Privacy Policy
Last updated: April 13, 2026
1. Who We Are
Dockbase ("we", "us", "our") is a delivery governance platform operated by Dockbase. We act as the data controller for the personal data processed through the Dockbase service. This policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
2. Data We Collect
We collect the minimum data necessary to operate the service:
- Account data: Email address and hashed password for authentication.
- Profile data: First and last name for attribution in governance records.
- Workspace data: Workspace names, team member associations, and role assignments.
- Governance records: Release decisions, sign-offs, evaluations, and audit logs created by your team.
- Usage data: Subscription status and billing metadata.
3. How We Use Your Data
- Service operation: Authenticating users, enforcing workspace access, and delivering governance features.
- Attribution: Displaying author names on decision entries, sign-offs, and audit records.
- Communication: Sending workspace invitations and essential service notifications.
- Billing: Managing subscription status and trial periods.
We do not sell your data, use it for advertising, or share it with third parties beyond what is necessary to operate the service.
4. Legal Basis for Processing
- Contract performance: Processing necessary to provide the service you signed up for.
- Legitimate interest: Security, fraud prevention, and service improvement.
- Consent: Where explicitly obtained (e.g., optional communications).
5. Data Sharing
We share personal data only with the following categories of recipients:
- Merchant of Record: Paddle.com handles the sale of our product, subscription management, payments, tax compliance, and invoicing on our behalf.
- Service providers: Infrastructure hosting (Supabase), transactional email delivery (Resend).
- Professional advisers: Legal and accounting advisers where required.
- Authorities: Where required by law or to protect our legal rights.
6. Data Isolation and Security
All workspace data is isolated at the database level using row-level security policies. There is no cross-tenant data access. Role-based access control (RBAC) is enforced for all operations. Data is encrypted in transit (TLS) and at rest. We implement appropriate technical and organisational measures to protect your data.
7. Data Retention
Governance records are retained for as long as your workspace exists. If you delete your account, all personal data and workspace data where you are the sole owner will be permanently removed. Data will be deleted or anonymised when no longer needed for the purposes for which it was collected. Audit logs for workspaces with multiple members may retain your name for governance continuity.
8. Your Rights
Under GDPR, you have the right to:
- Access: Export all your personal and workspace data from Workspace Settings.
- Rectification: Update your account information at any time.
- Erasure: Delete your account and all associated data from Workspace Settings.
- Portability: Download your data in a structured, machine-readable format (JSON).
- Restriction: Request restriction of processing by contacting us.
- Objection: Object to processing based on legitimate interest.
- Consent withdrawal: Withdraw consent at any time where processing is based on consent.
- Complaint: Lodge a complaint with a supervisory authority.
We will respond to rights requests within one month.
9. Cookies
Dockbase uses only essential cookies required for authentication and session management. We do not use analytics cookies, tracking pixels, or third-party advertising cookies.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the application. Continued use of Dockbase after changes constitutes acceptance.
11. Contact
For privacy-related inquiries, data access requests, or to exercise your GDPR rights, contact us at privacy@dockbaseapp.com.