Service providers
Every third party that can receive information you put into DocSync.
- Version
- 0.8
- Effective date
- Not set — in force for the pilot
- Source
- legal/SUBPROCESSORS.md
DocSync — Service providers who can receive your information
⚠️ PRE-RELEASE DRAFT — NOT LEGAL ADVICE — NOT SETTLED BY AN AUSTRALIAN LAWYER
What this is. A pre-release draft, prepared for review by an Australian legal practitioner. Not reviewed, settled or approved by one, and not legal advice to anyone. There is no registered company name, ABN, ACN or registered address yet: the bracketed placeholders are real gaps, listed in §7.
And it is nonetheless live, which is why the paragraph above matters. This page is served, without a login, at
docsync.tech/legal/subprocessors. It is a statement of fact about who can receive information you put into DocSync, not a promise: nobody accepts it and it grants no rights. The one commitment on the page — the 30 days' notice in §4 — takes effect when the pack is settled and issued, and §4.1 records that it was not given for the AI row that is already active.What happens next. A settled version will be issued once an Australian legal practitioner has reviewed this pack and every placeholder is filled, and everyone will be asked to accept the settled Terms and Privacy Policy it accompanies. Until then, and this is a rule we hold ourselves to rather than an instruction to you: we will not put this document into a tender or present it as a settled commercial commitment.
Every status and data category below is traceable to source code and infrastructure configuration read on 2026-08-27 (branch
full-web-app-build) and re-verified on 2026-08-31. Where a fact could not be established from code, this page says so in its own words — as a fact about the service — rather than making a claim.The statements about how this deployment is configured — the mail backend, the AI provider, the operator surface, the worker count, the backup destination and retention — were read off the production server itself on 2026-08-31, not from a file in the source repository. An earlier version of this pack drew a deployed value from a repository default and was wrong about it; a configuration claim now names where it was read.
Document version: 0.8 · Effective date: [EFFECTIVE DATE]
| Entity | [LEGAL ENTITY NAME] (ABN [ABN]) |
| Effective date | [EFFECTIVE DATE] — not set. This page is nonetheless published and current today; see the banner above |
| Last reviewed | 2026-08-27 |
| Published at | docsync.tech/legal/subprocessors |
| Notification contact | [CONTACT EMAIL] |
| Companion documents | legal/PRIVACY_POLICY.md · legal/DATA_RESIDENCY.md |
How to read this list. A "subprocessor" is any third party that could receive information you put into DocSync. We list every one — including the ones that are switched off — because turning one on is a configuration change rather than a new release, and we would rather you saw the whole map than only the live parts.
Start from the position this list is measured against — and it is derived from the table below, not written beside it. Everything you put into DocSync — your records, your files, your photographs and your backups — is held on one server in [HOSTING REGION]. That server is a virtual machine we rent from Microsoft Azure, so Azure holds it: row 2 records what Azure receives as everything, because the machine's disks — and any snapshot Azure takes of them — are Azure's to hold, and we have not verified how they are stored. Beyond that hosting provider, no third party holds a copy of your file store or your database: the off-site backup destination in row 7 has never been set, so no copy of either has ever left the machine.
That is a statement about copies, not about content, and this page no longer claims there is only one thing of yours that leaves — four consecutive drafts said something of that shape and each was falsified by a path sitting next to the one just fixed. What leaves that server today is a list, not a count: a place name and a pair of coordinates, to the weather service in row 4; our own domain name and an administrative email address, to the certificate authority in row 5; and AI prompt text, to the provider in row 1, which is the one that carries record text your team typed. Outbound email, through the mail relay in row 3, is a further path: built, switched on in the product, and delivering nothing: the deployment's mail backend is console, which writes each message to the server's own log and discards it, so row 3 receives nothing at all today. That is why row 3 is not marked ACTIVE, and why a password reset or an invitation reaches nobody. Row 3 states what the relay would receive the day a real mail transport is configured, because that is a configuration change rather than a new release.
