Privacy Policy

Applies to DocAccord / LC Clear at docaccord.com, docaccord.de, lcclear.com and lcclear.de. Last updated: October 2026.

This page is also available in German (language switcher, top right). Other languages fall back to this English version. The English version is the controlling one: in case of any conflict between language versions, the English version prevails.

1. Data Controller

The data controller within the meaning of the General Data Protection Regulation (GDPR) is:
DocAccord Group Ltd, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Managing Director: Albert Rempel
Phone: +49 (2241) 3283999, Email: info@docaccord.com
Companies House Registration Number: 17451988

1a. EU Representative (Art. 27 GDPR)

DocAccord Group Ltd is based in the United Kingdom and offers services to individuals in the EU. A representative in the European Union under Art. 27 GDPR will be appointed; until then, you can reach us at privacy@docaccord.com.

2. General Information

We process personal data under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

Important note: DocAccord / LC Clear is built for business customers (B2B); we do not offer our services to consumers.

3. Data Collection When Using the Application

3.1 Server Log Files

On every visit, our hosting provider automatically collects technical data (IP address, date/time of the request, page accessed, browser type, referrer URL). Purpose: secure and stable operation, abuse and fraud prevention (including rate limiting on login attempts). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operational security).

3.2 Registration and User Account

A user account is required to use the service. We collect: email address, company name, password (stored only as a bcrypt hash), and the time you accepted our Terms of Service. When signing in via Google or Apple (OAuth), we additionally receive the email address transmitted by those services. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

3.3 Document Checking (Core Function)

The content of documents you upload or enter is transmitted to the AI service providers named in section 5.2 for automated analysis, solely for the purpose of the check you requested against UCP 600 / ISBP 821. We process your uploaded original files only transiently for the check you requested; they are not retained after processing. From the check we keep derived data: metadata about the check (timestamp, L/C reference number, overall result, number of errors and warnings); the check report, that is, our own findings including the field values they refer to, with short source excerpts of at most 80 characters from which IBAN, BIC and card numbers have been redacted; and, where the L/C has a reference number and its fields were reviewed, we may retain the confirmed L/C terms (parties, banks, goods, amounts, dates and required documents) so that they can be reused without reading the L/C again. Where the reader was unsure about any L/C field, the terms are kept for reuse only after every uncertain field was confirmed or corrected by a person. For standby letters of credit and guarantees, the confirmed terms also include the text of the undertaking as read from the document; it can contain names and account numbers and is kept under the same rules (only after uncertain fields were confirmed, two years, then deleted). The check report and any stored confirmed L/C terms remain available in your account for two years and are then deleted (stored L/C terms two years from the day they were saved). The check metadata is not deleted after two years; section 9 says how long it is kept. DocAccord does not use your documents to train AI models. Legal basis: Art. 6(1)(b) GDPR.

DocAccord provides automated decision support. The system does not itself make decisions that produce legal effects concerning an individual or similarly significantly affect them. Customers remain responsible for reviewing the results and deciding how they are used; the independent examination by the bank is not replaced.

3.3a Feedback and the Bank's Answer (voluntary)

You can say whether individual findings were correct and record how the bank responded to a presentation (accepted or refused, which findings the bank cited, how many further discrepancies it raised). This is voluntary and is not passed on to the bank or any other third party. The bank's answer contains only rule references and numbers. Feedback on a finding also stores the values the finding compared (for example the amount on the invoice and in the credit), an optional note, and who gave it; these document values are deleted after two years, like the report. We use this information solely to measure and improve how often our checks are right, and evaluate it in aggregate. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in quality assurance). You may object at any time (Art. 21 GDPR). After your account is deleted, this information is kept without any link to you.

3.4 Voluntary Contribution to Test Cases (Opt-in)

In your account settings, you can voluntarily enable checks you run to be anonymized (company names, addresses, and tax IDs replaced with placeholders; the credit's own reference number removed) and used to test and improve our rule engine. This feature is disabled by default. Once enabled, anonymized cases are first reviewed internally by our team before ever being permanently added to our test suite. Legal basis: Art. 6(1)(a) GDPR (consent). You may withdraw this consent at any time, with future effect, from your account settings; withdrawing it also deletes the contributions our team has not reviewed yet. Contributions our team rejects are deleted after 30 days.

