This is a draft prepared from how the product actually works. It has not been reviewed by a lawyer and should be checked against the law that applies to you before it is relied on.
01Who this covers
This policy explains how Savvy Data Cloud Consulting FZE, Dubai, United Arab Emirates (“we”) handles personal data in connection with the Savvy DocGen service and this website. It applies to visitors to the site, to people who hold an account in the product, and to people who receive a document for signature through it.
It does not apply to Salesforce or Circularo themselves. Those are separate services under your own agreements with those providers, and their own privacy notices govern what they do with your data.
02Controller and processor
The distinction matters, because it changes who you should contact about what.
- We are the controller for account and website data: who signed up, who logs in, support correspondence, and technical logs from the site.
- We are a processor for the content you put through the product: your Salesforce records, the documents generated from them, and the details of the people you send those documents to. You decide what goes in and why; we act on your instructions.
If you are a customer, a separate data processing agreement should govern the processor relationship. Request one at hello@savvydocgen.com.
03What we collect
Account data
- Name, work email address and the tenant you belong to.
- A hashed password. We never hold the password itself and cannot recover it.
- Two-factor enrolment status and, where enabled, an encrypted authenticator secret and recovery codes.
- Role and permissions within your tenant.
Technical data
- Sign-in timestamps and failed attempt counts, used for lockout and rate limiting.
- Application error reports, which may include the page and action involved.
- Standard server logs.
Connection credentials
- Credentials for the services you connect: Salesforce, Circularo, storage and email. These are encrypted before storage and are never displayed back to you or to us after entry.
Customer content
- Salesforce record data drawn into a document, which is whatever your template asks for.
- The generated documents themselves and their signed counterparts.
- Recipient names and email addresses resolved from your Salesforce records, and the status of each signature request.
04How we use it
- To provide the service: generating documents, sending them for signature and returning the signed copy to your Salesforce record.
- To secure accounts: authentication, two-factor verification, lockout, and revoking sessions when a password changes.
- To support you when you raise a request, and to notify you about signature and generation events you have asked to be told about.
- To keep the service working: diagnosing errors, monitoring availability, and taking backups.
- To bill and administer your account.
We do not sell personal data, and we do not use your documents or Salesforce data to train models.
05Legal bases
Where the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies, or the GDPR where it reaches you, we rely on:
- Contract - to provide the service to you and administer your account.
- Legitimate interests - to secure the platform, prevent abuse, and improve reliability, balanced against your rights.
- Legal obligation - where we must retain records.
- Consent - only where we ask for it explicitly, which you can withdraw at any time.
06Who we share it with
We share personal data only with the providers needed to run the service.
Your Salesforce org is not a sub-processor. It is your system, which we connect to on your instruction.
We may also disclose data where we are legally required to, and we will tell you unless we are prohibited from doing so.
07International transfers
The service can be deployed in the region you require, including the Middle East. Where data moves between regions we rely on standard contractual clauses, together with your own written instruction that the service be deployed in a particular region.
08How long we keep it
- Account data - for as long as the account exists, then 90 days after closure.
- Generated documents and history - controlled by you. Set a retention period on your tenant and documents older than it are purged automatically, including the stored files. Set no period and they are kept until you delete them.
- Technical logs - 90 days.
- Backups - retained on a rolling schedule and overwritten in turn.
Templates, connections and user accounts are never removed by the retention purge.
09How we protect it
Passwords are hashed, stored credentials are encrypted with AES-256-GCM, sessions can be revoked instantly across every device, and a strict content security policy is served with every page. The full detail is on our security page, including the certifications we do not yet hold.
10Your rights
Subject to the law that applies to you, you may ask to access, correct, delete, export or restrict your personal data, object to processing, or complain to a supervisory authority.
Account owners can export a tenant's data from the product directly, as a package containing the metadata, the template files and time-limited links to generated documents. Account deletion is also available in-product.
If you are a signer rather than a customer, see the next section - your request usually needs to go to the organisation that sent you the document.
11People who sign documents
If you received a document for signature, your name and email address reached us from the Salesforce records of the organisation that sent it. They decide what is sent, to whom and why. We act on their instruction.
For access, correction or deletion, contact that organisation first. If you cannot identify them, write to us at hello@savvydocgen.com and we will route your request or tell you who to ask.
Where the sender requires it, you may be asked for a one-time code sent to your email address, or a password, before the document opens. That check exists to confirm the document reaches you and nobody else.
12Children
The service is for business use and is not directed at children. We do not knowingly collect their data. Note that a document generated by a customer may legitimately contain a child's details - for example a school enrolment - and in that case the customer is the controller of it.
13Changes
We will update this policy as the service changes. The version and date at the top always reflect the current text, and we will tell account holders about material changes before they take effect.
Privacy questions and data requests: hello@savvydocgen.com
Data protection representative: none appointed - privacy questions go to the address above