AI features are switched ON in the pilot deployment today, and prompt text leaves Australia. The deployment's provider setting is DeepSeek, an API key is configured, and the AI entitlement is active on the one company using DocSync. When someone uses one of the eight AI surfaces, the text of the prompt — which includes free text your team typed, and can therefore include a person's name — is sent to that provider, whose endpoint is outside Australia as at 2026-08-31 (the note on row 1 explains how that is determined and what would change it). Row 1 says what is sent. A company owner can switch AI off for their own company at any time from Company → Editions, at no charge, and you can ask us to do it for you.
The rows marked DORMANT and PENDING in §3 are paths that exist in the software and send nothing while they are off. We list them anyway, because turning one on is a configuration change rather than a new release.
Status key
| Status | Meaning |
|---|---|
| ACTIVE | Receives data today |
| NOT IN USE | A named provider, on a path the product uses, which receives nothing on this deployment because of a setting. Distinct from DORMANT: the feature is switched on in the product, and only the transport is not |
| PENDING | Configured path, scheduled to be switched on |
| DORMANT | Code path exists but is switched off and fails closed. Receives nothing |
| INFRASTRUCTURE | An infrastructure relationship that receives no customer content |
1. Providers that can receive customer information
| # | Provider | What we use them for | What they receive | Country of processing | Status today | Config seam |
|---|---|---|---|---|---|---|
| 1 | DeepSeek | AI drafting and summarising, across eight features — the project assistant, the RFI draft assist, the defect resolution draft, the RFI and transmittal chase notes, the submittal escalation note, the project health summary and the weekly review draft | Your typed question; on a follow-up, the earlier questions and answers in the same conversation (up to three earlier exchanges — each question and the Short answer section of its reply); record type, number, title, status and subtitle; ≤900-character excerpts of a record's own text; a project manager's weekly-review free text; per-tool counts; role labels; and, only if two separate gates are both open, budget totals. Email addresses, ABN-shaped numbers and Australian phone numbers are stripped automatically. No name field is sent — not the assignee, not the creator, not the attendee, not a contact — but a record title is free text somebody typed, a title can name a person, and on a residential job the project name is often the address. No files, photos, video, signatures or blobs | Outside Australia as at 2026-08-31 — read from the deployment's configuration, not hardcoded; see the note on this row. The specific country in which it processes is not established — we have not obtained the provider's published terms | ACTIVE. The deployment's provider setting is DeepSeek, a key is configured, and the AI entitlement is active on the one company using DocSync | AI_PROVIDER + API key; endpoint overridable |
| 2 | Microsoft Azure | Hosts the single virtual machine running everything | Everything — the VM holds the database and the file store | [HOSTING REGION]. The deployment plan specifies an Australian region; that has not yet been verified in the hosting portal, so we name the placeholder rather than assert a country | ACTIVE | Azure account |
| 3 | SMTP2GO | Outbound transactional email relay | Nothing today. On the day a real mail transport is configured: recipient address; subject (which often contains a project name or a record title); the full message body, including invite and password-reset links, and scheduled-report emails containing tables of your record data | An Australian and New Zealand company; the country in which its mail servers process our messages is not established, and we have asked | NOT IN USE. The deployment's EMAIL_BACKEND is console: DocSync writes each message to the server's own log and discards it, so no message is handed to this relay and it has received nothing. The product consequence is that a password reset, an invitation or a notification reaches nobody. This becomes ACTIVE the day EMAIL_BACKEND=smtp is set with credentials — a configuration change, not a release — and §5 requires us to tell you before that happens | EMAIL_BACKEND + SMTP host and credentials |
| 4 | Open-Meteo | Geocoding and weather for daily-log auto-fill | The location detail this service receives, in full. Geocode: the project's City field, and only when it holds a plain place name — letters plus the joiners a locality name can contain (space, hyphen, apostrophe, full stop), at most four words and 60 characters. The address line is never a source. Two limits: a street name typed into the City box does leave — Ocean Drive Terrigal contains no digits, so the check passes it — which on a residential job narrows a private dwelling to one street; and a City value that is not a plain place name yields no coordinates at all, costing a map pin rather than disclosing anything. Weather: a latitude, a longitude and a date. Those coordinates are the project's own free-typed fields, so a person can enter a dwelling-precision figure that never passed the City check; since 2026-08-31 they are rounded to two decimal places — about a kilometre — before they are sent, and the stored value keeps its full precision. No project name, no identifier, no key. Called server-side, so no end-user IP address is disclosed | Operated from Germany, according to its own published information; we have not independently verified where its servers are | ACTIVE | Hard-coded hosts, no key |
Notes on this list
On DeepSeek (row 1). This one is live. AI features are switched on in the pilot deployment — the provider setting is DeepSeek at deployment level and the AI entitlement is active on the one company using DocSync — so the row describes what is being sent, not what would be. Row 1 is the only routine cross-border flow of customer content that DocSync is capable of, which is why it is first.
