Doksa Logo Doksa.io
Home Literature Analysis Qualitative Coding Pricing
Login Register
Home Literature Analysis Qualitative Coding
Login Register

Privacy Policy

Last updated: October 2026

Found section

Quick Navigation

  • 1. Who We Are
  • 2. What Data We Collect
  • 3. Why We Collect Data
  • 4. Data Processing & AI Services
  • 5. Cookies
  • 6. Your Rights
  • 7. Security
  • 8. Data Retention
  • 9. Contact & Complaints

Doksa.io ("we", "us", "our") is a qualitative research analysis platform operated by NordAIConsult AS. For the purposes of the EU General Data Protection Regulation (GDPR), we are the data controller for personal data you provide when creating an account and using our service.

Company: NordAIConsult AS

Organization Number: 936 175 953

Country: Norway

Contact: privacy@doksa.io

Support: support@doksa.io

Account Information

  • Username, email address, password (hashed)
  • Account creation date, last login
  • Credit balance and transaction history

Research Documents You Upload

You decide what documents to upload for analysis. Your research data belongs to you.

Privacy-First Approach

Your source files are deleted as soon as their text is extracted, before the analysis itself runs. We extract the text, delete your original files, and send only the extracted text to our AI service provider for processing. Files from uploads that are abandoned before an analysis starts are deleted within 48 hours. We do not retain your research documents beyond this, and residual copies are purged from encrypted backups on our normal backup cycle.

What we keep, and for how long:

  • Extracted document text (the transcript segments used for qualitative coding): 30 days, then automatically deleted
  • Analysis results (literature extractions and reports; qualitative codes, patterns, theories - short quoted excerpts, not full transcripts): kept until you delete the analysis or your account, so you can revisit and re-export your work
  • Metadata: file name, upload date, analysis parameters (coding method, research questions, framework)

Usage & Technical Data

  • IP address, browser type, device information
  • Pages visited, features used, error logs
  • Session data (via cookies for authentication)
  • Stripe payment identifiers (no card numbers stored by us)

Contract Performance (GDPR Art. 6(1)(b))

Account data, uploaded documents, and analysis outputs are necessary to provide our service.

Legitimate Interest (GDPR Art. 6(1)(f))

Usage analytics, error monitoring, security logs, and fraud prevention.

Legal Obligation (GDPR Art. 6(1)(c))

Transaction records for tax compliance, fraud investigation when required.

Consent (GDPR Art. 6(1)(a))

Optional cookies beyond strictly necessary (you can refuse). Marketing emails (if you opt in).

⚠️ Important: Your Data Upload Decision

You decide what documents to upload. When you upload research documents for analysis, you are instructing us to send that content to our third-party AI service provider for processing.

You are responsible for ensuring you have the right to upload and process your documents (consent from participants, ethical approval, anonymization, etc.).

Third-Party AI Service Provider

  • Role: Our AI service provider processes your content on our behalf as a data processor under a signed data processing agreement (GDPR Article 28)
  • Location: Data may be processed outside the EU. Such transfers are covered by Standard Contractual Clauses (GDPR Article 46) incorporated into our data processing agreement
  • Purpose: AI-powered qualitative coding, thematic analysis, memo generation
  • Training: Our AI service provider does not use your data to train models (per their API terms)
  • Retention: Our AI service provider stores each request and its response for up to 30 days, after which they are deleted
  • Security: Encrypted in transit (TLS) and at rest

Our Infrastructure: Our primary infrastructure (application servers, database, file storage) is hosted in the EU. Some sub-processors, such as AI processing and transactional email delivery, may process limited data outside the EU under appropriate safeguards.

Data Processing Agreement: We have a signed data processing agreement with our AI service provider covering GDPR Article 28 requirements, including Standard Contractual Clauses for transfers outside the EU. A current list of our sub-processors is available upon request at privacy@doksa.io.

Other Service Providers

  • Stripe: Payment processing (PCI-DSS compliant; Stripe may process some data outside the EU under its own GDPR transfer safeguards)
  • Hosting: Cloud infrastructure in EU data centers
  • Email: Transactional emails (account notifications, receipts)

Strictly Necessary Cookies (No Consent Required)

  • sessionid: Authentication, keeps you logged in
  • csrftoken: Security protection against cross-site attacks
  • doksa_cookie_consent: Remembers your cookie choices (stored in your browser's local storage)

Privacy-Friendly Analytics (No Consent Required)

We use Plausible Analytics, a privacy-friendly alternative to Google Analytics. Plausible is designed to be GDPR compliant by default and does not require cookie consent because:

  • No cookies: Plausible doesn't use cookies at all
  • No personal data collection: We cannot identify you personally
  • No cross-site tracking: Your data stays on Doksa.io
  • Aggregate data only: Pages visited, referral sources, browser types (no individual tracking)
  • No data sharing: We don't sell or share your data with advertisers
  • EU-hosted: Data processed within the European Union

GDPR Compliant by Design

Plausible is compliant with GDPR, CCPA, and PECR. It doesn't track you across websites, doesn't generate a unique identifier for you, and doesn't collect any personal data. No cookie consent banner needed for Plausible.

