Privacy

MATERIAL
FIRST SEEN 2026-08-27 · VERSION 20260827_rev01 · FIRST CAPTURED VERSION

What changed, in plain language

Docker replaced a short summary page (which mostly linked out to the real policy, a GDPR data processing addendum, and a subprocessor note) with the full text of its Privacy Policy, dated August 26, 2026. The big substantive addition is a new section covering Docker's AI services (Agentic Platform, cloud sandboxes, MCP Gateway): Docker now describes collecting usage and telemetry data, storing API keys and access tokens you add, and automatically creating sandbox snapshots that can contain your AI prompts and the model's answers. Snapshots are deleted after 7 days unless "implicitly saved," in which case they are kept until you delete them or close your account. The full text also spells out data sharing with ad networks, joint promotion partners, event sponsors, and buyers of the business, and states Docker can change this policy at any time with notice only by posting it. On the plus side, Docker says it does not use your prompts or model responses to train AI models. The old page's promise about signing GDPR agreements with every subprocessor is no longer on this page.

Changes that may affect you

Docker now collects AI usage data, stores your API keys, and can capture your promptsMATERIAL
DATA COLLECTION

If you use Docker's AI products, Docker records how you use them (when sandboxes start and stop, which tools get called) and will hold onto any API keys or access tokens you save there. It also automatically takes snapshots when you pause a sandbox, and those snapshots can contain the questions you typed into an AI and the answers you got back. That is a lot more than the basic account and website data covered before.

(iv) credentials you choose to store - API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services; and (v) snapshots created automatically when you pause a sandbox and deleted within seven (7) days unless you implicitly save them; snapshots may include prompts submitted to and outputs received from AI models you use, and any other information you include in them.

What you can do — Avoid typing sensitive or confidential information into Docker's AI sandboxes, and only store API keys there if you need to. Rotate any keys you no longer want Docker to hold.

Saved sandbox snapshots are kept indefinitely, and "implicitly save" is not definedMATERIAL
DATA RETENTION

Snapshots you do not save go away after 7 days, but ones that count as "implicitly saved" are kept until you delete them or close your account. The policy never explains what you have to do to "implicitly save" one, so you could end up storing prompts and outputs long-term without realizing it. The policy is also inconsistent: one section says only your most recent snapshot is kept, another says saved snapshots stay until you delete them.

Snapshots you do not implicitly save are deleted within seven (7) days of creation, after which the paused sandbox cannot be restored. Snapshots you implicitly save are retained until you delete them or your account is closed.

What you can do — Check your saved sandbox snapshots and delete any you don't need. Ask Docker at privacy@docker.com what counts as "implicitly saving" a snapshot.

Your data can go to ad networks, promotion partners, event sponsors, and corporate customersMATERIAL
DATA SHARING

The full policy now on this page describes several ways your information moves outward: third-party ad networks track your activity across sites, joint promotion partners get your details if you show interest in a shared offer, event sponsors can contact you for their own marketing if you visit their booth or session, and Docker reports to corporate customers how people at particular company domains use its products. Docker does say it does not sell personal information or share it for cross-context behavioral advertising.

If you show an interest in a sponsor at an event hosted by Docker, Inc., such as attending their virtual or physical, event speaking session or booth, we will provide your data to such sponsors who may contact you for their own direct advertising and marketing purposes.

What you can do — Refuse non-essential cookies in Docker's cookie banner, use the unsubscribe link in marketing emails, and submit preferences at https://preferences.docker.com/privacy/.

Docker can rewrite this policy any time, with notice only by posting itMATERIAL
UNILATERAL CHANGES

Docker can change the privacy policy for any reason it likes, and the only warning you get is a new version appearing on its website. It is on you to keep checking. Simply continuing to use Docker counts as agreeing to the new terms.

This Privacy Policy may be updated from time to time for any reason, at our sole discretion. We will notify you of any material changes to our Privacy Policy by posting the new Privacy Policy on our Website. You are advised to consult this Privacy Policy regularly for any changes.
Your data can be sold along with the businessMINOR
DATA SHARING

If Docker is bought, merged, broken up, or shut down, customer data is treated as one of the assets that gets handed over. Whoever buys it inherits your information.

Data About Docker Customers is generally one of the transferred business assets in these types of transactions.
The promise to sign GDPR agreements with every subprocessor is gone from this pageMINOR
OTHER

The old page stated plainly that Docker signs a GDPR-compliant data processing agreement with each subprocessor it uses. That sentence, and the note about Docker's standard DPA for customers, are no longer here. The new policy still points to a Docker Data Processing Agreement, but the specific commitment about subprocessors is no longer visible.

Docker uses third party subprocessors, such as cloud computing service providers and customer support software, to provide our services. We enter into a GDPR-compliant data processing agreement with each subprocessor, and require the same of them.

What you can do — If you rely on Docker's subprocessor commitments for compliance, ask Docker for the current subprocessor list and DPA at privacy@docker.com.

Changelog

  1. ± CHANGEDShort summary page replaced with the full privacy policy

    The page used to be a brief overview with links to the real policy, a GDPR addendum explainer, and a note about subprocessors. It is now the complete privacy policy text, so all the detailed practices are visible on this page.

