Skip to content

Privacy Policy

This policy explains what personal information DocFlow Studio collects, why we collect it, how long we hold it, and what you can ask us to do with it. It is written to be read, not to be skimmed past.

Last updated: July 18, 2026

1. Who we are

DocFlow Studio is a software video production studio operated by Jorge Aguilar. For the purposes of the EU and UK General Data Protection Regulation, DocFlow Studio is the data controller for the information described in this policy.

Registered operating name and postal address: [legal entity name and registered address]. You can reach us about anything in this policy at [email protected].

This policy covers this website, the enquiries we receive through it, and the correspondence that follows with clients. That is the entire scope, because that is the only personal data we handle. DocFlow Studio produces video files and delivers them to the client — we do not host, stream, or publish video for anyone, so we never operate a platform on your behalf and never process data about the people who eventually watch a video. Our Terms of Service set that boundary out in full.

It does not cover the separate SaaS Master website and YouTube channel, which publish content under their own terms and privacy practices.

2. What we collect

We collect very little, and almost all of it is information you type into a form yourself.

Information you give us

When you submit the project request form, we collect the fields you complete:

  • Your name — so we know who we are replying to.
  • Work email address — the address we send the reply and any follow-up to.
  • Company name — context for the quote.
  • Product URL — so we can look at the software before responding.
  • Project details — whatever you choose to tell us about the videos you need. Please do not paste credentials, customer data, or anything confidential into this field; see section 9.

If you email us directly instead, we hold that correspondence and whatever it contains.

Information collected automatically

  • Server and security logs. Our hosting provider records standard request data — IP address, timestamp, page requested, user agent — which is used to keep the site running and to block abuse.
  • Aggregate analytics. We measure how many people reach each page and which pages they arrive from, so we know which pages are worth improving. Provider and configuration: [name your analytics provider here, or delete this bullet if you run none].

What we do not collect

This site has no user accounts, no logins, and no shopping cart. We do not ask for or store payment card details on this website. We do not buy contact lists, and we do not build advertising profiles or sell access to visitors.

We also collect nothing at all about anyone who watches a client’s video. We do not host client videos, run a player, or provide an embed — the finished files are delivered to the client, who publishes them on their own platforms. Viewer data from those platforms goes to the client and their providers, never to us. There is no end-user data held on any client’s behalf because there is no service of ours in that path.

3. Why we use it, and our lawful basis

Under GDPR we have to name a lawful basis for each use. Here they are in full.

Purpose
Replying to your project request and preparing a quote
Data
Name, work email, company, product URL, project details
Lawful basis
Steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b))
Purpose
Delivering a project you have engaged us for
Data
Contact details and project correspondence
Lawful basis
Performance of a contract (GDPR Art. 6(1)(b))
Purpose
Following up once on an enquiry that went quiet
Data
Name and work email
Lawful basis
Legitimate interests — running a business and answering the people who contacted it (GDPR Art. 6(1)(f))
Purpose
Keeping the site available and blocking abuse
Data
Server logs, IP address
Lawful basis
Legitimate interests — security and availability (GDPR Art. 6(1)(f))
Purpose
Understanding aggregate site traffic
Data
Page views, referrers, approximate region
Lawful basis
Legitimate interests, or consent where local law requires it for the storage used
Purpose
Keeping invoices and tax records
Data
Billing details for clients
Lawful basis
Legal obligation (GDPR Art. 6(1)(c))

We do not use your information to make automated decisions that produce legal or similarly significant effects, and we do not profile you.

4. Cookies, analytics, and embedded video

We do not use advertising cookies, retargeting pixels, or cross-site trackers on this website.

Analytics

Analytics here exist to answer one question: which pages are worth writing better. We look at totals, not at individuals. Current provider and whether it sets any cookie or identifier: [confirm your analytics provider and its cookie behaviour, then update this paragraph]. If a provider that stores identifiers on your device is introduced, a consent banner will be added at the same time — not afterwards.

Embedded video

Video examples on this site load as a static thumbnail with a play button, not as a live YouTube player. The thumbnail image itself is served from YouTube’s image CDN, so that request does reach Google and carries your IP address. No YouTube player, tracking script, or cookie loads until you click play. Once you do, YouTube receives your request and applies Google’s privacy policy. Choosing not to press play is a real opt-out here, which is exactly why the site is built this way.

Do Not Track and Global Privacy Control

We honour Global Privacy Control (GPC) signals as an opt-out of sale or sharing under US state privacy laws. Since we do not sell or share personal information as those laws define it, there is nothing for the signal to switch off — but it is respected regardless.

5. Who we share it with

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not disclose it for money or for anything else of value.

A small number of service providers process data on our behalf, under contract, and only on our instructions. They are:

  • Resend — delivers the email generated by the project request form to our inbox. It processes the contents of your submission in order to transmit it.
  • Our web host — serves this site and keeps the request logs described above. Provider and hosting region: [name your hosting provider and its region].
  • Our email provider — stores the correspondence between us for as long as we keep it. Provider: [name the mailbox provider for [email protected]].
  • Our analytics provider, if any[name it, or state that no third-party analytics are used].

