Privacy Terms and Notice

Privacy Terms and Notice

Privacy Terms and Notice

1. Purpose

This policy defines Karbon Digital Ltd.'s privacy notice and privacy terms requirements for Docufy.ai and related Karbon Digital products and services. Its purpose is to establish a transparent, lawful, and secure framework for collecting, using, storing, transferring, and otherwise processing personal information and sensitive business information across international jurisdictions, including when customer source documents contain personally identifiable information (PII) in encrypted or unencrypted form before upload. The policy also sets governance expectations for intelligent data processing, including multi-modal processing, automated classification, and AI-assisted outputs, so the service can be published and operated responsibly for enterprise and public-facing use.

  1. Scope

This policy applies to Karbon Digital Ltd.'s websites, applications, APIs, platforms, support channels, and related products and services, including Docufy.ai deployments and integrations, across all regions where Karbon Digital operates or provides services. It applies to employees, contractors, affiliates, subprocessors, and approved third parties that design, build, host, support, sell, administer, or secure these services, and to the processing of customer content, personal information, metadata, telemetry, and support information. Where customer contracts, sector-specific requirements, or applicable law impose stricter controls, the stricter requirement prevails.

3.  Privacy Terms

A1. Scope

This Privacy Notice applies to Karbon Digital Ltd. websites, applications, Application Programming Interfaces (APIs), Multi-context Protocol (MCP) interfaces, connectors, adaptors, hosted services, and related support and customer success interactions for Docufy.ai and other Karbon Digital products and services. This notice does not govern third-party services, websites, or platforms that are not operated by Karbon Digital, even if linked from our services; those providers' privacy notices apply.

A2. Information We Process

Depending on the product, configuration, and how you use our services, we may process: (a) account and identity data (name, business contact details, account credentials, authentication identifiers); (b) customer content and document metadata, including information contained in uploaded documents, images, attachments, extracted fields, and workflow records, which may include personal information or sensitive personal information; (c) usage, device, and network data (log data, IP address, browser and device attributes, timestamps, performance telemetry); (d) support, sales, and communications data; and (e) security and audit data generated to protect the services and investigate incidents.

A3. How We Use Information

We use information to provide, operate, secure, and improve Karbon Digital products and services; perform document ingestion, extraction, classification, validation, risk flagging, summarization, and workflow automation; authenticate users and administer accounts; provide support and implementation services; maintain audit trails, detect abuse, prevent fraud, and investigate security events; meet legal, regulatory, and contractual obligations; and communicate service updates. We do not use Customer Content to train general-purpose models unless explicitly permitted by contract and enabled by customer configuration.

A4. Legal Bases (Where Applicable)

Where required by applicable law, Karbon Digital relies on one or more lawful bases for processing, including performance of a contract, legitimate interests (such as security, service reliability, and product administration), compliance with legal obligations, consent where required, and other lawful bases recognized by applicable privacy laws. Customers using our enterprise services typically determine the lawful basis for their own end-user or employee data and may act as controllers/businesses, while Karbon Digital may act as processor/service provider/operator depending on the context.

A5. Sharing and Disclosure

We may disclose information to authorized affiliates, subprocessors, cloud and infrastructure providers, support providers, and other service providers that assist us in operating the services, subject to contractual confidentiality, privacy, and security obligations. We may also disclose information to professional advisors, in connection with a merger, financing, or asset transaction, or when required by law, court order, or valid governmental request. We do not sell personal information and we do not share personal information for cross-context behavioral advertising unless expressly stated in a product-specific notice.

A6. International Transfers

Karbon Digital may process and access information in multiple countries to provide global services, support, security operations, and resilience. Where personal information is transferred across borders, we implement appropriate safeguards as required by applicable law, which may include contractual transfer mechanisms, transfer impact assessments where applicable, organizational controls, and vendor due diligence. Data residency or regional processing options may be available depending on the product, deployment model, and customer contract.

A7. Security

Karbon Digital maintains administrative, technical, and physical safeguards designed to protect personal information and customer content, including role-based access controls, least-privilege practices, encryption in transit (for example, TLS) and encryption at rest, logging and monitoring, vulnerability management, secure development practices, and incident response procedures. Some products may support customer-managed keys, private networking, or dedicated deployment options by plan or contract. No method of transmission, processing, or storage is completely secure, and customers remain responsible for their own endpoint, identity, and pre-upload handling controls.

A8. Retention

We retain personal information and customer data only for as long as necessary to fulfill the purposes described in this notice and applicable contracts, including service delivery, security logging, auditability, dispute resolution, and legal compliance. Retention periods may vary by product configuration, deployment model, and customer instructions. We may delete, de-identify, or aggregate information when no longer needed, subject to legal holds, backup cycles, and mandatory retention requirements.

