Privacy Notice

Last updated: 15 September 2026

This notice covers docfolk.com, the application at app.docfolk.com, and the pages a workspace publishes through it. It is written for three different readers, and says at each point which one it means: someone with an account, someone whose details are inside a workspace, and someone who visits a page.

1. Who is responsible

The controller for what this notice describes as ours is:

Trader
Shift Videoproductions, sole proprietorship of Lars Grote
Address
Hoogweg 127, 9690 Kluisbergen, Belgium
Email
lars@shiftvideoproductions.com
Enterprise no.
0727.457.933
VAT
BE 0727.457.933

We are not required to appoint a data protection officer and have not. Write to lars@shiftvideoproductions.com for anything here.

2. Cookies and browser storage

In the app

The application sets only what a login needs. None of it tracks you, none of it is shared, and none of it asks for consent because there is nothing to consent to: remove it and you are signed out.

Strictly necessary storage in the app
NameSet byWhat it doesExpires
filmcrm-ownerDocfolkKeeps you signed in to your workspace. Signed; holds no personal data itself.30 days
filmcrm-guestDocfolkThe same, for a project guest login.30 days
portal_sessionDocfolkKeeps a client signed in to a client portal a workspace shared with them.30 days

On docfolk.com

The marketing site uses Google Consent Mode v2. Every consent signal starts at denied. Nothing in the first table is written unless you press Accept, and declining is one click on the same banner.

Set on docfolk.com only after you accept
NameSet byWhat it doesExpires
_ga, _ga_<property id>Google AnalyticsTells one returning browser from another and holds the state of the visit.2 years
_fbpMetaLets Meta report whether one of our ads led to a visit or a sign-up click.3 months
Always present on docfolk.com
NameSet byWhat it doesExpires
filmcrm-cookie-consentDocfolk (browser storage)Remembers whether you accepted or declined, so you are not asked on every page.Until you clear this site's data

On pages a workspace publishes

A Docfolk workspace can publish pages of its own: a client portal, a booking page, a form, a Story Audit, a whole website. Those pages belong to the workspace that published them, and that workspace is the controller for whatever you do there. The software gives them these, and only these:

Storage on pages published by a workspace
NameSet byWhat it doesExpires
site-consentDocfolk (browser storage)Your answer to that page's cookie question.Until you clear the site's data
site-langDocfolkThe language you chose on a multilingual site.1 year
fc_pDocfolkOnly after you accept on that page: lets the workspace that published it see that the person they sent the link to opened it and what they read. Never set before you accept.90 days

Change your mind at any time with the Manage cookies link in the footer of the page concerned, or by clearing the site's data in your browser.

3. If you have an account

For your account we are the controller. We hold:

  • Who you are: name, email address, a hash of your password (never the password), the time you confirmed your address, and the date and version of the terms you accepted. Basis: the contract (art. 6(1)(b) GDPR).
  • Billing: which plan, how many seats, how much AI you used on our key, invoices, and the reason you gave if you cancelled. Your card is held by Stripe and we never see it; Stripe sees your name, email, billing address and VAT number. Basis: the contract, and the legal duty to keep accounting records (art. 6(1)(c)).
  • Keeping the service safe: the IP address of sign-in attempts for a short window, to lock an account after repeated failure, and error logs that may carry a request path and a user id. Basis: legitimate interest in not being broken into (art. 6(1)(f)).
  • What you tell us: feedback sent from the app, and mail you send us. Basis: legitimate interest in answering you and improving the product.
  • Storage used: how many megabytes your workspace holds, summed daily, so a ceiling can be applied. A number, not a look inside.

Mail from us is about the account: confirming the address, resetting a password, a trial ending, a payment failing, a workspace about to be deleted. We do not send marketing mail to account holders unless you separately ask for it, and every mail that is not strictly about the account carries an unsubscribe link.

4. Where it goes

The application runs on Vercel and stores its database with Neon in Frankfurt. Files you upload are stored with Vercel. Payments go through Stripe. Account mail goes out through Resend. On the plan that includes AI, the text you submit to an AI feature goes to Anthropic to produce the answer, and Anthropic neither trains on it nor keeps it beyond a short abuse-monitoring window. That is the whole list of companies that touch your data on our account. Each one, where it is, and the legal basis for any transfer outside the EU is set out in the data processing agreement.

Services you connect yourself from Settings, with your own account or key (Google, Meta, LinkedIn, a transcription or enrichment provider, a CMS, your own AI key), are your relationship with that company. The tokens they give us are stored encrypted and used only to do what you asked; disconnect any of them at any time.

5. How long we keep it

  • Your workspace: until you delete it, which removes every record and every file at once, or until 30 days after a subscription or trial ends without renewal, with a warning a week before. Database backups roll off within seven days after that.
  • Invoices and billing identity: seven years, as Belgian accounting law requires.
  • Sign-in attempt records: minutes, not days.
  • Feedback and mail: as long as it is useful for the product, and deleted on request.
  • Analytics on docfolk.com: Google Analytics expires event data after 14 months.

6. If your details are inside someone's workspace

A Docfolk workspace belongs to a filmmaker or a video business, and what they keep in it (their clients, contacts, interviewees, crew) is theirs. If you are one of those people, the business that put you there is the controller of that data. We are their processor: we store it so the software works, we do not read it, and we act on it only as they instruct. The data processing agreement is the contract that binds us to that.

To exercise a right over that data, ask the business that holds it; the software gives them the tools to answer you. If you write to us instead, we tell you who to ask and pass your message on. We do not answer on their behalf.

Two things are worth knowing about what the software can do with such data. On the plan that includes AI, the workspace may send text about you to an AI model to draft something or to score how well a prospect fits, and those scores carry no legal or similar effect: a person decides, and the software says so where it shows them. And a workspace may publish a page to you and, only if you accept on that page, learn that you opened it.

7. If you visit docfolk.com

Google Analytics 4 tells us which pages get read and where visitors arrive from. Before you consent it runs without cookies and models aggregate traffic from a ping that carries no identifier; after you accept, it uses the cookies in section 2. The Meta Pixel measures whether our ads reach anyone and loads only after you accept; decline and it is never fetched. Neither is given your name or address. Bases: legitimate interest in knowing the site works (art. 6(1)(f)) before consent, your consent (art. 6(1)(a)) after it. See Google's notice and Meta's notice.

The live demo, where it is offered, opens a private throwaway workspace against an email address. The workspace is deleted when you sign out and in any case within about 12 hours; the address and the time of the visit are kept so a returning visitor is recognised rather than counted twice, and deleted on request. A marketing tick-box there is unticked by default, and ticking it sends your address to Kit, our mailing-list provider, with the wording you agreed to and the time. Every such mail has a one-click unsubscribe.

8. Your rights

For anything we hold as controller (sections 3, 4, 5 and 7) you can ask us, free of charge, and we answer within 30 days, to:

  • Access what we hold. For an account, Settings exports it as a file without asking us.
  • Correct what is wrong. Name and email you change yourself in Settings.
  • Erase it. Delete the workspace yourself in Settings; invoices stay for the seven years the law requires, nothing else does.
  • Restrict or object to anything we do on the basis of legitimate interest.
  • Take it with you in a machine-readable file, which is what the export is.
  • Withdraw consent at any time without affecting what was done before: Manage cookies in the footer, and the unsubscribe link in mail.

You can also complain to the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be. If your details are inside a workspace (section 6), your rights run against the business that holds them, and their supervisory authority is the one for where they are.

The retention of visit records on pages a workspace publishes is set by the software at 13 months, after which they are deleted; that figure is in the code, not in a promise.

9. Changes

When this notice changes, the new version appears here with a new last-updated date. A change that affects something you consented to asks you again rather than telling you afterwards. A change that reduces the protection of an account holder is announced by email fourteen days ahead.