1. Introduction
HachiAI Inc. ("HachiAI", "we", "us", or "our") operates Doculytix, an AI-powered document understanding platform that transforms unstructured documents—PDFs, scans, and images—into clean, structured data. Doculytix uses computer vision, optical character recognition (OCR), and semantic reasoning to extract fields, tables, and other data from documents at scale. We are committed to protecting the privacy and security of your personal information.
This Privacy Policy applies to information collected through the Doculytix website at doculytix.ai (the "Website"), the Doculytix platform, APIs, SDKs, and related services accessible via studio.doculytix.ai and api.hachiai.com (the "Services"), our marketing and sales activities, and any other interactions you may have with HachiAI in relation to Doculytix.
HachiAI is headquartered in Toronto, Canada, with offices in Montreal, Dallas, Dubai, Lahore, and Hyderabad. We serve enterprise and individual clients globally and comply with applicable data protection laws in all jurisdictions where we operate, including the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable provincial, state, and national data protection legislation.
By accessing the Doculytix Website or using the Doculytix Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use our Website or Services.
2. Data Controller Information
For the purposes of applicable data protection legislation, the data controller is:
HachiAI Inc.
Address:
207 Queens Quay W, Toronto, ON M5J 1A7, Canada
Email: hello@doculytix.ai
Website: https://doculytix.ai
When HachiAI processes personal data on behalf of our enterprise clients through the Doculytix platform, we act as a data processor (or "service provider" under CCPA). In such cases, the enterprise client remains the data controller and is responsible for ensuring it has the appropriate lawful basis and consent for sharing data with HachiAI for processing.
3. Information We Collect
We collect personal information in several ways, depending on how you interact with us. The categories of information we collect include the following.
3.1 Information You Provide Directly
| Category | Details |
|---|---|
| Contact Information | Name, email address, phone number, company name, job title, and mailing address, collected when you fill out forms, sign up for a Doculytix account, request a demo, or contact us. |
| Account Credentials | Username, email address, and password when you create an account on studio.doculytix.ai to access the Doculytix platform. |
| Communication Data | Content of emails, messages, chat transcripts, and other communications you send to us, including through our contact forms and support channels. |
| Payment Information | Billing address, payment method details, and transaction history. Credit card numbers and bank account details are processed by Stripe and other authorized payment processors on our behalf and are not stored on HachiAI's systems. |
| Professional Information | Company name, industry, role, department, and business requirements shared during sales conversations, onboarding, or support interactions. |
| API Credentials | API keys and tokens generated when you use the Doculytix REST API or SDKs (Python, Node, Go). |
3.2 Information Collected Automatically
When you visit our Website or use the Doculytix platform, we automatically collect technical, usage, and behavioural information through cookies, web beacons, pixels, and similar technologies, including third-party tracking tools.
| Category | Details |
|---|---|
| Device Information | Browser type and version, operating system, device type, screen resolution, and device identifiers. |
| Usage & Behavioural Data | Pages visited, time spent on pages, click patterns, scroll depth, referring URLs, search queries, navigation paths, content interactions, and session recordings. This data is used to analyze user behaviour and improve our Website and Services. |
| Network Information | IP address, approximate geographic location (city/country level), internet service provider, and connection type. |
| Cookie & Tracking Data | Session identifiers, preferences, and analytics data collected via first-party and third-party cookies, tracking pixels, and similar technologies. See Section 9 for details. |
| Platform Usage Data | API call volumes, document processing counts, credit usage, extraction types, error rates, and feature usage within the Doculytix platform. |
We use third-party analytics and tracking tools such as Google Analytics 4 (GA4), Cloudflare Web Analytics, Hotjar, and Microsoft Clarity. These tools collect aggregated and individual-level behavioural data, including session recordings and heatmaps.
3.3 Information from Third Parties and Lead Generation
We may receive personal information from third-party sources, including business partners and referral sources, publicly available databases and business directories, social media platforms (LinkedIn, Facebook, Instagram, X/Twitter), digital advertising platforms (Google Ads, LinkedIn Ads, Meta Ads), marketing and lead-generation partners, and our enterprise clients who share employee or end-user data for configuring and deploying Doculytix.
When you engage with our advertisements, sponsored content, webinars, downloadable resources, or social media profiles, we may collect your name, email address, company name, job title, and other professional information you provide through lead forms on these platforms.
