Version 1.2
Last revised on: August 2, 2026
This Usage Policy explains how Doppler AI, Inc. ("Doppler") processes Customer Content and usage-related information to provide the Services. It is incorporated into the Terms of Service. For personal information Doppler collects about you as an individual, see the Privacy Policy.
1. Definitions
Customer Content: the documents, files, records and other data your organization provides to the Services, such as credit agreements, CIMs, financial statements, loan tapes, covenant and borrowing base certificates, portfolio reporting packages and memos.
Output: the reports, analyses, extracted values, memoranda and summaries the Services generate in response to your use.
Data Layer: the structured, normalized representation of Customer Content that the Services build, including resolved entity records, extracted values, source citations, schema and ontology.
Usage Data: operational and telemetry data about how the Services perform and are used, such as request volumes, latency, error rates and feature utilization. Usage Data excludes Customer Content and anything derived from its substance.
Personal Data: information that identifies or can reasonably be linked to an individual.
2. What Doppler Processes
Depending on how you use the Services, Doppler processes:
Customer Content
The Data Layer
Output
Usage Data
Account and billing information
Support communications
3. How Doppler Uses Customer Content, Usage Data and Output
Doppler uses this information to:
deliver and operate the Services
build and maintain the Data Layer for your organization
provide support and troubleshoot issues
monitor, secure and improve the reliability of the Services
detect and prevent misuse
meet legal and regulatory requirements
Customer Content, Output and the Data Layer are used only for your organization and are not shared with, or exposed to, any other customer.
4. AI and Model Usage
The Services use artificial intelligence, including third-party foundation models, to process Customer Content and generate Output.
Doppler does not use Customer Content, Output or the Data Layer to train, fine-tune or otherwise develop any general-purpose or third-party foundation model. This applies to every customer by default and is not subject to an opt-in or opt-out.
Doppler contracts with each model provider on terms that prohibit training on any data Doppler sends, and uses enterprise or zero-retention tiers where a provider offers them.
Doppler uses aggregated and de-identified Usage Data to improve the Services.
Output is generated by artificial intelligence and may be incomplete or inaccurate. Doppler provides source citations so each extracted value can be traced to its source document. Output should be reviewed before it is relied on.
5. Human Review and Access Controls
Doppler personnel access Customer Content only to:
provide support requested by your organization
troubleshoot and maintain the Services
investigate suspected misuse or a security incident
comply with a legal obligation
Access is granted on a least-privilege basis, is logged, and is limited to personnel bound by written confidentiality obligations. Doppler does not review Customer Content for product research or model development. Where the Order Form specifies restricted access, Doppler accesses Customer Content only with your prior approval.
6. Third-Party Providers and Subprocessors
Doppler may use third-party providers, including hosting, infrastructure, model, monitoring, billing and communications providers, to deliver the Services. Where a provider processes Customer Content or Personal Data, it does so under a written agreement imposing data protection and security obligations no less protective than those in this Policy, and Doppler remains responsible for its performance. Doppler maintains a current list of its subprocessors and provides it on request to admin@doppleragents.com, and notifies customers who have provided a notice contact before a new subprocessor begins processing their Customer Content.
7. Retention and Deletion
Doppler retains Customer Content, Output and the Data Layer for as long as necessary to provide the Services and for legitimate business purposes such as security, dispute resolution and legal compliance. Retention periods vary by plan, configuration and applicable legal requirements. On request, or following termination, Doppler deletes or de-identifies Customer Content in accordance with its then-current deletion practices, other than copies retained in routine backups or as required by law.
Customer Content sent to model and infrastructure providers is subject to zero retention, or to retention of up to thirty (30) days, depending on the provider arrangement.
8. Security and Compliance
Doppler maintains an information security program with administrative, technical and physical safeguards designed to protect Customer Content and Personal Data against unauthorized access, use, disclosure, alteration and destruction.
Controls include encryption of data in transit and at rest, logical separation of each customer's environment, role-based access control with multi-factor authentication for production systems, logging and monitoring, mandatory confidentiality obligations and security training for personnel, security review of providers before onboarding, and a documented incident response process. Doppler notifies affected customers without undue delay after confirming a security incident affecting their Customer Content.
Doppler's control environment is designed and operated in alignment with the SOC 2 Trust Services Criteria. Doppler completes customer security reviews and questionnaires on reasonable request and makes available any third-party assessment report it holds.
9. Changes to This Policy
Doppler may update this Policy. Material changes are posted here with a new "Last updated" date. For customers with an active Order Form, a change that materially reduces Doppler's commitments takes effect at the start of the next renewal term.