A9. Your Rights

Depending on your jurisdiction and our role in the processing, you may have rights to request access, correction, deletion, portability, restriction, or objection, and to withdraw consent where processing is based on consent. You may also have rights relating to automated decision-making, appeal, or complaint to a supervisory authority, where applicable. If Karbon Digital processes information on behalf of an enterprise customer, we will generally direct your request to that customer or act in accordance with its documented instructions and applicable law.

A10. Contact

Privacy inquiries, data rights requests, and privacy complaints may be submitted to Karbon Digital Ltd. using the contact details published on the applicable Karbon Digital product website or in your contract/order documentation. To protect privacy and security, we may request verification of identity and authority before processing a request.

A11. Cookies, Analytics, and Similar Technologies

Karbon Digital websites and some product interfaces may use cookies, local storage, pixels, and similar technologies for authentication, session management, preferences, security, usage analytics, and service performance. Where required by law, we will provide notice and obtain consent for non-essential cookies or similar technologies. You can manage browser controls and, where available, in-product cookie preferences, but disabling certain technologies may affect functionality.

A12. Changes to this Privacy Notice

Karbon Digital may update this Privacy Notice from time to time to reflect product changes, legal requirements, or operational practices. We will post the updated version on the applicable website and update the effective date. Where required by law or contract, we will provide additional notice before material changes take effect.

4. Docufy.ai Privacy Terms

B1. Definitions

"Docufy.ai" means the Docufy.ai platform and related services, including web interfaces, APIs, connectors, adaptors, and support components. "Customer Content" means documents, images, text, data, metadata, prompts, attachments, and other materials submitted to or processed by Docufy.ai on behalf of a customer or authorized user. "Outputs" means results generated or returned by Docufy.ai, including extracted fields, classifications, summaries, validations, alerts, recommendations, and workflow actions. "Personal Information" or "PII" means information that identifies, relates to, describes, or can reasonably be linked to an individual under applicable law.

B2. Account Registration and Security

You must provide accurate registration information and keep it current. You are responsible for safeguarding credentials, API tokens, and access keys, for activity occurring under your accounts, and for assigning access only to authorized users. You must implement reasonable account security controls, including strong passwords and available multi-factor authentication (MFA), and promptly notify Karbon Digital of any suspected unauthorized access, credential compromise, or security incident affecting your use of Docufy.ai.

B3. Permitted Use and Acceptable Use

You may use Docufy.ai only for lawful business purposes and in accordance with these terms, your order form, and applicable law. You will not: (a) upload or process content without a lawful basis, authorization, or required notices/consents; (b) use the services to violate privacy, intellectual property, confidentiality, employment, export control, sanctions, anti-corruption, or other applicable laws; (c) interfere with or circumvent security, rate limits, or access controls; (d) introduce malware or malicious code; (e) probe, scan, or test systems without authorization; (f) reverse engineer the services except to the extent such restriction is prohibited by law; (g) use the services to build or benchmark a competing product in violation of contract; or (h) rely solely on Outputs for legal, medical, employment, credit, safety, or other high-impact decisions without appropriate human review and validation

B4. Intelligent Processing and PII in Source Documents

Docufy.ai is designed for intelligent processing of complex documentation and may process source documents that contain personal information, sensitive personal information, confidential business information, or regulated data, whether encrypted before upload or uploaded in unencrypted form. You are responsible for determining whether you have lawful authority and an appropriate legal basis to upload and process such documents, and for applying any required notices, consents, minimization, redaction, pseudonymization, or pre-upload encryption under your legal, contractual, or sector-specific obligations. Karbon Digital applies service-side security controls after receipt, including encryption in transit and at rest, but does not assume responsibility for your pre-upload collection, classification, or transmission practices outside the service.

B5. Data Rights and Licenses

As between the parties, you retain all right, title, and interest in and to Customer Content, subject to the rights granted in these terms. You grant Karbon Digital a limited, non-exclusive license to host, copy, transmit, process, display, and use Customer Content and related metadata solely as necessary to provide, secure, support, and improve the contracted services, enforce these terms, and comply with law. Karbon Digital retains all rights, title, and interest in the services, software, models, documentation, and aggregated or de-identified analytics that do not identify you or any individual, subject to applicable law and contract.

B6. Confidentiality

Each party may receive confidential information from the other in connection with the services. The receiving party will use at least reasonable care to protect confidential information, use it only for the purpose of performing under the applicable agreement, and restrict access to personnel and subprocessors with a need to know who are bound by confidentiality obligations. Confidential information does not include information that becomes public through no breach, was already lawfully known, is independently developed without use of the disclosing party's confidential information, or is lawfully received from a third party without restriction.

