Privacy policy
Version 1.1 · in force on 1er octobre 2026
Translation for information only. In case of discrepancy between language versions, the French version prevails.
1. Data controller
For account data and the wedoc.io website, the data controller is BKH Tech BV (Belgique, VAT BE 0792.957.182). Privacy contact: privacy@wedoc.io. For the data each client company records INSIDE its space (its own clients, documents…), the client company is the controller and WeDoc acts as processor, in accordance with the DPA.
2. Data processed and purposes
- Account: name, email, password (bcrypt-hashed — never readable), language, optional phone — to provide the service and secure access (performance of the contract).
- Billing: plan, subscription history; payment is processed by Stripe, which alone holds card data (legal obligation and performance of the contract).
- Security: login history (date, IP, browser), visible to each user under « My account » (legitimate interest: security).
- Support: contact requests and tickets, with their attachments (performance of the contract).
- Website audience: measurement WITHOUT cookies — a daily hashed, non-traceable identifier, purged after 90 days (legitimate interest: statistics). No audience data is cross-referenced with accounts.
- Consent evidence: document accepted, version, date, IP (legal obligation).
- AI assistant (optional, off by default): if your company enables it, the questions asked and the document or article excerpts needed to answer them are sent to a self-hosted search-and-generation engine running on our own servers, within the European Union — no data is sent to a third-party service. Exchanges (questions and answers) are kept for 90 days and then automatically purged (legitimate interest: service improvement and security).
3. Cookies
WeDoc uses a single cookie: the session cookie strictly necessary to log in. No advertising, analytics or tracking cookie — which is why no cookie banner is displayed.
4. Recipients and processors
- OVH (European Union) — server hosting and email sending.
- Stripe — payment processing.
- Google / Microsoft — only if you choose OAuth login.
No sale or transfer of data. No transfer outside the EU beyond the safeguards provided by these providers (standard contractual clauses).
5. Retention periods
- Account: for the duration of use; on deletion, actual erasure or irreversible anonymisation (see art. 6).
- Login history: 12 months.
- Website audience: 90 days.
- AI assistant exchanges (questions, answers): 90 days, automatic purge.
- Invoices and consent evidence: statutory periods (7 years for Belgian accounting records).
- Electronic signature — evidence file (signer identity, IP address, UTC timestamps, action log, cryptographic digests and signed PDF): 10 years, to preserve the evidential value of signed documents, including after account deletion.
- Data of a terminated space: returnable for 30 days, then deleted.
6. Your rights
You have the rights of access, rectification, erasure, restriction, objection and portability. Directly from « My account »: full export of your data (JSON) and deletion of your account — if your account produced content belonging to a space, it is irreversibly anonymised (identity erased, company content preserved). For any other request: privacy@wedoc.io (answer within 30 days). You may lodge a complaint with the Belgian Data Protection Authority (DPA — dataprotectionauthority.be).
7. Security
End-to-end TLS encryption, hashed passwords (bcrypt), hashed one-time tokens, strict data separation per company, revocable sessions, account blocking, logging of administration actions. In the event of a data breach involving risk, notification to the DPA within 72 hours and information of the individuals concerned.