What Studio does with your data, and what it never does.

No promises, but how it is built. For whoever lays a list of requirements beside this page.

For whoever assesses a tender

You read what we read.

Every action in your environment goes into one log, ours included. Every line says whose it is. Nobody can change or remove a line.

Audit logProduction
09:12your companyM. de Vries approved request AV-0014
09:40DocumindsSupport access opened · ticket SUP-2231 · read only · until 17:40
10:05your companyJ. Bakker released Reminder v5 to Production
12:15DocumindsSupport access ended, earlier than planned
A line cannot be changed or removed, not by us either.

Where your data is

In the customer's region; in Europe with Hetzner in Germany. An installation serves one region and knows only that region's data.

Never: store your data outside the region you are a customer in.

Isolation

Every customer has, per environment (Development, Test, Acceptance, Production), a walled-off space with a role of its own. Whoever does not belong there is refused by the database, not by a line of code.

Never: add customers' data together.

Access

Who may come in is up to your company administrator. Signing in happens at one address, account.documinds.com, on a full page. Whoever approves a letter without an account gets a one-time link that expires after one verdict.

Never: ask for a password on this website, in a window or in an email.

Support

Support access is off by default. Once you release it, it holds for one environment, with a reason and a ticket number, read only, and it closes by itself after eight hours at most.

Never: sign in as one of your users. That function does not exist.

Audit log

One log, in which you read what we read. Every line says whether it is ours or yours. A line cannot be changed or removed, not even by the owner of the database.

Never: keep a separate audit log that you do not see.

Retention

The retention term is set per letter, per template and per environment; the shortest wins. In Development and Test that is thirty days at most. Backups hold a copy for six months at most.

Never: keep a letter in Studio after the term you set.

Testing

In Development and Test all post goes to one test mailbox. Test data taken from a real run expires by itself, and never comes from Production.

Never: send a proof letter to a real address.

Connections

Keys to your systems are sealed with a master key that is kept outside the database. A connection logs only reference, duration and outcome.

Never: record what was sent or received over a connection.

Documents for your tender

We send them on request, with the name of the person who answers your questions.

Data processing agreementon request
Subprocessorson request
Security descriptionon request
Ask for them with your demo request