Last Updated: May 7, 2026
This Privacy Policy describes how DocAddin collects, uses, and protects information about you. It is written to align with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act / CPRA (CCPA). If you have questions, contact support@docaddin.com.
DocAddin (the “Service”) is an AI assistant for Microsoft Word, Excel, and PowerPoint, distributed as an Office Add-in and accessed via docaddin.com.
Data Controller (GDPR) / Business (CCPA):
The Service is provided from Spain. Spanish law applies (see Terms §13 for governing law of disputes; EU consumers retain the courts of their place of residence).
support@docaddin.com and our reply.DocAddin is a thin SaaS layer on top of third-party large language models. We do not train our own LLMs. To generate a response, your Prompt and the relevant Document Context are transmitted securely (TLS) to one of:
Under each provider’s enterprise / API terms, your prompts and outputs are not used to train their publicly available models.
Additional sub-processors:
Several of the sub-processors listed above are based in the United States. Where an EU/UK-to-US transfer occurs, we rely on the EU–US Data Privacy Framework (where the recipient is certified) or on the European Commission’s Standard Contractual Clauses (SCCs). We have completed transfer impact assessments for each provider.
If you are in the EU, UK, or EEA, you have the right to:
To exercise any of these rights, email support@docaddin.com. We respond within 30 days.
To submit a request, email support@docaddin.com. We may verify your identity using your registered email.
We set a small number of cookies for: session authentication, language preference, and (with your explicit consent) anonymous product analytics. You can decline analytics in the cookie banner; the Service still works fully. We do not use cross-site advertising trackers.
The Service is not directed to anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has registered, contact us and we will delete the account.
All traffic is encrypted in transit (TLS 1.2+). Passwords are hashed with bcrypt. Access to production systems is restricted to authorised operators using SSH keys and 2FA. We will notify affected users without undue delay (and within 72 hours where required by GDPR Art. 33) of any breach involving their data.
We may update this policy. Material changes will be announced by email and on the website at least 14 days before they take effect. The “Last Updated” date at the top reflects the most recent version.
When you install the DocAddin Chrome extension and grant access via Google sign-in, the extension requests three sensitive Google Workspace scopes. We access this data only while you are using the extension, and only in response to a prompt you submit:
| Scope | What we access | How we use it · Retention |
|---|---|---|
documents | Text content and structure of the currently open Google Doc. | Read your selection and surrounding paragraphs to understand the prompt; apply user-approved edits. Not retained — content is forwarded to the AI provider you chose for the single request and discarded. |
spreadsheets | Cell values, formulas, sheet metadata of the currently open Google Sheet. | Same as above, for Sheets operations. Not retained. |
drive.file | Read/write comments only on files you opened with DocAddin (drive.file is the narrowest possible Drive scope). | Add or read comments when you ask the assistant to. Not retained. |
We do not:
You can revoke access at any time at myaccount.google.com/permissions. After revocation the extension can no longer read or modify your Docs and Sheets.
Privacy enquiries: support@docaddin.com.