This Privacy Policy explains how Hoplo S.r.l. ("Hoplo", "we", "us") processes personal data in connection with DocZoom Studio, DocZoom Word, our websites, licensing systems, and support activities.
If you use the DocZoom app with a Google account, section 17 explains how we handle Google user data.
1. Who we are
DocZoom is provided by:
- Hoplo S.r.l.
- Registered office: Via Fontana 25, 20122 Milano (MI), Italy
- VAT / tax code: 08450220010
- Company registration / REA: MI - 2506530
- PEC: hoplo@legalmail.it
- Privacy contact: info@hoplo.com
- Support contact: info@hoplo.com
- Legal and general contact: info@hoplo.com
- Security and incident contact: info@hoplo.com
Data protection requests should be sent to info@hoplo.com. This Privacy Policy is intended to be read under Regulation (EU) 2016/679 ("GDPR") and applicable Italian data protection law.
2. Products covered
- DocZoom Studio, the customer's dedicated document intelligence environment.
- DocZoom Word, the Microsoft Word add-in that connects to the customer's DocZoom Studio instance.
- The DocZoom desktop app (macOS and Windows), which connects to the customer's DocZoom Studio instance.
- DocZoom websites and public pages, including
doczoom.ai. - The DocZoom activation, licensing, telemetry, support, and update systems.
3. Controller and processor roles
DocZoom is designed as a managed single-tenant service. Each customer is assigned a dedicated DocZoom Studio instance, instead of sharing one multi-tenant application database with other customers.
3.1 Customer content
When a customer uploads, indexes, searches, drafts, reviews, translates, anonymizes, or otherwise processes documents through DocZoom Studio or DocZoom Word, the customer normally acts as the data controller for that content. Hoplo acts as data processor and processes that content only to provide, secure, maintain, support, and improve the contracted service, according to the customer agreement and the Data Processing Addendum.
"Customer content" includes documents, document text, metadata, prompts, queries, selected Word text, AI responses, comments, project materials, chat attachments, and any personal data contained in them.
If you are an individual whose personal data appears in customer content processed through DocZoom, please contact the relevant DocZoom customer first. If Hoplo receives a request relating to customer content, Hoplo will normally forward it to the relevant customer, unless the law requires otherwise.
3.2 Hoplo controller data
Hoplo acts as controller for personal data processed for its own purposes, including website visits, marketing and sales communications, customer relationship management, billing, legal compliance, security, support, licensing, product telemetry, and service administration.
4. How DocZoom Word works
DocZoom Word is a Microsoft Word add-in. It is hosted by Hoplo at plugin.doczoom.ai and connects to the DocZoom Studio URL configured by the user or customer.
The add-in requires Microsoft Word permission to read and write the document because its features may analyze selected text, generate suggestions, insert text, apply edits, translate clauses, anonymize personal data, or run compliance checks.
DocZoom Word does not send the whole Word document to Hoplo merely because the add-in is installed. Content is processed when the user uses a feature that requires document text, selected text, attachments, or other input to be sent to the configured DocZoom Studio instance.
The add-in may store local configuration data, such as the configured Studio URL, user preferences, language, model preference, and a short-lived authentication token, using Microsoft Office storage mechanisms or browser local storage available to the add-in runtime.
5. Categories of personal data we process
5.1 Account and access data
We may process names, business email addresses, role, organization, language preferences, account identifiers, authentication data, IP addresses, login events, and security logs. Passwords, when managed by DocZoom, are stored as password hashes, not as clear text.
5.2 Customer content
Depending on how the customer uses DocZoom, customer content may include contracts, pleadings, corporate documents, transaction files, legal memoranda, email exports, audio transcripts, scanned documents, Word document text, selected text, comments, and personal data of staff, clients, counterparties, witnesses, and suppliers. Customer content may include special categories of personal data or data relating to criminal convictions and offences if the customer uploads such information. The customer is responsible for ensuring that it has a valid legal basis and authority to process that information.
