DocAccess Logo, powered by CivicPlus

Privacy Policy

Effective Date: August 1, 2026

DocAccess Privacy Policy

DocAccess, a CivicPlus product, converts documents published by public-sector organizations — local governments, school districts, colleges, and other public agencies — into accessible formats. We take the privacy of the communities we serve seriously, and we have written this Privacy Policy to be read by everyone DocAccess touches: the staff who administer it for their organization, the members of the public who read documents through it, and visitors to our marketing website. It explains what information we collect, how we use and protect it, how long we retain it, and the choices available to you. By using DocAccess or visiting docaccess.com, you agree to the practices described in this Privacy Policy.

The Short Version

Privacy policies reward careful reading, and we encourage it — but these are the commitments that define ours:

  • Reading documents requires no account and collects no Personal Information. Members of the public — including students — can read accessible documents without registering, and we do not build profiles of readers.

  • The DocAccess application contains no advertising. We display no advertisements, and we never share data from the application with advertisers.

  • Your organization owns its data. We use it solely to provide the Services.

  • We do not sell Personal Information — anyone's, ever.

  • Our marketing website (the public pages of docaccess.com, including this one) uses standard analytics and advertising measurement tags from Google to evaluate our own marketing. Those tags are never loaded in the application or the document viewer.

1. Scope: The Three Surfaces of DocAccess

Throughout this Privacy Policy, "Personal Information" means information that identifies or can reasonably be linked to an individual person, and the "Services" means the DocAccess platform as a whole. Because different parts of DocAccess handle information very differently, this policy distinguishes three surfaces:

  • The Marketing Website — the public informational pages of docaccess.com, such as the home page, pricing, and this policy.

  • The Application — the signed-in workspace where Customer staff manage their organization's documents and settings. ("Customer" means the organization that subscribes to DocAccess.)

  • The Document Viewer — the public, accessible reading experience for documents our Customers have published. Readers never need an account.

2. What Information We Collect

From Customer staff (account holders): name, work email address, phone number, organization and role, login credentials (passwords are stored only as secure one-way hashes), and the content and settings your organization puts into the Services. Payment transactions are processed by a payment gateway; card numbers are not stored or processed on our servers.

From document readers (the public): no Personal Information. Reading a document requires no account, no name, and no email address. To help our Customers understand how their documents are used, we record aggregate, de-identified view statistics: the document viewed, the time of the view, city-level geography, general device or browser type, and view counts. We do not store exact IP addresses with view records, we do not use precise geolocation, and we do not engage in cross-site tracking or behavioral profiling of readers.

From Marketing Website visitors: standard analytics data (pages visited, referral source, campaign parameters such as UTM codes) and any information you choose to submit through a contact or sign-up form.

From support interactions: the contents of support tickets, chats, and emails you send us, so that we can respond and improve the Services.

3. How We Collect Information

We collect information directly from you when you register an account, sign in, submit a form, upload or link documents, request a translation, connect with a visual-assistance agent, or contact support; and automatically, through the cookies and aggregate usage measurement described in this policy. We collect most Personal Information because you willingly provide it to us.

4. How We Use Information

  • To provide, operate, secure, and improve the Services.

  • To respond to support requests and communicate with account holders regarding their account and the Services.

  • To provide Customers with aggregate reporting on how their published documents are used.

  • To measure the effectiveness of our own marketing (Marketing Website only).

  • To comply with legal obligations.

5. Data Ownership

Our Customers own their content and data. Documents, accessible transcripts, account records, and exportable data belong to the Customer. Customers grant CivicPlus a limited license to reproduce, distribute, and display that content only as necessary to provide the Services — not an unlimited license, and not a right to use Customer content for unrelated purposes. Ownership and license terms are set out in the CivicPlus Master Services Agreement.

6. Data Retention

We retain information according to the following schedule — not indefinitely, and not simply "for as long as we need it":

  • Customer content (documents and accessible transcripts): retained while your subscription is active. Following termination of service, Customer content and Customer data are permanently deleted thirty (30) days after termination, in accordance with the Master Services Agreement.

  • Account records (staff names, email addresses, settings): retained for the life of the Customer relationship and deleted on the same post-termination schedule.

  • System and audit logs: retained for 12 months.

  • Support correspondence: retained for the life of the Customer relationship so that we can service the account.

  • Document view statistics: aggregate and de-identified — they contain no Personal Information — and retained to provide Customers with historical reporting.

  • Backups: encrypted backups age out automatically on a rolling schedule; deleted data leaves backup systems as those backups expire.

7. Deleting Your Data

  • Customer administrators may remove documents and user accounts directly in the Application at any time.

  • Any account holder may request deletion of their Personal Information by emailing support@docaccess.com. We will verify the request and complete deletion within thirty (30) days.

  • Upon termination of service, all Customer content and Customer data are permanently deleted on the 30-day schedule described above. Customers may export their data before termination.

  • Document readers have nothing to delete — reading documents creates no records about you as an individual.

8. How We Protect Information

DocAccess runs on U.S.-region cloud infrastructure. Data is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher. Access to production systems is restricted through role-based access control and multi-factor authentication, and operational access is logged and audited. We maintain separate staging and production environments, perform vulnerability scanning, and operate a vulnerability disclosure program. DocAccess has completed a SOC 2 Type I examination with an unqualified opinion (report available to Customers and prospective Customers under NDA), and our security program aligns with the NIST Cybersecurity Framework and ISO 27001 control families. Complete detail, including our security and AI FAQ, HECVAT, and VPAT, is published on our Security Practices page.

