Legal & Compliance
Legal & Compliance
We believe legal documentation should be readable, not buried. Everything governing your use of DashboardFox — your data rights, our security commitments, how we handle compliance — is here. If you're evaluating us for a security review or procurement process, email us directly and we'll go through your checklist line by line.
Core Agreements
Terms of Service
The agreement governing your use of DashboardFox — subscriptions, billing, data ownership, and your rights.
Privacy Policy
What personal data we collect, how we use it, and your rights — covering GDPR, UK GDPR, CCPA, and more.
Data Processing Agreement
GDPR-compliant DPA governing how we process customer data as your data processor. Includes UK and Swiss annexes.
Acceptable Use Policy
What you may and may not do with the platform — including agency white-labeling rules and IP restrictions.
Billing & Service
Refund Policy
30-day full refund on initial purchases. Annual plans retain access through the end of the paid year.
Fair Use Policy
Storage, query, API, and MAU limits by plan tier. Starter through Enterprise.
Service Level Agreement
Uptime commitment, incident response timelines, and scheduled maintenance policy.
Data & Security
Data Retention Policy
How long we keep different types of data — workspace data, backups, billing records, audit logs.
Breach Notification Policy
How we respond to security incidents and notify affected customers — 72-hour commitment.
Sub-processor Registry
Every third-party vendor with access to customer data — purpose, location, and transfer mechanism.
Cookie Policy
What cookies we set, why, and how to manage your preferences.
Vulnerability Disclosure Policy
How to report a security vulnerability responsibly — and what to expect from us.
Compliance Addenda
Business Associate Agreement
HIPAA BAA for healthcare customers — available on request via countersigned document.
FERPA Education Data Addendum
For K–12 and higher education customers handling student education records.
US State Privacy Rights
Rights under CCPA/CPRA and similar laws in Virginia, Colorado, Connecticut, Texas, Delaware, and others.
UK GDPR Addendum
How UK data protection law applies to your use of DashboardFox — IDTA transfers, ICO authority.
Canada Privacy — PIPEDA & Law 25
Federal PIPEDA and Quebec Law 25 — consent, portability, and breach notification requirements.
Australia Privacy Act
Australian Privacy Principles (APPs), cross-border disclosure, and OAIC complaints process.
Doing a security review or vendor assessment? We're a small team — you'll talk to engineers, not a sales rep. Email team@dashboardfox.com and we'll go through your checklist line by line. SOC 2 Type II is in progress; our full security posture is documented at /security/.
Legal inquiries, privacy requests, compliance questions:
team@dashboardfox.com