5.3 Product usage and telemetry
We may process technical and operational data, such as license identifier, instance status, service health, version numbers, resource usage, feature usage, quota consumption, error reports, IP address, network metadata, update status, and security events. Telemetry is used to operate the service, enforce licenses, support the customer, detect abuse, manage capacity, and secure the infrastructure.
5.4 Support data
When customers contact support, we may process names, email addresses, organization information, ticket content, diagnostic logs, screenshots, and any information voluntarily provided by the customer. Customers should avoid sending confidential documents to support unless strictly necessary.
5.5 Website, sales, and marketing data
When users visit our websites or contact us for information, demos, or commercial discussions, we may process IP address, browser/device data, pages visited, contact details, job title, company, messages, meeting notes, and marketing preferences.
6. Purposes and legal bases
For Hoplo controller data, the main purposes and legal bases are:
| Processing activity | Purpose | Legal basis |
|---|---|---|
| Website security logs and technical cookies | Operate the website, prevent abuse, secure public pages | Legitimate interest; legal obligations where applicable |
| Contact forms, demos, sales conversations | Reply to requests, take pre-contractual steps, manage the commercial relationship | Pre-contractual steps; legitimate interest; consent where required |
| Customer account administration | Create accounts, authenticate users, manage access and licenses | Contract performance; legitimate interest in access security |
| Billing and accounting | Issue invoices, manage payments, comply with tax/accounting duties | Contract performance; legal obligation |
| Licensing and service telemetry | Activate licenses, verify service health, enforce quotas, provide updates and support | Contract performance; legitimate interest in operating and securing the service |
| Security monitoring and incident response | Prevent misuse, investigate incidents, protect customer instances and Hoplo systems | Legitimate interest; legal obligation where applicable |
| Support tickets and diagnostics | Resolve customer requests and technical incidents | Contract performance; legitimate interest |
| Marketing communications | Send product updates or commercial communications | Consent where required; legitimate interest for existing B2B contacts where permitted |
| Legal claims and compliance | Establish, exercise, or defend legal claims and comply with legal duties | Legal obligation; legitimate interest |
For customer content, Hoplo processes personal data as processor under the customer agreement and DPA. The customer determines the applicable legal basis.
7. AI processing
DocZoom uses AI models to provide drafting, review, compliance, translation, anonymization, search, summarization, extraction, and other document intelligence features. Depending on the customer's configuration, AI processing may run on a local or dedicated customer-controlled runtime, through Hoplo-managed cloud provider integrations, or through third-party AI providers selected or enabled for the customer.
Customer content is not sold. Customer content is not used by Hoplo to train general-purpose AI models unless the customer has expressly agreed in writing. When third-party AI providers are used, relevant prompt content, document excerpts, retrieved sources, and outputs may be sent to those providers only to provide the requested feature and subject to the applicable customer configuration and subprocessors list.
DocZoom is intended to support professional review, not to replace it. Users remain responsible for checking AI outputs, legal references, citations, translations, anonymization suggestions, and final document language before relying on them.
8. Sources, legal databases, and web search
DocZoom may connect to legal databases, public legal sources, web search APIs, or customer-selected sources. Queries sent to those services may include the user question, selected text, or search terms required to retrieve relevant information. Customers can configure or restrict certain source categories depending on their deployment and subscription.
9. Retention
Retention depends on the data category and customer agreement.
- Customer documents and indexed content are retained in the dedicated customer instance until deleted by the customer or until the end of the contract, subject to agreed backup and offboarding periods.
- Chat attachments, where enabled as separate attachments, are temporary: the current design uses a 30-day lifetime plus a 7-day deletion grace period, after which eligible attachment records and objects are hard-deleted.
- Managed deployment backups use encrypted backups with, by default, 7 daily, 4 weekly, and 12 monthly restore points, unless the customer agreement sets a different retention.