Why this page can name a country at all, and what would change it — because the software does not hardcode one. Every AI screen in the product asks the server where a prompt would physically go under the configuration the server is actually running, and the server answers one of three things: offshore — a vendor endpoint whose address we ship (DeepSeek's own host, or Anthropic's, or Google's), and we know where those are; on this server — a local model on loopback, so nothing leaves the machine at all; or unspecified — an endpoint the operator supplied, whose country this process has no way to know, where saying "Australia" would invent a residency claim and saying "offshore" would state a falsehood, so it names no country. That mechanism exists because three screens once hardcoded the words "outside Australia", and a disclosure somebody reads before pressing a button has to describe the deployment they are actually using — a hand-written sentence cannot, because nobody re-reads it when the environment changes.
*As at 2026-08-31 the deployment answers offshore: AI_PROVIDER=deepseek, pointed at the vendor's own endpoint. Everything this page says about the AI provider's country is a fact about that configuration, not a permanent property of DocSync.* Changing it is one environment variable — which is why the screens ask instead of asserting, and why an onshore-or-on-premises answer costs a configuration change rather than a rebuild. If it changes, this page changes with it and the notice commitment applies.
What we will not tell you about that provider. The text of the prompt is sent to a third-party provider outside Australia. We do not warrant what that provider does with it, and we will not tell you that your prompt is excluded from that provider's training unless that provider's published terms say so and we have read them. We have not read them. If you require that no customer data reaches any third-party AI provider, tell us and we will keep AI features switched off for your company at no charge.
The order this happened in, stated plainly. We said we would obtain and assess the provider's published terms, and record on this page for each provider the country in which it processes, how long it keeps API inputs and whether it uses API inputs to train models, before AI was enabled for anyone. That is not what happened. AI was switched on in the pilot first and the assessment has not been done. The only company on the deployment is our own test company — read from the production database on 2026-08-30 — so no other DocSync customer's records have been involved. That is narrower than it sounds, and the first half of it is the only part we can evidence. Our own test company holds the names of real subcontractors, suppliers and workers; nobody has examined what personal information about those people its records contain; and we therefore do not claim that no individual's personal information has left the country. The sequence is the wrong way round, and Australian Privacy Principle 8.1 requires those steps to be taken before a disclosure, not after it. We would rather record that than write the assessment in the future tense and leave you to discover the order.
Who turns this on, and what does not stand behind it. In the product a company owner switches AI on for their own company, from Company → Editions, after ticking a box that says the text their team types — including record titles and notes that can name workers and subcontractors — goes to the destination the server reports, that they have told those people or are otherwise permitted to share it, and that the AI provider is a setting our operator can change, including to one outside Australia. The activation is refused without that tick, so for any future activation it is the consent record, not a notice. The same owner can switch it off there. There is no step in the software where we review or approve that decision, and nothing in the software checks whether we have read the provider's terms first. The assessment above is therefore our discipline as operator, not a control the product enforces. We are saying so rather than describing a gate that does not exist.
