What this document covers
TommDoc is an online document editor with user accounts, workspace management, real-time collaboration, AI assistance, file import, and document export. In order to provide these features, we process personal data relating to users and other data that may contain personal information.
This policy explains who processes the data, what categories of data may be involved, why we need them, who may receive them, how long they are retained, and what rights you have under applicable European Union laws.
Data controller
The data controller is MLJ solutions a.s., Školská 689/20, 110 00 Prague, Company ID 08579156. For privacy questions, rights requests, or any other personal data matter, you can contact us at info@tommdoc.com.
If you use TommDoc through an employer or another organization, that organization may also act as a separate controller for data contained in your workspace or documents. In that case, some requests may also need to be directed to your organization.
Data we may process
We may process account and contact details that you provide during registration or account management, such as your name, surname, email address, profile data, and details related to your organization or workspace.
We also process content data and operational metadata required to run the service, including documents, workspace structure, version history, real-time collaboration events, imported or uploaded files, exported files, technical logs, error information, device and network information, and data related to authentication and security.
If you use AI features, we may also process prompts, selected text, document content sent to the AI action, and generated outputs. We process those inputs only to the extent needed to provide the requested AI feature.
Why we use data
We use personal data mainly to operate accounts and workspaces, authenticate users, synchronize documents, save edits, manage version history, handle import and export workflows, provide AI features, communicate with customers, and deliver technical support.
We also use data to protect the service, prevent misuse, investigate incidents, maintain operational logs, improve reliability, and comply with legal obligations. Where needed, we may also use data to establish, exercise, or defend legal claims.
Legal bases for processing
In most situations, we process data because it is necessary to enter into and perform the contract for the TommDoc service, including account creation, login, document editing, real-time collaboration, and import, export, or AI-related actions.
We may also rely on our legitimate interests, especially for security, fraud prevention, abuse detection, internal service administration, performance and stability monitoring, and legal defense. If a specific use case requires consent, we will request it separately.
International transfers
Some service providers or their subprocessors may be located outside the European Economic Area. Where such transfers occur, we seek to ensure that an appropriate transfer mechanism under GDPR applies, such as an adequacy decision or standard contractual clauses.
The actual scope of international transfers depends on the features you use and on the infrastructure or integrations enabled for the relevant workspace.
Advertising and marketing tools
With your consent, we use third-party advertising and analytics tools to measure product and campaign performance and to display relevant advertising (remarketing). These tools are loaded via Google Tag Manager only after you grant consent in the cookie settings.
• Google Ads (Google Ireland Limited): conversion measurement and remarketing • Google Analytics 4 (Google Ireland Limited): measures how you use TommDoc • Meta Pixel (Meta Platforms Ireland Limited): conversion measurement and remarketing on Facebook and Instagram • LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company): conversion measurement and remarketing on LinkedIn
These tools may collect cookie and device identifiers, your IP address (truncated or anonymised where supported by the provider), browser and device information, pages visited and actions taken in the app (e.g. form submissions), referral source and campaign click identifiers (e.g. gclid, fbclid, li_fat_id), and an approximate location derived from your IP address.
The legal basis for this processing is your consent under Art. 6(1)(a) GDPR and the Czech Electronic Communications Act (Section 89(3) of Act No. 127/2005 Coll.). You can withdraw your consent at any time via the cookie settings, without affecting the lawfulness of processing based on consent given before its withdrawal.
Providers may process data outside the EU/EEA, particularly in the USA, based on the EU-US Data Privacy Framework and/or Standard Contractual Clauses. Cookie lifetimes are set by each provider and shown in the cookie settings; data held in advertising platforms is retained for the period set by the relevant provider.
Providers' privacy policies: Google: https://policies.google.com/privacy, Meta: https://www.facebook.com/privacy/policy, LinkedIn: https://www.linkedin.com/legal/privacy-policy
Retention
We retain data for as long as needed to operate the account, workspace, and service relationship, and then for an additional period where reasonably necessary for backup, security, incident handling, disaster recovery, legal compliance, and the defense of legal claims.
Retention periods may differ by data type. Document content, document versions, uploads, and operational logs do not necessarily follow the same schedule. When data is no longer needed, we delete it, anonymize it, or otherwise restrict further processing.
Your rights
Under applicable law, you may have the right to access your personal data, request correction of inaccurate data, request deletion, request restriction of processing, receive data portability, and object to processing based on legitimate interests. You also have the right to lodge a complaint with a competent supervisory authority.
If you use TommDoc through your employer or another organization, some requests may need to be handled primarily through that organization, especially where it determines the purposes of processing for workspace content.
Security and technical storage
We use reasonable technical and organizational safeguards to protect data against loss, unauthorized access, or misuse. This includes access controls, authentication, operational logging, tenant separation, and other measures appropriate to the nature of the service.
The frontend may use necessary technical storage, such as local storage or comparable mechanisms, to maintain login state, selected workspace state, or other essential interface behavior. Based on the current application shape, these mechanisms are not used for marketing profiling.
Contact and updates
If you have questions about this policy or want to exercise your rights, contact us at info@tommdoc.com. To process a request safely, we may ask for reasonable identity verification.
We may update this policy from time to time, especially if legal requirements, product features, or service providers change. The current version will always be published on this page.