- Security and audit events may be retained for security, compliance, and audit purposes (currently up to 6 years where that pipeline is enabled).
- License telemetry, support tickets, billing records, and website/marketing data are retained for as long as necessary for the purposes described above and to comply with legal obligations.
At contract end, export, deletion, instance decommissioning, and backup expiry are handled under the customer agreement, DPA, and offboarding process.
10. Subprocessors and recipients
Hoplo may use subprocessors to provide infrastructure, networking, security, AI, OCR, search, email, support, licensing, and other service components. The applicable subprocessors may vary by customer configuration. The subprocessors list is available at /en/legal/subprocessors. Hoplo does not sell customer content or personal data.
11. International transfers
DocZoom customer instances are designed to be hosted on dedicated infrastructure, typically in the European Union unless otherwise agreed. Some subprocessors may be established outside the European Economic Area, depending on the selected configuration (for example, providers used for AI model routing, security, web search, email delivery, support, or edge networking).
Where customer content or personal data is transferred outside the EEA, Hoplo will rely on an appropriate transfer mechanism, such as an adequacy decision adopted by the European Commission, the European Commission Standard Contractual Clauses, supplementary technical, contractual, and organizational measures, or a documented customer instruction or configuration. Customers requiring stricter residency or provider restrictions should agree those restrictions in the order form, DPA, or deployment configuration.
12. Security
Hoplo applies technical and organizational measures intended to protect personal data, including dedicated customer instances, TLS for data in transit, authentication and access controls, password hashing, rate limiting and security monitoring, document access policies and ACL checks, administrative access restrictions, hardened managed VPS provisioning, encrypted backups in managed deployments, and logging for security and operational diagnostics. No system can be guaranteed to be perfectly secure. Customers are responsible for managing their users, credentials, permissions, devices, documents, and lawful use of the service.
13. Data subject rights
Where Hoplo acts as controller, individuals may request access, rectification, deletion, restriction, portability, objection, or consent withdrawal where applicable under the GDPR. Requests can be sent to info@hoplo.com. Where the request relates to customer content, Hoplo may redirect the request to the relevant customer, because the customer is normally the controller for that content.
Individuals also have the right to lodge a complaint with the Italian Data Protection Authority or another competent supervisory authority. See https://www.garanteprivacy.it/.
14. Children's data
DocZoom is intended for professional and business use. It is not intended for children.
15. Changes to this policy
Hoplo may update this Privacy Policy from time to time. Material changes will be communicated where required by law or contract. The current version will be published on the DocZoom website.
16. Contact
Privacy contact: info@hoplo.com
Support and security incident contact: info@hoplo.com
Legal and general contact: info@hoplo.com
PEC: hoplo@legalmail.it
17. Google user data
This section applies to the DocZoom app (web and desktop) when you connect a Google account. It explains which data of your Google account DocZoom reads or writes, why, where the data stays, where it goes and how you remove access. Each customer organisation has its own dedicated DocZoom installation. For controller and processor roles, section 3 applies.
17.1 What data, and why
DocZoom accesses Google data only for the features you choose.
- Sign in with Google. Your name, email address and account identifier (
openid,email,profile), to let you in. - Sources. If you add a Google Drive folder or your Gmail mailbox in Sources, DocZoom copies its files or messages into your organisation's installation and indexes them, so you can search them with your other documents. Read-only permissions:
drive.readonly,gmail.readonly. Only you can see the copied messages. - Assistant connectors. If you connect your account in the Connectors panel, the assistant uses Gmail, Google Drive, Docs, Sheets and Calendar as tools. It reads only when you ask it. It writes only after you approve the action (see 17.2).