3.4 Document Data Processed by Doculytix
When delivering our Services, the Doculytix platform processes documents uploaded by users or transmitted via API. These documents may include PDFs, scanned images, photographs of documents, and other file formats. The content of these documents ("Document Data") may contain personal information of our clients' employees, customers, vendors, or other individuals—such as names, addresses, financial details, and identification numbers found in invoices, contracts, forms, and other business documents.
HachiAI offers multiple deployment models for Doculytix:
- Cloud-Hosted (Shared Multi-Tenant): For users on the Starter and Growth plans, documents are processed on HachiAI's managed cloud infrastructure. Document Data is processed and stored in accordance with our security standards (SOC 2 Type II certified) and applicable terms of service.
- Private VPC / On-Premises / Air-Gapped: For Enterprise clients who require dedicated or on-premises deployment, Doculytix can operate within the client's own infrastructure. In this model, Document Data remains in the client's environment and HachiAI does not collect or store the underlying Document Data.
Important: Regardless of the deployment model, HachiAI processes Document Data strictly as a data processor on behalf of our clients. We do not own, sell, or use Document Data for any purpose other than delivering the contracted Services. For Enterprise clients, our processing of Document Data is governed by the terms of our Master Services Agreement and Data Processing Agreement with each client.
3.5 Platform Performance and Analytics Data
HachiAI collects operational analytics and performance metrics from the Doculytix platform, regardless of the deployment model. This includes data such as extraction accuracy rates, processing volumes, API response times, error rates, credit consumption, and system health indicators. This analytics data is used to monitor service quality, troubleshoot issues, and improve our platform.
3.6 Anonymized Case Studies and Examples
HachiAI may use anonymized and aggregated descriptions of document processing workflows, extraction results, and outcomes to demonstrate Doculytix capabilities to prospective clients and for marketing purposes. These case studies do not identify the client by name or include any information that could reasonably be used to identify the client, unless the client has provided explicit written permission.
4. How We Use Your Information
We use personal information for the following purposes:
| Category | Details |
|---|---|
| Service Delivery | To provide, operate, maintain, and improve the Doculytix platform and Services; to process documents and extract structured data as requested by users; to provide customer support, technical assistance, and onboarding; to manage your account, API access, and credit usage; and to process payments. |
| Communications | To respond to your inquiries, demo requests, and support tickets; to send you service-related notices, updates, and security alerts; and to deliver marketing communications about our products, events, and educational content (with your consent where required by law). |
| Analytics and Improvement | To analyze Website usage patterns and improve user experience; to collect and analyze operational performance metrics from the Doculytix platform (such as extraction accuracy, processing volumes, and error rates) for quality monitoring and service improvement; to conduct internal research and development; and to generate aggregated, de-identified analytics and benchmarks. |
| Case Studies and Marketing | To create anonymized, non-identifying case studies and workflow examples based on client implementations for use in marketing, sales, and educational materials. Client names are never disclosed without explicit written permission. |
| Legal and Compliance | To comply with legal obligations, regulatory requirements, and lawful requests from public authorities; to enforce our terms of service and other agreements; to protect the rights, safety, and property of HachiAI, our clients, and the public; and to detect, prevent, and respond to fraud, security incidents, and technical issues. |
| Business Operations | To manage business relationships with enterprise clients and partners; to facilitate mergers, acquisitions, or asset sales (subject to standard confidentiality obligations); and to conduct audits and maintain internal records. |
5. Legal Bases for Processing
If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction that requires a lawful basis for processing personal data, we rely on the following legal bases under the GDPR:
| Category | Details |
|---|---|
| Contractual Necessity (Art. 6(1)(b)) | Processing necessary to perform our contract with you or your organization, including delivering Doculytix Services, managing accounts, processing payments, providing API access, and providing support. |
| Legitimate Interests (Art. 6(1)(f)) | Processing necessary for our legitimate business interests, including Website analytics, service improvement, fraud prevention, direct marketing to existing business contacts, and maintaining the security of our systems. We balance these interests against your rights and freedoms. |
| Consent (Art. 6(1)(a)) | Where we rely on your consent, such as for marketing communications to new contacts and placing non-essential cookies. HachiAI does not intentionally collect sensitive or special-category personal data (such as biometric, health, racial, religious, or political data). You may withdraw consent at any time. |
| Legal Obligation (Art. 6(1)(c)) | Processing necessary to comply with legal obligations, including tax reporting, responding to lawful data subject requests, and cooperating with regulatory authorities. |
6. Data Sharing and Disclosure
We do not sell your personal information. We do not rent, trade, or otherwise make personal information available to third parties for their own marketing purposes without your explicit consent.