3.5 Contact Form

When you write to us through the contact form, we store your name, email address, optionally your company, the topic you chose, your message and language, and a hash of your IP address for abuse prevention. Messages on the Security topic are also sent to privacy@docaccord.com. Purpose: answering your enquiry. Legal basis: Art. 6(1)(b) GDPR where it concerns a contract or an offer, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering enquiries). Retention: 180 days. The submission is also recorded in our security audit log (section 3.9), with a reference to your message but without your email address or IP address.

3.6 Partner Programme

When you apply as a partner, we store your company, contact person, email address, country, website, phone number and your description. To receive commission payouts you provide your bank details (IBAN and bank name); we store the IBAN encrypted. Purpose: assessing the application, running the partnership and paying commissions. Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) GDPR for accounting records. Retention: for the duration of the partnership; rejected applications, or applications not linked to an account, are deleted 12 months after their last update; accounting records are kept for the statutory periods (section 9). The application is also recorded in our security audit log (section 3.9) with your email address and IP address; both are kept there in plaintext for 12 months.

3.7 Referrals

Every account gets a personal referral link. If you register through such a link, we store who referred you and record the commission arising from your payments (amount, date, status). Whoever referred you sees you only under a customer number, not your name or email address, together with when you signed up, your last activity, the number of checks and the commission. An agency that operates DocAccord on your behalf sees your company name instead of the customer number. Purpose: settling the commission and support by the agency. Legal basis: Art. 6(1)(b) and (f) GDPR. Retention: as long as your account exists; accounting data for the statutory periods (section 9).

3.8 Use of the Partner API

For every call to our API for business customers we log the time, method, endpoint, status code, response time, the API key used, a short error message and the IP address. Purpose: security, abuse detection, the usage overview and support. Legal basis: Art. 6(1)(b) and (f) GDPR. Retention: the IP address is removed after 7 days, the entries are deleted after 12 months.

3.9 Security Audit Log

Security-relevant events (including registration, sign-in, changes to passwords and API keys, administrative actions on an account, and contact form submissions and partner applications, also from people without an account) are recorded in a tamper-evident, hash-chained log with the time, type of event, account ID (where there is one), email address and IP address. Purpose: evidence and investigation of security incidents and abuse. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of the service). Retention: the plaintext email address and IP address for 12 months; after that the entries remain in pseudonymous form (with the account ID) so the audit trail stays complete. If your account is deleted, the plaintext email address and IP address are deleted at once. Entries written before we introduced this separation (autumn 2026) still contain the email address and IP address in plaintext, because any change would break the tamper protection. If you ask us to erase them, we restrict their processing instead (Art. 18 GDPR) and use them only to investigate security incidents.

3.10 Doc Intelligence Assistant

When you ask the assistant a question, we send your question together with the check results stored in your account (findings, metadata and deadlines of your checks) to one of the AI service providers named in section 5.2 to generate the answer. Your uploaded original files are not sent, because we do not keep them after the check. We do not store questions or answers. Purpose: answering your question. Legal basis: Art. 6(1)(b) GDPR.

3.11 Tariff Lookups (Customs Clear)

When you request a tariff lookup for a line item, we send the goods description, the HS code and the countries of origin and destination to one of the AI service providers named in section 5.2, which uses a web search for it. The HS code and the country of origin are also looked up in the authorities' public tariff databases. No personal data is intended for this; please do not enter any in the goods description. Purpose: researching the applicable duty rate. Legal basis: Art. 6(1)(b) GDPR. The result is part of the check report.

3.12 Sanctions Screening

With every check we compare the parties, vessels and countries named in your documents against public sanctions and embargo lists, such as the consolidated lists of the EU, the USA and the United Kingdom. The comparison runs on our own servers against a copy of these lists stored there; no data is sent to third parties for it. Purpose: flagging possible sanctions hits before presentation. Legal basis: Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR (legitimate interest in complying with sanctions law). Hits appear as findings in the check report and are deleted with it after two years.

