Dokven

Loading Dokven.

Legal

Privacy Policy

How Dokven collects, uses, shares, and protects your personal data, written for global use across the GDPR, UK GDPR, CCPA/CPRA, PIPEDA, Quebec Law 25, LGPD, and the Australian Privacy Principles, including your rights and how to exercise them.

Effective: June 16, 2026Last updated: July 16, 2026Version: 1.1.0

1. Who we are and scope

This Privacy Policy explains how Fuzail Khan, a sole proprietor based in Toronto, Ontario, Canada and operator of the Dokven service, the controller of your personal data, collects, uses, shares, and protects information when you use Dokven(the "Service"). It is written to meet the requirements of privacy laws around the world, including the EU and UK GDPR, the California Consumer Privacy Act as amended by the CPRA and other US state laws, Canada's PIPEDA, Quebec's Law 25, Brazil's LGPD, and the Australian Privacy Principles.

Where local law gives you specific rights or requires specific disclosures, those apply to you in addition to this Policy. If anything here conflicts with a mandatory right you have under your local law, your local law governs.

Privacy Officer (Quebec Law 25)

The person responsible for the protection of personal data is Fuzail Khan. You can reach our privacy function at support@dokven.com for any question or request about your data.

2. Personal data we collect

We collect the following categories of data:

  • Account data: your email address, name (if provided), authentication identifiers, plan, and account settings. Authentication is handled by our database and auth provider.
  • Billing data: your subscription, plan, token balance, and transaction history. Payment card details are collected and processed directly by our payment processor; raw card numbers never reach our servers.
  • Customer Content: the Target URLs, journey definitions, API specifications, test configurations, and the reports, screenshots, video recordings, and artifacts your runs generate. You may submit personal data within Customer Content; you are responsible for having a lawful basis to do so.
  • Usage and device data: token usage and run logs, IP address, browser and device information, approximate location derived from IP, pages viewed, and interaction events used for analytics, security, and debugging.
  • Support and communications: messages you send us and the contents of those communications.
  • Cookies and similar technologies: as described in the Cookie Policy.

Running a scan sends data to your Target

When you run a test, the Service transmits requests from our infrastructure to the Target you choose. This discloses the act of testing, and the request contents you configure, to that third-party Target. You are responsible for ensuring you are authorized to send those requests. See the Acceptable Use Policy.

3. How we use personal data

  • to provide, operate, and maintain the Service and run the tests you request;
  • to create accounts, authenticate you, and provide support;
  • to process payments, manage subscriptions, and prevent fraud;
  • to secure the Service, enforce our terms, detect and prevent abuse, and debug failures;
  • to analyze and improve the Service and develop new features;
  • to communicate with you about your account, security, and service changes; and
  • to comply with law and respond to lawful requests.

5. How we share data and sub-processors

We do not sell your personal data for money. We share data only as needed to run the Service: with the sub-processors that host, secure, and power Dokven; with our payment processor for billing; with professional advisors; in connection with a merger, acquisition, or asset sale (with notice); and where required by law or to protect rights and safety.

The current list of sub-processors, what they do, the data categories involved, and their regions is published at Sub-processors. We require sub-processors to protect personal data under written terms consistent with this Policy and our Data Processing Addendum.

6. International data transfers

Dokven and its sub-processors may store and process your information in Canada, the United States, the European Union, and other countries. Where required, we rely on adequacy decisions or on Standard Contractual Clauses (and equivalent safeguards), and we conduct transfer impact assessments, to protect personal data transferred across borders.

For transfers out of the EEA or UK we use the European Commission's 2021 Standard Contractual Clauses (and the UK Addendum) with a transfer impact assessment. Under PIPEDA we remain accountable for personal data transferred to a service provider and require a comparable level of protection by contract. Under Quebec Law 25 we conduct a privacy impact assessment before transferring personal data outside Quebec. You may contact us for more information about the safeguards we use.

7. Data retention

We keep personal data only as long as needed for the purposes above, then delete or anonymize it. In general:

  • Account and billing records are kept for the life of your account and as required by tax and legal rules.
  • Customer Content and reports are kept while your account is active so you can revisit them, and deleted on request or when you delete them.
  • Heavy automation artifacts such as run traces and video recordings are retained for approximately 7 days and then auto-purged.
  • Logs and analytics are kept for a limited period for security, debugging, and product analysis.