And the one activation that has ever happened has no acknowledgement behind it. That tick is new. The AI entitlement on the pilot company was switched on 2026-08-24, so it predates the acknowledgement and no acknowledgement was recorded for it. There is no consent artefact standing behind the cross-border disclosure that is actually happening — only this paragraph. Anyone who asks for that artefact should be shown this sentence, not the screen.
What we do promise, because it is ours to promise: we do not use your data to train, fine-tune or improve any machine-learning model of our own, and we never will.
See PRIVACY_POLICY.md §8 for exactly what each feature sends, what the automatic scrubber removes, and — importantly — what it cannot remove. We accept responsibility under APP 8.1 rather than treating consent as covering it.
On Azure (row 2). Azure is a hosting provider, not a data recipient in the ordinary sense — but it is listed because the VM holds everything and pretending otherwise would be dishonest. The database, the file store and both application servers have no published ports; only the reverse proxy is exposed.
On SMTP2GO (row 3), and this is the row that changed. A mail relay sees the whole message, not just a link. Because our scheduled reports email a table of record rows and our invite emails carry a live 14-day acceptance link, this would be a more significant relationship than "we send notification emails" implies — which is why earlier versions of this page listed it as ACTIVE and described it as receiving message bodies. It does not, and it never has on this deployment. The pilot host runs EMAIL_BACKEND=console, which logs one line per message — recipient, subject, message length, not the body — and discards the message. Nothing is handed to the relay. So the row records what it would receive rather than what it does, its status is NOT IN USE, and the mail relay is not one of the things leaving this server.
Two things follow, and neither is comfortable. The first is a product limitation, stated here because it is also a fact about this page: invitations, password resets, notifications, share links and scheduled reports reach nobody today. Where DocSync confirms one of those actions on screen it reads this deployment's own email status first and says the message was not emailed rather than implying it was sent — the password-reset screen, the two invitation screens and the meeting-minutes screen all do. Every other screen says nothing about delivery in either direction, so nothing in DocSync should be read as proof that a message arrived. The second is a discipline: the day a mail transport is configured, this row goes ACTIVE and every statement above about what leaves the server changes with it. That is a .env edit and a restart, not a release, so it must be done together with the update to this page and the 30 days' notice §5 requires.
On Open-Meteo (row 4). The lowest-sensitivity entry on the page — and lowest is not none. We attach no identifier to the place name we send, and that is as far as the claim goes: in Australia a place name can be a rural property name, and a rural property name is frequently a family name, so a locality string can carry a household with it. Row 4 states what leaves; it makes no representation that what leaves is about nobody.
What changed on 2026-08-31, and why this page no longer makes an absolute claim at all. For three rounds the code tried to keep an absolute promise by removing what must not go — a regex, then a seven-word designator list, then a positional strip. Each was defeated by an address shape nobody had anticipated (a property name in front of the number, a spaced slash, a PO Box), and this page was rewritten each time to match. The approach was then inverted and the heuristics deleted: the address line is no longer read at all, and the City value is sent only if it passes an allow-list that says what a place name is. A digit cannot leave because a value containing one is never sent — not because we tried to take one out. That fix holds. The sentence written on top of it did not. A fourth version of "the only location detail that ever leaves" went onto this page and was falsified in the same week by the weather call, which sends the project's own latitude and longitude — fields a person types into, which the allow-list never touched. So row 4 now carries a list of what leaves instead of a claim about what does not, and the coordinates are rounded to two decimal places on the way out. An enumeration that is true is worth more than a superlative that is nearly true.
Two limits remain, and we would rather name them than let the stronger claim imply they do not exist. First, a street name typed into the City box does leave: Ocean Drive Terrigal contains no digits, so the allow-list passes it, and on a residential job that narrows a private dwelling to one street. Excluding it would need a list of street-type words — and St, Broadway and Beach are locality names too, which is the recognition problem this change exists to delete. Second, the cost: a City value that is not a plain place name — Parramatta NSW 2150, or a whole address typed into the box — yields no coordinates at all, so the project gets no map pin and its daily log falls back to manual weather entry. That costs a feature and discloses nothing, and it is the cheaper of the two failures. The screen that takes the City value says so where a person is typing it.
