Privacy Policy for DocsChat

1. Data Sovereignty & Collection

DocsChat operates under a strict model of Absolute Data Sovereignty. The App collects and processes the following types of data solely within your organization’s managed boundary:

  • User Information: Name, email address, user role, and authentication identifiers.

  • Chat & Document Data: User-submitted prompts, AI-generated responses, and text content processed during document interactions.

  • Metadata: Configuration settings, workspace preferences, log files, timestamps, selected LLM providers, and system-generated metrics to optimize the user experience.

  • Uploaded Documents: Files (such as PDFs, contracts, or HR policy manuals) uploaded for analysis from OneDrive.

Crucial Commitment: All files, chat histories, and configurations are securely stored inside your own Microsoft Dataverse instance or Azure Cosmos within your corporate Microsoft 365 tenant. We (the developers/providers of DocsChat) do not host, store, or have any form of access to your documents, conversations, or data.

2. How the App Processes Your Data

DocsChat processes data strictly to deliver its core collaborative functionalities:

  • Providing and improving DocsChat’s document intelligence and real-time chat functionality.

  • Facilitating Direct Mode (full file context inline processing) and RAG AI Mode (vector-based smart search filtering).

  • Enforce Entra ID access controls and security parameters.

  • Connect securely to your chosen AI models (Azure OpenAI or Google Gemini) via your administrator's Bring Your Own Model (BYOM) configuration.

All processing occurs dynamically. Your corporate files and conversations are completely isolated and are strictly barred from public AI model training.

3. Data Storage & Security

  • Tenant Isolation: All operational and document data is housed within Microsoft Dataverse or Azure Blob Storage, complying fully with Microsoft’s enterprise security frameworks.

  • Data Retention: DocsChat itself does not retain or store uploaded documents or user-provided data on external infrastructure. All data exists solely within your Microsoft Tenant. DocsChat does not impose custom retention schedules; it automatically respects and inherits any data retention or lifecycle policies configured in your Microsoft Power Platform Environment.

  • Security Measures: The App inherits and relies on Microsoft’s robust cloud security layers, tenant-level protections, and Entra ID authentication to maintain strict confidentiality and data integrity.

4. Data Sharing & Large Language Model (LLM) Integrations

  • No Third-Party Data Selling/Sharing: DocsChat does not sell, share, or disclose data to unauthorized third parties.

  • LLM API Architecture: When interacting with documents, text segments or inline file contents are transmitted exclusively to the specific AI endpoints configured by your administrator (via Azure OpenAI or Google Gemini enterprise APIs). These corporate API connections explicitly ensure that data sent through them is private and not used to train foundational public models.

5. Fixed Architecture & Ecosystem Integration

DocsChat honors existing user permission scopes based strictly on the immutable deployment package selected at download, with no option to switch configurations post-installation:

  • Code App Packages: Deploys as a standalone application built natively within your Microsoft Power Platform workspace with minimal setup required.

  • Web App Package: Deploys as a standalone Azure Static Web Site using high-performance Azure Functions and Azure Foundry, operating exclusively in RAG AI Mode to securely stream and query files from your corporate OneDrive.

6. Rights & Data Control

Because all data resides natively within your infrastructure, your organisation’s System Administrators retain absolute control. Admins have the unilateral right to access, update, audit, or permanently delete any data, chat logs, or files processed by the App at any time.

7. Compliance & Regulations

  • The App operates in alignment with global data protection frameworks, including GDPR and CCPA, by delegating data residency and storage handling to Microsoft Dataverse.

  • Microsoft Dataverse ensures geographical data residency constraints and compliance with rigid industry-specific standards.

8. Core Privacy References

For deeper insights into the underlying infrastructure protections, please consult:

9. Contact Information

If you have any questions or concerns regarding the implementation or data flow of this application within your environment, please contact your internal IT administrator or reach out to us directly at [[email protected]].

By deploying and using DocsChat, your organization acknowledges and agrees to the processing terms outlined in this Privacy Policy, alongside Microsoft’s standard Enterprise Privacy Policies.

Scroll to Top