doka-platform
Privacy Notice
See also the Terms of Use. · Back to sign in
1. Scope
This notice applies to the doka-platform software tools operated by Doka USA, Ltd. ("Doka," "we," "us") at digitaldoka.com and its subdomains (the "Platform"), including the developer hub and the applications that use its shared data layer. It describes the personal information the Platform processes about its users (Doka personnel). Business records within the Platform — such as customer and project information — are Doka business data and are handled under Doka's broader data-handling and confidentiality policies; this notice focuses on personal information about Platform users.
2. Information we process
- Account and identity information — provided through our authentication provider when your account is created and when you sign in: your name, email address, optionally a phone number, your password (stored by the authentication provider, never by Doka in readable form), and multi-factor authentication factors.
- Authorization information — the role and entitlements assigned to your account (for example, which applications and which records you may access), maintained by Doka administrators.
- Usage and technical information — records generated as you use the Platform, including sign-in events, request logs, IP address and device/browser information processed by our hosting and authentication providers, and short-lived session tokens.
- Change and audit records — when you make changes through the Platform (for example, editing access rights or submitting a change request), the Platform records what changed, when, and the account that made the change.
- Preferences — limited settings stored in your browser (such as your selected environment) for convenience.
3. How we use this information
- to authenticate you and enforce which data and features you are authorized to use;
- to operate, maintain, secure, and improve the Platform;
- to keep an audit trail of changes for security, accountability, and troubleshooting;
- to communicate with you about access and operational matters;
- to comply with legal obligations and enforce our Terms of Use.
We process this information for Doka's legitimate internal business and employment purposes. We do not sell personal information, and we do not use it for advertising.
4. Service providers
The Platform relies on the following providers, which process information on Doka's behalf for the purposes shown. Each processes only what is needed for its function.
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication and account management | Identity, credentials, MFA, sign-in events |
| Neon | Database hosting (United States, AWS) | Account records, authorization, business data, audit log |
| Netlify | Application hosting and delivery | Technical/request information (e.g. IP) |
| Google (Workspace, Drive) | Email intake and file transfer for scheduled data synchronization | Business data exports; the email address they are sent to |
| Zapier | Automating scheduled data synchronization | Business data exports in transit |
| GitHub (Actions) | Software delivery and encrypted backups | Encrypted database backups |
Doka may also disclose information where required by law, to protect the rights, safety, or property of Doka, its personnel, or others, or in connection with a corporate transaction.
5. Where information is stored
Platform data is stored primarily in the United States (database hosting on Amazon Web Services infrastructure in a U.S. region). Certain providers listed above may process limited technical information in other locations in the course of delivering their services.
6. Retention
- Account and authorization records are retained while your account is active and as needed afterward for legitimate business and legal purposes.
- Session tokens are short-lived (on the order of a minute) and are not stored by Doka.
- Change and audit records are retained to preserve an accountable history.
- Encrypted database backups are retained on a rolling basis (currently up to 90 days).
- Certain business data (such as project records) is synchronized from a system of record and refreshed on a schedule, replacing prior copies.
7. How we protect information
The Platform enforces access at the database level so that each user can reach only the data their role and entitlements permit; access controls are enforced by the system rather than by individual applications. We require multi-factor authentication, encrypt data in transit, encrypt backups, follow least-privilege practices for credentials, and maintain an audit trail of changes. No system can be guaranteed perfectly secure, but we work to protect information appropriately for its sensitivity.
8. Your choices and requests
- You can reset your password through the "Forgot password" option on the sign-in screen.
- You can update certain account details through your account settings.
- Account creation, changes to access, and deactivation are handled by Doka administrators; when your authorization ends, your access is deactivated.
- To ask a question about this notice or make a request regarding your personal information, contact IT-USA@doka.com. Depending on your location and applicable law, you may have rights regarding your personal information; we will handle such requests in accordance with applicable law and Doka policy.
9. Changes to this notice
We may update this notice from time to time. Material changes will be reflected by updating the effective date above and, where appropriate, by notice to users.
10. Contact
Doka USA, Ltd. — IT-USA@doka.com