Legal basis: GDPR Art. 6(1)(f) - Legitimate Interest. We have a legitimate interest in understanding how our site is used to improve it, and Plausible's privacy-first approach ensures minimal impact on your rights.

Learn more: Plausible Privacy Documentation

Microsoft Clarity, Session Recordings & Heatmaps (Consent Required)

We use Microsoft Clarity to understand how users interact with our site through heatmaps and anonymized session recordings. This helps us identify UX issues and improve the platform. Clarity only loads if you accept analytics cookies in our consent banner, and it does not load at all if you decline.

  • Session recordings: Visual recordings of how users navigate (all personal data is masked)
  • Heatmaps: Shows where users click, scroll, and spend time
  • Privacy protections: Automatically masks sensitive input fields, credit card numbers, passwords
  • Consent-based: Loaded only after you accept analytics cookies
  • Bug fixing & usability: Recordings help us fix issues and improve the platform

What's Recorded?

Clarity records mouse movements, clicks, scrolling behavior, and page navigation. Typed content in sensitive fields (passwords, payment info) is automatically masked.

Legal basis: GDPR Art. 6(1)(a) - Consent. Clarity loads only after you accept analytics cookies in our consent banner and does not load if you decline. We use this data solely to improve user experience and fix technical issues.

Learn more: Microsoft Clarity Privacy Documentation

✓ Access

Request a copy of your personal data

✓ Rectification

Correct inaccurate data

✓ Erasure

Delete your data ("right to be forgotten")

✓ Portability

Receive your data in machine-readable format

✓ Restrict Processing

Limit how we use your data

✓ Object

Object to processing based on legitimate interest

How to exercise your rights: Email privacy@doksa.io with your request.

Response time: We will respond within one month. For complex requests, we may extend by two months and will notify you.

We implement technical and organizational measures appropriate to the risk (GDPR Article 32):

  • Encryption: TLS 1.2+ for data in transit, AES-256 at rest
  • Authentication: Hashed passwords (PBKDF2 with SHA-256), secure session management
  • Access Control: Role-based permissions, principle of least privilege
  • Monitoring: Security logs, intrusion detection, regular audits
  • Backups: Regular encrypted backups with secure retention
  • Vendor Security: All processors assessed for GDPR compliance

Data Breach Notification: Where a breach poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours where feasible (GDPR Article 33) and inform affected users without undue delay (Article 34).

Our Data Minimization Commitment

We follow the GDPR principle of storage limitation: we keep your data only as long as necessary.

  • Source documents: Deleted as soon as their text is extracted
  • Extracted document text (transcripts): Automatically deleted after 30 days
  • Analysis results: Kept until you delete the analysis or your account
  • Account data: Deleted when you delete your account
Data Type Retention Period Legal Basis
Source documents (PDFs, Word, etc.) Deleted as soon as text is extracted GDPR Art. 5(1)(e) - Storage limitation
Extracted document text (transcripts) 30 days GDPR Art. 5(1)(e) - Storage limitation
Analysis results (literature and qualitative) Until you delete the analysis or your account Service delivery - your research outputs stay available
Account information (active) While account is active Contract performance
Personal data after account deletion Immediately anonymized GDPR Article 17
Transaction records (anonymized) 5 years Norwegian Bookkeeping Act
Invoice records 5 years Norwegian Bookkeeping Act
Payment processing records 120 days Chargeback protection
Security logs 90 days Security & fraud prevention
Support correspondence 3 years Legal defense & quality improvement

When You Delete Your Account

Your personal information (username, email, profile) is immediately anonymized. A recovery backup is kept for 24 hours so you can undo the deletion; after that window expires, your account cannot be restored.

Legal Compliance Retention:

We may retain anonymized system data for legal and regulatory compliance, including:

  • Transaction and invoice records (Norwegian accounting law: 5 years)
  • Payment processing records (chargeback protection: 120 days)
  • Audit logs and system backups
  • Anonymized file metadata for copyright compliance (3 years)

Important: This anonymized data is not linked to your identity and is retained solely for legal, financial, and security purposes as required by law. Under GDPR Recital 26, anonymized data is not considered personal data.

Active Account: You can delete individual documents at any time from your account dashboard. To delete your entire account, visit your account settings or email support@doksa.io.

Data Protection Contact

Email: privacy@doksa.io

Right to Complain

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR.

Find your local supervisory authority: EDPB Member List

We may update this policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or a prominent notice on our website. Continued use after notification constitutes acceptance.

Version history: Available upon request to privacy@doksa.io

Privacy Policy • Terms of Service • FAQ & Disclaimers • Methodology • Pricing

© 2026 Doksa.io by NordAIConsult AS