    Docker's [Privacy Policy](https://www.docker.com/legal/docker-privacy-policy) details the different ways personal data received from users of our website ("Website") collected via the Website, email, SMS, telephone, WAP or other means may be collected, used, and disclosed by Docker.

    Docker, Inc., ("Docker" or "we") provides this Privacy Policy to inform users of our policies and procedures regarding the collection, use and disclosure of information and/or personal data received from users of our websites ("Website"), services, applications, or software ("Services"), where we determine the means and purposes of processing the data (i.e., where we are the "controller" of the data).

  2. + ADDEDNew section on Docker's AI services and what they collect

    Docker now describes what it collects when you use its AI products: billing details, records of the compute you run, usage and telemetry (when sandboxes start and stop, which MCP tools get called), any API keys or access tokens you save, and automatic snapshots that can contain your prompts and the AI's answers.

    **Docker AI Services (Docker Agentic Platform, Cloud Sandboxes, and MCP Gateway).** When you use Docker's self-service AI services, Docker collects and processes the following categories of information:

  3. + ADDEDSnapshot storage and deletion rules

    Pausing a sandbox automatically saves a snapshot. Snapshots you do not "implicitly save" disappear after 7 days. Ones you do save stay until you delete them or close your account. One section also says only your most recent snapshot is kept.

    Snapshots you implicitly save are retained until you delete them or your account is closed.

  4. + ADDEDDocker says it will not train AI models on your prompts

    When you plug in your own API key for a provider like Anthropic, OpenAI, Google, or Cursor, your prompts go to that provider under your own agreement with them. Docker states it does not use your prompts or the responses to train AI models.

    Docker does not select the model provider for you and does not use your prompts or the provider's responses to train AI models.

  5. + ADDEDDocker can change this policy at any time; using the service means you accept it

    The policy can be updated for any reason at Docker's discretion, and the only notice is posting the new version on the website. Continuing to use Docker counts as agreeing.

    This Privacy Policy may be updated from time to time for any reason, at our sole discretion. We will notify you of any material changes to our Privacy Policy by posting the new Privacy Policy on our Website.

  6. + ADDEDDetailed sharing practices now spelled out on this page

    The page now describes sharing with service providers, joint promotion partners, third-party ad networks, event sponsors who may market to you directly, domain-level usage reports given to corporate customers, and transfer of your data if the business is sold.

    we will provide your data to such sponsors who may contact you for their own direct advertising and marketing purposes

  7. − REMOVEDSubprocessor and DPA explanations removed from this page

    The old page said Docker signs a GDPR-compliant data processing agreement with each subprocessor and offers a standard DPA to customers. That specific promise is no longer on this page, though the policy still references a Docker Data Processing Agreement.

    Docker uses third party subprocessors, such as cloud computing service providers and customer support software, to provide our services. We enter into a GDPR-compliant data processing agreement with each subprocessor, and require the same of them.

  8. + ADDEDUS hosting and international transfers described

    Docker's AI services run on infrastructure in the United States. Data from Europe, the UK, and Switzerland is transferred under the Data Privacy Framework or Standard Contractual Clauses, and using the service counts as consent to the transfer.

    Docker's self-service AI services (including the Docker Agentic Platform, cloud sandboxes, and MCP Gateway) are hosted on infrastructure located in the United States.

  9. + ADDEDState privacy rights sections added (California, EEA/UK/Switzerland, other US states)

    The full text includes how to ask what data Docker holds, correct it, delete it, and who to contact. Docker states it does not sell or share personal information for cross-context behavioral advertising.

    The right to opt-out of the sale or sharing of your personal information by us. We do not sell or share for cross-context behavioral advertising any of the categories of personal information that we collect about California residents.

