Privacy Notice

How Doxa Privacy collects, uses, and protects personal information — on our website, and within our privacy compliance platform.

Effective: June 1, 2025

No Sale, No Sharing

We do not sell your data or use third-party advertising.

Rule-Based, Not AI

Deterministic logic, not AI or ML models.

Contextual Integrity

Data flows only in consistent contexts.

1. Scope and Our Two Roles

This Notice applies to personal information we handle through doxaprivacy.com and its subdomains, the Doxa Scanner, and the Doxa platform (together, the "Services"). We handle personal information in two distinct roles, and your rights depend on which applies.

As a Business / Controller

When you visit our website, request a demo, subscribe to our newsletter, or hold a Doxa account, we determine why and how your personal information is used. For this information, we are the business or controller, and the rights in Section 10 apply directly to us.

As a Service Provider / Processor

When you use the platform to generate a privacy notice or complete a Privacy Impact Assessment (PIA), you may enter personal information about your own customers, employees, or other data subjects. We process that information only on your documented instructions and solely to produce the deliverable you requested. For that information we are a service provider or processor, and you — our customer — are the controller responsible to those individuals.

2. Information We Collect

As a business, we collect the following categories. We collect only what we need — we do not use analytics, advertising, or third-party tracking technologies.

CategoryExamplesSource
Identifiers & Contact DataName, business email, employer, job title, phone numberYou
Account DataUsername, authentication credentials, role, subscription tierYou
Commercial DataProducts purchased, billing records, transaction historyYou and our payment processor
CommunicationsSupport tickets, correspondence, newsletter preferencesYou
Technical/Operational DataIP address, session logs, and security event recordsAutomatically

3. Customer Content We Process on Your Behalf

When you use the platform, you provide information — including personal information about your own data subjects — so that Doxa can generate a privacy notice or complete a PIA. We call this Customer Content. We handle it under strict limits:

  • We process Customer Content solely to generate the privacy notice or PIA you request, and for no independent purpose of our own.
  • We do not sell it, share it for advertising, or use it to build profiles.
  • Customer Content is processed to produce your deliverable and is not retained to persist within Doxa's systems beyond what is described in Section 9.
  • We combine Customer Content only within your own account context — never across customers.

Contextual Integrity Commitment

Customer Content flows only within the context you defined when you entered it: your assessment, your notice, your account. That contextual boundary is a design principle of the platform, not merely a policy statement.

The Doxa Scanner

When you enter a URL into the Doxa Scanner, we perform an automated, point-in-time review of that website's publicly available pages only to produce a Disclosure Coverage Score. You may scan anonymously. If you sign in, your scan history is saved to your account so you can track changes over time; if you are not signed in, we do not associate the scan with an account. The Scanner produces a factual, heuristic score — not a legal conclusion — and complete compliance still requires qualified counsel.

4. How and Why We Use Information

As a business, we use the personal information in Section 2 to:

  • Provide the Services: Create and maintain your account, deliver features, and respond to requests.
  • Billing and administration: Process payments, manage subscriptions, and keep required records.
  • Communicate with you: Send service messages, respond to support, and deliver the newsletter you subscribed to.
  • Security and integrity: Detect, prevent, and respond to fraud, abuse, and security incidents.
  • Legal compliance: Meet legal, regulatory, tax, and audit obligations.

We use Customer Content only as described in Section 3.

5. Sensitive Information

"Sensitive personal information" includes government identifiers, financial account details, precise geolocation, racial or ethnic origin, religious beliefs, health information, sexual orientation, biometric or genetic data, and the contents of certain communications.

In our capacity as a business

We do not seek to collect sensitive personal information about our website visitors or account holders, and we do not use any sensitive personal information we do receive to infer characteristics about you. We use it only for the purposes permitted under applicable law — such as providing the Services and ensuring security — and not for any purpose that would require your right to limit the use of sensitive personal information. Where a state law requires opt-in consent before processing sensitive data, we obtain it.

As a processor of Customer Content

Your PIA or notice project may itself describe sensitive categories of data — including health and reproductive-health information, biometric or genetic data, and children's data — as part of the assessment you are performing. When it does, we process that information strictly as your service provider, only to produce your deliverable, under the same limits in Section 3. We apply heightened safeguards to these categories and do not use them for any purpose of our own.

Reproductive-Health Information

Where reproductive- or sexual-health information appears in Customer Content, we treat it as sensitive information subject to the strictest handling. We do not disclose it except as needed to render your deliverable or as required by law, and we do not respond to requests for it that lack a valid legal basis.

