Doksa Logo Doksa.io
Home Document Analysis Qualitative Coding Pricing
Login Register
Home Document Analysis Qualitative Coding
Login Register

Privacy Policy

Last updated: May 2026

Found section

Quick Navigation

  • 1. Who We Are
  • 2. What Data We Collect
  • 3. Why We Collect Data
  • 4. Data Processing & AI Services
  • 5. Cookies
  • 6. Your Rights
  • 7. Security
  • 8. Data Retention
  • 9. Contact & Complaints

Doksa.io ("we", "us", "our") is a qualitative research analysis platform operated by NordAIConsult AS. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for personal data you provide when creating an account and using our service.

Company: NordAIConsult AS

Organization Number: 936 175 953

Country: Norway

Contact: privacy@doksa.io

Support: support@doksa.io

Account Information

  • Username, email address, password (hashed)
  • Account creation date, last login
  • Credit balance and transaction history

Research Documents You Upload

You decide what documents to upload for analysis. Your research data belongs to you.

Privacy-First Approach

Your source documents are deleted promptly after analysis completes. We extract the text, send it to our AI service provider for processing, receive the results, and then delete your original files. Files from analyses that fail or are abandoned are deleted within 48 hours. We do not retain your research documents beyond this, and residual copies are purged from encrypted backups on our normal backup cycle.

What we keep temporarily (30 days):

  • Analysis results: codes, themes, patterns, structured outputs
  • Metadata: file name, upload date, document length
  • Analysis parameters: coding method, research questions, framework

After 30 days, analysis results are automatically deleted. Export your results before then.

Usage & Technical Data

  • IP address, browser type, device information
  • Pages visited, features used, error logs
  • Session data (via cookies for authentication)
  • Stripe payment identifiers (no card numbers stored by us)

Contract Performance (GDPR Art. 6(1)(b))

Account data, uploaded documents, and analysis outputs are necessary to provide our service.

Legitimate Interest (GDPR Art. 6(1)(f))

Usage analytics, error monitoring, security logs, and fraud prevention.

Legal Obligation (GDPR Art. 6(1)(c))

Transaction records for tax compliance, fraud investigation when required.

Consent (GDPR Art. 6(1)(a))

Optional cookies beyond strictly necessary (you can refuse). Marketing emails (if you opt in).

⚠️ Important: Your Data Upload Decision

You decide what documents to upload. When you upload research documents for analysis, you are instructing us to send that content to our third-party AI service provider for processing.

You are responsible for ensuring you have the right to upload and process your documents (consent from participants, ethical approval, anonymization, etc.).

Third-Party AI Service Provider

  • Role: Our AI service provider acts as a data processor under GDPR Article 28
  • Location: Data may be processed outside the EU. We rely on our AI provider's data processing terms and standard contractual safeguards for any such transfer
  • Purpose: AI-powered qualitative coding, thematic analysis, memo generation
  • Training: Our AI service provider does not use your data to train models (per their API terms)
  • Retention: Our AI service provider retains API logs for up to 30 days for abuse monitoring, then deletes
  • Security: Encrypted in transit (TLS) and at rest

Our Infrastructure: Our primary infrastructure (application servers, database, file storage) is hosted in the EU. Some sub-processors, such as AI processing and transactional email delivery, may process limited data outside the EU under appropriate safeguards.

Data Processing Agreement: We use AI service providers that offer GDPR-compliant data processing terms covering Article 28 requirements, and we are finalizing our data processing agreement and transfer safeguards with them. A current list of our sub-processors is available upon request at privacy@doksa.io.

Other Service Providers

  • Stripe: Payment processing (PCI-DSS compliant, EU servers)
  • Hosting: Cloud infrastructure in EU data centers
  • Email: Transactional emails (account notifications, receipts)

Strictly Necessary Cookies (No Consent Required)

  • sessionid: Authentication, keeps you logged in
  • csrftoken: Security protection against cross-site attacks
  • cookie_consent: Remembers your cookie choices

Privacy-Friendly Analytics (No Consent Required)

We use Plausible Analytics, a privacy-friendly alternative to Google Analytics. Plausible is designed to be GDPR compliant by default and does not require cookie consent because:

  • No cookies: Plausible doesn't use cookies at all
  • No personal data collection: We cannot identify you personally
  • No cross-site tracking: Your data stays on Doksa.io
  • Aggregate data only: Pages visited, referral sources, browser types (no individual tracking)
  • No data sharing: We don't sell or share your data with advertisers
  • EU-hosted: Data processed within the European Union

GDPR Compliant by Design

Plausible is compliant with GDPR, CCPA, and PECR. It doesn't track you across websites, doesn't generate a unique identifier for you, and doesn't collect any personal data. No cookie consent banner needed for Plausible.

Legal basis: GDPR Art. 6(1)(f) - Legitimate Interest. We have a legitimate interest in understanding how our site is used to improve it, and Plausible's privacy-first approach ensures minimal impact on your rights.

