Privacy Policy
Last updated: August 25, 2026
YOUR PRIVACY IS IMPORTANT TO US. This Privacy Policy describes how Shirah Technologies ("we," "us," or "our") collects, uses, and protects information when you use our Documents Service microservice (the "Service").
1. Information We Collect
We collect information necessary to provide our document management services. The types of information we collect include:
1.1 Document Data
- Uploaded documents and their contents
- Document metadata (filename, size, type, creation date)
- Document status and approval information
- File hash values for integrity verification
1.2 Service Usage Information
- API access logs and usage patterns
- Authentication and authorization records
- System performance and error logs
- Notification delivery status
1.3 Technical Information
- IP addresses and request headers
- Browser type and version (for web interface access)
- Operating system information
- Session identifiers and tokens
2. How We Use Information
We use the collected information solely for providing and improving our document management services:
- Processing and storing uploaded documents securely
- Managing document workflows and approval processes
- Sending notifications and webhook callbacks as configured
- Providing administrative interfaces and reporting
- Maintaining system security and preventing unauthorized access
- Troubleshooting technical issues and improving service performance
- Ensuring compliance with service terms and policies
3. Data Security and Protection
We implement comprehensive security measures to protect your data:
3.1 Encryption
- All data transmission is encrypted using TLS 1.3
- Data at rest is encrypted using AES-256 encryption
- Database connections use encrypted channels
3.2 Access Controls
- Role-based access control with principle of least privilege
- Multi-factor authentication for administrative access
- Regular access reviews and permission audits
3.3 Monitoring and Auditing
- Comprehensive audit logging of all system activities
- Real-time security monitoring and threat detection
- Regular security assessments and penetration testing
4. Data Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal information to third parties except in the following circumstances:
- Service Integration: With your configured external systems via webhooks and API callbacks
- Legal Requirements: When required by law, court order, or government request
- Security Purposes: To protect our rights, property, or safety, or that of our users
- Service Providers: With trusted third-party service providers under strict confidentiality agreements
5. Data Retention
We retain your data only as long as necessary to provide our services and fulfill legal obligations:
- Active Documents: Retained according to your service configuration
- Audit Logs: Retained for 7 years for security and compliance purposes
- System Logs: Retained for 90 days for troubleshooting and performance monitoring
- Deleted Data: Securely purged within 30 days of deletion request
6. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request access to your personal information we hold
- Correction: Request correction of inaccurate personal information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data in a machine-readable format
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
To exercise these rights, please contact us using the information provided in Section 9.
7. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure that such transfers comply with applicable data protection laws through:
- Standard Contractual Clauses approved by relevant authorities
- Adequacy decisions by competent data protection authorities
- Other appropriate safeguards as required by law
8. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Providing in-service notifications for significant changes
Your continued use of the Service after any changes constitutes acceptance of the updated Privacy Policy.
9. Contact Information
If you have questions about this Privacy Policy or our data practices, please contact us at:
Email: [email protected]
Subject Line: Privacy Policy Inquiry
Response Time: 5-7 business days
Data Protection Officer: [email protected]
This Privacy Policy was last modified on August 25, 2026 and is effective immediately.
© 2026 Shirah Technologies. All rights reserved.