6. Automated Processing

The Doxa platform uses automated, rule-based logic built into the product to help draft privacy notices and Privacy Impact Assessments from the information you enter. This processing is deterministic: it applies defined rules and mappings to your inputs to assemble a draft. We want you to understand exactly what this does and does not mean.

  • We do not use artificial intelligence or machine learning. Our processing is driven by fixed logic, not AI or ML models.
  • Because we use no such models, we do not — and could not — use your information to train, fine-tune, or improve any AI model.
  • Human review is a required gate. Automated output is a draft. No notice is delivered and no high-risk assessment is approved without review and written sign-off by a qualified privacy professional.
  • The system does not make final decisions on its own. Outputs are not legal advice or legal conclusions.
  • No solely-automated decisions about you. We do not use automated processing to make decisions that produce legal or similarly significant effects about our website visitors or account holders.

7. Disclosures to Third Parties

We disclose personal information only to the limited recipients needed to run the Services, each bound by contract to protect it and use it only for the purpose we specify:

  • Infrastructure & hosting providers: Secure cloud hosting and storage of the Services.
  • Payment processor: Processing subscription payments.
  • Professional advisors: Legal, accounting, and audit support, under confidentiality.
  • Authorities, when required: Compliance with law, valid legal process, or protection of rights and safety.

We may also disclose information in connection with a merger, acquisition, or financing, subject to this Notice. We do not disclose Customer Content to any recipient except as instructed by you or as strictly necessary to provide the Services.

8. No Sale, No Sharing, No Targeted Advertising

We state this affirmatively: in the preceding twelve months and today, Doxa Privacy has not sold personal information and has not shared it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable state laws. We do not process personal information for targeted advertising. Because we conduct none of these activities, there is nothing for you to opt out of in these respects — but your other rights in Section 10 remain fully available.

9. Retention

We keep personal information only as long as needed for the purpose it was collected, then delete or de-identify it.

  • Account and contact data — for the life of your account and a limited period afterward to meet legal, tax, and audit obligations.
  • Customer Content — retained only as needed to generate and deliver your notice or PIA and to make the finished deliverable available to you within your account; it is not retained to persist in our systems beyond that purpose.
  • Security and transaction records — for the period required by law and sound security practice.

10. Your Privacy Rights

Depending on your state of residence, you may have the following rights over the personal information for which we are the business/controller. We do not discriminate against you for exercising them.

RightWhat It Means
Know / AccessConfirm whether we process your personal information and obtain a copy.
CorrectFix inaccurate personal information we hold about you.
DeleteRequest deletion of your personal information, subject to legal exceptions.
PortabilityReceive your personal information in a portable, readily usable format.
Limit Sensitive PIDirect us to limit use of sensitive personal information to permitted purposes (CPRA).
Opt out of profilingOpt out of profiling in furtherance of decisions with legal or similarly significant effects.
Opt out of sale/share/targeted adsAvailable by right — though, as stated in Section 8, we conduct none of these activities.
AppealWhere your state provides it (e.g., VA, CO, CT, TX), appeal our decision on your request.
Non-discriminationReceive equal service and pricing when you exercise your rights.

11. How to Exercise Your Rights

Submit a request by emailing [email protected]. We will verify your identity before responding, generally by confirming information already associated with your account. You may use an authorized agent, with proof of authorization.

We respond within the timeframe your state law requires — typically 45 days, extendable once where permitted, with notice to you. If we decline a request, we will explain why and, where your state provides an appeal, how to appeal. If your appeal is denied, you may contact your state Attorney General.

If you are a data subject of one of our customers and your request concerns Customer Content, please contact that organization directly. As their service provider, we will assist them in fulfilling your request but cannot act on it independently.

12. Security

We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information — including encryption in transit and at rest, access controls on a least-privilege basis, and logging and monitoring for security events. No system is perfectly secure, but security is fundamental to how the platform is built and operated.

13. Children

The Services are intended for businesses and privacy professionals, not for children. We do not knowingly collect personal information from children under 13 (or the higher age set by your state) through our website or accounts. Where children's data appears within Customer Content as part of an assessment, we process it only as your service provider, under the heightened safeguards described in Section 5.

14. Changes to This Notice

We will update this Notice as our practices or the law change. When we make material changes, we will revise the "Effective" date above and, where appropriate, notify you through the Services or by email. Prior versions are available on request.

15. Contact Us

For any question about this Notice or your personal information:

Doxa Privacy (Bantu Heirs LLC)

Privacy inquiries: [email protected]

Attn: Chief Privacy Officer