Compliance

Data protection and compliance

Everything your legal team needs to evaluate Doku: where data is processed, who else is involved, and under which safeguards.

Doku is part of Google for Startups.

Built onCloudflareGoogle Cloud

Our role under the GDPR and Law 1581

Both the European GDPR and Colombia's Law 1581 distinguish the same two roles, and Doku acts as each depending on the data.

Controller

For your account data: name, email, hashed password, avatar and product usage. We decide why and how it is processed.

Processor

For the content your team uploads: tasks, projects, files, comments and AI conversations. We process it on your instructions; your organisation remains the controller.

How we protect each thing

What we do with each kind of data, on which infrastructure, and which audits back that provider.

Your files, protected

Global network

Attachments you upload are stored encrypted in object storage, separate from the database. Every download checks that you belong to the space before serving the file.

Cloudflare
ISO 27001ISO 27018ISO 27701SOC 2 Type IIPCI DSS Level 1

Your database, isolated

United States

Accounts, tasks and projects live in a managed database, encrypted at rest and backed up automatically. Every query verifies space membership before returning a single row.

Google Cloud
ISO/IEC 27001ISO 27017ISO 27018ISO 27701SOC 1/2/3CSA STAREU Cloud Code of Conduct

Secure connections

Global network

All traffic between your browser and Doku travels encrypted over TLS. The app is delivered from a global network with denial-of-service protection built in.

Cloudflare
ISO 27001SOC 2 Type IIPCI DSS Level 1

Artificial intelligence features

United States

What you write to the assistant is processed on Google Cloud enterprise infrastructure. We do not train models on your team's content.

Google Cloud
Covered by Google Cloud's certifications

Sign-in and integrations

Global

Optional: they only come into play if you choose to connect them. We never receive your password for those services, only a session identifier.

Google CloudGitHubFigma
Only if you choose to connect them

Where your data lives

No ambiguity, because it's the first question any serious review asks:

  • Database (accounts, tasks, projects): Google Cloud, in the United States.
  • Files and avatars: Cloudflare object storage.
  • Web app and API: Cloudflare's global network.
  • Backups: managed by the database provider, in the same region.

This means an international transfer of data outside the EEA. It relies on the European Commission's Standard Contractual Clauses, incorporated into the data processing agreements with each provider, and on our providers' certification under the EU-US Data Privacy Framework.

Our own certifications

We are in the process of certifying to ISO 27001. In the meantime, we'd rather you read this here than discover it in an audit:

  • The certifications above belong to our infrastructure providers. Certified infrastructure does not automatically certify whoever runs on it — it does mean the data centre, network and storage layers are independently audited.
  • We're a small team and we're advancing in phases, prioritising the controls that genuinely protect customer data over the paperwork.
  • If your procurement process requires ISO 27001 or SOC 2, write to us: we'll tell you exactly where we stand and keep you posted on progress.

Ask us about certifications

Your rights

If you are in the European Union or the United Kingdom, the GDPR gives you these rights over your personal data:

  • Access: obtain a copy of the data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your account and personal data.
  • Restriction: ask us to restrict processing while a complaint is resolved.
  • Portability: receive your data in a structured, commonly used format.
  • Objection: object to processing based on legitimate interest, including analytics.
  • Withdraw consent: at any time, without affecting processing carried out before.

To exercise them, email [email protected] from your account address. We respond within 30 days at most, as Article 12(3) GDPR requires.

If you believe we handle your data improperly, you can lodge a complaint with your national supervisory authority — in Spain, the Agencia Española de Protección de Datos (aepd.es).

Data protection in Colombia (Law 1581)

If you or your company are in Colombia, the habeas data regime — Statutory Law 1581 of 2012 and Decree 1377 of 2013 — grants you these rights as a data subject:

  • Know, update and rectify your personal data, and access it free of charge.
  • Request proof of the authorisation granted for processing.
  • Be informed about how your data has been used.
  • Revoke the authorisation and request deletion when processing does not respect the law's principles and guarantees.
  • File complaints with the supervisory authority for violations of the data protection regime.

To exercise them, email [email protected] from your account address. We answer queries within 10 business days and complaints within 15, the deadlines set by articles 14 and 15 of Law 1581.

The supervisory authority is the Superintendencia de Industria y Comercio — SIC (sic.gov.co), where you can file complaints once the direct claim with us has been exhausted. International data transfers (article 26) are disclosed in the Privacy Policy and rest on the authorisation you grant by accepting it and on the data processing agreements with each provider.

Security measures

Encryption in transit, per-workspace isolation, role-based access control, hashed passwords and share links, and a membership check on every database query.

See the security page

Privacy contact

For data processing agreements (DPAs), security questionnaires, or any privacy question:

[email protected]