Privacy.

Docenta holds client tax data on behalf of the firms that use it. This page states the shape of that arrangement. The binding document is the data processing agreement executed with your firm at onboarding, and it governs where this page and it differ.

A firm’s data belongs to the firm. Docenta processes it to do the work the firm asks for and for no other purpose. It is not used to train models, it is not sold, and it is not shared between firms. Every table that holds it carries firm-scoped row-level security in the database rather than checks in the application, so isolation is enforced beneath the code rather than by it.

Access inside a firm follows the firm’s own assignments. A person sees the clients they are assigned to and no others, and the same boundary applies to the agents, which run under a person’s identity rather than above it.

Reads of a taxpayer identifier are recorded before they are answered. Everywhere else in the product, including in agent prompts, memos, audit payloads and logs, an identifier appears as its last four digits.

Docenta is in Beta and is not yet SOC 2 Type II certified. That is stated on the front page as well, because it is the kind of thing a firm should not have to search for.

Sub-processors, retention periods, deletion on termination and breach notification are set out in the data processing agreement. Ask and we will send the current version before you commit to anything.

Questions about this page go to a person. Write to us and we will answer. Request access.