DDOCLOOP

Legal

Privacy Policy

Last updated: August 21, 2026

1. Who we are

DocLoop is operated by Calyvent (“we”, “us”). This policy explains what we collect, why, and the narrow ways it leaves your hands. Questions: hello@calyvent.com.

2. What we collect

  • Account data: your name, firm name, email address, chosen profession, and a salted hash of your password (never the password itself).
  • Client and engagement records you create: names, emails, phone numbers, companies, notes about your clients; engagement titles, due dates, recurrence settings; document-type definitions; and request statuses such as received, reviewed, or rejected.
  • Session data: an opaque session cookie that keeps you logged in. No advertising or analytics cookies today.
  • Operational logs: standard server logs kept for security and reliability.

Today DocLoop tracks document metadata only — it does not store the documents themselves. If file storage is ever introduced, this policy will be updated first.

3. Your clients’ data: you are in charge

The client information in your ledger belongs to a relationship between you and your clients. For that data, you act as the controller (the party deciding why and how it is processed) and we process it only on your instructions, to run the service for you. We do not email, contact, market to, or profile your clients. For your own account data, Calyvent is the controller.

4. Why we process

  • to provide the service (accounts, ledgers, reminders);
  • to secure accounts and prevent abuse;
  • to communicate service notices and billing when applicable;
  • to comply with law.

We never sell personal data and run no ad networks.

5. Who else touches it

Only vetted infrastructure providers, each under contract, processing the minimum needed: hosting (Vercel), database hosting (Neon), transactional email for auth/reminders (Resend), and payments when billing exists (Stripe). Their identities may change as we improve the stack; current providers are listed here and updated as needed.

6. Retention & deletion

We keep your data while your account is active. Delete your account (or write to us) and we delete production data within 30 days; encrypted backups purge on their normal cycle thereafter. Data we must retain by law (e.g., billing records) is retained only as long as required.

7. Security

Passwords are stored as bcrypt hashes; sessions are opaque tokens in HTTP-only cookies; traffic is encrypted in transit. No system is perfectly secure — keep independent backups of anything you cannot afford to lose (see Terms §3).

8. Your rights

Depending on where you live (including GDPR in the EU/UK and CCPA/CPRA in California), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Exercise them from inside the app or by emailing hello@calyvent.com. If you are a professional using DocLoop, requests from your clients about their data should be handled by you as controller — tell us and we will assist where required.

9. International transfers

Our providers may process data in the United States and other countries. Where required, transfers rely on provider certifications such as the EU Standard Contractual Clauses.

10. Children

DocLoop is not directed at anyone under 18, and we do not knowingly collect their data.

11. Changes

Material changes will be announced in the app or by email before taking effect. Continued use after changes means acceptance.

12. Contact

Privacy questions: hello@calyvent.com. See also our Terms of Service.

← Back home