LEGAL

Privacy Policy

DocZoom app, DocZoom Studio and DocZoom Word · Last updated: 28 September 2026Hoplo S.r.l.

This Privacy Policy explains how Hoplo S.r.l. ("Hoplo", "we", "us") processes personal data in connection with DocZoom Studio, DocZoom Word, our websites, licensing systems, and support activities.

If you use the DocZoom app with a Google account, section 17 explains how we handle Google user data.

1. Who we are

DocZoom is provided by:

  • Hoplo S.r.l.
  • Registered office: Via Fontana 25, 20122 Milano (MI), Italy
  • VAT / tax code: 08450220010
  • Company registration / REA: MI - 2506530
  • PEC: hoplo@legalmail.it
  • Privacy contact: info@hoplo.com
  • Support contact: info@hoplo.com
  • Legal and general contact: info@hoplo.com
  • Security and incident contact: info@hoplo.com

Data protection requests should be sent to info@hoplo.com. This Privacy Policy is intended to be read under Regulation (EU) 2016/679 ("GDPR") and applicable Italian data protection law.

2. Products covered

  • DocZoom Studio, the customer's dedicated document intelligence environment.
  • DocZoom Word, the Microsoft Word add-in that connects to the customer's DocZoom Studio instance.
  • The DocZoom desktop app (macOS and Windows), which connects to the customer's DocZoom Studio instance.
  • DocZoom websites and public pages, including doczoom.ai.
  • The DocZoom activation, licensing, telemetry, support, and update systems.

3. Controller and processor roles

DocZoom is designed as a managed single-tenant service. Each customer is assigned a dedicated DocZoom Studio instance, instead of sharing one multi-tenant application database with other customers.

3.1 Customer content

When a customer uploads, indexes, searches, drafts, reviews, translates, anonymizes, or otherwise processes documents through DocZoom Studio or DocZoom Word, the customer normally acts as the data controller for that content. Hoplo acts as data processor and processes that content only to provide, secure, maintain, support, and improve the contracted service, according to the customer agreement and the Data Processing Addendum.

"Customer content" includes documents, document text, metadata, prompts, queries, selected Word text, AI responses, comments, project materials, chat attachments, and any personal data contained in them.

If you are an individual whose personal data appears in customer content processed through DocZoom, please contact the relevant DocZoom customer first. If Hoplo receives a request relating to customer content, Hoplo will normally forward it to the relevant customer, unless the law requires otherwise.

3.2 Hoplo controller data

Hoplo acts as controller for personal data processed for its own purposes, including website visits, marketing and sales communications, customer relationship management, billing, legal compliance, security, support, licensing, product telemetry, and service administration.

4. How DocZoom Word works

DocZoom Word is a Microsoft Word add-in. It is hosted by Hoplo at plugin.doczoom.ai and connects to the DocZoom Studio URL configured by the user or customer.

The add-in requires Microsoft Word permission to read and write the document because its features may analyze selected text, generate suggestions, insert text, apply edits, translate clauses, anonymize personal data, or run compliance checks.

DocZoom Word does not send the whole Word document to Hoplo merely because the add-in is installed. Content is processed when the user uses a feature that requires document text, selected text, attachments, or other input to be sent to the configured DocZoom Studio instance.

The add-in may store local configuration data, such as the configured Studio URL, user preferences, language, model preference, and a short-lived authentication token, using Microsoft Office storage mechanisms or browser local storage available to the add-in runtime.

5. Categories of personal data we process

5.1 Account and access data

We may process names, business email addresses, role, organization, language preferences, account identifiers, authentication data, IP addresses, login events, and security logs. Passwords, when managed by DocZoom, are stored as password hashes, not as clear text.

5.2 Customer content

Depending on how the customer uses DocZoom, customer content may include contracts, pleadings, corporate documents, transaction files, legal memoranda, email exports, audio transcripts, scanned documents, Word document text, selected text, comments, and personal data of staff, clients, counterparties, witnesses, and suppliers. Customer content may include special categories of personal data or data relating to criminal convictions and offences if the customer uploads such information. The customer is responsible for ensuring that it has a valid legal basis and authority to process that information.