Customer sign-in supports single sign-on (SAML 2.0 / OIDC) and enforces password strength requirements; multi-factor authentication is required for privileged roles and available to all users.

9. How We Use Cookies

Cookies are small text files a website stores in your browser so it can recognize you on a return visit. DocAccess uses them differently on each surface:

  • In the Application: cookies are used solely for functionality — keeping you signed in and remembering your preferences. No advertising or cross-site tracking cookies are used in the Application or the Document Viewer.

  • On the Marketing Website: we use first-party cookies to attribute sign-ups to our own marketing campaigns (for example, UTM and referral parameters), and Google tags (loaded via Google Tag Manager) for analytics and advertising measurement, as described in the Advertising section below.

You may configure your browser to warn you about cookies or to refuse them entirely; consult your browser's Help menu. If you disable cookies, the Marketing Website will continue to work, but you will not be able to sign in to the Application, as sign-in depends on a session cookie.

10. Third-Party Service Providers

We use a deliberately small set of third-party service providers (subprocessors), strictly to operate the Services. We do not sell, rent, or trade Personal Information, and we do not share it with third parties for their own marketing. The categories of providers we use, and what each receives, are:

  • Cloud infrastructure and hosting (U.S. regions) — stores and serves Customer content and account data.

  • AI document processing — receives document content transiently to generate accessible versions. Processing is request-scoped, and Customer data is not used to train shared models.

  • Translation services — receive document text only when a reader requests a translation.

  • Visual-assistance services — connected only when a reader chooses to contact a live assistance agent.

  • Email delivery — receives the email address and message content for account and support email we send.

  • Payment processing — a payment gateway processes transactions; card data is not stored or processed on our servers.

  • Analytics and marketing tags (Marketing Website only) — receive standard website analytics signals from the Marketing Website, never from the Application or Document Viewer.

We treat our specific vendor list as confidential business information, and we provide it to Customers and prospective Customers upon request. Every provider that handles Customer data is bound by contractual confidentiality and data-protection obligations consistent with this policy, and each receives only the data required for its function. Should we make a material change to the categories of providers we use, we will update this policy and notify Customer administrators.

We may also disclose information where required to comply with the law, to enforce our agreements, or to protect the rights, property, or safety of DocAccess, our Customers, or others.

Links to other sites: documents and pages may contain links to websites we do not operate. Their privacy practices are governed by their own policies, and we encourage you to review them.

11. Advertising

The DocAccess Application and Document Viewer contain no advertising. We display no advertisements; we use no advertising cookies, web beacons, or tracking pixels in the Application or Viewer; and we never share Application or reader data with advertisers or ad networks. There is, accordingly, nothing to opt out of within the product itself.

On the Marketing Website only, we use Google tags to measure the performance of our own advertising campaigns (for example, recording that a visit originated from one of our advertisements). These tags may set cookies from Google. You may control this through Google Ad Settings, the Network Advertising Initiative opt-out page, or the Google Analytics opt-out browser add-on. These marketing tags are never loaded in the Application or the Document Viewer.

12. Do Not Track

The Application and Document Viewer do not track users across websites, so there is no cross-site tracking for a Do Not Track signal to disable. On the Marketing Website, you may use the opt-out tools listed above together with your browser's cookie controls.

13. Children's Privacy (COPPA)

DocAccess is designed so that children can safely read published documents without providing any Personal Information: the Document Viewer requires no account, no registration, and no personal details, and it contains no advertising and no behavioral tracking. DocAccess accounts are created only for staff of our Customer organizations; we do not knowingly create accounts for, or collect Personal Information from, children under 13. If you believe a child has provided us Personal Information, please contact support@docaccess.com and we will delete it promptly.

14. Student Data and FERPA

DocAccess does not require or collect student education records to operate. Document readers, including students, are anonymous to us. Where a school or district Customer's published content includes information subject to FERPA, we process it solely as the institution's service provider, at the institution's direction, under our written agreement — we do not use it for any other purpose, and the institution retains full ownership and control, including deletion, as described in this policy.

15. GDPR and International Visitors

DocAccess serves U.S. public-sector organizations and operates in U.S. cloud regions. For any personal data of individuals in the European Economic Area or United Kingdom contained in Customer content, we act as a processor on the Customer's documented instructions. Individuals may exercise rights of access, correction, and erasure over their Personal Information by contacting support@docaccess.com.

16. California Privacy Rights (CalOPPA and CCPA)

  • You may visit our Marketing Website, and read documents in the Document Viewer, anonymously.

  • This policy is linked from our website footer and includes the word "Privacy."

  • We do not sell or share Personal Information as those terms are defined by the California Consumer Privacy Act, and we do not use Personal Information from the Application for cross-context behavioral advertising.

  • California residents may request access to or deletion of their Personal Information via support@docaccess.com. Account holders may also update their Personal Information by logging in to their account.

17. Email Communications (CAN-SPAM)

We send account holders transactional email regarding their account and the Services, along with occasional product updates. Marketing email includes an unsubscribe link, and you may opt out of all non-essential email at any time by using that link or by emailing support@docaccess.com. We honor opt-outs promptly.

18. Changes to This Policy

When we update this policy, we will post the new version on this page with a new effective date. For material changes — including material changes to the categories of third-party providers we use — we will notify Customer administrators by email.

19. Contact Us

Questions about this policy or our privacy practices are welcome: support@docaccess.com, or through the CivicPlus contact page. Security documentation, including our SOC 2 report (under NDA), HECVAT, and VPAT, is available via our Security Practices page.