Full text changes

COLOUR MARKS THE SEVERITY OF A FLAGGED CLAUSE · + AND − MARK ADDED AND REMOVED

1#### Docker respects your preferences concerning the collection and use of your personal data. These are some of the measures we take to protect your personal data.
1Last Update: August 26, 2026
22
3### Privacy Policy
3Docker, Inc., ("Docker" or "we") provides this Privacy Policy to inform users of our policies and procedures regarding the collection, use and disclosure of information and/or personal data received from users of our websites ("Website"), services, applications, or software ("Services"), where we determine the means and purposes of processing the data (i.e., where we are the "controller" of the data).
44
5Docker's [Privacy Policy](https://www.docker.com/legal/docker-privacy-policy) details the different ways personal data received from users of our website ("Website") collected via the Website, email, SMS, telephone, WAP or other means may be collected, used, and disclosed by Docker.
5This Privacy Policy does not apply to data that we receive through other means, including offline and as part of employment relationships, or to personal data that we process on behalf of our customers. If you are looking for information about how we process personal data that one of our customers provided to us, please refer to the relevant controller's privacy statement. The relevant controller may, for example, be your employer if it is a user of Docker products and services. Where you subscribe to Docker's self-service AI services as an individual, this Privacy Policy applies to the personal data we collect from you as described below; where you use the Services under an agreement between Docker and your organization, Docker processes content on your organization's behalf as described in the Docker Data Processing Agreement.
66
7### Data Processing Addendum
7This Privacy Policy may be updated from time to time for any reason, at our sole discretion. We will notify you of any material changes to our Privacy Policy by posting the new Privacy Policy on our Website. You are advised to consult this Privacy Policy regularly for any changes. Unless applicable laws require us to obtain consent in a different manner, by using or accessing the Docker Services, you are accepting the practices described in this Privacy Policy, and you are consenting to our processing of your information as set forth in this Privacy Policy now and as amended by us. If you have any questions or comments about this Privacy Policy or our use of your personally identifiable information, please contact us using this form https://preferences.docker.com/privacy/.
88
9The [EU General Data Protection Regulation (GDPR)](https://en.wikipedia.org/wiki/General_Data_Protection_Regulation) came into effect on May 25, 2018. GDPR has a long reach and applies if you are based in the EU or do business in the EU. If you have any EU personal data in your Docker account, such as names, email addresses, ID numbers, or anything else that is personally identifiable, then GDPR applies. You are a Controller of personal data under GDPR, so you need to enter into GDPR-compliant data processing agreements with any online services and third party vendors you rely on, including Docker. These agreements are called a Data Processing Addendum, or DPA. The processing of EU personal data must be governed by a [GDPR-compliant data processing agreement](https://gdpr-info.eu/art-28-gdpr/). Docker provides a [standard DPA](https://docker.io/static/Data_Processing_Agreement.pdf) to extend GDPR privacy principles, rights, and obligations regarding personal data stored in the production system/technical instance of Docker's subscriptions and/or services provided by Docker and ordered by a Docker customer.
9**1\. Services Use and Information Collected**
1010
11### Subprocessors
11Docker collects information from individuals who visit the Website ("Visitors") and individuals who register to use the Services ("Customers") either individually or on behalf of an entity. Docker may also collect information about how you use the Services, such as activity data, feature usage and product version data. This information may be aggregated or identifiable as further described in this Privacy Policy. Docker may collect data to improve our operations and to understand how to provide you with the best experience.
1212
13Docker uses third party subprocessors, such as cloud computing service providers and customer support software, to provide our services. We enter into a GDPR-compliant data processing agreement with each subprocessor, and require the same of them.
13When registering to use or expressing an interest in obtaining additional information about the Services, Docker may require you to provide us with personal contact information, such as name, company name, address, phone number, and email address ("Required Contact Information"). When purchasing the Services, Docker may require you to provide us with financial qualification and billing information, such as billing name and address, partial credit card number, and the number of employees within the organization that will be using the Services ("Billing Information"). Docker may also ask you to provide additional information, such as company annual revenues, number of employees, or industry ("Optional Information"). Required Contact Information, Billing Information, and Optional Information are referred to collectively as "Data About Docker Customers." As you navigate the Website, Docker may also collect information through the use of commonly-used information-gathering tools, such as cookies and Web beacons ("Website Navigational Information"). Website Navigational Information includes standard information from your Web browser (such as browser type and browser language), your Internet Protocol ("IP") address, and the actions you take on the Website (such as the Web pages viewed and the links clicked). By choosing to provide any information to Docker, you are giving Docker permission to use and store such information consistent with this Privacy Policy.
14
15**Docker AI Services (Docker Agentic Platform, Cloud Sandboxes, and MCP Gateway).** When you use Docker's self-service AI services, Docker collects and processes the following categories of information: (i) account and billing information - your name, email address, billing address, and payment card details are collected directly by our payment processor, Stripe, for billing purposes; Docker does not store your full payment card number; (ii) compute and configuration records - information about the compute you start, including the duration of each run and its configuration; (iii) usage and telemetry data - sandbox lifecycle events (such as start and stop), MCP Gateway tool calls, and correlations between sandboxes and tool calls; (iv) credentials you choose to store - API keys and access tokens for third-party AI model providers and MCP-connected tools, which we store securely on your behalf in order to provide the Services; and (v) snapshots created automatically when you pause a sandbox and deleted within seven (7) days unless you implicitly save them; snapshots may include prompts submitted to and outputs received from AI models you use, and any other information you include in them. Service logs relating to your use of the AI services are written to Docker's logging infrastructure and are required for the operation and security of the Services.