5.3 Product usage and telemetry

We may process technical and operational data, such as license identifier, instance status, service health, version numbers, resource usage, feature usage, quota consumption, error reports, IP address, network metadata, update status, and security events. Telemetry is used to operate the service, enforce licenses, support the customer, detect abuse, manage capacity, and secure the infrastructure.

5.4 Support data

When customers contact support, we may process names, email addresses, organization information, ticket content, diagnostic logs, screenshots, and any information voluntarily provided by the customer. Customers should avoid sending confidential documents to support unless strictly necessary.

5.5 Website, sales, and marketing data

When users visit our websites or contact us for information, demos, or commercial discussions, we may process IP address, browser/device data, pages visited, contact details, job title, company, messages, meeting notes, and marketing preferences.

6. Purposes and legal bases

For Hoplo controller data, the main purposes and legal bases are:

Processing activityPurposeLegal basis
Website security logs and technical cookiesOperate the website, prevent abuse, secure public pagesLegitimate interest; legal obligations where applicable
Contact forms, demos, sales conversationsReply to requests, take pre-contractual steps, manage the commercial relationshipPre-contractual steps; legitimate interest; consent where required
Customer account administrationCreate accounts, authenticate users, manage access and licensesContract performance; legitimate interest in access security
Billing and accountingIssue invoices, manage payments, comply with tax/accounting dutiesContract performance; legal obligation
Licensing and service telemetryActivate licenses, verify service health, enforce quotas, provide updates and supportContract performance; legitimate interest in operating and securing the service
Security monitoring and incident responsePrevent misuse, investigate incidents, protect customer instances and Hoplo systemsLegitimate interest; legal obligation where applicable
Support tickets and diagnosticsResolve customer requests and technical incidentsContract performance; legitimate interest
Marketing communicationsSend product updates or commercial communicationsConsent where required; legitimate interest for existing B2B contacts where permitted
Legal claims and complianceEstablish, exercise, or defend legal claims and comply with legal dutiesLegal obligation; legitimate interest

For customer content, Hoplo processes personal data as processor under the customer agreement and DPA. The customer determines the applicable legal basis.

7. AI processing

DocZoom uses AI models to provide drafting, review, compliance, translation, anonymization, search, summarization, extraction, and other document intelligence features. Depending on the customer's configuration, AI processing may run on a local or dedicated customer-controlled runtime, through Hoplo-managed cloud provider integrations, or through third-party AI providers selected or enabled for the customer.

Customer content is not sold. Customer content is not used by Hoplo to train general-purpose AI models unless the customer has expressly agreed in writing. When third-party AI providers are used, relevant prompt content, document excerpts, retrieved sources, and outputs may be sent to those providers only to provide the requested feature and subject to the applicable customer configuration and subprocessors list.

DocZoom is intended to support professional review, not to replace it. Users remain responsible for checking AI outputs, legal references, citations, translations, anonymization suggestions, and final document language before relying on them.

8. Sources, legal databases, and web search

DocZoom may connect to legal databases, public legal sources, web search APIs, or customer-selected sources. Queries sent to those services may include the user question, selected text, or search terms required to retrieve relevant information. Customers can configure or restrict certain source categories depending on their deployment and subscription.

9. Retention

Retention depends on the data category and customer agreement.

  • Customer documents and indexed content are retained in the dedicated customer instance until deleted by the customer or until the end of the contract, subject to agreed backup and offboarding periods.
  • Chat attachments, where enabled as separate attachments, are temporary: the current design uses a 30-day lifetime plus a 7-day deletion grace period, after which eligible attachment records and objects are hard-deleted.
  • Managed deployment backups use encrypted backups with, by default, 7 daily, 4 weekly, and 12 monthly restore points, unless the customer agreement sets a different retention.
  • Security and audit events may be retained for security, compliance, and audit purposes (currently up to 6 years where that pipeline is enabled).
  • License telemetry, support tickets, billing records, and website/marketing data are retained for as long as necessary for the purposes described above and to comply with legal obligations.

