This Privacy Policy explains how Agreedock, trading as AgreeDock (“AgreeDock,” “we,” “us,” or “our”), collects, uses, shares, stores, and protects personal data when you use our website, applications, and related services.
It also explains AgreeDock’s role when businesses and individuals use the Service to create Forms and collect information or signatures from other people.
AgreeDock is operated by:
Agreedock
Privacy contact: info@agreedock.com
Website: www.agreedock.com
For personal data concerning AgreeDock accounts, billing, website use, support, security, and our business operations, Agreedock is generally the data controller.
For personal data submitted through a Form created by an AgreeDock Customer, the Customer is generally the data controller and AgreeDock generally processes that information on the Customer’s behalf.
This Privacy Policy applies when you:
This Privacy Policy does not govern the independent privacy practices of AgreeDock Customers, Stripe, or other third-party services.
AgreeDock may have different legal roles depending on the context.
AgreeDock generally acts as a controller when we determine why and how personal data is processed, including when we process:
AgreeDock generally acts as a processor when a Customer uses the Service to collect or store personal data through a Form.
In that context:
The information we collect depends on how you interact with AgreeDock.
When you create or manage an account, we may collect:
When you purchase a paid plan, we may collect or receive:
Payments are processed by Stripe or another payment provider identified during checkout. Payment-card details are provided to the payment provider and are processed according to that provider’s privacy practices.
Depending on the payment integration, AgreeDock may not receive or store complete payment-card details.
Customers may create Forms containing:
A Respondent completing a Form may provide:
The categories of personal data collected through a Form are determined by the Customer.
When you use the Service, we may automatically collect:
We use this information to operate, protect, understand, and improve the Service.
When you contact us, we may collect:
Please avoid sending sensitive personal data to our support team unless it is necessary.
Where applicable, we may collect:
We collect personal data:
Where the GDPR or similar law applies, we rely on one or more of the following legal bases.
We process account, usage, support, and billing information to:
The legal basis is normally performance of a contract or taking steps at your request before entering into a contract.
We may process technical, usage, support, and account information to:
The legal basis is normally our legitimate interest in operating and improving the Service. Where required, we will rely on consent.
We process account, technical, submission, and log information to:
The legal basis is our legitimate interest in protecting the Service, our users, and our legal rights. Processing may also be necessary to comply with a legal obligation.
We process billing, transaction, account, and communication information to:
The legal basis may be performance of a contract, compliance with a legal obligation, or our legitimate interests.
We may send messages concerning:
These communications are normally necessary to perform our contract or operate the Service.
We may send product news, offers, educational content, or other marketing communications where:
You may unsubscribe at any time using the link in the message or by contacting us.
We rely on consent where legally required, including for certain:
You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn.
When you complete a Customer’s Form, AgreeDock generally processes your information on behalf of that Customer.
The Customer is responsible for explaining:
AgreeDock does not determine whether a Customer’s questions are necessary or appropriate.
Privacy requests concerning a Customer Form should normally be sent directly to the Customer. Where you send such a request to AgreeDock, we may forward it to the relevant Customer or assist the Customer in responding.
We may independently process limited technical or security information associated with a Form submission where necessary to secure the Service, prevent abuse, comply with law, or establish legal claims.
A signature collected through AgreeDock is personal data.
Depending on how the Service is configured, a signature may be accompanied by information such as:
AgreeDock does not use signature images to identify individuals through biometric matching unless this is expressly introduced, explained, and supported by an appropriate legal basis.
Customers must not use signature information for unrelated purposes without a lawful basis.
Customers control the content of their Forms and may request information that is sensitive or specially protected.
AgreeDock does not require Customers to collect such information as part of the ordinary operation of the Service.
Customers are responsible for determining whether they may lawfully collect information concerning:
We may restrict the collection of particular information where we believe the Service does not provide safeguards suitable for the proposed processing.
We may share personal data in the following circumstances.
Form submissions are made available to the Customer that created the Form and to people the Customer authorises to access its account.
The Customer controls access permissions within its organisation.
We use service providers that help us operate AgreeDock, including providers of:
These providers may process personal data only to provide their contracted services or for other purposes permitted by applicable law.
Stripe processes payment and billing information when you purchase an AgreeDock Subscription.
Stripe may act as an independent controller for certain processing, including compliance, fraud prevention, and payment-network activities. Stripe’s handling of personal data is governed by its own privacy documentation.
We may share information with lawyers, accountants, auditors, insurers, and other professional advisers where reasonably necessary and subject to appropriate confidentiality obligations.
We may disclose information where we reasonably believe disclosure is necessary to:
Personal data may be disclosed or transferred in connection with a merger, acquisition, financing, restructuring, insolvency, or sale of all or part of our business.
