Legal

Dokima Privacy Notice

Last updated: 4 August 2026

1. Who we are

Northloom Ltd (company number SC895860) is the controller of the personal data described in this notice. Northloom Ltd is registered in Scotland at 5 South Charlotte Street, Edinburgh, EH2 4AN. In this notice, “Northloom”, “we”, “us” and “our” refer to Northloom Ltd. Dokima is a Northloom product.

Contact us about privacy or legal matters at contact@northloom.ai. Product support is available at support@dokima.net and security reports may be sent to security@northloom.ai.

2. Scope

This notice covers personal data we process in connection with dokima.net, sales and trial applications, customer administration, licensing, billing, support, product-security reports and business communications.

Dokima is a business-to-business product. It is not intended for consumers or children.

3. Information we collect

Depending on how you interact with us, we may collect:

  • Business contact data: name, work email address, telephone number, job title, employer, business address and correspondence.
  • Sales and trial data: organisation details, intended use, repositories and team size, procurement information, application answers and our assessment or approval notes.
  • Account and licence data: customer organisation, plan, authorised contacts, licence or entitlement identifiers, activation and expiry information, product version and basic service events needed to provide and protect the licence.
  • Billing data: billing contact, billing address, tax information, subscription, invoice and payment status. Stripe processes full payment-card details; we do not receive or store the full card number or security code.
  • Due-diligence data: information required for customer, sanctions, restricted-party, destination and end-use screening, including information about organisations, directors, beneficial owners or authorised representatives obtained from you or reputable public and commercial sources.
  • Support and security data: support requests, diagnostic material you choose to provide, communications, reports submitted to us about the security of Dokima or our services, and our response records.
  • Website and security data: IP address, date and time, requested page, user-agent and related server or security logs. The present website does not use advertising or analytics cookies. It currently requests website font files from Google Fonts, which may receive request information such as an IP address and browser details.
  • Marketing preferences: whether you wish to receive or stop receiving relevant product communications.

4. Source code, findings and AI runners

Dokima is installed and run in the customer’s environment. Dokima never uploads repository source code to Northloom or to any Northloom-operated service, under any licence. Source code remains on systems controlled by the customer.

For paid customers, Dokima never uploads findings, vulnerability information, evidence, reports, prompts or local Dokima state to Northloom. Those materials remain on systems controlled by the customer. If a paid customer independently chooses to send material to Northloom for support, that is a voluntary disclosure by the customer; it is not an upload performed by Dokima.

The free open-source licence works differently. Source code is still never uploaded to Northloom. As a condition of using that licence, vulnerability information generated by Dokima is uploaded to Northloom, kept private for 120 days after Dokima first records each finding, and then released publicly. The open-source licence does not offer a private-report opt-out; organisations that require findings to remain private must use a paid licence.

A customer may configure a third-party or local AI runner. The runner is selected and controlled by the customer and may receive source code, prompts and related review context directly from the customer’s environment. Northloom does not receive that material through the runner. The runner provider’s terms and privacy practices apply independently, and customers must assess them before use.

Customers should remove unnecessary personal data and secrets before voluntarily sending support material to Northloom. Any future change to these data flows will be described here before it is introduced.

5. Why we use information and our lawful bases

We use personal data to:

  • assess and respond to enquiries and trial requests (our legitimate interests in developing customer relationships, and contractual necessity where the individual is personally a party);
  • create and administer subscriptions, licences, product access, support and renewals (our legitimate interests in performing and administering business contracts, and contractual necessity where the individual is personally a party);
  • invoice, account for payments and meet tax, corporate and record-keeping duties (contractual necessity and legal obligation);
  • conduct customer, sanctions, export, destination and end-use checks and prevent fraud or misuse (legal obligation where applicable and our legitimate interests in lawful, responsible trade);
  • secure our websites, systems, licences and product, investigate abuse and handle vulnerability reports (legitimate interests and, where applicable, legal obligation);
  • establish, exercise or defend legal claims (legitimate interests and legal obligation); and
  • send relevant business-to-business product communications where permitted (legitimate interests or consent, as required).

Where we rely on legitimate interests, we consider whether those interests are proportionate and whether your rights override them. You may object to processing based on legitimate interests.

We do not use personal data for solely automated decisions that produce legal or similarly significant effects. Customer or trial approval decisions include human review.

6. Who receives information

We disclose personal data only where reasonably necessary to:

  • service providers supporting website hosting and security, business email and productivity, billing and payments, customer support, software delivery and business administration;
  • professional advisers, auditors, insurers and prospective investors or purchasers under appropriate confidentiality duties;
  • government, law-enforcement, tax, sanctions or regulatory authorities where required or reasonably necessary; and
  • another entity in connection with a reorganisation, financing, sale or transfer of all or part of our business, subject to appropriate safeguards.

Current core providers include Vultr for website infrastructure, Google Workspace for business email and documents, and Stripe for billing and payments. We do not sell personal data.

7. International transfers

Some providers may process personal data outside the United Kingdom. Where UK data-protection law requires a transfer safeguard, we use an applicable UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved EU standard contractual clauses, or another lawful mechanism. Contact us for further information about safeguards relevant to your data.

8. Retention

We keep personal data only for as long as reasonably needed for the relevant purpose:

  • unsuccessful sales and trial enquiries: normally 24 months after the last substantive interaction;
  • contracts, customer administration, invoices, payment and screening records: normally for the customer relationship and 6 years afterward;
  • ordinary support records: normally 3 years after closure;
  • reports submitted to us about the security of Dokima or our services: normally 6 years after closure, where a longer record is useful to track product risk and disclosure history; this does not include findings generated for paid customers, which Dokima does not upload to Northloom;
  • vulnerability information uploaded under the free open-source licence: kept private for 120 days after Dokima first records each finding and then released publicly under the open-source programme terms;
  • website and security logs: normally 30 days, unless an event requires longer investigation or preservation;
  • direct-marketing records: until opt-out or normally 24 months after the last meaningful engagement; and
  • legal disputes or regulatory matters: for as long as required to resolve the matter and meet related legal duties.

Backups may retain deleted data for a limited additional period before being overwritten. We may retain anonymised information that no longer identifies an individual.

9. Security

We use proportionate technical and organisational measures intended to protect personal data against unauthorised access, loss, alteration and disclosure. No system can be guaranteed completely secure. Please send suspected product or service vulnerabilities to security@northloom.ai and do not include unnecessary personal data.

10. Your rights

Subject to applicable law and exceptions, you may ask us to:

  • provide access to your personal data;
  • correct inaccurate or incomplete data;
  • erase data;
  • restrict processing;
  • provide certain data in a portable format;
  • stop processing based on legitimate interests; or
  • withdraw consent where consent is the lawful basis.

You may opt out of marketing at any time. To exercise a right, contact contact@northloom.ai. We may need to verify your identity and authority. You may complain to the UK Information Commissioner’s Office at ico.org.uk, although we invite you to contact us first so we can try to resolve the issue.

11. Territorial availability

Northloom presently offers Dokima only to approved business customers established in the United States, Canada, the United Kingdom, Australia, New Zealand, Jersey, Guernsey or the Isle of Man. Website controls may restrict access from other locations. Those controls are not a substitute for customer due diligence and may not always identify a visitor’s location accurately.

12. Changes

We may update this notice when our product, providers or legal obligations change. We will post the current version with a revised date and provide additional notice where a change materially affects individuals.