What happened before that date, because it does not un-happen. Until 2026-08-31, a project with no City set had its address line shortened by one of those heuristics and sent, and street numbers did reach the geocoder. Projects located under the old rule are not re-geocoded — a project is looked up at most once, ever — and the project.geocode audit rows record the query that was sent at the time.
2. Infrastructure — no customer content
| # | Provider | Purpose | What they receive | Country |
|---|---|---|---|---|
| 5 | Let's Encrypt / ISRG | Issues and renews our HTTPS certificate over ACME | Our domain name and an administrative email address. The domain is published in public Certificate Transparency logs. No customer content | United States |
| 6 | get.tech / Radix | Domain registration and authoritative DNS | Registrant details; DNS query traffic. No customer content | Not established. We have not confirmed where the registrar handles registrant data, and we will state it here when we have |
On the registrar (row 6). Two things we know and would rather say. We have not confirmed whether WHOIS privacy is enabled on the domain registration, and domain auto-renew is currently switched off — which is not a privacy matter at all, but it is a business-continuity risk to a service you would be depending on, and you should hear it from us.
3. Pending and dormant — switched off today
We list these because each becomes active through a configuration change. Every one of them fails closed: without its configuration the feature returns an error rather than working insecurely.
DeepSeek does not belong to this category. It is ACTIVE and it is listed in §1. Rows 13, 14 and 15 are the alternative AI backends, which are not selected.
| # | Provider | Purpose | What they would receive | Status today |
|---|---|---|---|---|
| 7 | Microsoft Azure Blob Storage | Off-site backup destination | A complete copy of the entire database and every uploaded file, unencrypted by us (protected by TLS in transit, the provider's own at-rest encryption, and the secrecy of a shared-access URL) | PENDING — the destination has never been set. Nothing has ever left the box. The storage account's region is chosen independently of the VM's and must be set to an Australian region |
| 8 | A rented GPU host (3D reconstruction worker) | Turns a site walkthrough video into a 3D model | Full site walkthrough video files plus the capture name. Its queue is not scoped to one company — a single worker would receive video from every company on the deployment | DORMANT — every worker route returns an error without its token. A fully on-premises 3D path exists, so this disclosure is avoidable |
| 9 | Xero | Accounting bill export | Vendor and supplier names, line descriptions, amounts, dates, invoice numbers | DORMANT — disabled, no token, not present in the production configuration |
| 10 | QuickBooks Online / Intuit | Accounting bill export | Same as Xero | DORMANT — as above |
| 11 | An inbound-mail provider (vendor not yet chosen) | Files emails sent to a project address into that project | Sender address, recipient, subject, body and attachments — including from third parties who have never used DocSync | DORMANT — the webhook returns an error without its secret |
| 12 | Stripe | Edition and subscription billing | Nothing is sent to Stripe by this software. It is an inbound webhook stub only — no SDK, no outbound call | DORMANT — returns an error without its secret |
| 13 | Anthropic | Alternative AI backend | Same categories as row 1 | DORMANT — code present, not selected. United States |
| 14 | Google (Gemini) | Alternative AI backend | Same categories as row 1 | DORMANT — code present, not selected. United States / global |
| 15 | Self-hosted local model (Ollama) | Local AI backend — the zero-disclosure AI option | Nothing leaves the host | DORMANT (available). Same host as the deployment |
Row 15 is worth noticing. If cross-border AI is unacceptable to you, DocSync's AI features can run on a model hosted on the same server as your data, and the cross-border disclosure disappears entirely. Ask us.
4. Our commitment when this list changes
This is the part that matters, because a list nobody maintains is worse than no list.
