Privacy Policy
Ticket2Doc Privacy Policy, Data Handling, and In-Memory Sanitization Practices.
Privacy Policy
Effective Date: July 2026
At Ticket2Doc, operated by Ticket2Doc Technologies (“Company”, “we”, “us”, or “our”), we take data protection and privacy seriously. This Privacy Policy details how we collect, use, store, and protect information when you register for an account, access our website at ticket2doc.com, or utilize our SaaS application and webhook integration services at portal.ticket2doc.com.
1. Information We Collect
A. Account & Registration Data
When you create a Ticket2Doc account, we collect personal and organizational information, including:
- Contact Details: Work email address, full name, and phone number.
- Organization Metadata: Company / MSP name, tenant identifier, and administrator settings.
- Billing & Payment Details: Payment card numbers, billing addresses, and subscription details processed securely via our PCI-compliant third-party payment processor (Stripe). We do not store full credit card numbers on our servers.
B. Integration & API Credentials
To operate the automated SOP pipeline, you provide integration credentials:
- Syncro PSA Credentials: Webhook secret tokens and API endpoints.
- Hudu Knowledge Base Credentials: Hudu instance base URLs and API keys.
- Encryption: All API keys, tokens, and sensitive integration credentials are encrypted at rest using per-tenant AES-256 Fernet symmetric encryption keys.
C. Webhook Payload Data & Ticket Content
When a service ticket is updated or resolved in Syncro PSA and triggers a webhook:
- We receive raw ticket metadata, title, technician resolution notes, customer company names, and ticket custom field flags.
- In-Memory Sanitization: Before ticket resolution notes are submitted to Large Language Model (LLM) providers for SOP generation, raw text passes through an automated in-memory scrubbing filter that redacts IP addresses, user passwords, credentials, API secrets, and private hostnames (replacing them with
[REDACTED_IP],[REDACTED_SECRET], etc.).
2. Zero-Persistence & Data Retention Policy
- Transient Processing: Raw un-sanitized ticket text exists only in volatile memory during the webhook execution lifecycle and is not written to permanent disk storage.
- Generated Content: Formatted SOP articles are pushed directly to your connected Hudu Knowledge Base API and are not stored permanently by Ticket2Doc after transmission.
- Account Data: Account registration data, tenant configuration, and encrypted API integration keys are retained for as long as your account remains active.
3. Data Encryption & Security Measures
We implement multi-layered security controls to protect your data:
- Data in Transit: All network traffic to and from Ticket2Doc web applications and API endpoints is encrypted using Transport Layer Security (TLS 1.3).
- Data at Rest: All sensitive database attributes, including Hudu API keys and secret tokens, are stored using AES-256 Fernet encryption with key separation.
- Access Control & MFA: Multi-Factor Authentication (MFA / TOTP) is enforced for account administrators to prevent unauthorized access.
4. How We Share Information
We do not sell, rent, or trade your personal data or ticket content to third parties. We share information only with trusted third-party service providers necessary to operate our platform:
- LLM Subprocessors: OpenAI / Anthropic APIs (processed under strict zero-data-retention for training agreements).
- Infrastructure Providers: Cloud hosting, database, and logging providers operating under strict security standards.
- Payment Processors: Stripe for subscription billing.
5. Your Data Rights & Choices
Depending on your jurisdiction, you have the right to:
- Access, correct, or update your account information via the Ticket2Doc portal.
- Request deletion of your account and associated encrypted credentials.
- Export your account configuration and event logs.
To exercise these rights or submit a privacy query, contact us at [email protected].
6. Updates to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy on our site with a revised effective date or by sending an email notification.