Privacy Policy
DonePact Technologies Private Limited ("DonePact", "Company", "we", "us", or "our") respects privacy and is committed to protecting personal data, confidential business information, and customer content entrusted to us.
DonePact operates an AI-native agreement operations, workflow automation, and contract intelligence platform designed to help organizations collaborate before, during, and after execution of agreements.
This Privacy Policy explains how DonePact collects, uses, processes, stores, transfers, protects, and discloses information when individuals or organizations access or use:
- the DonePact website
- the DonePact web platform
- mobile applications
- APIs and integrations
- Microsoft Word Add-ins and extensions
- workflow automation features
- AI-assisted capabilities
- AI Agents
- related services and infrastructure.
(collectively, the “Platform” or “Services”).
This Privacy Policy should be read together with the DonePact Terms of Use, applicable customer agreements, Data Processing Addenda (if any), and security documentation.
Important Disclosures
B2B Platform — DonePact is intended solely for use by businesses and organizations.
Customer-Controlled Platform — Customer organizations control the data uploaded to the Platform, workflows configured within the Platform, integrations enabled, permissions granted to users and systems, AI Agent configurations, and automated actions and approval flows.
AI-Assisted Platform — The Platform may use artificial intelligence, machine learning systems, automations, and AI Agents to assist with workflows, drafting, extraction, summarization, analytics, routing, recommendations, and other operational tasks. AI-generated outputs may contain inaccuracies, omissions, hallucinations, or incorrect interpretations and must be independently reviewed by appropriate human personnel.
Third-Party Integrations — The Platform may integrate with third-party systems including communication tools, cloud storage providers, CRMs, ERPs, productivity platforms, identity providers, e-signature providers, and AI providers. Customer organizations are responsible for enabling, configuring, monitoring, and supervising such integrations.
1 Scope and Applicability
This Privacy Policy applies to personal data and related information processed through:
- the DonePact Platform
- customer workflows
- APIs
- integrations
- customer support interactions
- websites and online services
- AI-assisted features
- workflow automation services
- AI Agents.
DonePact provides services globally. Accordingly, personal data may be processed across multiple jurisdictions and may be subject to different data protection laws.
DonePact processes personal data in accordance with applicable laws and recognized privacy principles including lawfulness, transparency, purpose limitation, data minimization, integrity and confidentiality, and accountability.
Depending on applicable jurisdiction, DonePact may process personal data in accordance with:
- the Digital Personal Data Protection Act, 2023 (India)
- the Information Technology Act, 2000 and applicable rules
- the General Data Protection Regulation (GDPR)
- the UK GDPR and UK Data Protection Act
- the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- and other applicable privacy or data protection laws.
2 Information We Collect
2.1 Personal Information
Depending on usage of the Platform, DonePact may collect:
- names
- e-mail addresses
- business contact details
- organization information
- job titles
- user identifiers
- account credentials
- billing information
- authentication data
- IP addresses
- approximate location information
- device identifiers.
2.2 Customer Content & Agreement Data
Customer organizations and Authorized Users may upload, generate, store, process, transmit, or manage:
- contracts and agreements
- templates and playbooks
- workflows and approval records
- comments and collaboration records
- negotiation drafts and redlines
- attachments and supporting documents
- prompts and workflow instructions
- AI interactions
- audit logs
- metadata
- communications.
Such information may contain personal data relating to employees, counterparties, consultants, customers, vendors, or other individuals. Customer content remains the property of the applicable customer organization.
2.3 Workflow & Operational Data
DonePact may collect information relating to operation of workflows and automations including:
- approval sequences
- workflow configurations
- routing rules
- assignment history
- timestamps
- activity logs
- document interactions
- execution events
- reminder events
- AI-assisted workflow actions.
2.4 AI Interaction Data
DonePact may process prompts, instructions, AI-generated outputs, AI interaction history, semantic search inputs, extraction requests, workflow recommendations, and AI Agent activity logs. Such information may be processed to provide AI-assisted Services, maintain security, improve functionality, monitor abuse, troubleshoot issues, and improve platform performance.
2.5 Integration Data
Where integrations are enabled by Customer, DonePact may access or process information from integrated systems including:
- communication systems
- CRM platforms
- ERP systems
- e-mail platforms
- cloud storage systems
- collaboration tools
- e-signature systems
- authentication providers
- AI providers.
2.6 Usage & Telemetry Data
DonePact may collect feature usage information, system interaction data, performance metrics, diagnostic information, telemetry, crash reports, log data, API usage information, and session information.
2.7 Cookies & Similar Technologies
DonePact may use cookies, tokens, pixels, local storage, analytics technologies, and similar technologies to authenticate users, maintain session security, improve functionality, analyze usage patterns, monitor platform performance, and remember user preferences. Where required by law, DonePact will obtain consent before placing non-essential cookies.
3 How We Use Information
DonePact may use information to:
- provide and operate the Services
- authenticate users
- manage accounts
- enable workflows and automations
- support AI-assisted functionality
- facilitate collaboration
- maintain security
- detect abuse or fraud
- troubleshoot issues
- improve platform functionality
- develop new features
- support integrations
- monitor platform performance
- communicate with users
- comply with legal obligations
- enforce agreements.
DonePact may also use aggregated, anonymized, or de-identified information for analytics, benchmarking, platform optimization, operational intelligence, product development, and service improvement.
4 Data Controller / Processor Roles
4.1 Customer Organizations
Where customer organizations upload or process personal data through the Platform, the customer organization acts as the data controller, data fiduciary, or equivalent governing entity determining the purpose and means of processing.
4.2 DonePact as Service Provider
In such cases, DonePact acts primarily as a processor or service provider processing data on behalf of the customer organization and in accordance with customer instructions, applicable agreements, and applicable law.
4.3 DonePact as Independent Controller
DonePact may independently act as a controller or data fiduciary in relation to account registration, billing, customer support, security monitoring, compliance obligations, marketing communications, and platform administration.
5 AI Agents, Automation & Automated Processing
5.1 AI-Assisted Features
The Platform may use artificial intelligence, machine learning technologies, workflow automations, and AI Agents to assist with drafting suggestions, summarization, metadata extraction, semantic search, clause analysis, workflow routing, approval recommendations, risk identification, negotiation assistance, analytics, and operational recommendations.
5.2 Human Oversight
AI features are designed to assist human users and are not intended to replace independent legal, commercial, operational, or professional judgment. Customer organizations remain solely responsible for supervising workflows, reviewing AI outputs, validating decisions, approving actions, and ensuring compliance with applicable law.
5.3 Automated Workflows
Customer-configured workflows and AI Agents may route approvals, generate notifications, assign tasks, trigger reminders, synchronize data across systems, update records, recommend actions, and initiate configured automated actions. Customer organizations are solely responsible for configuring, reviewing, monitoring, validating, and supervising such workflows and automations.
5.4 AI Training Restrictions
Unless expressly authorized by Customer in writing, DonePact does not use customer contracts or confidential customer content to train generalized AI models for unrelated third parties customer-specific data remains logically segregated DonePact does not permit third-party AI providers to independently train their public models using Customer content submitted through the Platform.
5.5 AI Limitations
AI-generated outputs may contain inaccuracies, omissions, hallucinations, or incomplete analysis. DonePact does not guarantee the accuracy, completeness, legality, enforceability, or suitability of AI-generated outputs.
6 Integrations & Third-Party Services
6.1 Third-Party Integrations
The Platform may integrate with third-party systems and services including CRM systems, ERP systems, cloud storage providers, communication tools, collaboration platforms, identity providers, accounting platforms, e-signature providers, and AI providers.
