Trust & Privacy
Privacy & Data Handling
Last updated: July 2026
DOSSA helps businesses manage supplier documents and compliance — including the FSVP program for U.S. food importers. Handling your documents responsibly is the whole point of the product, so we keep this plain-language. This page explains what we collect, where it goes, and the commitments behind it.
What we collect
- Account data — name, work email, company, and role, so we can create and secure your account.
- Documents you upload — supplier certificates, lab results, audits, and related files, plus the data extracted from them.
- Usage data — logs and metadata we use to operate the service, secure it, and improve reliability.
How your data is protected
- Tenant isolation.Every customer's data is scoped to their organization. Our access layer enforces this on every query, and it is verified by an automated test in our release pipeline — not just a convention.
- Encryption. Data is encrypted in transit (TLS) and at rest. Sensitive fields carry an additional layer of application-level encryption.
- Access control. Multi-factor authentication is available, and administrative access is restricted and logged.
- Backups. We keep point-in-time backups with a tested restore process so your data survives failures.
AI processing — where your documents go
DOSSA uses AI to categorize documents, extract fields, and draft FSVP analyses. To do this, the contents of the documents and records you submit are sent to our AI sub-processor for processing and returned to you. We want to be completely clear about what that means:
Our AI sub-processor: Anthropic (Claude API)
- Your data is not used to train AI models.Under Anthropic's commercial terms, inputs and outputs from the API are not used for model training.
- You keep your data. You retain all rights to what you submit and own the outputs generated for you.
- Contractual data protection. A Data Processing Addendum (with Standard Contractual Clauses) governs this processing.
- Zero-retention available. For customers who require it, we can arrange zero-data-retention processing, under which request and response contents are not stored by the sub-processor.
We will keep this sub-processor list current and give notice of material changes. If you need our executed DPA or a zero-retention arrangement for your account, contact us.
Data retention & deletion
We keep your data for as long as your account is active and as needed to provide the service. Deletions are honored, and records are soft-deleted first so they can be recovered from accidental loss before permanent removal. On account closure, we delete or return your data on request, except where we must retain it to meet a legal obligation.
Your responsibility
DOSSA assists with FSVP and document-compliance tasks but does not replace professional judgment. You — and your Qualified Individual — remain responsible for reviewing, verifying, and approving all determinations, documents, and regulatory filings. AI output is a starting point, not a determination, and is labeled as such in the product. DOSSA is not a substitute for legal, regulatory, or food-safety advice.
Contact
Questions about privacy, a data-processing agreement, a sub-processor detail, or want to responsibly disclose a security issue? Use our contact formand note that it's a privacy or security matter — it reaches our team directly.
This page describes our current practices and will evolve as the product does. It is provided for transparency and is not a contract; the terms of your agreement with DOSSA govern.