16
17**2\. Use of Information Collected**
18
19Docker uses Data About Docker Customers to perform the services requested. Docker may also use Data About Docker Customers for marketing purposes. For example, Docker may use information you provide to contact you to further discuss your interest in the Services and to send you information regarding Docker and its partners, such as information about promotions or events. Docker uses credit card information you provide for payment, solely to check the financial qualifications of prospective Customers and to collect payment for the Services. Docker uses Website Navigational Information to operate and improve the Website. Docker may also use Website Navigational Information alone or in combination with Data About Docker Customers to provide personalized information about Docker. Docker uses the usage, telemetry, and compute records described in Section 1 to operate, secure, meter, bill for, and improve the Services, including to correlate resource usage with your account for billing and support purposes.
20
21**3\. Docker Website, Cookies and Navigation Information**
22
23**3.1 Website and Navigation Information**
24
25Docker may use commonly used information gathering tools, such as cookies and Web beacons, to collect information about your computer and software, how you navigate and interact with the Website, and other Website Navigational Information. This section describes the types of Website Navigational Information that may be collected on the Website and how this information may be used.
26
273.1(a) Cookies - Docker may use cookies to make interactions with the Website easy and meaningful. When you visit the Website, Docker's servers send a cookie to your computer. Standing alone, cookies do not include your name or contact information. They merely recognize your Web browser. Unless you choose to identify yourself to Docker, either by responding to a promotional offer, opening an account, or filling out a Web form, you remain anonymous to Docker. Docker uses cookies that are session-based and persistent-based. Session cookies exist only during one session. They disappear from your computer when you close your browser software or turn off your computer. Persistent cookies remain on your computer after you close your browser or turn off your computer. and are automatically deleted a certain amount of time after they have been set. If you have chosen to identify yourself to Docker, Docker uses session cookies containing encrypted information to allow Docker to uniquely identify you. Each time you log into the Services, a session cookie containing an encrypted, unique identifier that is tied to your account is placed on your browser. These session cookies allow Docker to uniquely identify you when you are logged into the Services and to process your online transactions and requests. Session cookies are required to use the Services. Docker may use persistent cookies that only Docker can read and use to identify browsers that have previously visited the Website. When you purchase the Services or provide Docker with personal information, a unique identifier is assigned to you. This unique identifier is associated with a persistent cookie that Docker places on your Web browser. Docker is especially careful about the security and confidentiality of the information stored in persistent cookies. For example, Docker does not store account numbers or passwords in persistent cookies. You may refuse to accept cookies by activating the setting on your browser which allows you to refuse the setting of cookies. If you disable your Web browser's ability to accept cookies, you will be able to navigate the Website, but you will not be able to successfully use the Services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you log on to our site. Docker may use information from session and persistent cookies in combination with Data About Docker Customers to provide you with information about Docker and the Services.
28
293.1(b) Web Beacons - Docker may use Web beacons alone or in conjunction with cookies to compile information about Customers and Visitors' usage of the Website and interaction with emails from Docker. Web beacons are clear electronic images that can recognize certain types of information on your computer, such as cookies, when you viewed a particular Website tied to the Web beacon, and a description of a Website tied to the Web beacon. For example, Docker may place Web beacons in marketing emails that notify Docker when you click on a link in the email that directs you to one of the Websites. Docker uses Web beacons to operate and improve the Website and email communications including for marketing purposes. Docker may use information from Web beacons in combination with Data About Docker Customers to provide you with information about Docker and the Services.
30
313.1(c) Flash Cookies - Docker may use local shared objects, also known as Flash cookies, to store your preferences or display content based upon what you view on our site to personalize your visit. Third parties, with whom Docker partners to provide certain features on our site or to display advertising based upon your Web browsing activity, use Flash cookies to collect and store information. Flash cookies are different from browser cookies because of the amount of, type of, and how data is stored. Cookie management tools provided by your browser will not remove Flash cookies.
32
333.1(d) IP Addresses - When you visit the Website, Docker may collect your Internet Protocol ("IP") addresses to track and aggregate non-personal information. For example, Docker may use IP addresses to monitor the regions from which Customers and Visitors navigate the Website.
34
353.1(e) Third Party Cookies - From time to time, Docker may engage third parties to track and analyze usage and volume statistical information from individuals who visit the Website. Docker may also use other third-party cookies to track the performance of Docker advertisements. The information provided to third parties does not include personal information, but this information may be re-associated with personal information after Docker receives it. Docker may also contract with third-party advertising networks that collect IP addresses and other Website Navigational Information on the Website and emails and on third-party websites. Ad networks follow your online activities over time by collecting Website Navigational Information through automated means, including through the use of cookies. They use this information to provide advertisements about products and services tailored to your interests. You may see these advertisements on other Websites. This process also helps us manage and track the effectiveness of our marketing efforts.
36
37**4\. Public Forums, Refer a Friend, and Customer Testimonials**
38
