional information for the EEA, United Kingdom and Switzerland
B.1 Supervisory authority and right to lodge a complaint
Start and Power has no establishment in the European Union, so the one-stop-shop mechanism under Art. 56 GDPR does not apply. This means you may complain directly to the supervisory authority in your country.
If you believe that the processing of your data infringes the regulations, you have the right to lodge a complaint with the competent authority. We would be grateful if you first contacted us at privacy@docil.ai or our EU representative (Section 1) so that we can try to resolve the matter.
- EU/EEA Member States: the authority of your country of residence, your place of work, or the place where the alleged infringement occurred. The full directory is available at edpb.europa.eu.
- Spain: Agencia Española de Protección de Datos (AEPD) — C/ Jorge Juan, 6, 28001 Madrid — www.aepd.es
- United Kingdom: Information Commissioner’s Office (ICO) — www.ico.org.uk
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC) — www.edoeb.admin.ch
B.2 Mandatory nature of the data
The data marked as mandatory in the forms is necessary for the performance of the contract. If you do not provide it, we will not be able to provide you with the Service. Connecting data sources is always voluntary, although without it the analysis functionality is not available.
B.3 Data Processing Agreement (DPA)
If you are a business customer and need a signed DPA in accordance with Art. 28 GDPR, with the Standard Contractual Clauses incorporated, write to us at privacy@docil.ai.
Contacto
Start and Power LLC 1621 Central Ave, Cheyenne, WY 82001, United States
Privacy and exercise of rights: privacy@docil.ai General: hello@startandpower.com · hello@docil.ai Web: https://docil.ai
EU Representative (Art. 27 GDPR): Stella and Pow OU