3.13 Emails About Your Account

Besides emails about registration, sign-in and your password, we send through our email service provider (section 5.2): up to three onboarding emails in the first days after a free account is registered, as long as no check has been run; deadline notices about your letters of credit (at most one digest email per day); and notices before an inactive account is deleted automatically (section 3.14). You can switch off onboarding emails and deadline notices in your profile. Purpose: introducing the service, reminding you of deadlines, warning you before deletion. Legal basis: Art. 6(1)(b) GDPR for deadline and deletion notices, Art. 6(1)(f) GDPR (legitimate interest in onboarding new customers) for onboarding emails. Retention: we only store when which email was sent, as long as your account exists.

3.14 Automatic Deletion of Inactive Free Accounts

Free accounts that go unused for a long time are deleted automatically. After 90 days without activity you receive a first reminder, and another after 104 and after 111 days; after 121 days without activity the account is deleted or, where statutory retention obligations apply, anonymised. Accounts on a paid plan or with an active subscription are excluded, as are team member accounts while the team owner has a subscription and accounts that still have team members. An account is never deleted sooner than 10 days after the last reminder. Purpose: not keeping data longer than necessary. Legal basis: Art. 6(1)(f) GDPR in conjunction with Art. 5(1)(e) GDPR (storage limitation).

4. Cookies and Tracking

For sign-in, we store a session token and your language preference in your browser's local storage; this data is sent by your browser with every request to our servers to keep you signed in and remember your language choice. This is not a cookie, and this processing is necessary to provide the service (Art. 6(1)(b) GDPR).

If you choose between the light and the dark appearance on the website or in the app, we store that choice in a cookie named docaccord_theme (value “light” or “dark”, kept for one year). Your browser sends it to our servers so that the page is delivered in the chosen appearance from the first paint. It contains no personal data and is set only when you choose an appearance explicitly; choosing “System” removes it. It serves only this function that you selected; storing the cookie is strictly necessary for it (section 25(2) no. 2 TDDDG).

With your consent, we additionally use Google Ads (Google Ireland Limited) to measure which advertising led visitors to our website and whether that resulted in a registration or purchase (conversion measurement). The Google Ads script is loaded only after you consent; before that, no connection to Google is made. This may set cookies on your device. We pass on the page visited only without its parameters and fragment. This processing takes place exclusively on the basis of your consent (Art. 6(1)(a) GDPR), which you can grant or decline via the cookie notice on our website. Your choice is stored in your browser's local storage (entry docaccord_ads_consent). You can withdraw your consent at any time with effect for the future through the “Cookie settings” link at the bottom of every page, or right here: . This also removes the Google Ads cookies stored under docaccord.com (_gcl_*); cookies Google sets on its own domains can be deleted in your browser settings. No conversion measurement takes place without your consent. Further information: Google's privacy policy at policies.google.com/privacy.

5. Disclosure of Data to Third Parties

Personal data is disclosed to third parties only where necessary for the performance of a contract (Art. 6(1)(b) GDPR), where there is a legal obligation (Art. 6(1)(c) GDPR), or where you have given your consent (Art. 6(1)(a) GDPR).

5.1 Hosting

This application is operated on servers of Hetzner Online GmbH (Germany). A data processing agreement (DPA) is in place with our hosting provider. Data transmission between your browser and our servers is encrypted (TLS/SSL).

5.2 Service Providers

  • Anthropic PBC (USA), Mistral AI SAS (France), Google LLC (USA) - AI-powered processing of document content and requests
  • Paddle - Merchant of Record for purchases of subscriptions, check credits and single checks (payment, invoicing, VAT, refunds), acting as its own controller
  • Resend - sending emails (registration, sign-in, password reset, onboarding emails, deadline notices, deletion notices)
  • Google LLC / Apple Inc. - only when you use the respective sign-in option (OAuth); their sign-in scripts are loaded only when you click the respective button
  • Google Ireland Limited (Google Ads) - only with your consent, see section 4

Data processing agreements or appropriate safeguards are in place with all processors. The safeguards for transfers to countries outside the EU are described in section 6.

5.3 Changes to Service Providers

Changes to the list of service providers are recorded here with their date. Customers with a data processing agreement are also told in advance by email to the account owner.

  • September 2026: start of this changelog; the list in section 5.2 is the state at that date.