39Docker may provide bulletin boards, blogs, or chat rooms on the Website. Any personal information you choose to submit in such a forum may be read, collected, or used by others who visit these forums, and may be used to send you unsolicited messages. We encourage you not to post any sensitive details on these public forums. Customers and Visitors may elect to use Docker's referral program to inform friends about the Website. When using the referral program, Docker requests the friend's name and email address. Docker will automatically send the friend a one-time email inviting him or her to visit the Website. Docker does not store this information. Docker may post a list of Customers and testimonials on the Website that contain information such as Customer names and titles. Docker obtains the consent of each Customer prior to posting any information on such a list or posting testimonials.
40
41**5\. Third party providers**
42
43**Third-Party AI Model Providers.** Docker's AI services may allow you to connect your own API key for third-party AI model providers of your choice (such as Anthropic, OpenAI, Google, or Cursor). When you do so, your prompts and the provider's responses are transmitted to that provider under your own agreement with the provider, and the provider's processing of that information is governed by its privacy policy, not this one. Docker does not select the model provider for you and does not use your prompts or the provider's responses to train AI models. If you save a sandbox image or snapshot, it may contain prompts and responses from your session. We retain only your most recent snapshot; earlier snapshots and images are deleted within 7 days. Your most recent snapshot remains until you delete it or your account is deleted.
44
45**6\. Disclosures of Information Collected**
46
47Docker may disclose Data About Docker Customers to Docker's service providers so that these service providers can contact Customers and Visitors who have provided contact information on our behalf. Docker may also disclose Data About Docker Customers to Docker's service providers to ensure the quality of information provided. Docker also provides information on how particular domains (e.g., www.companyx.com ) access and use our Website, Services, and particular features or uploads to customers for their business purposes, for example, so they can improve or target their software and other offerings.
48
49From time to time, Docker may collaborate with other companies to jointly offer products or services. If you purchase or specifically express interest in a jointly-offered product or service from Docker, Docker may disclose Data About Docker Customers collected in connection with your purchase or expression of interest to our joint promotion collaborator(s), once Docker has notified you of the information to be disclosed and obtained your consent to the disclosure of the information. Docker does not control our joint promotion collaborators' use of the Data About Docker Customers we collect, and their use of the information will be in accordance with their own privacy policies. Docker may use third-party service providers to manage credit card processing. Neither Docker nor such service providers will be permitted to store, retain, or use Billing Information except for the sole purpose of credit card processing on Docker's behalf. Docker reserves the right to use or disclose information provided if required by law or if Docker reasonably believes that use or disclosure is necessary to protect Docker's rights and/or to comply with a judicial proceeding, court order, or legal process.
50
51Under the EU-U.S. and Swiss-U.S. Data Privacy Framework, Docker is responsible for the processing of personal data received from Customers from the EU, the UK, and Switzerland and onward transfers to a third party acting as an agent on our behalf. We comply with the Data Privacy Framework Principles for such onward transfers and remain liable in accordance with the Data Privacy Framework Principles if third-party agents that we engage to process such information about you on our behalf do so in a manner inconsistent with the Data Privacy Framework Principles, unless we prove that we are not responsible for the event giving rise to the damage.
52
53**7\. Users from outside the United States**
54
55Docker and its Services are based and provided primarily in the U.S., and Docker's offices are headquartered in the U.S. Docker's self-service AI services (including the Docker Agentic Platform, cloud sandboxes, and MCP Gateway) are hosted on infrastructure located in the United States. Please be aware that information you provide to Docker, or that we obtain as a result of your use of the Services, may be processed and transferred to the U.S. and other countries where we and our service providers operate and may be subject to local laws. Where we transfer personal data from the European Economic Area, the United Kingdom or Switzerland, we do so in accordance with applicable cross-border transfer mechanisms under the GDPR, UK GDPR and the Swiss Federal Act on Data Protection, including, as applicable, the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework and/or Standard Contractual Clauses and equivalent instruments. For users in other jurisdictions, we take steps designed to ensure that any international transfers comply with applicable local law and that appropriate safeguards are in place. By using the Website, participating in any of the Services, or by providing Docker with your information, you consent (unless applicable laws require us to obtain consent in a different manner) and acknowledge that your information may be transferred to, stored in and processed in the U.S. and other countries as described in this Privacy Policy, and Docker will take all steps reasonably necessary to ensure that your data is treated securely in accordance with this Privacy Policy.
56
57**8\. Supplemental Privacy Notices for the EEA, UK, Switzerland, California and other US States**
58
59Depending on your country, region or state of residence the Supplemental Privacy Notices A through C of this Privacy Policy may also apply to you.
60
61**9\. Communications Preferences; Opt In Policy**
62
63Docker offers Customers and Visitors who provide contact information a means to choose how Docker uses the information provided. You may manage your receipt of marketing and non-transactional communications by clicking on the "unsubscribe" link located on the bottom of Docker's marketing emails. Additionally, you may send a request specifying your communications preferences by contacting us using this form https://preferences.docker.com/privacy. If, at any time after registering, you change your mind about receiving information from us or about the use of information volunteered by you, please send us a request specifying your new choice. Please contact us as specified herein.
64
65**10\. Correcting and Updating Your Information**
66
67Customers may view, update or change their registration information by logging in to their accounts at www.docker.com. Requests to access, change, or delete your information will be handled within 30 days.
68
69**11\. Security**
70