Where required, we will provide notice and continue to protect personal data in accordance with applicable law.
We may share information where you instruct us to do so, including when you enable an integration or export information to another service.
AgreeDock is established in Lithuania, within the European Economic Area.
Some service providers may process personal data outside Lithuania or outside the EEA.
Where personal data is transferred to a country that has not been recognised as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:
Customers should review our Data Processing Addendum and subprocessor information for details relevant to Customer-controlled data.
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide the Service, meet legal obligations, resolve disputes, and enforce agreements.
Retention depends on the category of information.
We generally retain account information while the account is active and for [30 DAYS] after account closure, unless a longer period is required for legal, security, fraud-prevention, or dispute-resolution purposes.
Customer Content is generally retained until:
Following deletion from active systems, information may remain in encrypted or access-restricted backups for up to [90 DAYS] before being overwritten, unless retention is required by law.
Customers are responsible for establishing appropriate retention periods for their Forms.
Invoices, transaction records, tax information, and related records may be retained for the period required by accounting, tax, anti-fraud, and other applicable laws.
Technical, diagnostic, and security logs are generally retained for up to [12 MONTHS], unless a longer period is required to investigate an incident or establish legal claims.
Support records may be retained for up to 24 months after the request is resolved, unless they are needed for an active account, dispute, security investigation, or legal requirement.
Marketing preferences and consent records are retained while relevant and for a reasonable period afterwards to demonstrate compliance. Suppression records may be retained to ensure that a person who opted out is not contacted again.
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, or access.
These measures may include:
Security measures are reviewed based on the nature, scope, context, and risks of the processing.
No system is completely secure. Customers should use appropriate account controls, limit internal access, and maintain independent copies of records where necessary.
Where AgreeDock becomes aware of a personal-data breach, we will investigate and take reasonable steps to contain and address it.
Where AgreeDock acts as a processor, we will notify the affected Customer without undue delay where required by applicable data-protection law.
Where AgreeDock acts as a controller, we will notify the appropriate supervisory authority and affected individuals where legally required.
Depending on your location and the circumstances, you may have the right to:
These rights may be subject to legal conditions, limitations, and exceptions.
To exercise a right concerning data AgreeDock controls, contact info@agreedock.com.
We may request information needed to verify your identity and locate the relevant data.
We normally respond within one month, although the period may be extended where permitted for complex or numerous requests.
When your request concerns information submitted through a Customer’s Form, the Customer is normally responsible for handling the request.
You should contact the Customer identified in the Form or in the Customer’s privacy notice.
AgreeDock may:
AgreeDock cannot normally delete a Customer-controlled record solely at a Respondent’s request without instructions from the Customer, unless AgreeDock is legally required to do so.
Please contact us first at info@agreedock.com so that we can try to resolve your concern.
You also have the right to lodge a complaint with the Lithuanian State Data Protection Inspectorate.
You may also contact the data-protection authority in the EU or EEA country where you live, work, or believe an infringement occurred.
AgreeDock may use cookies, local storage, pixels, software development kits, and similar technologies.
These technologies may be used for:
Strictly necessary technologies may be used without consent where permitted by law.
Non-essential analytics or marketing technologies will be used only where we have an appropriate legal basis, including consent where required.
Additional information should be provided in the AgreeDock Cookie Policy or cookie-preference interface.
You may adjust cookie preferences through our consent interface and through your browser settings.
You may opt out of marketing emails by:
Opting out of marketing does not prevent us from sending necessary account, billing, security, legal, or Service-related communications.
AgreeDock does not currently use personal data to make decisions that produce legal or similarly significant effects based solely on automated processing.
If this changes, we will provide the information and safeguards required by applicable law.
AgreeDock accounts are not intended for children who cannot legally enter into a contract.
Customers may create Forms intended to be completed for or concerning minors only where they have determined that the processing is lawful and have obtained parental or guardian authorisation where required.
Customers should avoid collecting information from children unless it is necessary and appropriate for the relevant purpose.
If you believe a child has provided personal data to AgreeDock unlawfully, contact info@agreedock.com
The Service may contain links to or integrations with third-party websites and services.
We are not responsible for the privacy practices of third parties. You should review their privacy policies before providing information or enabling an integration.
We may update this Privacy Policy to reflect changes to:
We will update the effective date when changes are made.
Where changes materially affect your rights or how we use personal data, we will provide additional notice where appropriate, such as an email, website notice, or in-product notification.
For privacy questions or requests, contact:
Agreedock
Privacy email: info@agreedock.com
Website: www.agreedock.com