8. Your privacy rights

Depending on where you live, you may have some or all of the following rights regarding your personal data:

  • Access and portability: obtain a copy of your data and, where applicable, receive it in a portable format (GDPR/UK GDPR, CCPA/CPRA, Law 25, LGPD, APPs).
  • Rectification: correct inaccurate or incomplete data.
  • Erasure / deletion: ask us to delete your data, subject to legal exceptions.
  • Restriction and objection: restrict or object to certain processing, including processing based on legitimate interests.
  • Withdraw consent: withdraw consent at any time where we rely on it.
  • Opt out of sale/sharing and limit sensitive data (US): see the California and US state section below.
  • De-indexation (Law 25): request that we stop disseminating personal data or de-index it where the law allows.
  • Complaint:lodge a complaint with your local data-protection authority (for example, your EU supervisory authority, the UK ICO, the Office of the Privacy Commissioner of Canada, or the Commission d'accès à l'information du Québec).

To exercise any right, email support@dokven.com. We will respond within the time required by your law (for example, without undue delay and within one month under the GDPR, or 45 days under the CCPA, extendable as the law permits). We will not discriminate against you for exercising your rights, and we may need to verify your identity first.

9. California and US state privacy rights

If you are a resident of California or another US state with a comprehensive privacy law, you have the rights to know, access, correct, and delete your personal information, and to opt out of the "sale" or "sharing" of personal information and the use of sensitive personal information beyond what is necessary to provide the Service. We do not sell personal information for money.

  • We honor the Global Privacy Control (GPC) browser signal as a valid opt-out of sale/sharing where applicable.
  • You can exercise these rights, including "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information," by emailing support@dokven.com. No account is required to opt out.
  • The categories we collect, our purposes, and the categories we disclose to sub-processors are described above and at Sub-processors, covering at least the prior 12 months.
  • You may use an authorized agent to submit requests, subject to verification.

10. Marketing communications and CASL

We send service and account messages (for example security, billing, and important updates) as part of providing the Service; you cannot opt out of these while you have an account. We currently do not run a general marketing-email program. If and when we introduce marketing or promotional email, the following will apply:

  • we will obtain consent where required (including express opt-in consent under Canada's Anti-Spam Legislation, CASL, and the GDPR/ePrivacy rules), with no pre-checked boxes;
  • every commercial electronic message will identify the sender and include a working unsubscribe mechanism that we honor promptly (within 10 business days under CASL) and keep functional for at least 60 days; and
  • we will keep records of consent and update this Policy and our sub-processor list accordingly.
CASL penalties can reach CAD $1 million per violation for an individual and CAD $10 million per violation for a corporation. We take electronic-message compliance seriously.

11. Children

The Service is not directed to children and is intended for users who are adults or of the age of majority in their jurisdiction. We do not knowingly collect personal data from children under 16, and under Quebec Law 25 we do not collect personal data from a minor under 14 without parental consent. If you believe a child has provided us personal data, contact support@dokven.com and we will delete it.

12. How we protect data

We use technical and organizational measures including encryption in transit, access controls, ownership checks on artifacts, and sub-processor diligence. No method of transmission or storage is perfectly secure, but we work to protect your data and to notify you and regulators of a personal-data breach where the law requires. More detail is on the Security page.

13. Cookies and tracking

We use essential storage for core functionality and, with consent where required, analytics technologies. The full inventory, categories, and how to control them are in the Cookie Policy.

14. Changes and contact

We may update this Policy. Material changes will be reflected in the version and "Last updated" date above and, where appropriate, communicated to you. The contacts for privacy matters are below.

PurposeContact
Privacy requests and questionssupport@dokven.com
Privacy Officer (Law 25)Fuzail Khan, support@dokven.com
EU / UK representativeNot currently appointed; EEA and UK users may contact support@dokven.com
Postal mailToronto, Ontario, Canada

Questions about this document? Contact support@dokven.com (legal) or support@dokven.com (privacy). We review and update these policies as the product and the law change; the version and dates above always reflect the current text.