Privacy Policy for TemplateDocs

Last Updated: July 18, 2026

Thank you for visiting TemplateDocs ("we," "us," or "our"). TemplateDocs is operated by ByteSail, located in Kfar Adummim, Israel.

This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our website, application, APIs, forms, and related services (collectively, the "Service").

By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree with the practices described in this policy, please do not use the Service.

This Privacy Policy is intended to provide information required by applicable privacy laws, including the General Data Protection Regulation (GDPR) and the California Privacy Rights Act (CPRA), where applicable.

This Privacy Policy applies to personal information that TemplateDocs processes for its own purposes, such as account and website information. When customers use TemplateDocs to process personal data in templates, forms, workflows, documents, or other Customer Data, TemplateDocs generally acts as a processor or service provider on behalf of the customer. That processing is governed by our Data Processing Addendum at https://templatedocs.io/dpa.

1. Information We Collect

We collect personal information necessary for providing and operating our services. The information we collect depends on how you use the Service.

1.1. Personal Information

We may collect the following personal information when you use our services:

Payments are processed by Paddle, our merchant of record. TemplateDocs does not directly receive or store full payment card details.

Under GDPR, where applicable, we process personal information based on contractual necessity, legitimate interests, consent, and compliance with legal obligations, depending on the purpose of the processing.

1.2. Customer Data

Customers may submit, store, or process content through the Service, including:

The nature of Customer Data is determined by each customer. TemplateDocs does not control what personal data customers choose to process through the Service.

Where Customer Data contains personal data, the customer is responsible for determining the purposes and lawful basis for that processing and for providing any notices or obtaining any consents required by applicable law.

1.3. Non-Personal Information

We collect limited technical and usage information to analyze trends, operate and improve our services, and identify technical issues. This may include:

Product analytics and error telemetry are configured with data-minimization, masking, and pseudonymization measures. Where applicable, this data is processed under our legitimate interests (Article 6(1)(f) GDPR) in operating and improving the Service while respecting user privacy.

We do not use Customer Data for advertising or to train AI models.

2. How We Use Your Information

We collect and process personal information to:

Customer Data is processed only as necessary to provide the Service, follow customer instructions, secure and protect the Service, comply with applicable law, and as otherwise described in our Data Processing Addendum.

3. Legitimate Interest for Analytics

We process limited usage analytics to improve our services while minimizing the personal information involved. This data helps us enhance product performance, usability, and security.

Our analytics approach:

Where applicable, this processing is based on our legitimate interests in operating and improving the Service while respecting user privacy.

If you prefer to opt out of analytics tracking, you can disable it via your account settings.

4. Customer Data Processing and Retention

Customer Data may be processed and retained as follows:

When a workflow run is deleted, associated step inputs and outputs, logs, and generated files are removed. When a template is deleted, its stored files and related metadata are removed.

When an account is deleted, we delete the account and Customer Data owned by organizations that are deleted with it, subject to limited backup retention, legal obligations, and records that third parties such as Paddle must retain for tax, accounting, or compliance purposes.

5. Data Sharing and Disclosure

We do not sell or rent personal information or Customer Data.

We use trusted third-party service providers to operate the Service. Depending on the features used, these may include:

ProviderPurposeProcessing Location
Google Cloud Platform and Google services

Cloud services and infrastructure, logging, secrets management, document processing, and URL-safety scanning

Primarily European Union; some security services may operate globally
SupabaseDatabase, authentication, file storage, and backupsEuropean Union
ResendDefault email deliveryUnited States and European Union
CrispCustomer support and website messagingEuropean Union
MixpanelProduct analytics and error telemetry using masked or pseudonymized dataEuropean Union
PaddlePayments and billing as merchant of recordUnited Kingdom and United States
Microsoft Azure and Microsoft servicesAdditional cloud services and document processingDepends on the service and configuration
OpenAI, Anthropic, and Google AICustomer-invoked AI features and automated outbound-email moderationUnited States and other locations depending on provider and service

These service providers are permitted to process data only as necessary to provide their services to us and are subject to applicable contractual and data protection obligations.

When a customer configures its own SMTP server or another third-party integration, Customer Data may be sent directly to that destination at the customer's instruction.

Document content may temporarily pass through Microsoft or Google services when customers use features that require document editing or conversion.

Outbound workflow emails may be automatically analyzed by AI services for abuse moderation, and embedded URLs may be checked through Google Web Risk or similar security services. This processing is performed to protect the Service and its users. If a customer configures its own SMTP server, workflow email content is not sent to our default email-delivery provider or to these AI providers for outbound-email moderation.

We may also disclose information where required by law, to protect legal rights or security, or in connection with a merger, acquisition, financing, or sale of assets, subject to applicable safeguards.

Our Data Processing Addendum contains the authoritative list of subprocessors that may process Customer Personal Data.

6. International Data Transfers

Our primary application infrastructure, databases, queues, and file storage are located in Europe.

ByteSail is established in Israel, and authorized personnel may access production systems and Customer Data from Israel where necessary for support, debugging, security, or legal compliance.

Some service providers may process data outside the European Economic Area or Israel. Where required by applicable law, we use appropriate safeguards for international transfers, such as adequacy decisions or contractual protections.

7. Children's Privacy

Our services are not intended for children under 13 years of age. We do not knowingly collect personal information directly from children under 13.

Customers are responsible for ensuring that their own use of the Service, including Forms, complies with applicable requirements relating to children and minors.

8. Security

We implement appropriate technical and organizational measures designed to protect personal information and Customer Data from unauthorized access, alteration, disclosure, or destruction.

These measures include, as applicable:

Additional information about the security measures applied to Customer Personal Data is available in our Data Processing Addendum.

While we use reasonable safeguards, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Information About Other Individuals

Customers may submit or collect information about other individuals through the Service, including through forms, APIs, webhooks, integrations, and other ways of submitting data to the Service. In those cases, the customer determines what information is collected, why it is processed, and how it is used.

The customer is responsible for:

Public forms may display "Powered by TemplateDocs" or similar service branding. TemplateDocs does not provide a customer-specific privacy notice to individuals submitting information through the Service.

If your information was submitted to TemplateDocs by one of our customers and you wish to exercise privacy rights regarding that information, you should generally contact that customer. We will provide reasonable assistance to the customer where required by applicable law.

Our website does not use cookies for analytics tracking. However, essential cookies and similar technologies may be used to enable necessary website and application functionality, such as authentication, security and support.

You can configure your browser to refuse cookies, but this may affect certain features of the Service.

11. Your Rights

Under applicable privacy laws, including GDPR and CPRA where relevant, you may have rights regarding personal information that TemplateDocs controls, including the right to:

You will not be discriminated against for exercising applicable privacy rights.

To exercise rights regarding account information or other personal information controlled by TemplateDocs, contact us at support@templatedocs.io.

For personal data contained in Customer Data, requests should generally be directed to the relevant TemplateDocs customer. TemplateDocs provides in-product deletion controls and reasonable assistance to customers responding to data-subject requests.

12. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, provide the Service, or meet legal, accounting, security, and compliance obligations.

Specific retention periods for Customer Data are described in Section 4 above and may depend on the customer's plan and organization settings.

Analytics data is retained according to our data retention settings in Mixpanel and is masked or pseudonymized as described above.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by email or through the Service.

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy, please contact us at support@templatedocs.io.

ByteSail
23 Eretz Binyamin
Kfar Adummim
Israel