Legal

Privacy Policy

Effective date: 1 February 2026  ·  Last updated: 1 June 2026

1. Who We Are

Dashly Software ("Dashly", "we", "us", or "our") is a software business registered under the Registration of Business Names Act No. 16 of 2011 of Zambia, operating from House No. 3, Chimanga Road, Salama Park, Lusaka, Zambia. We provide Dashly - a cloud-based project portfolio management platform for businesses and teams ("the Service").

This Privacy Policy explains how we collect, use, store, and protect personal data when you use the Service. By using Dashly, you agree to the practices described here.

2. Data We Collect

We collect only what is necessary to provide the Service.

Account data

  • Full name and email address (provided at signup or via invitation)
  • Job title (optional, provided during onboarding)
  • Profile avatar (optional)
  • Authentication credentials, managed securely via Supabase Auth

Workspace and project data

  • Company name, industry, country, currency, and timezone
  • Project details: names, budgets, timelines, statuses, notes, risk scores, and financial figures
  • Milestones, comments, and activity logs associated with your projects
  • Financial calculation history stored when you run tools within the platform
  • Team membership and role assignments within workspaces
  • Feedback submissions (bug reports, feature requests, and general feedback) submitted via the in-app feedback widget
  • Public share tokens generated when you share a project via a public link

Usage data

  • Browser type, device type, and IP address
  • Pages visited and features used within the Service
  • Error logs for debugging and service improvement

3. How We Use Your Data

  • To create and manage your account and workspace
  • To provide, operate, and improve the Service
  • To send transactional emails (invitations, password resets, notifications)
  • To generate AI-powered project health insights using anonymised project metrics
  • To respond to support requests
  • To comply with applicable legal obligations

We do not sell, rent, or trade your personal data to third parties for marketing purposes.

4. Third-Party Services

Dashly uses the following trusted third-party providers to deliver the Service:

  • Supabase - database, authentication, and file storage (data hosted in the EU)
  • Resend - transactional email delivery
  • Anthropic - AI-powered project health recommendations (project metrics only, no personal identifiers are sent)
  • Vercel - application hosting and edge delivery

Each provider operates under their own privacy policy and data processing agreements. We ensure they meet appropriate data protection standards before use.

5. Data Storage and Security

Your data is stored on Supabase infrastructure. We implement row-level security, strict workspace isolation, and encrypted connections (TLS). Access within a workspace is governed by role-based permissions (Dashmaster, Dashkeeper, Observer).

No system is completely secure. We will notify affected users promptly in the event of a data breach that poses a risk to their rights or freedoms.

6. Data Retention

We retain your account and project data for as long as your account is active. If you delete your account or leave a workspace, your personal profile data is removed. Project data created within a workspace remains under the control of that workspace's Dashmaster until explicitly deleted.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your account and personal data - available directly in Settings → Account
  • Export your personal data as a JSON file - available in Settings → Account → Export My Data
  • Revoke public share links for your projects at any time
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact us at privacy@dashly.co. We will respond within 30 days.

8. Public Share Links

Dashly allows you to generate a public, read-only link for any project. Anyone with this link can view the project's summary without logging in. No personal data about the viewer is collected when they access a public share link. You can revoke a share link at any time from the project detail page.

You are responsible for deciding what project data is appropriate to share publicly. Do not generate share links for projects containing sensitive or confidential information you do not intend to be publicly accessible.

9. Cookies and Local Storage

Dashly uses session cookies and local storage solely to maintain your authenticated session and workspace preferences. We do not use tracking or advertising cookies.

Local storage is also used to remember in-app preferences such as your theme selection, sidebar state, changelog read position, and whether you have completed the onboarding tour. This data never leaves your device and is not transmitted to our servers.

If you enable two-factor authentication (2FA), a TOTP secret is stored securely in your account record in Supabase. No device-level keys or biometric data are collected.

10. Children

The Service is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect data from minors.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify users of material changes by email or via an in-app notice at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this policy or our data practices, contact:

Dashly Software

House No. 3, Chimanga Road, Salama Park, Lusaka, Zambia

privacy@dashly.co