We may share personal information in the following limited circumstances:
Service Providers and Subprocessors
We engage trusted third-party service providers who process personal information on our behalf to support our operations. All service providers are contractually bound to process data only on our instructions, maintain appropriate security measures, and comply with applicable data protection laws. Our current subprocessors include:
| Provider | Category | Purpose |
|---|---|---|
| Stripe | Payment Processing | Processes credit card and payment transactions. PCI DSS Level 1 certified. |
| HubSpot | CRM | Customer relationship management, lead tracking, and sales pipeline management. |
| Mailchimp (Intuit) | Email Marketing | Marketing email campaigns, newsletters, and transactional email delivery. |
| Google (GA4, GTM, Ads) | Analytics & Advertising | Website analytics, tag management, and advertising via Google platforms. |
| Meta (Facebook/Instagram) | Advertising | Advertising and retargeting via Meta Pixel. |
| Advertising | Advertising and lead generation via LinkedIn Insight Tag and LinkedIn Ads. | |
| Hotjar | Behavioural Analytics | Session recordings, heatmaps, and user behaviour analysis. |
| Microsoft (Clarity) | Behavioural Analytics | Session recordings and heatmaps for Website usability analysis. |
| Cloudflare | CDN & Analytics | Content delivery, DDoS protection, DNS, and web analytics. |
| Cloud Infrastructure | Hosting & Storage | Cloud-hosted deployments use infrastructure selected per requirements (e.g., AWS, Azure, GCP). Specific provider disclosed in Enterprise DPAs. |
This list may be updated from time to time. Material changes to our subprocessor list will be communicated to affected Enterprise clients in accordance with our Data Processing Agreement obligations.
- Enterprise Clients: When processing Document Data as a data processor, we may share information with our clients as required by the terms of our Data Processing Agreement and in accordance with their instructions.
- Legal Requirements: We may disclose personal information when required by law, regulation, or legal process (such as a court order or subpoena), or when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of HachiAI, our users, or the public.
- Business Transfers: In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, personal information may be transferred as part of that transaction. We will notify affected individuals of any change in ownership or use of their personal information, and any choices they may have regarding their information.
- With Your Consent: We may share your personal information with third parties when you have given us explicit consent to do so.
7. International Data Transfers
HachiAI is headquartered at 207 Queens Quay W, Toronto, ON M5J 1A7, Canada, and operates globally with offices in Montreal (Canada), Dallas (United States), Dubai (United Arab Emirates), Lahore (Pakistan), and Hyderabad (India). Your personal information may be transferred to and processed in countries other than your country of residence.
When we transfer personal data outside the EEA, the UK, or other jurisdictions with transfer restrictions, we implement appropriate safeguards, including Standard Contractual Clauses (SCCs) as approved by the European Commission, adequacy decisions where applicable, binding corporate rules or other approved transfer mechanisms, and supplementary technical and organizational measures where necessary. For transfers from Canada, we comply with PIPEDA's accountability requirements.
You may request a copy of the safeguards we use by contacting us at hello@doculytix.ai.
8. Data Security
HachiAI takes the security of your personal information seriously. We are SOC 2 Type II certified and HIPAA compliant, and we maintain a comprehensive information security program that includes:
- Technical Safeguards: Encryption of data in transit (TLS 1.2+) and at rest (AES-256); multi-factor authentication; regular vulnerability scanning, penetration testing, and security audits; network segmentation and firewall protections; intrusion detection and prevention systems; and automated monitoring and alerting.
- Organizational Safeguards: Role-based access controls; mandatory security awareness training; background checks for personnel with access to personal data; documented incident response and breach notification procedures; and vendor security assessments.
- Platform Architecture: The Doculytix platform is designed with a security-first architecture. For cloud-hosted deployments, Document Data is processed in SOC 2 Type II certified infrastructure with encryption at rest and in transit, logical tenant isolation, and strict access controls. For Enterprise clients on private VPC or air-gapped deployments, Document Data remains entirely within the client's environment.
While we implement industry-leading security measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we continuously work to protect your personal information and promptly address any incidents.
