Controller
For your account data: name, email, hashed password, avatar and product usage. We decide why and how it is processed.
Compliance
Everything your legal team needs to evaluate Doku: where data is processed, who else is involved, and under which safeguards.
Doku is part of Google for Startups.
Both the European GDPR and Colombia's Law 1581 distinguish the same two roles, and Doku acts as each depending on the data.
For your account data: name, email, hashed password, avatar and product usage. We decide why and how it is processed.
For the content your team uploads: tasks, projects, files, comments and AI conversations. We process it on your instructions; your organisation remains the controller.
What we do with each kind of data, on which infrastructure, and which audits back that provider.
Attachments you upload are stored encrypted in object storage, separate from the database. Every download checks that you belong to the space before serving the file.
Accounts, tasks and projects live in a managed database, encrypted at rest and backed up automatically. Every query verifies space membership before returning a single row.
All traffic between your browser and Doku travels encrypted over TLS. The app is delivered from a global network with denial-of-service protection built in.
What you write to the assistant is processed on Google Cloud enterprise infrastructure. We do not train models on your team's content.
Optional: they only come into play if you choose to connect them. We never receive your password for those services, only a session identifier.
No ambiguity, because it's the first question any serious review asks:
This means an international transfer of data outside the EEA. It relies on the European Commission's Standard Contractual Clauses, incorporated into the data processing agreements with each provider, and on our providers' certification under the EU-US Data Privacy Framework.
We are in the process of certifying to ISO 27001. In the meantime, we'd rather you read this here than discover it in an audit:
If you are in the European Union or the United Kingdom, the GDPR gives you these rights over your personal data:
To exercise them, email [email protected] from your account address. We respond within 30 days at most, as Article 12(3) GDPR requires.
If you or your company are in Colombia, the habeas data regime — Statutory Law 1581 of 2012 and Decree 1377 of 2013 — grants you these rights as a data subject:
To exercise them, email [email protected] from your account address. We answer queries within 10 business days and complaints within 15, the deadlines set by articles 14 and 15 of Law 1581.
Encryption in transit, per-workspace isolation, role-based access control, hashed passwords and share links, and a membership check on every database query.
For data processing agreements (DPAs), security questionnaires, or any privacy question: