Privacy Policy
Effective Date: June 30, 2026 | Last Updated: July 4, 2026
Skillhanger Limited (RC 1711272), trading as Middledoc (“Middledoc,” “we,” “us,” or “our”) is a trading name of Skillhanger Limited, a company registered in the Federal Republic of Nigeria (RC 1711272). We operate the document collection and e-signature platform available at middledoc.com(the “Service”). This Privacy Policy explains what personal data we collect, how we use and share it, and what rights you have over your data. By using the Service you agree to the practices described here.
If you are a business customer using Middledoc to collect documents from your own clients, you are a “data controller” and Middledoc acts as your “data processor.” Our Data Processing Agreement (DPA), available at middledoc.com/legal/dpa, governs that relationship and supplements this Policy.
1. Who We Are
Middledoc is a software-as-a-service platform operated by Skillhanger Limited, a company founded in 2026 and registered in the Federal Republic of Nigeria. Our registered contact address for privacy matters is:
Skillhanger Limited (trading as Middledoc)48a Ogudu, Lagos, Nigeria
RC 1711272
Email: [email protected]
2. Data We Collect
2.1 Account Information
When you create a Middledoc account we collect:
- Full name and email address
- Password (stored as a bcrypt hash — we never store plaintext passwords)
- Company or firm name (optional)
- Subscription plan and billing tier
- Account creation date and last login timestamp
2.2 Documents and Files You Upload
Middledoc is a document collection platform. When you or your clients upload files through the Service we receive and store:
- The document files themselves (PDFs, images, spreadsheets, and other formats you submit)
- File metadata: filename, size, MIME type, upload timestamp, uploader IP address
- AI classification results generated by our document recognition feature (document type labels such as “W-2,” “Invoice,” “Bank Statement,” etc.)
- E-signature audit trail data: signer name, email, IP address, timestamp, and signature image
- Document request status and checklist completion data
Important: Middledoc does not control what documents you or your clients upload. If you upload documents containing special-category personal data (health records, financial data, identity documents), you are responsible for ensuring you have the right to process and share that data with us.
2.3 Usage Data
We automatically collect technical information when you use the Service:
- IP address and approximate geographic location (country/region)
- Browser type, operating system, and device type
- Pages visited within the Service, feature interactions, and session duration
- HTTP request logs (method, URL path, response code, response time)
- Error logs and crash reports
We do not use Google Analytics or any third-party behavioral tracking scripts. Usage data is collected from our own server logs and infrastructure only.
2.4 Payment Information
We do not store your credit card numbers or full payment credentials on our servers. Payments are processed by Stripe (for US and international customers) and Paystack (for customers in Africa). These processors store payment instrument data under their own PCI DSS compliant environments. We receive only tokenized payment identifiers, subscription status, and billing history metadata.
2.5 Client Contact Data You Provide
When Middledoc account holders add clients to the platform (for document request management), they provide client names and email addresses. This data is stored on our behalf and governed by the DPA when the account holder is acting as a data controller.
2.6 Communication Data
When you contact us by email, we retain the contents of that correspondence including your email address, subject matter, and any attachments you send, for the purpose of resolving your inquiry.
3. How We Use Your Data
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the Service: creating accounts, processing document uploads, generating e-signatures, sending email reminders | Performance of contract (Art. 6(1)(b)) |
| AI document classification: sending document content to OpenAI or Anthropic APIs to generate classification labels | Performance of contract (Art. 6(1)(b)) |
| Payment processing: collecting subscription fees through Stripe or Paystack | Performance of contract (Art. 6(1)(b)) |
| Sending transactional emails: upload confirmations, document request notifications, password resets, billing receipts via SendGrid | Performance of contract (Art. 6(1)(b)) |
| Security and fraud prevention: detecting abuse, rate limiting, IP-based access controls | Legitimate interests (Art. 6(1)(f)) |
| Service improvement: analyzing aggregated, de-identified usage patterns to improve product features | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance: retaining records as required by applicable law, responding to lawful government requests | Legal obligation (Art. 6(1)(c)) |
| Customer support: responding to your inquiries and resolving disputes | Legitimate interests (Art. 6(1)(f)) |
We do not sell your personal data. We do not use your personal data for advertising purposes or share it with ad networks.
4. Third-Party Service Providers (Sub-Processors)
We share data with the following sub-processors strictly to operate the Service. Each is bound by contractual data protection obligations.
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Cloudflare, Inc. | CDN, DNS, DDoS protection, document storage (R2) | All traffic passing through middledoc.com; uploaded files | USA (global edge network); EU (R2 document storage) |
| Render Services, Inc. | Application and API hosting | All application data processed by our servers | USA |
| OpenAI, L.L.C. | AI document classification | Document content submitted for classification | USA |
| Anthropic, PBC | AI document classification (alternative provider) | Document content submitted for classification | USA |
| Twilio (SendGrid) | Transactional email delivery | Recipient email address, email subject and body | USA |
| Stripe, Inc. | Payment processing (US/international) | Name, email, billing details (tokenized) | USA |
| Paystack (Stripe subsidiary) | Payment processing (Africa) | Name, email, billing details (tokenized) | Nigeria / USA |
| Paddle.com Market Ltd | Merchant of record for subscription payments (international) | Name, email, billing details (tokenized); Paddle acts as merchant of record | United Kingdom |
| Render Services, Inc. (Managed PostgreSQL) | Relational database hosting | All structured account and metadata | USA (Ohio) |
AI Processing Note: When you use the AI document classification feature, the content of the document is transmitted to OpenAI or Anthropic for processing. These providers process data under API terms that restrict use of your data for training their models without explicit consent. We have configured our API integrations to use data-handling modes that prevent your documents from being used to train third-party AI models. However, you should exercise discretion before enabling AI classification on highly sensitive documents. You may disable AI classification on a per-request basis.
5. Data Retention
| Data Category | Retention Period |
|---|---|
| Account information (name, email, hashed password) | Duration of account plus 90 days after deletion request |
| Uploaded documents and files | Duration of account; deleted within 30 days of account termination unless you export first |
| E-signature audit trail records | 7 years from date of signing (legal requirement for enforceable signature records) |
| Payment and billing records | 7 years (tax and accounting legal obligation) |
| Server and access logs | 90 days rolling |
| Email communication records (support) | 3 years |
| AI classification results | Duration of account; deleted with associated document |
When a retention period expires we securely delete or irreversibly anonymize the data. Backups are purged on a rolling 30-day cycle.
6. Your Rights (GDPR — EEA, UK, Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) or applicable national law:
- Right of access (Art. 15): You may request a copy of the personal data we hold about you, including the categories of data, the purposes of processing, and any third parties with whom we share it.
- Right to rectification (Art. 16): You may request that we correct inaccurate or incomplete personal data about you.
- Right to erasure / “right to be forgotten” (Art. 17): You may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, or where you have withdrawn consent. Note that certain data (e.g., e-signature audit trails, billing records) must be retained for legal compliance and cannot be deleted on request.
- Right to data portability (Art. 20):You may request your personal data in a structured, commonly used, machine-readable format (JSON or CSV). Log in to your account and navigate to Settings > Account > Export Data, or contact us at [email protected].
- Right to restriction of processing (Art. 18): You may request that we restrict processing of your data in certain circumstances, such as when you contest the accuracy of the data.
- Right to object (Art. 21): You may object to processing based on our legitimate interests at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
- Right to withdraw consent: Where processing is based on consent you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: You have the right to lodge a complaint with your national data protection supervisory authority. In the EU, you may contact the supervisory authority in the member state of your habitual residence.
To exercise any of these rights, email [email protected]with the subject line “Data Rights Request” and a description of your request. We will respond within 30 days. We may ask you to verify your identity before acting on your request.
7. California Privacy Rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you additional rights.
7.1 Categories of Personal Information Collected
In the preceding 12 months we have collected the following CCPA categories of personal information:
- Identifiers: Name, email address, IP address, account ID
- Commercial information: Subscription plan, billing history
- Internet or other electronic network activity: Usage logs, feature interactions
- Professional or employment-related information: Firm name (if provided)
- Inferences: Account activity patterns used for service improvement (not for profiling)
- Sensitive Personal Information: The contents of documents you upload may contain sensitive information. We process this solely to provide the Service.
7.2 Your CCPA Rights
- Right to Know: You may request disclosure of the personal information we collect, use, disclose, and sell.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is necessary.
- Right to Limit Use of Sensitive Personal Information: We use sensitive personal information only to provide the Service, not for profiling or advertising.
- Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a CCPA request, email [email protected]with the subject “California Privacy Request.” We will respond within 45 days (extendable by an additional 45 days with notice).
8. International Data Transfers
Skillhanger Limited (trading as Middledoc) is incorporated in Nigeria. Our infrastructure and third-party service providers are primarily located in the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States, which may have data protection laws that differ from your country of residence.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on:
- Standard Contractual Clauses (SCCs):Our DPA incorporates the European Commission's approved Standard Contractual Clauses (June 2021 version) for controller-to-processor transfers.
- Adequacy decisions: Where available and applicable.
- UK International Data Transfer Agreements (IDTAs): For transfers involving UK data subjects.
Our sub-processors that handle EEA/UK personal data have executed SCCs with us or participate in equivalent transfer mechanisms. A copy of our SCCs is available upon written request to [email protected].
9. Cookies and Tracking Technologies
Middledoc uses a minimal cookie approach. We set only one category of cookie:
- Session authentication cookie (httpOnly JWT): A single, httpOnly, Secure, SameSite=Strict cookie that stores your encrypted JSON Web Token (JWT) authentication credential. This cookie is strictly necessary to keep you logged in. It cannot be read by JavaScript and is not accessible to third parties.
We do not set advertising cookies, third-party tracking cookies, analytics cookies (Google Analytics, Mixpanel, etc.), or persistent fingerprinting identifiers. Because we use only strictly necessary cookies, no cookie consent banner is technically required, but we provide full disclosure here and in our Cookie Policy at middledoc.com/legal/cookies.
10. Children's Privacy
The Service is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected data from a person under 16, please contact us immediately at [email protected] and we will delete that data promptly.
11. Security Measures
We implement industry-standard security measures to protect your personal data:
- All data in transit is encrypted using TLS 1.3
- Documents at rest are encrypted using AES-256 on Cloudflare R2
- Authentication uses bcrypt-hashed passwords and httpOnly JWT tokens
- Access to production systems is restricted to authorized personnel with MFA required
- We conduct regular security audits and remediate findings promptly
- Our infrastructure achieved a security rating of A- in independent auditing
For full details see our Security Policy at middledoc.com/legal/security. No method of transmission over the internet or electronic storage is 100% secure. In the event of a data breach affecting your personal data we will notify you as required by applicable law.
12. Links to Third-Party Services
The Service may contain links to third-party websites or services (such as QuickBooks for integration). This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email (to the address associated with your account) at least 14 days before the change takes effect, and we will update the “Last Updated” date at the top of this page. Your continued use of the Service after the effective date constitutes acceptance of the updated policy. If you disagree with material changes you may terminate your account before the effective date.
14. Contact Us
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact:
Skillhanger Limited (trading as Middledoc)48a Ogudu, Lagos, Nigeria
RC 1711272
Email: [email protected]
We aim to respond to all privacy inquiries within 5 business days and to complete data subject requests within the legally required timeframe.