9. Cookies and Tracking Technologies
Our Website uses cookies, pixels, web beacons, and similar tracking technologies—including those provided by third parties—to enhance your experience, analyze user behaviour, and support our marketing and lead-generation efforts.
| Category | Details |
|---|---|
| Strictly Necessary (Required) | Essential for Website functionality, security, and session management. Cannot be disabled. |
| Performance / Analytics (Optional) | Help us understand how visitors interact with our Website by collecting usage statistics and behavioural data. Tools used: Google Analytics 4, Cloudflare Web Analytics, Hotjar, and Microsoft Clarity. |
| Functional (Optional) | Remember your preferences, language, and settings to provide a personalized experience. |
| Marketing / Targeting (Optional) | Used to deliver relevant advertisements, retarget visitors across platforms, and track the effectiveness of marketing and lead-generation campaigns. Tools used: Google Ads remarketing tag, Meta Pixel, LinkedIn Insight Tag, and Google Tag Manager. |
Third-party tracking tools on our Website may collect data about your online activity across different websites over time. These include Google Analytics 4 and Google Ads, Meta Pixel, LinkedIn Insight Tag, Hotjar, and Microsoft Clarity. Each tool processes data in accordance with its respective privacy policy. We encourage you to review these policies.
You can manage your cookie preferences through your browser settings or through our cookie consent banner when available. Most browsers allow you to block or delete cookies. However, blocking strictly necessary cookies may impair Website functionality. Where required by law (such as under the ePrivacy Directive in the EU), we will obtain your consent before placing non-essential cookies.
Our Website currently does not respond to "Do Not Track" browser signals, as there is no universal standard for how websites should respond to such signals. However, you may opt out of tracking through your cookie preferences or browser settings.
10. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements.
| Category | Details |
|---|---|
| User Account Data | Duration of the account relationship plus 3 years following termination, unless a longer period is required by law. |
| Prospect / Lead Data | Up to 2 years from last meaningful interaction, unless consent is renewed. |
| Website Analytics Data | Aggregated analytics retained indefinitely. Identifiable session data retained for up to 26 months. |
| Document Data (Platform Processing) | For cloud-hosted plans, processed documents are retained as specified in the applicable terms of service. For Enterprise clients, retention is as specified in the applicable Master Services Agreement. Data is deleted or returned upon contract termination within 30 days unless legal retention obligations apply. |
| Financial / Billing Records | 7 years as required by tax and accounting regulations. |
| Platform Analytics / Metrics | Aggregated operational metrics retained indefinitely for benchmarking. Raw performance logs retained for 12 months. |
| Lead-Generation Data | Up to 2 years from collection or last meaningful interaction, unless consent is renewed or a business relationship is established. |
| Communication Records | Up to 3 years from the date of communication, or longer if related to an ongoing business relationship or legal matter. |
When personal information is no longer needed, we securely delete or anonymize it using industry-standard methods.
11. Your Privacy Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information. We respect these rights and will respond to valid requests in accordance with applicable law.
11.1 Rights Under GDPR (EEA and UK Residents)
If you are a resident of the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation:
| Category | Details |
|---|---|
| Right of Access | Request a copy of the personal data we hold about you, along with information about how it is processed. |
| Right to Rectification | Request correction of inaccurate or incomplete personal data. |
| Right to Erasure | Request deletion of your personal data where there is no compelling reason for continued processing. |
| Right to Restrict Processing | Request that we limit how we use your data in certain circumstances, such as while we verify its accuracy. |
| Right to Data Portability | Receive your personal data in a structured, commonly used, machine-readable format, and transmit it to another controller. |
| Right to Object | Object to processing based on legitimate interests or for direct marketing purposes at any time. |
| Right to Withdraw Consent | Withdraw consent at any time where processing is based on consent. Withdrawal does not affect the lawfulness of prior processing. |
| Right to Lodge a Complaint | Lodge a complaint with your local data protection authority if you believe your rights have been violated. |
We will respond to your request within 30 days of receipt. In certain complex cases, we may extend this period by an additional 60 days, and we will notify you of any extension.
11.2 Rights Under CCPA/CPRA (California Residents)
You have the right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive personal information, and the right to non-discrimination. HachiAI does not sell personal information. Contact us at hello@doculytix.ai. We will respond within 45 days (extendable by 45 days if reasonably necessary).
11.3 Rights Under PIPEDA (Canadian Residents)
You have the right to access, correct, withdraw consent (subject to legal or contractual restrictions), and to file a complaint with the Office of the Privacy Commissioner of Canada. We will respond within 30 days.
11.4 Rights Under Other Frameworks
If you are located in Brazil (LGPD), Australia (Privacy Act 1988), or another jurisdiction with applicable data protection laws, you may have similar rights. Contact us at hello@doculytix.ai to exercise any rights available to you.
12. Children's Privacy
Our Website and Services are not intended for individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal information from a child without appropriate consent, we will take steps to delete that information as promptly as possible. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at hello@doculytix.ai.
13. Third-Party Links and Services
Our Website may contain links to third-party websites, services, or platforms that are not operated or controlled by HachiAI. This Privacy Policy does not apply to such third-party sites. We encourage you to review the privacy policies of any third-party services before providing them with your personal information. HachiAI is not responsible for the privacy practices or content of third-party websites.
14. Automated Decision-Making and Profiling
The Doculytix platform uses artificial intelligence, computer vision, and semantic reasoning to process documents and extract structured data. When acting as a data processor on behalf of clients, Doculytix may engage in automated processing of personal data contained within documents as directed by the client.
HachiAI does not currently use automated decision-making that produces legal effects or similarly significant effects on individuals in relation to our Website visitors or marketing contacts. We may implement automated lead-scoring and lead-qualification tools (such as HubSpot lead scoring) to prioritize sales outreach; such scoring is used solely for internal sales prioritization and does not produce legal effects or restrict your access to our Services.
The Doculytix platform provides confidence scores on extracted data to assist users in reviewing and validating results. Low-confidence extractions trigger human review workflows. If we implement automated decision-making with legal or similarly significant effects in the future, we will update this Privacy Policy, provide appropriate notice, and where required, obtain consent or provide a mechanism to request human review.
15. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, HachiAI will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in compliance with GDPR Article 33.
Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will also notify those individuals directly without undue delay. For breaches involving Document Data processed on behalf of Enterprise clients, we will notify the affected client in accordance with the timelines specified in our Data Processing Agreement.
Under PIPEDA and Canadian breach notification regulations, HachiAI will report breaches of security safeguards involving personal information that create a real risk of significant harm to the Office of the Privacy Commissioner of Canada and to affected individuals as required.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, you may contact us using the following information:
| Category | Details |
|---|---|
| hello@doculytix.ai | |
| Mailing Address | HachiAI Inc., 207 Queens Quay W, Toronto, ON M5J 1A7, Canada |
| Website | https://doculytix.ai/contact/ |
HachiAI does not currently have a dedicated Data Protection Officer (DPO). All privacy-related inquiries, including GDPR requests, are handled by our operations team at hello@doculytix.ai. As we expand into the EU/UK market, we will appoint a DPO and/or an Article 27 representative as required, and their contact details will be published here and on our Website.
If you are not satisfied with our response to your inquiry or complaint, you have the right to lodge a complaint with the appropriate data protection authority in your jurisdiction. For Canadian residents, complaints may be filed with the Office of the Privacy Commissioner of Canada (www.priv.gc.ca). For EEA residents, contact your local supervisory authority. For California residents, you may contact the California Attorney General's office.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on our Website with a revised "Effective Date" at the top, sending an email notification to registered users and Enterprise clients for significant changes, and providing a summary of key changes. Your continued use of the Doculytix Website or Services after the posting of changes constitutes your acceptance of the updated Privacy Policy.
18. Supplementary Provisions
18.1 GDPR Representative
HachiAI does not currently have an establishment in the EEA or the UK. As we expand into the EU/UK market, we will appoint a representative under Article 27 of the GDPR as required. In the interim, all privacy-related inquiries from EEA or UK residents should be directed to hello@doculytix.ai.
18.2 CCPA Metrics
As required by the CCPA, HachiAI will publish annual metrics regarding the number of data subject requests received, complied with (in whole or in part), and denied, along with the median response time. These metrics will be made available on the Doculytix Website.
18.3 Accessibility
This Privacy Policy is available in accessible formats upon request. If you require this document in an alternative format, please contact us at hello@doculytix.ai.
18.4 Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Province of Ontario, Canada, without regard to its conflict of law provisions, except where superseded by mandatory applicable data protection legislation in your jurisdiction.