71Docker uses administrative, technical, and physical security measures intended to protect Data About Docker Customers. However, we cannot guarantee that hackers or unauthorized personnel will not gain access to your personal information despite our efforts. You should note that in using the Website and our related services, your information will travel through third party infrastructures which are not under our control. We cannot protect, nor does this Privacy Policy apply to, any information that you transmit to other users of the Website.
72
73**12\. Change of Control**
74
75As Docker develops its business, it may buy or sell assets or business offerings. Data About Docker Customers is generally one of the transferred business assets in these types of transactions. Docker may also transfer such information in the course of considering or engaging in corporate divestitures, mergers, or dissolution.
76
77**13\. Contacting Us**
78
79Questions regarding this Privacy Policy or the information practices of the Website should be directed to this form https://preferences.docker.com/privacy/ or by mailing Docker Privacy, 3790 El Camino Real, #1052, Palo Alto, CA 94306 USA.
80
81**14\. Events**
82
83As part of the registration process for events hosted by Docker which you register to attend, we may request personal data such as: your name, address, email address and country, and details relevant to your occupation or employer and familiarity with the Services. This information is required to process your registration for the event and to provide you with relevant event materials. This data may be disclosed to event sponsors contracted with Docker under the terms of the event and our Privacy Policy. If you show an interest in a sponsor at an event hosted by Docker, Inc., such as attending their virtual or physical, event speaking session or booth, we will provide your data to such sponsors who may contact you for their own direct advertising and marketing purposes. In that case, the exhibitors' use of your information would be subject to the exhibitors' privacy policies. For events sponsored by Docker, the event host may provide your personal data to Docker, subject to your consent. Docker will use the data as set forth in the Use of Information section of this Privacy Policy.
84
85**15\. Supplemental Privacy Notices**
86
87**Supplement A - Supplemental EEA+ Privacy Notice**
88
89Our Privacy Policy explains how Docker collects and uses personal data when you use the Services. We address this Supplemental EEA+ Privacy Notice to you if you use our Services and are located in the European Economic Area (EEA), United Kingdom (UK) or Switzerland (collectively EEA+).
90
91If you are located in the EEA, the EU General Data Protection Regulation applies to the processing of your personal data. If you are located in the UK, the UK General Data Protection Regulation applies to the processing of your personal data. If you are located in the EEA or UK, references to the "GDPR" below are references to the General Data Protection Regulation as it applies in the country where you are located. If you are located in Switzerland, the provisions of the Swiss Federal Data Protection Act (the "FDPA") apply to you, and references to the GDPR below shall be interpreted analogously for the purposes of applying the FDPA.
92
93**1\. Who is the Data Controller?**
94
95Docker Inc. is the responsible controller for personal data that you submit through our Website. Docker Inc.'s representative in the EU is Docker Germany GmbH and in the UK is Docker (UK) Limited.
96
97**2\. What are the legal bases for processing?**
98
99To the extent required by applicable law, we collect and process personal data of individuals located in the EEA+ only where there exists a legal basis for doing so. Such legal bases are as follows:
100
101- It is in accordance with your consent, per Art. 6(1)(a) of the GDPR, when you accept non-essential cookies via our cookies banner, and when you implicitly save a snapshot of your sandbox session for retention beyond the standard seven (7) day period.
102- It is necessary for us to perform a contract with you specifically, the terms and conditions that apply to our Services or take steps at your request prior to entering into the contract, per Art. 6(1)(b) of the GDPR, including processing your billing information, compute and configuration records, stored credentials, and snapshots created automatically when you pause a sandbox, to provide Docker's AI services you request.
103- It is necessary to comply with our legal obligations, per Art. 6(1)(c), such as if we are required by law to disclose personal data to law enforcement agencies or governmental authorities.
104- It is necessary for us or third parties to pursue legitimate interests that are not outweighed by your privacy and other fundamental interests, per Art. 6(1)(f) of the GDPR. Those legitimate interests are to provide corporate customers and other users of our Services with a good and safe experience, administer and enforce our contractual and legal rights, develop new services and features that we can offer to you and others, and manage our business operations and relationships with you and third parties, including collecting service usage and telemetry data (such as sandbox lifecycle events and MCP tool-call metadata) to operate, secure, meter, and improve the Services.
105- It is necessary for our legitimate interests, per Art. 6(1)(f) of the GDPR, to exercise our legal rights or defend legal claims.
106- It is necessary, per Art. 6(1)(f) of the GDPR, to give effect to a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider.
107
108**3\. On What Basis Do We Transfer Personal Data Across Borders?**
109
110The European Commission's adequacy decision for the EU-U.S. Data Privacy Framework (EU-U.S. DPF) entered into force on July 10, 2023.
111
112Docker, Inc. and its U.S. subsidiary (Infosiftr, LLC.) adhere to the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework Principles regarding the collection, use, and retention of personal data that is transferred from the European Union and Switzerland to the U.S.
113
114Docker complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Docker has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. Docker has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/. Where we transfer personal data from the EEA, the UK or Switzerland to countries that are not subject to an adequacy decision or where the Data Privacy Framework program does not apply to a particular transfer, we implement other appropriate safeguards, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, and comparable contractual mechanisms under the Swiss Federal Act on Data Protection, together with supplementary technical and organizational measures, where required.
115
116**4\. How Long Do We Retain Personal Data?**
117
118In general, we store personal data only as long as necessary to fulfill the purpose for which we collected it (the "General Retention Period"), except in the following situations:
119
120- Where applicable laws require us to retain your personal data for a legally prescribed period beyond the General Retention Period, in which case we will keep that personal data for the legally prescribed time period before deleting it;
