Personal data processing terms
Version 2026-10-05.1 · 2026-10-05
1. Roles and instructions
These rules supplement Docx terms and privacy policy for organization, law-office and mediator workspaces. Organizations determine the purposes of processing client, employee, case and service data. DOKIQS LLC acts as a data controller for its own account, security and payment functions and as the relevant authorized processor for technical actions instructed by an organization. A specific written agreement, where concluded, defines the particular instructions.
2. Data scope and lawful basis
Workspace data may include clients, representatives, employees, contract parties and beneficiaries, contacts, identifiers, cases, attachments, messages and financial records. Organizations must have a lawful basis for collection, upload and transfer, necessary consents and authority. Special-category, children’s and professionally confidential data are supplied only under appropriate legal conditions and to the necessary extent.
3. Permitted technical actions
Within organization-confirmed actions, data may be collected, entered, stored, organized, displayed according to permissions, used to prepare documents and delivered to a chosen recipient. These rules do not authorize independent advertising use or sale of private organization data. Processing beyond instructions requires a separate lawful basis.
4. Access and confidentiality
Organizations grant and promptly revoke employee and representative access, ensure individual account use and appropriate confidentiality obligations. The platform controls access and encrypts the designated sensitive data. Organizations separately secure their devices, exported files and external links. Publication and private office storage are different actions.
5. Suppliers and international transfers
Hosting, files, message delivery and actually activated integrations may involve suppliers described in the privacy policy. Access is limited to the relevant function. Required international-transfer safeguards and permissions are not replaced by general organization consent. Organizations may not instruct unlawful transfers.
6. Requests and incidents
On receiving a data-subject request, the parties cooperate to locate data, supply permissible copies, correct, block or erase data while protecting others. Platform technical assistance does not remove the organization’s responsibility to its client. Detected incidents are communicated through the relevant channel and necessary containment and mandatory notification measures are taken.
7. Service termination and copies
Before ending a workspace, organizations may use available export or document download functions and request necessary data. Deletion takes account of legal retention, other signatories’ copies and backups. Continuing retention without a corresponding purpose is not authorized.
8. Written particulars and contact
Relationships requiring specific processing instructions must record in writing the purpose, basis, data and subject scope, recipients, safeguards and other necessary terms. These public rules do not certify that a separate agreement or regulatory permission already exists. Request a contract or clarification through the established Contact us channel.
9. Legal basis
These rules apply subject to mandatory Armenian legal requirements. Personal Data Protection Law: https://www.arlis.am/hy/acts/229131 . Consumer Rights Protection Law: https://www.arlis.am/hy/acts/226867 . Electronic Document and Electronic Digital Signature Law: https://www.arlis.am/hy/acts/218694 . Armenian Civil Code: https://www.arlis.am/hy/acts/230025 . Subsequent changes are governed by the mandatory rule applicable to the relevant relationship.