1. Who we are
Northdoc is a product of Northcape Technology Pty Ltd (ABN 62 691 614 516) of Melbourne, Victoria, Australia ("we", "us"). This policy explains what personal information we handle when you use Northdoc, why, and what you can do about it. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
It sits alongside our Terms of Service.
2. What we collect
- Account details: your email address, and a hash of your password if you set one.
- Workspace details: workspace names, the members you invite and their roles, and your API keys (stored only as SHA-256 hashes).
- Billing details: payments go through Stripe, which sends the payment receipts. We see the amount, the last four digits of your card and your billing email, never your full card number.
- Usage and logs: what was processed and charged, an API request log (method, path, status, duration, which key was used, and the calling IP address and user agent), and server logs that may include your IP address, kept for security.
- Support: emails you send us.
3. Documents you send us
Documents you upload or ask us to fetch may contain personal information about other people: names on invoices, details in contracts, claims or medical records. You control that content. You decide what to send and how long to keep it, and you must have the right, and any consent needed, to have it processed.
We handle document content only to provide the service on your instructions. We do not look through it, combine it with other data, or use it for anything else, and we never use it to train models.
4. How we use it
- to run your account, log you in and process your documents;
- to charge for usage, issue receipts and keep the records tax law requires;
- to send service emails such as login links, invitations, receipts and notice of changes to our terms or this policy;
- to keep the service secure, prevent abuse and fix problems;
- to answer your questions and meet our legal obligations.
5. Where it is stored and processed
Document content is processed and stored in Australia. Our application servers and database run in Sydney. OCR and layout analysis, the AI models that read documents and answer questions, and the model that makes embeddings all run in Australian data centres. Document content is not sent outside Australia.
Two providers may handle some personal information outside Australia, including in the United States: Stripe, for payments, and our email delivery provider, for transactional email. They receive only what they need for billing and email, never document content. The security page shows the full path a document takes.
7. How long we keep it
- Uploaded files are deleted straight after analysis, once page images are rendered. Files from failed documents are deleted after 24 hours.
-
Results
(text, pages, extractions and page images) are kept for the document's
retention_seconds, counted from when it completes: 24 hours by default, at most 7 days on the free trial, and longer or indefinitely on pay-as-you-go if you choose. A completed document whose result has never been fetched is kept for at least 24 hours. -
Document records
(the file name, the source URL, the options you sent and the questions you asked)
stay after a result expires, so the document can still answer
410 document_expired. They are deleted when you delete the document or the workspace. -
Deleting a document
through the API (
DELETE /documents/{id}) purges it immediately. - API request logs are kept for 30 days.
- Usage and billing records are kept as needed for your account and for tax.
- Account details are kept while your account is open. When it closes we delete them, except what the law requires us to keep.
8. Security
Northdoc is served over HTTPS only, with HSTS. Passwords and API keys are stored as hashes, access is scoped to each workspace, and API requests are logged for audit.
If a data breach is likely to cause serious harm, we will notify affected customers and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
10. Your rights
You can ask to access the personal information we hold about you, to correct it, or to delete it. Much of it you can update or delete yourself in your account settings and workspace. For anything else, email admin@northcape.tech. We may need to confirm your identity first, and we may keep some records the law requires.
If your information is inside a document a Northdoc customer sent us, please contact that customer: they control the document, and we act on their instructions.
11. Complaints
If you have a concern about how we handle personal information, email admin@northcape.tech first. We aim to respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. Changes to this policy
We will update this policy when our practices or providers change, and change the date at the top. If a change is material, we will tell you by email or on the site at least 14 days before it takes effect.
13. Contact
Privacy questions and requests: email admin@northcape.tech. Northcape Technology Pty Ltd (ABN 62 691 614 516), Melbourne, Victoria, Australia.
Northdoc is a product of Northcape Technology Pty Ltd (ABN 62 691 614 516), Melbourne, Australia.