Privacy policy
Version 4 · 2026-10-05
1. Controller and contact
DOKIQS LLC (ԴՈԿԻՔՍ) controls processing for platform accounts, security and technical operation. A law firm, organization or selected recipient may have separate responsibilities for data received for its own purposes. Use Contact us for questions, correction or deletion requests. We may request proportionate identity verification to assess a request, but never your password or PIN.
2. Data processed
Depending on the function, data include names, patronymic, date of birth, citizenship, addresses, phone, email, username, organization details, settings and verification states. Document functions use your answers, selected facts, documents, attachments, signature image and confirmation data. Workspaces may contain case, message, meeting, invoice and payment-record information.
3. Sign in with Google and Apple (Google user data)
If you choose “Sign in with Google” on the website or in the iOS or Android app, Docx requests only Google’s basic sign-in scopes: openid, email and profile. From the ID token returned by Google we receive your Google account identifier, email address, whether Google has verified that address, and your first and last name. We use these data only to sign you in, to create or link your Docx account (prefilling the registration form and confirming your email address) and to protect the account against misuse. We store only the Google account identifier linked to your Docx account, together with the email address and name you keep in your profile. We do not receive or store your Google password, Google access or refresh tokens, contacts, Gmail, Drive or Calendar data, and we do not request access to them. Google user data are not sold, not used for advertising, not used to train AI models and not transferred to third parties, except to the hosting provider needed to run the service or where required by law. Docx’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy https://developers.google.com/terms/api-services-user-data-policy , including the Limited Use requirements. Deleting your Docx account immediately removes the Google link; you can also revoke Docx’s access at any time at https://myaccount.google.com/permissions . Sign in with Apple works the same way: we keep the Apple account identifier and the email address Apple shares with us, which may be a private relay address.
4. Purposes and grounds
Data are used to provide the account and service you request, prepare documents, deliver them to your chosen recipient, manage access, review identity, protect security and meet legal obligations. Processing requiring consent relies on the relevant choice; other processing relies on a basis permitted by applicable law. Required fields are marked. Withholding them may prevent the function that depends on them.
5. Identity materials and signature
An identity request contains a snapshot of identity details, the document expiry date and 2–3 images depending on document type. Materials are stored encrypted and accessible to authorized administrators. Request views and decisions are recorded. Passport details and saved signatures are accessed through the protected procedure. Submitting images does not imply automatic facial recognition or comparison with a government database.
6. AI and translations
When you send a message to DOCX AI, the message and necessary conversation context are processed through the OpenAI API to generate a response. Requests use store:false; this does not imply the absence of all provider technical logs. Do not send secrets or unnecessary personal data. Identity-verification images and saved signatures are not included in chat requests by the platform. Interface and fact translations use a stored dictionary and do not require sending user data to a translation provider.
7. Recipients and processing abroad
Within your chosen action, data may reach the stated recipient, professional, authorized organization employee or signing party. Technical processing involves Render for hosting, Cloudflare R2 for files, OpenAI for AI requests, Google Analytics for separately consented analytics, and actually connected email, SMS and push suppliers. The Render server region used is Frankfurt. Other processing locations depend on supplier contracts and routing. International transfers require the protection level, safeguards and permissions required by Armenian law; general consent does not replace them. Activating an external integration transfers only the necessary and authorized data for that function.
8. Retention and deletion
Account and document data are retained as necessary for the active service, security, mandatory records or a justified dispute-related purpose. Earlier identity requests may remain to substantiate verification and replacement history. Deletion or restriction requests are assessed against the data category and relevant obligations. Deleting an account copy does not remove a copy already sent to a recipient. Backups and lawfully retained evidence may follow separate retention processes; immediate universal erasure is not promised.
9. Your rights
You may request information about processing, access, correction of inaccurate data and, where provided by law, blocking, destruction or withdrawal of consent. Locking verified passport fields does not remove your right to request correction: use document replacement or contact support. Requests are handled under applicable statutory procedures and deadlines. You may complain to the competent personal-data protection authority or a court.
10. Browser storage and optional services
Browser storage holds sign-in state, security confirmations, language, theme and necessary current data. Google Analytics 4 loads only after analytics consent and is disabled in environments configured as a sandbox. We measure public page-group visits, main links and speed. Google also receives device and browser technical information and cookie identifiers. Our events exclude documents, passport data, signatures, names, email addresses, sign-in secrets and referral codes. Private workspace measurement is disabled. Preferences and Analytics cookies last up to 180 days. Declining prevents Analytics loading; withdrawing removes its cookies and reloads the page. Change your choice with the button on this page or the cookies page. Do Not Track and Global Privacy Control are respected. Google processing details: https://policies.google.com/technologies/partner-sites . WhatsApp interactions also use that service’s terms.
11. Security and your role
Access restrictions and encryption of certain sensitive data are used, without promising absolute security. Use a secure device, sign out on shared devices, keep your own copies and avoid unnecessary third-party data. Upload special-category data, minors’ data or another person’s confidential information only when necessary and lawfully permitted. Security incidents are addressed through containment and applicable notification measures.