121- Where your personal data is relevant to potential legal claims by or against us, in which case we will keep that personal data for as long as the legal claims can be made or, if it has been made, for as long as the personal data is relevant to the resolution of the claims or any appeal thereto;
122- Where we are instructed by a court order, subpoena, or other legal directive to retain your personal data beyond the General Retention Period; and
123- Where we need a reasonable period of additional time to verify that the purposes for which we collected your data no longer apply and to delete the data following such verification.
124
125If none of these exceptions apply to certain personal data, we will retain personal data for as long as necessary to fulfill the purpose for which we collected it, which in most cases does not exceed 12 months. Pausing a sandbox automatically creates a snapshot so your session can be restored. Snapshots you do not implicitly save are deleted within seven (7) days of creation, after which the paused sandbox cannot be restored. Snapshots you implicitly save are retained until you delete them or your account is closed.
126
127**5\. Do You Have to Provide Personal Data?**
128
129There is no law or contract stating that individuals in the EEA+ have to use our Services. We will try to tell you what personal data we need from you to provide certain Services or a certain level of quality of Services to you. In those cases, if you do not provide the personal data that we request from you, we will not be able to provide you with the Services or level of quality of Services that you request from us.
130
131**6\. Your Rights**
132
133You have the following rights, subject to conditions and in some cases limitations under the data protection laws that apply to you:
134
135- To object, on grounds relating to your particular situation, to the processing of your personal data by us. This includes the right to object to our processing of your personal data for direct marketing and the right to object to our processing of your personal data where we are performing a task in the public interest or pursuing our legitimate interests or those of a third party. If we process your personal data based on our legitimate interests or those of a third party, or in the public interest, you can object to this processing, and we will cease processing your personal data, unless the processing is based on compelling legitimate grounds or is needed for legal reasons. Where we use your personal data for direct marketing for our own products and services, you can always object and opt out of future marketing messages using the unsubscribe link in such communications.
136- To obtain from us confirmation as to whether your personal data is being processed, and, where that is the case, to request access to details about how we process your personal data and copies of the personal data.
137- To transfer or receive a copy of your personal data in a usable and portable format if we process it on the basis of your consent or a contract with you.
138- To obtain from us the rectification of inaccurate personal data concerning you.
139- To ask us to erase your personal data to the extent it is not required for legally required purposes or an exception to erasure applies under applicable law.
140- To withdraw your consent at any time with future effect if we process your personal data on the basis of consent.
141- To request restriction of processing of your personal data, in which case, it would be marked and processed by us only for certain purposes.
142
143Docker is subject to the authority of the Federal Trade Commission regarding its adherence to the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
144
145You also have the right to lodge a complaint with a supervisory authority, but we encourage you to first contact us with any questions or concerns. You may view a list of supervisory authorities in the EEA, UK and Switzerland and their respective contact information here: EEA: https://edpb.europa.eu/about-edpb/board/members\_en; United Kingdom: https://ico.org.uk/global/contact-us/; Switzerland: https://www.edoeb.admin.ch/de/kontakt
146
147Under certain conditions, more fully described on the Data Privacy Framework website, including when other dispute resolution procedures have been exhausted, you may invoke binding arbitration.
148
149In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Docker commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner's Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
150
151You may also contact Docker by emailing privacy@docker.com or by sending postal mail to: Docker, Inc., 3790 El Camino Real # 1052, Palo Alto, CA 94306, (415) 941-0376
152
153**Supplement B - Supplemental Privacy Notice for California Residents**
154
155These disclosures supplementing our Privacy Policy are provided by Docker and apply solely to residents of the State of California ("consumers" or "you") with respect to personal information Docker processes as a business. Any terms defined in the California Consumer Privacy Act of 2018, as amended from time to time, including by the California Privacy Rights Act of 2020 and its implementing regulations ("CCPA") have the same meaning when used in these disclosures. These disclosures do not reflect our collection, use, or disclosure of California residents' personal information, or data subject rights, where an exception or exemption under the CCPA applies.
156
157**1\. Personal Information Collected by Docker**
158
159We have set out below categories of personal information about California residents we have collected, and as applicable disclosed, for a business purpose in the preceding 12 months. The table is followed by a description of the purposes for which we collected personal information. In the preceding 12 months we did not sell or share for cross context behavioral advertising, the personal information of California residents.
160
161**2\. Business or Commercial Purpose for Collecting Personal Information**
162
163We use the personal information for the following business purposes:
164
165- To verify your identity;
166- To perform the services requested by individuals who register or visit our sites;
167- For marketing purposes, such as sending information about Docker and its partners and promoting events;
168- To check the financial qualifications of prospective customers and collect payment for the services;
169- To operate and improve our products and our sites;
170- To provide personalized information about Docker;
171- To process and investigate reports under Docker codes and policies for employees;
172- To respond to law enforcement requests and as required by applicable law or court order;
173- To prepare for and give effect to any mergers, acquisitions, business sales or similar transactions; and
174- To otherwise establish, defend or protect Docker's rights or interests, including in the context of anticipated or actual litigation with third parties.
175
176We do not have actual knowledge that we sell or share for cross context behavioral advertising, the personal information of California residents under 16 years of age.
177
178**3\. CCPA Rights as amended by the CPRA**
179
180As a California resident, you have the following rights under the CCPA:
