Privacy Policy
This policy explains what personal information DocFlow Studio collects, why we collect it, how long we hold it, and what you can ask us to do with it. It is written to be read, not to be skimmed past.
Last updated: July 18, 2026
1. Who we are
DocFlow Studio is a software video production studio operated by Jorge Aguilar. For the purposes of the EU and UK General Data Protection Regulation, DocFlow Studio is the data controller for the information described in this policy.
Registered operating name and postal address: [legal entity name and registered address]. You can reach us about anything in this policy at [email protected].
This policy covers this website, the enquiries we receive through it, and the correspondence that follows with clients. That is the entire scope, because that is the only personal data we handle. DocFlow Studio produces video files and delivers them to the client — we do not host, stream, or publish video for anyone, so we never operate a platform on your behalf and never process data about the people who eventually watch a video. Our Terms of Service set that boundary out in full.
It does not cover the separate SaaS Master website and YouTube channel, which publish content under their own terms and privacy practices.
2. What we collect
We collect very little, and almost all of it is information you type into a form yourself.
Information you give us
When you submit the project request form, we collect the fields you complete:
- Your name — so we know who we are replying to.
- Work email address — the address we send the reply and any follow-up to.
- Company name — context for the quote.
- Product URL — so we can look at the software before responding.
- Project details — whatever you choose to tell us about the videos you need. Please do not paste credentials, customer data, or anything confidential into this field; see section 9.
If you email us directly instead, we hold that correspondence and whatever it contains.
Information collected automatically
- Server and security logs. Our hosting provider records standard request data — IP address, timestamp, page requested, user agent — which is used to keep the site running and to block abuse.
- Aggregate analytics. We measure how many people reach each page and which pages they arrive from, so we know which pages are worth improving. Provider and configuration: [name your analytics provider here, or delete this bullet if you run none].
What we do not collect
This site has no user accounts, no logins, and no shopping cart. We do not ask for or store payment card details on this website. We do not buy contact lists, and we do not build advertising profiles or sell access to visitors.
We also collect nothing at all about anyone who watches a client’s video. We do not host client videos, run a player, or provide an embed — the finished files are delivered to the client, who publishes them on their own platforms. Viewer data from those platforms goes to the client and their providers, never to us. There is no end-user data held on any client’s behalf because there is no service of ours in that path.
3. Why we use it, and our lawful basis
Under GDPR we have to name a lawful basis for each use. Here they are in full.
- Purpose
- Replying to your project request and preparing a quote
- Data
- Name, work email, company, product URL, project details
- Lawful basis
- Steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b))
- Purpose
- Delivering a project you have engaged us for
- Data
- Contact details and project correspondence
- Lawful basis
- Performance of a contract (GDPR Art. 6(1)(b))
- Purpose
- Following up once on an enquiry that went quiet
- Data
- Name and work email
- Lawful basis
- Legitimate interests — running a business and answering the people who contacted it (GDPR Art. 6(1)(f))
- Purpose
- Keeping the site available and blocking abuse
- Data
- Server logs, IP address
- Lawful basis
- Legitimate interests — security and availability (GDPR Art. 6(1)(f))
- Purpose
- Understanding aggregate site traffic
- Data
- Page views, referrers, approximate region
- Lawful basis
- Legitimate interests, or consent where local law requires it for the storage used
- Purpose
- Keeping invoices and tax records
- Data
- Billing details for clients
- Lawful basis
- Legal obligation (GDPR Art. 6(1)(c))
We do not use your information to make automated decisions that produce legal or similarly significant effects, and we do not profile you.
6. International transfers
DocFlow Studio works with clients worldwide, and the providers listed above operate infrastructure in more than one country. If you contact us from the European Economic Area, the United Kingdom, or Switzerland, your information will likely be transferred to and stored in [state the countries where your host, mailbox, and email provider store data].
Where a transfer leaves the EEA or the UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) in our contracts with those providers, or on an adequacy decision covering the destination country. You can request a copy of the transfer safeguards that apply by writing to [email protected].