Learn more: Plausible Privacy Documentation

Microsoft Clarity, Session Recordings & Heatmaps (Consent Required)

We use Microsoft Clarity to understand how users interact with our site through heatmaps and anonymized session recordings. This helps us identify UX issues and improve the platform. Clarity only loads if you accept analytics cookies in our consent banner, and it does not load at all if you decline.

  • Session recordings: Visual recordings of how users navigate (all personal data is masked)
  • Heatmaps: Shows where users click, scroll, and spend time
  • Privacy protections: Automatically masks sensitive input fields, credit card numbers, passwords
  • Consent-based: Loaded only after you accept analytics cookies
  • Bug fixing & usability: Recordings help us fix issues and improve the platform

What's Recorded?

Clarity records mouse movements, clicks, scrolling behavior, and page navigation. Typed content in sensitive fields (passwords, payment info) is automatically masked.

Legal basis: GDPR Art. 6(1)(a) - Consent. Clarity loads only after you accept analytics cookies in our consent banner and does not load if you decline. We use this data solely to improve user experience and fix technical issues.

Learn more: Microsoft Clarity Privacy Documentation

PostHog (Product Analytics - Optional)

If enabled, we use PostHog for advanced product analytics to understand feature usage and user journeys.

  • Event tracking: Tracks specific actions (e.g., "started qualitative analysis", "created visualization")
  • Feature flags: Allows gradual feature rollouts to ensure stability
  • User properties: Aggregate metrics (e.g., total credits used, analyses completed) - no personal identifiers
  • Privacy-first: Can be self-hosted for complete data control
  • Anonymization: We anonymize user identifiers where possible

Legal basis: GDPR Art. 6(1)(f) - Legitimate Interest. Understanding how researchers use our platform helps us build better tools for the research community.

✓ Access

Request a copy of your personal data

✓ Rectification

Correct inaccurate data

✓ Erasure

Delete your data ("right to be forgotten")

✓ Portability

Receive your data in machine-readable format

✓ Restrict Processing

Limit how we use your data

✓ Object

Object to processing based on legitimate interest

How to exercise your rights: Email privacy@doksa.io with your request.

Response time: We will respond within one month. For complex requests, we may extend by two months and will notify you.

We implement technical and organizational measures appropriate to the risk (GDPR Article 32):

  • Encryption: TLS 1.2+ for data in transit, AES-256 at rest
  • Authentication: Hashed passwords (bcrypt), secure session management
  • Access Control: Role-based permissions, principle of least privilege
  • Monitoring: Security logs, intrusion detection, regular audits
  • Backups: Regular encrypted backups with secure retention
  • Vendor Security: All processors assessed for GDPR compliance

Data Breach Notification: Where a breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours where feasible (GDPR Article 33) and inform affected users without undue delay (Article 34).

Our Data Minimization Commitment

We follow the GDPR principle of storage limitation: we keep your data only as long as necessary.

  • Source documents: Deleted immediately after analysis completes
  • Analysis results: Automatically deleted after 30 days
  • Account data: Deleted when you delete your account
Data Type Retention Period Legal Basis
Source documents (PDFs, Word, etc.) Deleted immediately after processing GDPR Art. 5(1)(e) - Storage limitation
Analysis results 30 days Service delivery + user convenience
Account information (active) While account is active Contract performance
Personal data after account deletion Immediately anonymized GDPR Article 17
Transaction records (anonymized) 5 years Norwegian Bookkeeping Act
Invoice records 5 years Norwegian Bookkeeping Act
Payment processing records 120 days Chargeback protection
Security logs 90 days Security & fraud prevention
Support correspondence 3 years Legal defense & quality improvement

When You Delete Your Account

Your personal information (username, email, profile) is immediately anonymized. You lose access to all files and data, and your account cannot be restored after the undo window expires.

Legal Compliance Retention:

We may retain anonymized system data for legal and regulatory compliance, including:

  • Transaction and invoice records (Norwegian accounting law: 5 years)
  • Payment processing records (chargeback protection: 120 days)
  • Audit logs and system backups
  • Anonymized file metadata for copyright compliance (DMCA: 3 years)

Important: This anonymized data is not linked to your identity and is retained solely for legal, financial, and security purposes as required by law. Under GDPR Recital 26, anonymized data is not considered personal data.

Active Account: You can delete individual documents at any time from your account dashboard. To delete your entire account, visit your account settings or email support@doksa.io.

Data Protection Contact

Email: privacy@doksa.io

Right to Complain

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR.

Find your local supervisory authority: EDPB Member List

We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or a prominent notice on our website. Continued use after notification constitutes acceptance.

Version history: Available upon request to privacy@doksa.io

Privacy Policy • Terms of Service • FAQ & Disclaimers • Methodology • Pricing

© 2026 Doksa.io by NordAIConsult AS