Beyond those processors, we disclose personal information only where we are legally required to — a valid court order, a lawful request from a public authority, or to establish or defend a legal claim — or where a business transfer occurs, in which case this policy travels with the data and you will be told before anything changes.

6. International transfers

DocFlow Studio works with clients worldwide, and the providers listed above operate infrastructure in more than one country. If you contact us from the European Economic Area, the United Kingdom, or Switzerland, your information will likely be transferred to and stored in [state the countries where your host, mailbox, and email provider store data].

Where a transfer leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our contracts with those providers, or on an adequacy decision covering the destination country. You can request a copy of the transfer safeguards that apply by writing to [email protected].

7. How long we keep it

We keep things for as long as they are useful for the purpose we collected them, and then we delete them.

  • Enquiries that do not become projects — kept for up to 24 months, so we can pick up the thread if you come back, then deleted.
  • Client project correspondence — kept for the duration of the engagement and for 24 months afterwards, so we can answer questions about work we did for you.
  • Project video files — final exports, raw captures, and editable project files are kept for [same retention window as the Terms of Service, e.g. 90 days after final delivery] and then permanently deleted. We deliver files to the client and do not archive them; keeping master copies is the client’s responsibility. This window must match the one stated in our Terms of Service.
  • Product access credentials you give us — deleted at the end of the project, and we ask you to revoke the account at your end as well.
  • Invoices and tax records — kept for the period our tax law requires, which is longer than any of the above and is not something we can shorten on request.
  • Server and security logs — retained on our host’s standard schedule, typically a short rolling window.

Ask us to delete something sooner and we will, unless we are legally required to keep it.

8. Your rights

Wherever you live, you can ask us to show you what we hold about you, correct it, or delete it. Write to [email protected] and we will respond within 30 days. We do not charge for this, and we will never treat you differently for asking.

If you are in the EEA, UK, or Switzerland (GDPR)

You have the right to:

  • Access the personal data we hold about you, and receive a copy.
  • Have inaccurate data corrected.
  • Have your data erased, where we have no overriding obligation to keep it.
  • Restrict how we process your data while a dispute is resolved.
  • Receive your data in a portable, machine-readable format, or have it sent to another controller.
  • Object to processing based on our legitimate interests, including any direct marketing — an objection to marketing is always honoured, with no balancing test.
  • Withdraw consent at any time, where consent was the basis, without affecting processing that already happened.

You also have the right to complain to your national supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority in your country of residence. We would rather you came to us first, but that route is yours regardless.

If you are a California resident (CCPA / CPRA)

You have the right to:

  • Know the categories and specific pieces of personal information we have collected, the sources, the purpose, and the categories of third parties we disclose to.
  • Delete personal information we collected from you, subject to legal exceptions.
  • Correct inaccurate personal information.
  • Opt out of the sale or sharing of personal information — we do not sell or share it, so there is nothing to opt out of, and we honour GPC signals anyway.
  • Limit the use of sensitive personal information — we do not collect any.
  • Not be discriminated against for exercising any of these rights.

The categories we collect map to “identifiers” (name, email) and “commercial information” (details of the services you enquired about) under the CCPA. An authorised agent may submit a request on your behalf with written proof of authorisation. We may need to verify your identity by confirming you control the email address the enquiry came from.

Other US state privacy laws

Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have broadly equivalent rights of access, correction, deletion, and appeal. Use the same address and we will apply whichever framework covers you. If we decline a request, you may appeal by replying to our decision; we will respond to the appeal in writing.

9. How we protect it

The strongest protection on this site is that there is not much to protect. There is no database of visitors, no accounts, and no stored payment details.

  • The site is served over HTTPS only, with strict transport security and standard hardening headers.
  • Form submissions are transmitted to our inbox rather than accumulating in a public-facing database.
  • Access to our email and project files is protected by strong, unique credentials and multi-factor authentication.
  • Access to client product accounts is limited to what a project needs, and revoked when it ends.

A word about product credentials

Producing videos usually means logging into your software. Please give us a dedicated account scoped to a sandbox, demo tenant, or staging environment — never a shared admin login, and never an account with access to real customer records. Do not send credentials through the website form. We will agree a secure channel with you, and we will ask you to revoke the account when the project closes.

No system is perfectly secure. If a breach affects your personal information and creates a real risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.

10. Children

This is a business-to-business service. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us information, write to [email protected] and we will delete it.

11. Changes to this policy

When this policy changes, the date at the top of the page changes with it. If a change materially affects how we handle information you have already given us, we will contact the people affected directly rather than relying on you to re-read the page.

12. Contact us

Questions, access requests, deletion requests, and complaints all go to the same place:

Privacy contact

DocFlow Studio

Attn: Jorge Aguilar, Founder & Producer

[email protected]

Postal address: [registered postal address]

Put “Privacy request” in the subject line and we will route it correctly the first time.