Skip to main content
Doris is designed to support customers’ regulatory obligations, with a focus on UK and EU GDPR-related requirements.

GDPR

  • Roles: In most customer deployments, the customer acts as controller and Doris Labs acts as processor
  • Instructions: Processing is carried out under customer instructions, product configuration, and the applicable agreement
  • Data subject rights: Product features are intended to help customers respond to access, rectification, erasure, portability, and restriction requests
  • No sale of customer data: Customer personal data is not sold for unrelated advertising or third-party monetization
  • AI processing: AI-assisted processing is performed under commercial service terms rather than to train publicly available models

Data Processing Agreement

A Data Processing Agreement (DPA) is available for eligible customers and typically covers:
  • Scope and categories of personal data processed
  • Security measures (Schedule 4 of our MSA)
  • Sub-processor obligations and notification procedures
  • International data transfer safeguards
  • Data subject rights cooperation
  • Breach notification timelines
  • Audit rights
Contact sales@meetdoris.com to request a copy of our DPA.

Sub-Processors

We may engage third-party service providers to support delivery of the service:
Sub-ProcessorServicePrimary Location
Microsoft AzureCloud infrastructure, compute, and storageUK South
Azure OpenAIAI inferenceUK South / US East
Auth0Authentication and identity managementUK / EEA
StripePayment processingUS / Global
DatadogApplication monitoring and telemetryEEA
SentryError trackingEEA
Customer-configured integrations (enabled at your discretion):
IntegrationServiceLocation
Google Calendar APICalendar sync and meeting recordingCustomer-configured
Microsoft GraphCalendar and email integrationCustomer-configured
HubSpotCRM integrationCustomer-configured
SalesforceCRM integrationCustomer-configured
AttioCRM integrationCustomer-configured
GongConversation intelligenceCustomer-configured
Sub-processor notices and objection rights, where offered, are governed by the applicable customer agreement.

Security Reviews

  • Available assurance materials and review rights, if any, are governed by contract
  • Security reviews may be satisfied through documentation, questionnaires, or other reasonable verification methods
  • Any additional review process is subject to scope, confidentiality, operational constraints, and legal requirements

Assurance Roadmap

Doris Labs continues to mature its control environment and may pursue independent attestations over time:
FrameworkStatus
SOC 2-aligned controlsInternal program maturity in progress
ISO 27001-aligned controlsInternal program maturity in progress
The security measures documented in this trust center reflect our current operating practices at a high level and do not constitute a certification or contractual guarantee unless expressly stated in writing.

Secure Development Lifecycle

Our SDLC incorporates security at every stage:
  • Source control: Code changes are tracked in version control with review workflows
  • Static analysis: Security scanning and dependency checks are integrated into development workflows
  • Secrets management: Sensitive values are managed through dedicated secret stores and runtime delivery
  • Environment separation: Production and non-production environments use separate credentials and infrastructure boundaries
  • CI/CD security: Deployment pipelines use short-lived or federated authentication where supported