Privacy Policy
Last updated: 18 June 2026
This policy explains how PaperOrg for Business ("PaperOrg", "we") handles personal data when an accounting or fiduciary firm uses our document-intelligence platform. It is written for the firms that use us and the people whose documents they manage.
Who is responsible for your data
For documents and client information a firm uploads, the firm is the data controller and PaperOrg acts as its processor under a Data Processing Agreement. For the firm's own account data (the names, emails and logins of its team), PaperOrg is the controller. This policy covers both; the processor relationship is detailed in our DPA.
What we process
- Account data: name, email, securely hashed password, and (if enabled) a two-factor secret.
- Workspace data: firm, client and folder names, roles and access grants.
- Documents you upload and the data our AI extracts from them (e.g. supplier, amounts, VAT, dates).
- Audit logs: who did what and when, including IP address and browser, for security and accountability.
- Technical logs needed to operate and secure the service.
How your data is protected
- Every document is encrypted at rest with authenticated encryption (XChaCha20-Poly1305) before it is stored.
- All traffic is encrypted in transit (TLS). Every document open is access-checked and logged.
- Access is default-deny: team members see only the clients and folders they are explicitly granted.
- Two-factor authentication is available for every account.
- Nightly encrypted backups are kept in EU object storage.
Where your data is stored
Documents and backups are stored in the European Union. Our application runs on EU-based servers (Germany) and our encrypted backups are held in EU-jurisdiction object storage.
Sub-processors we rely on
| Provider | Purpose | Location |
|---|---|---|
| EU hosting provider | Application servers | EU (Germany) |
| Cloudflare R2 | Encrypted document storage & backups | EU jurisdiction |
| Anthropic | AI extraction of fields from documents | US — under EU Standard Contractual Clauses |
| Email/SMTP provider | Transactional email (invites, alerts) | EU |
Document content sent to our AI sub-processor is processed only to extract accounting fields, transiently, and is not used to train their models. We give firms reasonable notice of new sub-processors.
Lawful bases
We process data to perform our contract with the firm, to pursue our legitimate interest in keeping the service secure and auditable, and to meet legal obligations. Where PaperOrg is processor, the firm is responsible for the lawful basis covering its clients' data.
How long we keep it
Account data is kept for the life of the account. Documents remain until the firm deletes them; deleted documents are removed from active storage and rotate out of backups. Audit logs are retained to provide a meaningful security history.
Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, portability, or object to processing. If your data was uploaded by a firm acting as controller, we will direct your request to that firm. To exercise a right, contact us at privacy@paperorg.com.
Cookies
We use only the essential cookies needed to keep you signed in and to protect forms. No advertising or third-party tracking cookies.
Changes & contact
We will post any material change here and update the date above. Questions about this policy or your data: privacy@paperorg.com.