4.1 Advance notice
We publish the full list of every service provider that can receive information you put into DocSync — including the ones that are switched off — at docsync.tech/legal/subprocessors, and we will not let a new provider receive your information until we have updated that list and given you at least 30 days' written notice by email to your company owner.
This commitment was not met for the provider in row 1. AI was switched on in the pilot deployment before this page existed, so no list was updated and no 30 days' notice was given. §1's note says so at length. We are repeating it here because this is the section that makes the promise, and a reader who lands on this page from a procurement questionnaire should not have to scroll back up to find out that the one ACTIVE cross-border row is the one the promise was not kept for.
If you object to a new provider within those 30 days, tell us: we will either keep the feature that uses it switched off for your company, or you may terminate the affected part of your subscription and we will refund the unused portion of anything you have prepaid. Two things you should know about how this works. The notice is written and sent by a person, not generated by the system — there is no automated broadcast. And if we ever have to replace a provider immediately for a security or continuity reason, we will make the change first and tell you within five business days, with our reasons.
The notice will state:
- the provider's name and what they will do;
- the categories of information they will receive;
- the country in which they will process it;
- the date the change takes effect;
- how to object.
The same notice period applies when an existing provider changes the country in which it processes your information, and when we replace one provider with another performing the same function.
4.2 Your right to object
If you object in writing before the change takes effect, we will:
- discuss it with you and try to find a workable alternative — for several rows above one genuinely exists (AI can be switched off per company, or run on a local model; 3D reconstruction has an on-premises path);
- if no alternative works and you do not want to proceed, you may terminate the affected part of the service, or the whole service, without penalty and without paying for any unused period, and we will give you a full export of your data before you go.
We will not treat silence as agreement to a change you were never told about. If we fail to give notice, the change is not authorised by this list.
4.3 Emergency changes
If a provider fails suddenly — an outage, a security incident, an account termination — we may need to switch to a replacement before the notice period runs. If that happens we will make the change first and tell you within five business days, with our reasons, and your objection right in §4.2 still applies afterwards.
4.4 Keeping this list current
- This list is published at
docsync.tech/legal/subprocessorswith a version number and an effective date. - We review it at least every 6 months and whenever a configuration change touches a provider.
- Every change bumps the version and is recorded in §6.
- You can ask to be told of changes by emailing
[CONTACT EMAIL]. That is a person adding you to a list, not a subscription feature.
4.5 How this promise is actually kept — the part vendors leave out
Every provider on this page is switchable by editing one configuration value and restarting a container. No code change, no deployment, no review. One line could move every customer's prompt text from one overseas company to a different overseas company, and nothing in the software would stop it or record it. A promise the deployment process can break in ten seconds is worse than no promise, so we are telling you what stands behind this one instead of implying a system does.
- The list is a published, versioned page. This one. It is served from the same file that is reviewed and versioned in our source control, so the page and the record cannot drift apart.
- The notice is an email a person writes and sends to your company owner. At our scale that is performable by one person and it needs no broadcast feature. We are not going to build one and call it a control.
- A written operational rule binds the configuration seam. Changing the AI provider, the storage endpoint, the mail host, the backup destination or the 3D worker token requires this list to be updated and customer notice given first. That rule lives in our operations documentation, where the person doing the change will actually read it.
If we ever break this promise, the failure will look like a configuration change nobody wrote down. That is the thing to hold us to.
5. Complete list of outbound hosts
For a customer's IT team doing egress review, this is every external hostname the API server can contact, taken from an exhaustive search of the source:
| Hostname | Purpose | Active? |
|---|---|---|
api.deepseek.com | AI provider | Yes — AI features are switched on in the pilot deployment |
api.anthropic.com | Alternative AI provider | No |
generativelanguage.googleapis.com | Alternative AI provider | No |
localhost:11434 | Local AI model — never leaves the host | No |
geocoding-api.open-meteo.com | Geocoding | Yes |
api.open-meteo.com | Weather forecast | Yes |
archive-api.open-meteo.com | Historical weather | Yes |
api.xero.com | Accounting export | No |
quickbooks.api.intuit.com | Accounting export | No |
| The mail relay host | Outbound email | Yes |
| The ACME certificate authority | TLS certificates | Yes (infrastructure) |
| The off-site backup destination | Backups | Not set |
The web application makes no third-party requests at all. Its Content-Security-Policy blocks connections to any host other than our own, fonts are self-hosted from build time, and a search of the entire web source finds no external URL outside test fixtures. No analytics, no telemetry, no session replay, no third-party error tracking, no CDN, no tracking pixels.