12. Updates and languages
Material changes are communicated on the website or through an available contact channel. All three language versions describe the same functions and aim to convey the same meaning. Contact us to clarify inconsistencies; translation does not limit your statutory rights.
13. Notifications and vehicles
The registration plate and registration certificate number of an added vehicle are stored encrypted. Until the traffic police database is connected, these details are not considered verified against government records and no data is received from that database. You can remove a vehicle from your account. Your stated date of birth, region of residence, whether you have added a vehicle, and registered web, iOS or Android usage in the last 90 days may be used to target in-platform notifications. You can change or clear your region in personal details. Platform registration does not locate your device. Notifications are stored in your account with their read status; access to organization notifications depends on your permissions.
14. Consequences of account deletion
You can request deletion on the passport details page. Before confirmation, the platform displays file and document counts, the DXT balance to be lost and affected organizations. Acceptance of the consequences, your current password and six-digit PIN are required. Solely owned organizations are also deleted unless ownership is transferred to an active member first. Copies already held by other parties and necessary anonymous technical and financial references remain; they do not restore your account or access. Account access ends immediately; removal from external file storage uses a retryable job in case of connection failures.
15. Professional status and business registration
To verify advocate or mediator status, we process the certificate number, submitted documents, stated expiry date and review outcome. Uploaded documents are stored encrypted and accessible to an administrator authorized to review them. Business registration involves organization details, the applicant’s declaration of authority and a link to the named director or founder. Ordinary businesses and offices matching an already verified professional’s qualification are created without additional approval. Where needed, representative documents are reviewed. Managing a business account does not transfer legal ownership of the organization.
16. Data sources
Data come from you, your chosen representative or professional, another transaction party, authorized organization employees and technical service operation. Public professional directories use relevant official public sources. Matching a phone number or email may prompt a professional-page verification suggestion but does not replace identity verification.
17. Family relationships and minors’ data
The family function processes a child’s names, birth date, gender, representation relationship, supporting document and review outcome. These data verify authority and beneficiary eligibility for the chosen service. Representatives provide only necessary information within their authority. Supporting files are stored encrypted. Ending a relationship restricts new actions but does not delete lawful copies of existing agreements held by other parties.
18. Services, orders and offer-drafting applications
Creating or ordering a service or asking an office to draft an offer uses the offer description, requirements, price, beneficiary and customer information, selected contract, discussions, attachments and statuses. Only the chosen application’s data are sent to the office. Signed documents and necessary information are available to relevant parties according to the action and permissions.
19. Cases, tasks and financial records
Office workspaces may process client contacts, case numbers, categories, judges, meetings, tasks, employees, messages, expenses and payment records. Owners and managers must grant the minimum necessary access. Organizations independently determine lawful purposes for their clients’ data and are responsible for informing them.
20. Web push and messages
With permission, we store the web push subscription endpoint, technical keys, device-account link and enabled state for notification delivery. Disable push through the platform or browser. Signing out removes the device’s subscription from the platform account. Notifications may appear on a locked screen; configure device privacy settings. Operational messages do not establish blanket advertising consent.
21. DXT, payments and referral links
Data include order number, amount, DXT allocation and use, payment method and status, bank transaction references, refund result, referral code and bonus conditions. Full card numbers, CVV and bank secrets are entered on the bank or payment supplier page; never send them to Docx support. Referral links support bonus calculations and prevention of duplicate or fraudulent allocations.
22. Public information and corrections
Public pages expose names, photos, professional status, workplace, contacts and published offers to visitors. Passport materials, signatures and private cases are not thereby published. Request a directory correction or justified removal through support, identifying the page and issue. Search-engine caches may update later.
23. Retention criteria and exercising rights
Retention depends on an active account or order, necessary evidence and mandatory accounting or legal requirements. It is limited by the relevant purpose; indefinite retention of all data is not specified. Information about categories and retention grounds is available on request. You may request a data or content copy when service ends, subject to other people’s rights.
24. Data requests and incidents
Submit requests through the established Contact us channel, identifying the account or page, request and reason. Proportionate identity or authority evidence may be required, never your password, PIN or CVV. Access, correction, blocking, destruction and consent-withdrawal requests follow applicable legal procedures and deadlines. Incidents involve containment, recovery and mandatory notification measures. You may contact Armenia’s competent personal-data protection authority or a court.
25. Legal basis
These rules apply subject to mandatory Armenian legal requirements. Personal Data Protection Law: https://www.arlis.am/hy/acts/229131 . Consumer Rights Protection Law: https://www.arlis.am/hy/acts/226867 . Electronic Document and Electronic Digital Signature Law: https://www.arlis.am/hy/acts/218694 . Armenian Civil Code: https://www.arlis.am/hy/acts/230025 . Subsequent changes are governed by the mandatory rule applicable to the relevant relationship.