Privacy Policy
How we collect, use, and protect your information
This privacy policy describes our current data handling practices. It is a working document and may be updated as our practices evolve. Please check back periodically for changes.
Who We Are
Papereg is a form management and document processing platform that helps organizations create, collect, and manage form submissions. This privacy policy explains how Papereg ("we", "us", "our") handles information in connection with our services.
Controller vs. Processor
Depending on the context, Papereg acts in different roles:
| Scenario | Papereg's Role | What This Means |
|---|---|---|
| User account data (email, profile) | Controller | We decide why and how this data is processed |
| Workspace form submissions | Processor | The workspace owner determines the purpose; we process on their behalf |
| Public form submissions | Processor | The form creator determines what data is collected; we store and process it per their configuration |
| AI document extraction | Processor | We process uploaded documents on behalf of the workspace owner using Anthropic Claude |
What We Collect
Account Data
- Email address (required for registration)
- First and last name (optional)
- Phone number and job description (optional)
- Password (stored as bcrypt hash only)
Workspace Data
- Workspace name, branding, and configuration
- Form definitions, field configurations, and templates
- Form submissions and associated field data
- File attachments and uploaded documents
- Audit logs of data access and modifications
Usage Data
- API request logs (endpoint, timestamp, status)
- Error reports (when Sentry is enabled)
Public Form Data
When someone fills out a public form, we collect whatever data the form creator has configured. Public form submissions do not require an account.
Why We Process Data
| Purpose | Data Used |
|---|---|
| Providing the service | Account data, workspace data, form submissions |
| Authentication and security | Email, hashed passwords, session tokens, API tokens |
| AI document extraction | Uploaded PDF/image content, form field definitions |
| Email notifications and event actions | Email addresses, submission data (as configured by workspace admins) |
| Error monitoring and debugging | Error stack traces, request metadata |
| Integration sync (when configured) | Submission data sent to connected apps (e.g., CRM) |
AI Processing
When users upload documents for form extraction or submission pre-filling, the document content is sent to Anthropic Claude via their API. Per Anthropic's API terms, this data is not used for model training.
Only the document content and relevant field definitions are sent. No account information, workspace settings, or unrelated submission data is included.
AI processing is initiated only by explicit user action (uploading a document). It does not run in the background or on existing data.
Subprocessors & Service Providers
We use the following third-party services:
| Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic | Document analysis (Claude API) | Uploaded document content |
| AWS S3 (or compatible) | File storage | Uploaded files and attachments |
| Resend | Email delivery | Recipient email addresses, email content |
| Sentry | Error monitoring (optional) | Error details, request metadata |
When workspace administrators connect external apps (e.g., Zoho Bigin), those services also become processors of the specific submission data configured for sync.
Data Retention & Deletion
- Account data is retained while the account is active
- Workspace data is retained while the workspace exists
- Deleting a workspace removes its entire tenant schema and all associated data
- Soft-deleted submissions can be restored by workspace administrators; permanently deleted data is not recoverable
Honest disclosure
We do not yet have a formally documented retention schedule or automated data purge process. Account and workspace deletion are manual processes. We are working to formalize these procedures.
International Transfers
Papereg's infrastructure is hosted in the United States. If you are located outside the US, your data will be transferred to and processed in the US.
We do not currently have Standard Contractual Clauses (SCCs) or other formal transfer mechanisms in place. If this is a requirement for your organization, please contact us.
Your Rights
You may have rights regarding your personal data depending on your jurisdiction. These may include the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Request a copy of your data in a portable format
To exercise any of these rights, please contact us at privacy@papereg.com.
If your data was submitted through a workspace form, please contact the workspace owner directly, as they are the data controller for that information.
Children's Data
Papereg is not directed at children under 16 and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
Changes to This Policy
We may update this privacy policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Contact
For privacy-related inquiries:
Privacy & Security: privacy@papereg.com
Security questions?
If you have questions about our security practices or need additional information for your procurement process, we're here to help.
Contact Us