Privacy Policy
DocQube — Maskan Technologies Private Limited
Last Updated: 1st April 2026
Maskan Technologies Private Limited (“we,” “us,” or “our”), a company incorporated under the Companies Act, 2013, with CIN U62020KA2023PTC172104, having its registered office at No. 1776, Ground Floor, 15th Main, 5th Block, 1st Stage, Kalyananagar, Bangalore 560043, Karnataka, India, operates the DocQube platform (“the Platform”).
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use DocQube. It applies to all users of the Platform, including administrators and authorized users of our client organizations.
1. Information We Collect
1.1 Information You Provide Directly
- Account information: name, email address, and password (stored as a PBKDF2-SHA256 hash; we never store plaintext passwords).
- Documents and files: any documents, files, images, or other content you upload to, create on, or store through the Platform.
- Communication data: messages sent through the Platform’s real-time collaboration features, comments on documents, and notification preferences.
- Signature data: if you use the digital signing feature, the signature images (drawn, typed, or uploaded) you create.
1.2 Information Collected Automatically
- Authentication data: session tokens (JWT), CSRF tokens, and login timestamps. Tokens are stored in HttpOnly secure cookies.
- IP addresses: captured on every request for audit trail purposes and stored in activity logs.
- Usage and activity data: file access events (open, upload, edit, share, download, delete), version history actions, and collaboration activity. This data forms your audit trail.
- Device and browser information: User-Agent string (recorded during digital signing for audit purposes). We do not use browser fingerprinting.
1.3 Information We Do Not Collect
- We do not use cookies for advertising or third-party tracking.
- We do not use analytics tracking tools (such as Google Analytics).
- We do not collect location data beyond IP addresses.
- We do not sell, rent, or trade your personal data to any third party under any circumstances. This commitment survives termination of your account.
1.4 Google Workspace API Data
When you choose to integrate Google Drive with DocQube, we request access to your Google Drive files (specifically the drive.readonly scope) to allow you to seamlessly browse and import your documents directly into our Platform.
Limited Use Disclosure: DocQube's use and transfer to any other app of information received from Google APIs will strictly adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data for serving advertisements or training AI models, and we strictly use it only to provide the document import functionality you explicitly requested.
2. How We Use Your Information
We process your personal data solely for the following purposes:
- Providing the Service: user authentication and authorization, document storage and management, file conversion, sharing, collaboration, and all Platform features.
- Security: malware scanning of uploaded files (via ClamAV), CSRF protection, rate limiting, encryption of sensitive data (AES-256-GCM), and maintaining audit trails.
- AI-powered features (when enabled): the Document Assistant (RAG system) processes document text to generate embeddings for search and question-answering. Text chunks are sent to our AI sub-processor (NVIDIA-hosted LLM endpoints) for query processing. You control which documents are submitted to the AI assistant.
- Notifications: sending email notifications for document sharing, version updates, role changes, and password resets.
- Platform improvement: aggregated, anonymized usage statistics to improve Platform performance and reliability. We never use individual user data or documents for training AI models.
3. Legal Basis for Processing
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and applicable data protection legislation, we process your personal data on the following bases:
- Contract performance: processing necessary to provide the Platform services under the agreement between us and your organization.
- Legitimate interests: security measures, fraud prevention, audit logging, and Platform integrity.
- Consent: for optional features such as the AI Document Assistant, where you choose which documents to process.
- Legal obligation: where we are required to retain or disclose data under applicable law.
4. Data Storage and Security
4.1 Where Your Data Is Stored
Your data is processed and stored across the following locations:
- Primary infrastructure: hosted in UAE (application servers, PostgreSQL database, Redis cache, document processing engine, ClamAV antivirus service).
- Cloud storage: Backblaze B2 (EU Central) for document file storage.
- AI processing: NVIDIA-hosted LLM endpoints for document Q&A queries, when you use the AI Document Assistant feature.
4.2 Security Measures
We implement industry-standard security measures including: AES-256-GCM encryption for sensitive data at rest, HTTPS/TLS for all data in transit, JWT authentication with HttpOnly secure cookies, CSRF protection on all state-changing requests, role-based access control (RBAC) with granular permissions, ClamAV malware scanning on all file uploads, comprehensive audit trails, path traversal and SSRF protection, input validation and HTML sanitization, and regular security updates.
4.3 Multi-Tenant Isolation
DocQube implements multi-tenant architecture with complete data isolation. Your organization’s data is logically segregated from all other organizations through tenant-specific identifiers at the database level and isolated storage paths. Users of one organization cannot access data belonging to another organization.
5. Data Sharing and Sub-processors
We share your data only with the following categories of third-party service providers (“sub-processors”), and only to the extent necessary to provide the Platform:
| Sub-processor | Purpose | Data Shared | Location |
|---|---|---|---|
| Backblaze B2 | Cloud storage for documents and files | Uploaded files, document versions | EU Central |
| NVIDIA-hosted LLM API | AI document Q&A (optional, user-initiated) | Document text chunks for queries | United States |
| ClamAV (self-hosted) | Malware scanning on file uploads | File binary data (scanned, not stored externally) | UAE (Our Infrastructure) |
| Document Processing Engine (self-hosted) | Document format conversion and extraction | Document content during conversion | UAE (Our Infrastructure) |
| SMTP Provider | Email notifications and invitations | Recipient names, emails, notification content | Configured per organization by client |
We will notify your organization at least thirty (30) days before engaging any new sub-processor. We do not sell, rent, or provide your data to advertisers, data brokers, or any parties not listed above.
6. Cross-Border Data Transfers
As described in Section 5, your data may be transferred to and processed in EU Central and the United States. We ensure that all cross-border transfers comply with the UAE Personal Data Protection Law by implementing appropriate safeguards, including contractual protections with our sub-processors that impose data protection obligations consistent with this Privacy Policy.
7. Data Retention
- Active account data: retained for the duration of your organization’s subscription.
- Deleted files: soft-deleted items in your Trash are automatically cleaned up by our system within 24 hours. Permanently deleted files are removed from all storage systems.
- After subscription termination: your data is retained for thirty (30) days to allow data export, after which it is permanently and irreversibly deleted from all systems, including backups.
- Audit logs: activity logs are retained for the duration of the subscription for your organization’s compliance purposes.
- Authentication tokens: access tokens expire after 30 minutes; refresh tokens expire after 7 days. Revoked tokens are blacklisted in Redis with TTL matching their remaining lifetime.
8. Your Rights
Under the UAE Personal Data Protection Law and other applicable legislation, you have the following rights:
- Right of access: request a copy of your personal data held by us.
- Right to rectification: request correction of inaccurate or incomplete data.
- Right to erasure: request deletion of your personal data (subject to legal retention requirements).
- Right to restrict processing: request limitation of how we process your data.
- Right to data portability: request your data in a commonly used, machine-readable format.
- Right to object: object to processing based on legitimate interests.
To exercise any of these rights, contact us at the address provided in Section 11. We will respond within thirty (30) days. Note that some requests may need to be routed through your organization’s administrator, as your organization acts as the data controller.
9. Children’s Privacy
DocQube is an enterprise platform not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify users of material changes by posting a notice on the Platform or by email. We encourage you to review this Privacy Policy periodically.
11. Contact Us
If you have questions about this Privacy Policy, wish to exercise your data protection rights, or want to report a data protection concern, please contact:
Maskan Technologies Private LimitedNo. 1776, Ground Floor, 15th Main, 5th Block, 1st Stage,
Kalyananagar, Bangalore 560043, Karnataka, India
Email: support@docqube.com