6. International Data Transfers

Anthropic, Resend, Google, and Apple (also) process data in the USA. We ensure an adequate level of data protection through EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and, where applicable, the respective provider's participation in the EU-US Data Privacy Framework (adequacy decision pursuant to Art. 45 GDPR).

DocAccord Group Ltd is based in the United Kingdom. For transfers of personal data from the EU to us, the European Commission's adequacy decision for the United Kingdom applies (Implementing Decision (EU) 2021/1772 of 28 June 2021 under Art. 45 GDPR, as amended and extended by Commission Implementing Decision (EU) 2025/2574 (C(2025) 8771) of 19 December 2025, which applies until 27 December 2031 unless it is extended).

7. Your Rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction of processing (Art. 18 GDPR), data portability (Art. 20 GDPR), objection to processing (Art. 21 GDPR), and the right to withdraw any consent given at any time (Art. 7(3) GDPR). The right to erasure does not apply where statutory retention obligations (e.g. HGB, AO) apply.

To exercise these rights, an informal message to privacy@docaccord.com is sufficient. You can also download a copy of your data (Art. 15 and 20 GDPR) as a file yourself in Settings. The account owner can also request deletion of the account in Settings; we carry it out within 30 days, provided a renewing subscription has been cancelled and team members removed first. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR):

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2-4, 40213 Düsseldorf, Germany
Phone: +49 211 38424-0, Email: poststelle@ldi.nrw.de, Website: www.ldi.nrw.de

8. Data Security

We store passwords exclusively as bcrypt hashes. Sessions are secured via time-limited JWT tokens, which are immediately invalidated on a password change. Login and registration attempts are protected against automated attacks by rate limiting. Two-step sign-in with a code sent by email or with an authenticator app is available to every account that signs in with a password; we store the app's key encrypted and the recovery codes only as hashes. Database backups are encrypted, and partners' bank details are stored encrypted. Data transmission is encrypted (TLS/SSL).

9. Retention Period

Product data: we store account and usage data for as long as your account exists. After your account is deleted, data that is no longer required is deleted or anonymized, unless a statutory retention obligation applies. For the results of your checks and the other data of the service, these periods apply:

  • Check reports, stored confirmed L/C terms and the document values quoted in feedback on findings: two years (stored L/C terms from the day they were saved; for standby letters of credit and guarantees this includes the text of the undertaking)
  • Check metadata (timestamp, L/C reference number, overall result, number of errors and warnings): kept while the account exists, with no deletion date; after the account is erased it stays without a link to you
  • Contact messages: 180 days
  • API call log: IP address 7 days, entries 12 months
  • Security audit log: plaintext email and IP address 12 months, pseudonymous after that
  • Verification and password links and sign-in codes: 30 days after expiry or use
  • Webhook delivery logs: 90 days
  • Technical records of AI calls (cost and processing statistics, no document content): 24 months
  • Rejected test case contributions (section 3.4): 30 days
  • Rejected or unlinked partner applications: 12 months after their last update
  • Inactive free accounts: deleted after 121 days without activity (section 3.14)
  • Deletion requests by the account owner: carried out within 30 days (a renewing subscription must be cancelled and team members removed first)
  • Server logs: rotated automatically and kept only for a short period

Accounting and billing records: independently of these periods for product data, we keep records that are subject to statutory retention periods (in particular § 257 HGB, § 147 AO: generally 6 or 10 years) for as long as the law requires. This covers invoice, payment and commission data. The periods for product data and the statutory retention periods are independent of each other.

10. Minors

Our services are directed exclusively at business customers and not at persons under 18 years of age. We are not aware that we process personal data of minors; should we become aware of this, we will delete the relevant data immediately.

11. Changes to This Policy

We will update this Privacy Policy whenever changes to our data processing make this necessary (e.g. new service providers or features). The version published on this page at the time of your visit applies.

12. Privacy Contact

DocAccord Group Ltd, Attn: Management / Data Protection
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: privacy@docaccord.com, Phone: +49 (2241) 3283999

No internal Data Protection Officer has been appointed, as the statutory requirements for doing so (Art. 37 GDPR, § 38 BDSG) are not met. We will respond to your request as quickly as possible, and no later than within one month.