181
182- The right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, the categories of third parties to whom we disclose personal information, and the specific pieces of personal information we have collected about you. You may only exercise your right to know twice within a 12-month period.
183- The right to delete personal information that we have collected from you, subject to certain exceptions.
184- The right to correct inaccurate personal information that we maintain about you.
185- The right to opt-out of the sale or sharing of your personal information by us. We do not sell or share for cross-context behavioral advertising any of the categories of personal information that we collect about California residents.
186- The right to limit our use and disclosure of sensitive personal information to purposes specified in Cal. Civil Code 1798.121(a). We do not use or disclose sensitive personal information for purposes other than those specified in Cal. Civil Code 1798.121(a).
187- The right not to receive discriminatory treatment by the business for the exercise of privacy rights conferred by the CCPA, in violation of California Civil Code § 1798.125, including an employee's, applicant's, or independent contractor's right not to be retaliated against for the exercise of their CCPA rights.
188
189**4\. How to Exercise CCPA Rights**
190
191To submit a request to exercise your rights to know, delete or correct, please populate our web form https://preferences.docker.com/privacy/ or call +1 415.941.0376
192
193Verification: Only you, or someone legally authorized to act on your behalf, may make a request related to your personal information. You may designate an authorized agent by taking the steps outlined under "Authorized Agent" further below. In your request or in response to us seeking additional information, you, or your authorized agent, must provide sufficient information to allow us to reasonably verify that you are, in fact, the person whose personal information was collected which will depend on your prior interactions with us and the sensitivity of the personal information being requested. We may ask you for information to verify your identity and, if you do not provide enough information for us to reasonably verify your identity, we will not be able to fulfill your request. We will only use the personal information you provide to us in a request for the purposes of verifying your identity and to fulfill your request.
194
195Authorized Agents: You can designate an authorized agent to make a request under the CCPA on your behalf if: the authorized agent is a natural person or a business entity and the agent provides proof that you gave the agent signed permission to submit the request; and you directly confirm with Docker that you provided the authorized agent with permission to submit the request. If you provide an authorized agent with power of attorney pursuant to Probate Code sections 4121 to 4130, it may not be necessary to perform these steps and we will respond to any request from such authorized agent in accordance with the CCPA.
196
197Contact Us: If you have any questions or comments about these disclosures or our practices, please contact us at: Email address: privacy@docker.com; Phone: +1 415.941.0376; Postal address: Docker Privacy, 3790 El Camino Real, # 1052, Palo Alto, CA 94306 USA
198
199**Supplement C - Supplemental Privacy Notice for other US States**
200
201Depending on your state of residence, one or more U.S. state data privacy laws other than the CCPA may apply to our processing of your personal information, including the Colorado Privacy Act ("CPA"), the Connecticut Data Privacy Act ("CTDPA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Utah Consumer Privacy Act ("UCPA"), and other comprehensive state consumer privacy laws that may be in effect in the state where you reside. However, these laws also include various exceptions and exemptions that may apply to our processing of your personal information, such as where the information is publicly available, or where the information pertains to your role as an employee or professional.
202
203If an exception or exemption applies, the privacy rights described in this Supplemental Privacy Notice for other US States may not apply to some or all of the personal information we hold about you. Docker does not engage in profiling/automated decision making that produces legal or similarly significant effects.
204
205**1\. Personal Information Collected by Docker and Use.**
206
207Docker collects certain categories of personal information when you use the Services, including identifiers, internet or other related network activity, commercial information, geolocation data tied to your IP address, and other personal information, and, for Docker's AI services, the categories described in Section 1 of the Privacy Policy (including usage and telemetry data, stored credentials, and content you choose to retain). A more detailed description of the personal information we collect and how we use it is provided in the "Services Use and Information Collected," and "Use of Information Collected" sections of the Privacy Policy.
208
209Docker may collect personal identifiers from you automatically. These identifiers include IP address, device identifiers, advertising ID and other information about your browser or device. We may collect this information via cookies and other tracking technologies and use it to enhance, customize, improve and notify you about our Services. This is further described in the Privacy Policy.
210
211**2\. Disclosure of Personal Information.**
212
213In connection with providing you the Services, we may disclose your personal information to third parties and other entities as described in the Privacy Policy.
214
215**3\. Privacy Rights.**
216
217Depending on the applicable laws in your state of residence, you may have the right to the following: request to confirm whether we process your personal information and to access such personal information; request to correct inaccuracies in your personal information; request deletion of your personal information, subject to certain exceptions; request to obtain a copy of your personal information; request to opt-out of processing of personal information for purposes of targeted-advertising; request to opt-out of the "sale" of personal information; and opt-out of profiling in furtherance of decisions that produce legal or similarly significant effects.
218
219To request to exercise your rights please contact privacy@docker.com. We may need to verify your identity to process your request. If we are unable to verify your identity, we reserve the right to not process your request. If we refuse to take action on a request, we will provide instructions on how you may appeal the decision. We will respond to requests consistent with applicable law.
220
221You may use an authorized agent to submit a request on your behalf, but we may ask your agent to provide information to verify that they have the proper authority to act on your behalf or ask you to verify your identity with us directly. The exercise of any of your rights will not result in different pricing, service levels, and/or use of any no-fee Services.