logoOKR Dash
☰
  • Sign in / Register
  • Product
  • Pricing
  • Resources ❯
    • Why OKR Dash?
      See how we're different
    • Knowledge base
      Become an expert in OKRs
    • Help center
      Learn how to use OKR Dash
    • Book a demo
      Book a demo or send us an email
  • About ❯
    • Our story
      How OKR Dash came to be
    • What's new
      Our latest improvements
    • Contact us
      We respond fast!
Sign in

Data & Security

Last updated: 28 April 2026  ·  Also see: Terms & Conditions  ·  Privacy Policy

Contents

  • 1. Security Practices
  • 2. Data Handling
  • 3. GDPR
  • 4. Your Rights
  • 5. Data Processing Commitments
  • 6. Sub-processors
  • 7. Contact

1. Security Practices

OKR Dash is operated by Waypoint Software Pty Ltd (ACN 695 352 295). We take the security of your data seriously and have implemented a number of technical and organisational measures to protect it.

Encryption in transit

All communication between your browser and our servers is encrypted using HTTPS/TLS. We enforce HTTPS (HTTP Strict Transport Security) and redirect all plain HTTP traffic.

Encryption at rest

Data stored in our database and on disk is encrypted at rest by our infrastructure providers (Heroku, Amazon Web Services). Backups are also encrypted.

Access controls

Access to production systems and customer data is restricted to authorised personnel on a need-to-know basis. We use strong authentication for administrative access to infrastructure.

Passwords

We never store passwords in plain text. Passwords are hashed using a strong, modern algorithm (bcrypt) before storage.

Dependency and vulnerability management

We regularly review and update dependencies to address known vulnerabilities. We follow OWASP guidance in our development practices.

Incident response

In the event of a data breach that affects your personal data, we will notify affected users and relevant authorities as required by applicable law, including GDPR Article 33 (notification within 72 hours where required).

2. Data Handling

Where your data is stored

All customer data is stored on servers in the European Union (AWS EU region). Data is not routinely transferred outside the EU, except where sub-processors are involved (see Sub-processors below).

Backups

We maintain automated, encrypted database backups. Backups are retained for a rolling period to allow recovery from data loss scenarios.

Data isolation

Each Workspace is logically isolated. Users can only access data within the Workspaces they have been invited to join.

Retention and deletion

We retain your data for as long as your account remains active. If you request deletion of your account, we will delete your personal data within 30 days, except where retention is required for legal purposes (e.g. billing records). You can request account deletion by emailing hello@okr-dash.com.

3. GDPR

Entity definition

Waypoint Software Pty Ltd (ACN 695 352 295) is an Australian company. For users in the European Economic Area (EEA) and United Kingdom, we comply with the General Data Protection Regulation (GDPR) and the UK GDPR respectively.

Our role

We act in two capacities depending on the data in question:

  • Data Controller for account and identity data (e.g. your email address, login credentials, billing information). We determine the purpose and means by which this data is processed.
  • Data Processor for the content you and your team enter into the Service (e.g. OKRs, key results, check-ins, comments). This data is processed strictly on your organisation's behalf and only to provide the Service.

Lawful bases for processing

We rely on the following lawful bases under GDPR Article 6:

  • Legal obligation (Art. 6(1)(c)): where required to comply with applicable law.
  • Contract (Art. 6(1)(b)): processing necessary to provide the Service you have subscribed to.
  • Legitimate interests (Art. 6(1)(f)): service improvement, security monitoring, and product communications, balanced against your rights.
  • Consent (Art. 6(1)(a)): for optional marketing communications. Withdrawable at any time.

4. Your Rights Under GDPR

If you are located in the EEA or UK, you have the following rights:

  • Right of access (Art. 15): request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): ask us to correct inaccurate data.
  • Right to erasure (Art. 17): request that we delete your personal data, subject to legal exceptions.
  • Right to restriction (Art. 18): ask us to limit how we process your data.
  • Right to data portability (Art. 20): receive your data in a portable format.
  • Right to object (Art. 21): object to processing based on legitimate interests.
  • Rights related to automated decision-making (Art. 22): we do not make automated decisions with significant legal or similar effects.

To exercise any of these rights, email hello@okr-dash.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.

You also have the right to lodge a complaint with a supervisory authority. If you are in the UK, this is the Information Commissioner's Office (ICO). If you are in the EU, contact your national supervisory authority.

5. Data Processing Commitments

Where we act as a Data Processor for your organisation's content data, we commit to the following:

  • We will process personal data only on your documented instructions and for the purpose of providing the Service.
  • We will ensure that personnel authorised to process personal data are bound by confidentiality obligations.
  • We will implement appropriate technical and organisational security measures as described in this page.
  • We will not sub-process personal data to any third party without informing you. Our current list of sub-processors is published below and will be kept up to date.
  • We will assist you in responding to requests from data subjects exercising their rights under GDPR.
  • We will delete or return personal data upon your request at the end of the contract.
  • We will notify you without undue delay if we become aware of a personal data breach affecting your data.

If your organisation requires a signed Data Processing Agreement (DPA), please email hello@okr-dash.com.

6. Sub-processors

We use the following third-party sub-processors to provide the Service. All are bound by appropriate data processing agreements.

Provider Purpose Data location
Heroku (Salesforce) Application hosting and deployment EU
Amazon Web Services (AWS) Database hosting, storage, and backups EU
Stripe Payment processing and subscription management USA
SendGrid (Twilio) Transactional and marketing email delivery USA
OpenAI AI-powered features (e.g. OKR suggestions, insights) USA
Plausible Analytics Privacy-friendly, cookieless website analytics (no personal data) EU

We will update this list when we add or remove sub-processors. If you have questions about a specific provider, contact hello@okr-dash.com.

7. Contact

For any security or data protection enquiries:

Waypoint Software Pty Ltd
hello@okr-dash.com

To report a security vulnerability, please email hello@okr-dash.com with details. We will acknowledge all reports within 48 hours and aim to resolve confirmed issues promptly.

Product

  • OKR software
  • Pricing
  • What's new
  • Book a demo

Resources

  • Why OKR Dash?
  • Help center
  • Knowledge base

Articles

  • Habit loops for high-performing OKRs
  • Align company OKRs to teams
  • Make strategy visible everywhere
  • Create a living OKR system

Company

  • About us
  • Contact us
  • Terms & Conditions
  • Privacy
  • Data & Security

© 2019-2026 Waypoint Software Pty Ltd (ACN 695 352 295).