6. Change log
| Version | Date | Change |
|---|---|---|
| 0.1 | 2026-08-27 | Initial draft, compiled from a code and infrastructure audit. Not served |
| 0.2 | [EFFECTIVE DATE] | Countries named for the weather service and the certificate authority; the mail relay's processing country recorded as not established; the refusal to warrant a third party's training use added; the geocoder's street-number case disclosed; notice period fixed at 30 days; §4.5 added. Correction made on 2026-08-30 before publication: an earlier draft of this page described the AI provider as DORMANT and wrote row 1 in the prospective voice. That was wrong. The production configuration was read on that date and AI is ACTIVE — row 1, the outbound-host table and every note about it are now written in the present tense. Not issued |
| 0.3 | [EFFECTIVE DATE] | The opening position derived from the table rather than composed beside it — the hosting provider holds the machine, and the claim is now about every OTHER third party (rows 2 and 7 are the evidence). Surface count corrected from five to eight in the header note and row 1. Row 4's geocoder entry strengthened: the street number no longer reaches the geocoder, with the two residual limits (the street name and suburb do go; an address that reduces to nothing gets no coordinates) stated in the same sentence. §4.1 now carries the caveat that the 30-day notice was not given for the ACTIVE AI row. The pilot mitigation restated in the only form that was measured. "Served" and "issued" separated. Not issued |
| 0.4 | [EFFECTIVE DATE] | The banner rewritten — it used to declare the page not in force while the product served it; it now states the true position (a pre-release draft that is nonetheless live, with a settled version to follow). Row 4 rewritten: the geocoder's address-line fallback was deleted from the code on 2026-08-31, so the address line is no longer a source at all; the row now carries the absolute claim plus its two residual limits, and the note above records that street numbers did leave before that date and that historic geocodes are not re-run. The AI country wording derived from configuration rather than hardcoded, with the mechanism and the date named. The cross-border acknowledgement tick corrected: the pilot's live entitlement predates it and has no acknowledgement row. The residency absolute now carries the mail-relay carve-out inside the sentence. Not issued |
| 0.5 | [EFFECTIVE DATE] | Row 3 (the mail relay) corrected from ACTIVE to NOT IN USE. The pilot host's EMAIL_BACKEND was read on 2026-08-31: it is console, which logs each message on our own server and discards it, so the relay has received nothing and the mail relay is not one of the things leaving the server. Earlier versions asserted an ACTIVE recipient of message bodies on no reading of the deployment; the banner's provenance sentence now names where a configuration value was read. The product consequence — a password reset or an invitation reaches nobody — is stated rather than implied. The geocode superlative deleted. "The only location detail that ever leaves…" had been written a fourth time and was falsified again, this time by the weather call, which sends the project's own free-typed latitude and longitude; row 4 now enumerates what leaves and records that those coordinates are rounded to two decimal places on the way out. The residency superlative deleted likewise: the enumeration stays, "and nothing else" goes. The metadata row's effective-date gloss corrected: it denied that this page was in force while the banner said it was. Not issued |
| 0.6 | [EFFECTIVE DATE] | The location statement is no longer a count. Four successive drafts published a count of the things carrying part of a project's location off the server and each was falsified within the week; the pack now states the list and states no number — the City field, the project's stored latitude and longitude, and the project's own name, which goes to the AI provider in a prompt and which on a residential job is often the street address. Row 1's note already carried that last fact while the count beside it said two. The undelivered-mail sentence corrected: the pack said DocSync says so on screen; the password-reset screen said the opposite, in green, to a signed-out stranger. That screen now reads the deployment's own email status before it answers, as do the two invitation screens and the meeting-minutes screen, and the sentence names which surfaces do and says the rest are silent. The draft banner's provenance paragraph rejoined the banner — a missing > had split the warning box in two on the served page here, in the Privacy Policy and in the residency page. Not issued |