7. How long we keep it
We keep things for as long as they are useful for the purpose we collected them, and then we delete them.
- Enquiries that do not become projects — kept for up to 24 months, so we can pick up the thread if you come back, then deleted.
- Client project correspondence — kept for the duration of the engagement and for 24 months afterwards, so we can answer questions about work we did for you.
- Project video files — final exports, raw captures, and editable project files are kept for [same retention window as the Terms of Service, e.g. 90 days after final delivery] and then permanently deleted. We deliver files to the client and do not archive them; keeping master copies is the client’s responsibility. This window must match the one stated in our Terms of Service.
- Product access credentials you give us — deleted at the end of the project, and we ask you to revoke the account at your end as well.
- Invoices and tax records — kept for the period our tax law requires, which is longer than any of the above and is not something we can shorten on request.
- Server and security logs — retained on our host’s standard schedule, typically a short rolling window.
Ask us to delete something sooner and we will, unless we are legally required to keep it.
8. Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, or delete it. Write to [email protected] and we will respond within 30 days. We do not charge for this, and we will never treat you differently for asking.
If you are in the EEA, UK, or Switzerland (GDPR)
You have the right to:
- Access the personal data we hold about you, and receive a copy.
- Have inaccurate data corrected.
- Have your data erased, where we have no overriding obligation to keep it.
- Restrict how we process your data while a dispute is resolved.
- Receive your data in a portable, machine-readable format, or have it sent to another controller.
- Object to processing based on our legitimate interests, including any direct marketing — an objection to marketing is always honoured, with no balancing test.
- Withdraw consent at any time, where consent was the basis, without affecting processing that already happened.
You also have the right to complain to your national supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the authority in your country of residence. We would rather you came to us first, but that route is yours regardless.
If you are a California resident (CCPA / CPRA)
You have the right to:
- Know the categories and specific pieces of personal information we have collected, the sources, the purpose, and the categories of third parties we disclose to.
- Delete personal information we collected from you, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information — we do not sell or share it, so there is nothing to opt out of, and we honour GPC signals anyway.
- Limit the use of sensitive personal information — we do not collect any.
- Not be discriminated against for exercising any of these rights.
The categories we collect map to “identifiers” (name, email) and “commercial information” (details of the services you enquired about) under the CCPA. An authorised agent may submit a request on your behalf with written proof of authorisation. We may need to verify your identity by confirming you control the email address the enquiry came from.
Other US state privacy laws
Residents of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with comprehensive privacy laws have broadly equivalent rights of access, correction, deletion, and appeal. Use the same address and we will apply whichever framework covers you. If we decline a request, you may appeal by replying to our decision; we will respond to the appeal in writing.
9. How we protect it
The strongest protection on this site is that there is not much to protect. There is no database of visitors, no accounts, and no stored payment details.
- The site is served over HTTPS only, with strict transport security and standard hardening headers.
- Form submissions are transmitted to our inbox rather than accumulating in a public-facing database.
- Access to our email and project files is protected by strong, unique credentials and multi-factor authentication.
- Access to client product accounts is limited to what a project needs, and revoked when it ends.
A word about product credentials
Producing videos usually means logging into your software. Please give us a dedicated account scoped to a sandbox, demo tenant, or staging environment — never a shared admin login, and never an account with access to real customer records. Do not send credentials through the website form. We will agree a secure channel with you, and we will ask you to revoke the account when the project closes.
No system is perfectly secure. If a breach affects your personal information and creates a real risk to you, we will notify you and the relevant supervisory authority within the timeframes the law requires.
10. Children
This is a business-to-business service. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has sent us information, write to [email protected] and we will delete it.
11. Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects how we handle information you have already given us, we will contact the people affected directly rather than relying on you to re-read the page.
12. Contact us
Questions, access requests, deletion requests, and complaints all go to the same place:
Privacy contact
DocFlow Studio
Attn: Jorge Aguilar, Founder & Producer
Postal address: [registered postal address]
Put “Privacy request” in the subject line and we will route it correctly the first time.