| Service | What the assistant reads | What it can write, only with your approval | Permissions |
|---|---|---|---|
| Gmail | Searches and reads threads, messages, attachments, drafts and labels | Sends, replies to and forwards email; creates, edits and sends drafts; creates and applies labels; moves to trash or spam and restores | gmail.readonly, gmail.send, gmail.compose, gmail.modify |
| Google Drive | Searches files, reads content, file details and permissions | Creates and copies files; edits, shares or moves a file to trash | drive.readonly, drive.file, drive |
| Google Docs | Reads documents | Creates and edits documents | documents.readonly, documents |
| Google Sheets | Reads spreadsheets and values | Creates spreadsheets; changes values and formulas; adds rows or columns | spreadsheets.readonly, spreadsheets |
| Google Calendar | Lists calendars, searches and reads events, finds free time | Creates, changes or deletes events; responds to invitations | calendar.calendarlist.readonly, calendar.events.readonly, calendar.events.freebusy, calendar.events |
On Google's consent page you can untick the permissions you do not want to give: DocZoom turns on only the features of the permissions you granted.
17.2 How we use it
- Only for the features you see and ask for in the app: sign-in, Sources and search, the assistant's answers, the actions you approve.
- The assistant reads live, only to answer a request of yours. It does not read your accounts in the background, does not export them in bulk (at most 25 results per search) and does not copy what it reads into Sources.
- Every action in your name is shown to you in a card with its exact content and is carried out only if you approve that card. No approval covers more than one action.
- In Gmail and Drive DocZoom never deletes permanently: at most it moves items to trash. It never creates automatic forwarding or filters in Gmail.
17.3 Where it stays and how we protect it
- The data stays in your organisation's DocZoom installation. The access keys to your account (tokens) are kept only there, encrypted and bound to you and to the account. The desktop app and the browser never receive them.
- The connection service
oauth.doczoom.aireceives from Google only a one-time code and passes it to the installation within 2 minutes. It never receives the tokens or the content of your accounts. - Attachments and files read by the assistant are converted to text in a temporary folder that is deleted right away. The file does not enter Sources.
- For each action the installation keeps a log entry without texts: kind, date, outcome, number and domains of the recipients, and a fingerprint of the approved content. Full recipient addresses are kept for at most 21 days, the rest for 12 months. Your organisation can shorten these periods.
- Files and messages copied into Sources stay in the installation until your organisation deletes them or the contract ends (section 9).
17.4 Which AI models receive it
To write an answer, the assistant sends the AI model only what it needs to answer your request. Data from your Google accounts, both what the assistant reads and the documents that reached Sources from Google, goes only to:
- a local model running on your organisation's infrastructure;
- or zero data retention model providers, which neither keep the data nor use it to train models.
The providers are listed on the Subprocessors page. For transfers outside the European Union, section 11 applies.
17.5 Whom we share it with
- With the model providers in section 17.4, only to give you the answer.
- With no one else, except: for security (for example to investigate abuse), to comply with the law, or, only after your explicit consent, in a merger, acquisition or sale of the business.
- We do not sell the data, we do not use it for advertising or profiling, and we do not pass it to other apps, not even to third-party assistants connected to the installation.
17.6 Who can read it
No person at Hoplo or in your organisation reads the data of your Google accounts, except: if you ask us to for specific data (for example to solve a problem you report), if it is needed for security, or if the law requires it.
17.7 No model training
We do not use data received from Google APIs to create, train or improve artificial intelligence models, ours or anyone else's.
17.8 Removing access and asking for deletion
- In the app's Connectors panel you can turn off a single feature or disconnect the account: the tokens are deleted from the installation at once. When you disconnect you can also remove DocZoom's access from your Google account.
- At any time you can remove access on the Third-party connections page of your Google account. This removes access for all of DocZoom for that account, Sources included.
- To delete other data, write to your organisation or to info@hoplo.com.
17.9 Limited Use
DocZoom's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. For Gmail, Drive, Calendar, Docs and Sheets data we also comply with the Google Workspace API User Data and Developer Policy.
17.10 Contact
Privacy: info@hoplo.com
Certified email (PEC): hoplo@legalmail.it