| 0.7 | [EFFECTIVE DATE] | The counting is gone from this page and from the whole pack. Version 0.6 stopped counting what carries a project's location off the server but kept counting the egress paths themselves — a bolded number of them, in seven places across six documents. A count goes stale the moment a path is added and a list does not, which is how four earlier versions of the location sentence came to be wrong, so every one of them now reads what leaves that server today is a list, not a count followed by the named items, and scripts/check_legal_pack.py fails on a bare count of egress points. The AI passage corrected, and it is the substantive change. Version 0.6 asserted that no part of DocSync could reach the AI provider except through the entitlement check; that was disproved from a clean shell in two lines. What is stated now, everywhere the pack discusses it: email addresses, ABN-shaped numbers and Australian phone numbers are removed on every path, because the removal was moved inside the one method that opens the connection to the provider — and, in the same breath, that it cannot recognise a person's name, so free-text titles and the project's own name travel as typed. The entitlement check is described as what it is: a commercial gate, not a privacy control. The published rate ceilings re-read after the authentication windows were re-keyed, and §2.3 of the SLA — which carried an unfilled blank in the probe URL, spelled in lower case and therefore invisible to the placeholder register — renamed to [SERVICE DOMAIN]. Not issued |
| 0.8 | [EFFECTIVE DATE] | The AI evidence budget re-read from the code. The assistant's budget was raised from 8 records x 420 characters to 10 x 900 -- 3,360 to 9,000 characters of a customer's own records into a prompt that leaves Australia -- and five in-force documents, this one included, went on publishing the old pair. All five now print the figures the running code enforces, and the Privacy Policy's illustration of what that free text can be was widened to name a photo's caption and an incident description, which became quotable in the same round. The checker now reads the two constants out of the API source (evidence-budget): it had reported 21/21 PASS while all five were wrong, because every check it had compared the pack against other parts of the pack, and a figure that only agrees with itself is not checked. Not issued |
On "served" versus "issued", because two rows of this table used to say "Not published" while four documents said the page is published. Both statements are true of different things, and the words are now kept apart. Served: this file is in the code-declared registry of public documents and is rendered, without a login, by the public /legal/[slug] route — so wherever the current build runs, the page is there. Issued: no version of this page has been given to a customer, attached to a tender, or relied on, because the whole pack is a pre-release draft awaiting Australian legal review and every page says so at the top. The commitments in §4 take effect when the pack is settled and issued, not before. This page is a statement of fact rather than a promise, so nothing here turns on that distinction — but the Terms and the Privacy Policy are different: those two ARE ticked by every user before an account is created, and they are the operative terms between us and the pilot users we invite. Their banners say so.
Every future version records what changed, when it took effect, and when notice was given.
7. Placeholders on this page
| Placeholder | What it is | Status |
|---|---|---|
[LEGAL ENTITY NAME] | The Australian entity that will operate DocSync | Does not exist. Not to be inferred from the product name or the domain |
[ABN] | Australian Business Number | Not issued |
[EFFECTIVE DATE] | Date this list takes effect | Not set |
[CONTACT EMAIL] | Published contact for subprocessor questions and notifications | Not created. Must not be the send-only no-reply@ address used in config |
[HOSTING REGION] | The cloud region the production server runs in | Unconfirmed — must be verified in the hosting portal |
End of draft. Prepared for review by an Australian legal practitioner. No corporate name, ABN, ACN or address has been inferred from the product name, the domain, or anything else.