At contract end, export, deletion, instance decommissioning, and backup expiry are handled under the customer agreement, DPA, and offboarding process.

10. Subprocessors and recipients

Hoplo may use subprocessors to provide infrastructure, networking, security, AI, OCR, search, email, support, licensing, and other service components. The applicable subprocessors may vary by customer configuration. The subprocessors list is available at /en/legal/subprocessors. Hoplo does not sell customer content or personal data.

11. International transfers

DocZoom customer instances are designed to be hosted on dedicated infrastructure, typically in the European Union unless otherwise agreed. Some subprocessors may be established outside the European Economic Area, depending on the selected configuration (for example, providers used for AI model routing, security, web search, email delivery, support, or edge networking).

Where customer content or personal data is transferred outside the EEA, Hoplo will rely on an appropriate transfer mechanism, such as an adequacy decision adopted by the European Commission, the European Commission Standard Contractual Clauses, supplementary technical, contractual, and organizational measures, or a documented customer instruction or configuration. Customers requiring stricter residency or provider restrictions should agree those restrictions in the order form, DPA, or deployment configuration.

12. Security

Hoplo applies technical and organizational measures intended to protect personal data, including dedicated customer instances, TLS for data in transit, authentication and access controls, password hashing, rate limiting and security monitoring, document access policies and ACL checks, administrative access restrictions, hardened managed VPS provisioning, encrypted backups in managed deployments, and logging for security and operational diagnostics. No system can be guaranteed to be perfectly secure. Customers are responsible for managing their users, credentials, permissions, devices, documents, and lawful use of the service.

13. Data subject rights

Where Hoplo acts as controller, individuals may request access, rectification, deletion, restriction, portability, objection, or consent withdrawal where applicable under the GDPR. Requests can be sent to info@hoplo.com. Where the request relates to customer content, Hoplo may redirect the request to the relevant customer, because the customer is normally the controller for that content.

Individuals also have the right to lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority. See https://www.garanteprivacy.it/.

14. Children's data

DocZoom is intended for professional and business use. It is not intended for children.

15. Changes to this policy

Hoplo may update this Privacy Policy from time to time. Material changes will be communicated where required by law or contract. The current version will be published on the DocZoom website.

16. Contact

Privacy contact: info@hoplo.com
Support and security incident contact: info@hoplo.com
Legal and general contact: info@hoplo.com
PEC: hoplo@legalmail.it

17. Google user data

This section applies to the DocZoom app (web and desktop) when you connect a Google account. It explains which data of your Google account DocZoom reads or writes, why, where the data stays, where it goes and how you remove access. Each customer organisation has its own dedicated DocZoom installation. For controller and processor roles, section 3 applies.

17.1 What data, and why

DocZoom accesses Google data only for the features you choose.

  • Sign in with Google. Your name, email address and account identifier (openid, email, profile), to let you in.
  • Sources. If you add a Google Drive folder or your Gmail mailbox in Sources, DocZoom copies its files or messages into your organisation's installation and indexes them, so you can search them with your other documents. Read-only permissions: drive.readonly, gmail.readonly. Only you can see the copied messages.
  • Assistant connectors. If you connect your account in the Connectors panel, the assistant uses Gmail, Google Drive, Docs, Sheets and Calendar as tools. It reads only when you ask it. It writes only after you approve the action (see 17.2).
ServiceWhat the assistant readsWhat it can write, only with your approvalPermissions
GmailSearches and reads threads, messages, attachments, drafts and labelsSends, replies to and forwards email; creates, edits and sends drafts; creates and applies labels; moves to trash or spam and restoresgmail.readonly, gmail.send, gmail.compose, gmail.modify
Google DriveSearches files, reads content, file details and permissionsCreates and copies files; edits, shares or moves a file to trashdrive.readonly, drive.file, drive
Google DocsReads documentsCreates and edits documentsdocuments.readonly, documents
Google SheetsReads spreadsheets and valuesCreates spreadsheets; changes values and formulas; adds rows or columnsspreadsheets.readonly, spreadsheets
Google CalendarLists calendars, searches and reads events, finds free timeCreates, changes or deletes events; responds to invitationscalendar.calendarlist.readonly, calendar.events.readonly, calendar.events.freebusy, calendar.events