B7. Privacy and Data Processing

Karbon Digital will process personal information in accordance with this Privacy Notice, applicable product terms, and any applicable Data Processing Addendum (DPA) or equivalent data processing terms. Where Karbon Digital acts as a processor, service provider, or similar role, it will process Customer Content and personal information only on documented instructions (except as required by law), implement appropriate technical and organizational measures, support reasonable audit and assistance obligations as contracted, and flow down appropriate privacy and security obligations to authorized subprocessors.

B8. Service Levels, Support, and Changes

Service levels, support commitments, maintenance windows, and feature availability are defined by the applicable plan, statement of work, service level agreement, or order form. Karbon Digital may modify, enhance, or discontinue features to improve security, reliability, compliance, or functionality, provided it will not materially reduce contracted core functionality during a paid term except as permitted by contract, legal requirement, or security necessity. Karbon Digital may update these terms and the privacy notice with notice as required by law or contract.

B9. Disclaimers

Docufy.ai uses intelligent processing and automated extraction, and Outputs may be incomplete, inaccurate, or not fit for your specific use case without review. Except as expressly stated in a signed agreement, the services are provided on an "as is" and "as available" basis, and Karbon Digital disclaims all implied warranties, including merchantability, fitness for a particular purpose, and non-infringement, to the maximum extent permitted by law. Nothing in these terms limits rights that cannot be waived under applicable consumer protection law.

B10. Limitation of Liability

To the maximum extent permitted by law and except as otherwise expressly provided in a signed agreement, Karbon Digital will not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, loss of goodwill, business interruption, or loss/corruption of data, even if advised of the possibility of such damages. Any liability cap, exclusions, or super-caps for specific claims (such as confidentiality, privacy, or indemnity claims) will be governed by the applicable contract, order form, or negotiated enterprise terms.

B11. Indemnification

You will defend, indemnify, and hold harmless Karbon Digital and its affiliates, officers, directors, employees, and agents from third-party claims, damages, liabilities, and costs (including reasonable legal fees) arising from or related to your Customer Content, your violation of these terms or applicable law, or your misuse of the services. If an enterprise agreement applies, indemnification obligations, procedures, exclusions, and liability caps in that agreement will control to the extent of any conflict.

B12. Termination

You may stop using the services at any time, subject to any committed subscription term. Karbon Digital may suspend or terminate access, in whole or in part, for material breach, non-payment, security risk, legal or regulatory requirement, suspected fraud or abuse, or actions that threaten service integrity or other users. Upon termination or expiration, access to the services and Customer Content will be handled in accordance with the applicable contract, retention settings, and documented deletion/export procedures, subject to legal holds, backup retention cycles, and security logging requirements.

B13. Governing Law

Governing law, jurisdiction, and venue are determined by the applicable customer agreement, order form, or click-through terms accepted for the relevant product or service. If no separate enterprise agreement applies, the governing law and dispute resolution forum stated in the applicable online terms or ordering terms will apply, subject to mandatory rights and venue protections that cannot be waived under applicable law.

B14. Contact

Questions regarding these privacy terms, the Privacy Notice, data processing, or security may be directed to Karbon Digital Ltd. using the contact information provided in your order form, enterprise agreement, or the relevant Karbon Digital product website.

B15. Export Controls and Sanctions Compliance

You may not use, access, export, re-export, or transfer the services or related technical information in violation of applicable export control or sanctions laws. You represent that you are not prohibited from receiving the services under applicable trade restrictions and that you will not permit access by prohibited persons or in prohibited jurisdictions except as authorized by law.

B16. Order of Precedence

If there is a conflict among these online terms, a product-specific addendum, a Data Processing Addendum, an order form, or a signed enterprise agreement, the documents will govern in the following order unless expressly stated otherwise: signed enterprise agreement and order form, product-specific addendum or DPA, then these online terms and notices.

For questions or feedback about this policy, contact the Compliance Team at legal@karbondigital.com

Ready to transform your workflows?

Try Docufy now

Ready to transform your workflows?

Try Docufy now

Ready to transform your workflows?

Try Docufy now

Ready to transform your workflows?

Try Docufy now

© 2026. All Rights Reserved.

Powered by Karbon Digital Ltd

Innovated in Canada Engineered for the World

© 2026. All Rights Reserved.

Powered by Karbon Digital Ltd

Innovated in Canada Engineered for the World

© 2026. All Rights Reserved.

Powered by Karbon Digital Ltd

Innovated in Canada Engineered for the World

© 2026. All Rights Reserved.

Powered by Karbon Digital Ltd

Innovated in Canada Engineered for the World