6.2 Customer Authorization
By enabling integrations, Customer authorizes DonePact to access, process, retrieve, transmit, synchronize, organize, and exchange Customer Data with such integrated systems in accordance with Customer configurations and instructions.
6.3 Third-Party Terms
Use of third-party services may be subject to separate terms, privacy policies, and licensing conditions imposed by the applicable provider.
6.4 Third-Party Responsibility
DonePact does not own or control third-party services and is not responsible for third-party privacy practices, third-party outages, API failures or modifications, acts or omissions of third-party providers, unauthorized access arising from Customer configurations, or data loss or synchronization issues caused by third-party systems.
6.5 Third-Party AI Providers
Certain AI functionality may utilize third-party infrastructure or AI providers. Customer acknowledges that prompts, instructions, and related data may be processed through such providers solely for providing the Services. DonePact implements contractual and technical measures designed to restrict unauthorized use of Customer Data by such providers.
7 Information Sharing & Disclosure
DonePact does not sell personal data.
DonePact may disclose information to service providers and sub-processors cloud infrastructure providers AI providers supporting platform functionality payment processors customer-authorized integrations professional advisers affiliates in connection with mergers or corporate transactions where required by law or to protect legal rights, security, or operations.
All service providers and sub-processors are subject to appropriate contractual confidentiality and data protection obligations.
8 International Data Transfers
DonePact may process or transfer personal data across jurisdictions where DonePact, its affiliates, infrastructure providers, sub-processors, or service providers operate.
Where required by applicable law, DonePact implements appropriate safeguards including contractual protections, Standard Contractual Clauses, technical and organizational safeguards, security controls, and transfer impact mitigation measures.
9 Data Security
DonePact implements commercially reasonable technical, administrative, organizational, and physical safeguards designed to protect information against unauthorized access, accidental loss, destruction, misuse, alteration, and disclosure.
Security measures may include encryption in transit, encryption at rest where appropriate, role-based access controls, logging and monitoring, authentication controls, secure infrastructure, vulnerability management, internal security policies, and employee confidentiality obligations.
No method of transmission or storage is completely secure, and DonePact cannot guarantee absolute security.
Security Incident Notification — Where required by law or contract, DonePact will notify affected customers of confirmed security incidents involving customer personal data within a commercially reasonable time after becoming aware of the incident.
10 Data Retention
DonePact retains personal data only for as long as reasonably necessary to provide the Services, maintain security, comply with legal obligations, resolve disputes, and enforce agreements.
Customer organizations are responsible for exporting and archiving their information. Upon termination, DonePact may delete Customer Data after applicable retention periods unless otherwise required by law or agreed by contract. Residual copies may temporarily remain in backup systems before permanent deletion.
11 Data Portability & Export
Where supported by the Platform or required by applicable law, customers may export or retrieve Customer Data and related records. DonePact may provide reasonable assistance relating to data export subject to applicable agreements and technical limitations.
12 User Rights
Depending on applicable law, individuals may have rights relating to access, correction, deletion, restriction of processing, portability, objection to processing, withdrawal of consent, and grievance redressal. Requests may be submitted using the contact information below. Where DonePact acts solely as a processor on behalf of customer organizations, requests relating to customer-controlled data may need to be directed to the relevant customer organization.
13 Children's Privacy
The Services are intended solely for business users and individuals who are at least eighteen (18) years of age. DonePact does not knowingly collect personal data from children.
14 Changes to This Privacy Policy
DonePact may update this Privacy Policy from time to time. Updated versions will be posted on the Platform with revised effective dates. Continued use of the Services after updates constitutes acceptance of the revised Privacy Policy.
15 Contact Information & Grievance Officer
DonePact Technologies Private Limited
401 Landmark Premises
Juhu Tara Road
Mumbai – 400049
India
E-mail: joydeep.nandy@donepact.com
For privacy-related inquiries, please include “Privacy Request” in the subject line. Where required by applicable law, DonePact has appointed a Grievance Officer / privacy contact to address data protection concerns.
