Privacy policy
Last updated: 8/4/2026
This page is maintained by Nordic Tender ApS (trading as "DocMaker") to answer common privacy questions about the DocMaker service. It is not legal advice.
Who we are
The DocMaker service is operated by Nordic Tender ApS ("we", "us"), a company registered in Denmark. Nordic Tender ApS is the data controller for personal data processed in connection with your use of DocMaker. You can reach us at privacy@docmaker.org.
Data we collect and why
- Account data (email, optional name, hashed password / OAuth identifier) — to create and secure your account. Legal basis: performance of contract.
- Documents you upload and derived files — to provide the requested conversion, editing or signing tool. Legal basis: performance of contract.
- Usage metrics (tool used, file size, success/failure, timestamps, IP, user agent) — to operate the service, prevent abuse and improve reliability. Legal basis: legitimate interests.
- Billing data (plan, subscription status, billing email, country, VAT ID where applicable) — to manage your subscription. Legal basis: performance of contract and legal obligation (tax/accounting).
- Support correspondence — to answer your questions. Legal basis: legitimate interests.
How files are handled
Where possible we process files entirely in your browser. Cloud-routed files are encrypted in transit (TLS) and at rest, stored in per-user buckets, and accessed via short-lived signed URLs. Retention follows your plan: 1 hour on Free, 7 days on Pro, configurable on Business.
Who we share data with
We do not sell your data and we do not share it with advertising networks. We use the following categories of processors and partners to run the service:
- Paddle.com Market Ltd — our Merchant of Record and payment processor. Paddle handles checkout, payments, billing, invoicing, sales tax and refunds, and processes your name, billing address, email and payment details for these purposes. See Paddle's privacy notice.
- Cloud hosting and database — to host the application, store account data and run server functions.
- Email delivery — to send transactional emails (sign-in links, receipts, account notifications).
- Professional advisors (legal, accounting) and competent authorities where required by law.
Some processors may transfer data outside the EU/EEA. Where this happens, transfers are protected by adequacy decisions or Standard Contractual Clauses.
Retention
Uploaded files are retained according to your plan and then deleted automatically. Account data is retained while your account is active and deleted (or anonymised) within 90 days of account closure. Billing records are retained for the period required by Danish accounting law (currently 5 years).
Your rights
You can export or delete your account and all associated files at any time from your account settings. Under the GDPR you also have the right to access, rectify, restrict or object to processing, to data portability, and to withdraw consent. You can exercise these rights by emailing privacy@docmaker.org; we will respond within one month. You also have the right to lodge a complaint with your local supervisory authority (in Denmark: Datatilsynet).
Security
We apply appropriate technical and organisational measures to protect personal data, including TLS encryption in transit, encryption at rest for stored files, per-user access isolation via row-level security, signed short-lived download URLs, hashed credentials, least-privilege access for staff, audit logging, and regular dependency and security reviews.
Cookies
DocMaker uses strictly necessary cookies for authentication and theme preferences only. We do not use third-party analytics or advertising trackers.
Contact
Nordic Tender ApS — privacy@docmaker.org.