On Google's consent page you can untick the permissions you do not want to give: DocZoom turns on only the features of the permissions you granted.

17.2 How we use it

  • Only for the features you see and ask for in the app: sign-in, Sources and search, the assistant's answers, the actions you approve.
  • The assistant reads live, only to answer a request of yours. It does not read your accounts in the background, does not export them in bulk (at most 25 results per search) and does not copy what it reads into Sources.
  • Every action in your name is shown to you in a card with its exact content and is carried out only if you approve that card. No approval covers more than one action.
  • In Gmail and Drive DocZoom never deletes permanently: at most it moves items to trash. It never creates automatic forwarding or filters in Gmail.

17.3 Where it stays and how we protect it

  • The data stays in your organisation's DocZoom installation. The access keys to your account (tokens) are kept only there, encrypted and bound to you and to the account. The desktop app and the browser never receive them.
  • The connection service oauth.doczoom.ai receives from Google only a one-time code and passes it to the installation within 2 minutes. It never receives the tokens or the content of your accounts.
  • Attachments and files read by the assistant are converted to text in a temporary folder that is deleted right away. The file does not enter Sources.
  • For each action the installation keeps a log entry without texts: kind, date, outcome, number and domains of the recipients, and a fingerprint of the approved content. Full recipient addresses are kept for at most 21 days, the rest for 12 months. Your organisation can shorten these periods.
  • Files and messages copied into Sources stay in the installation until your organisation deletes them or the contract ends (section 9).

17.4 Which AI models receive it

To write an answer, the assistant sends the AI model only what it needs to answer your request. Data from your Google accounts, both what the assistant reads and the documents that reached Sources from Google, goes only to:

  • a local model running on your organisation's infrastructure;
  • or zero data retention model providers, which neither keep the data nor use it to train models.

The providers are listed on the Subprocessors page. For transfers outside the European Union, section 11 applies.

17.5 Whom we share it with

  • With the model providers in section 17.4, only to give you the answer.
  • With no one else, except: for security (for example to investigate abuse), to comply with the law, or, only after your explicit consent, in a merger, acquisition or sale of the business.
  • We do not sell the data, we do not use it for advertising or profiling, and we do not pass it to other apps, not even to third-party assistants connected to the installation.

17.6 Who can read it

No person at Hoplo or in your organisation reads the data of your Google accounts, except: if you ask us to for specific data (for example to solve a problem you report), if it is needed for security, or if the law requires it.

17.7 No model training

We do not use data received from Google APIs to create, train or improve artificial intelligence models, ours or anyone else's.

17.8 Removing access and asking for deletion

  • In the app's Connectors panel you can turn off a single feature or disconnect the account: the tokens are deleted from the installation at once. When you disconnect you can also remove DocZoom's access from your Google account.
  • At any time you can remove access on the Third-party connections page of your Google account. This removes access for all of DocZoom for that account, Sources included.
  • To delete other data, write to your organisation or to info@hoplo.com.

17.9 Limited Use

DocZoom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. For Gmail, Drive, Calendar, Docs and Sheets data we also comply with the Google Workspace API User Data and Developer Policy.

17.10 Contact

Privacy: info@hoplo.com
Certified email (PEC): hoplo@legalmail.it

Vuoi vedere DocZoom in azione?

Richiedi una demo personalizzata con i tuoi documenti di test.