Docora

Privacy Policy

Docora · Last updated:

What this policy covers

This document explains how the Docora mobile app (package ID com.norvera.docora), developed by Norvera, handles personal data. The same text is inside the app and is updated with it; both are generated from a single source so the two copies cannot drift apart.

The email, messaging and cloud apps you open a PDF or CSV with, after sharing it from Docora, fall outside this policy.

On this device

Your customers, products, prices, documents and settings are stored in a database on the phone itself. There is no sign-up step and no account is created for you; the app is fully usable with no account and no connection. In that state nothing you enter ever leaves the device.

What is held on the device is the following:

  • Customer records — name, legal name, address, phone, email, tax id and tax office, notes.
  • Product and service records — name, code, price, group, campaign and status.
  • Documents — your quotes, orders, delivery notes and invoices; their lines, totals, dates, numbers and the payments you recorded.
  • Your company details — the legal name, address, tax details, IBAN and bank name printed on documents, along with the logo you chose.
  • Settings — country, currency, paper/number/date format, tax rates, numbering series, document designs and appearance preference.

If you connect an account

Connecting an account is optional and is how you get a backup, a second device and colleagues working on the same records. You type in a server address — one run by Norvera, or one you run yourself — and from then on the app sends that server the records you have made: customers, products, prices, documents and the company details printed on them, along with your email address and your device’s identifier.

Your data is sent to the server address you entered and to no other. If you never enter one, nothing is sent anywhere. If you run the server yourself, you are the controller of those records and Norvera has no access to them.

Syncing happens on its own while the app is open: shortly after you change something, and every few minutes. Drafts you have not issued are not sent and stay on that device. Use an https:// server address so that what travels between the phone and the server is encrypted.

Photos

The app asks for your photo library only when you choose a company logo, and reads only the picture you pick. The camera and the microphone are never requested.

The image is stored with your documents on the phone and is printed on them. It leaves the device only if you have connected an account, in which case it is sent to your server so your colleagues’ copies of the documents show it too. If you decline the permission, the rest of the app works exactly as before — only the logo stays empty.

What is never collected

There is no analytics, no usage tracking, no crash reporting and no advertising in this app, and no third-party service of any kind. Your advertising identifier (IDFA) is never requested, so iOS never shows its tracking prompt.

It does not read your location, your contacts, your calendar or any photo other than the one you chose as a logo. It contains no code that talks to anybody except the server address you entered yourself.

Who else can see your records

Only people you invite to your organisation, by email address. What each of them can see is set by the role you give them, and the server sends each device only the records that role allows — a colleague who may not see documents is not sent them. People in a different organisation cannot see any of your records at all.

An invitation is a single-use code the app generates; passing it on is up to you, as Docora sends no email. The code works once, for that address, for seven days.

Your customers’ details are your records. By entering them you become a data controller towards your own customers; the lawful basis on which you hold those records, and how long you keep them, are your responsibility.

How it is protected

On the device, protection rests on the operating system’s app sandbox: no other app can read Docora’s database. Session tokens are held in the device’s secure store (the iOS Keychain).

On the server, passwords are hashed with Argon2id and are never stored in a form anybody can read, including us. Sign-in sessions use short-lived tokens that are renewed and can be revoked. Failed sign-ins and similar security events are recorded on the server so a break-in attempt can be noticed.

How long it is kept

Records are kept until you delete them. Deleting one leaves a small marker recording that it was deleted, which is how your other devices learn to remove their copy; those markers are kept.

Anything that never left the phone is gone from the server’s point of view because it was never there.

Deleting your data and your account

You can delete your account from the app, under Settings, and it is deleted rather than switched off — there is no hidden copy to restore. Organisations where you are the only member are deleted with everything in them. An organisation other people still work in is kept for them, and you are asked to hand ownership to somebody else first.

Records on your own phone are left alone: they are your work, and the app keeps running offline afterwards. To erase everything on the device, uninstall the app.

If you never connected an account, there is no copy for you to ask us to erase in the first place.

Children

Docora is a tool for businesses. It is not designed for or directed at children, and it does not knowingly collect anything from them.

Your rights

Turkey’s Personal Data Protection Law No. 6698 (Article 11) and the EU General Data Protection Regulation (GDPR) grant you the right to access, correct and erase your personal data.

If you never connected an account, these rights are satisfied by design: Norvera processes no data about you. Accessing your data means opening the app; erasing it means uninstalling it.

If you connected to a server run by Norvera, Norvera is the controller for those records and you can exercise your rights by writing to the address below. If you run the server yourself, the records never reach us; there, you are the controller and requests are made to you.

Changes to this policy

This text is part of the app and changes with it, so an updated app carries its updated policy rather than pointing at a page that may have moved. This page is updated from the same source, and the date at the top says when the wording last changed.

Contact

Write to us with any question about this policy or how the app relates to your data:

support@norvera.net

Back to the app page