Trust

Security Policy

Dazhboards Pty Ltd (ABN 73 669 295 096), trading as Dazhboards and operating the Dazhboards platform (the "Platform", "we", "us", or "our").

1. Purpose and Scope

1.1 This Security Policy ("Policy") describes the technical and organisational measures by which we secure the Platform and the data processed through it. It applies to all customers, authorised users, and parties who connect their systems to, or access, the Platform.

1.2 The Platform operates as an oversight layer. It connects to a customer's booking, communication, and operational systems to analyse activity and provide assistance. This Policy governs how the Platform accesses, processes, secures, and retains data in the course of providing those services.

1.3 This Policy should be read together with our Privacy Policy, Software Terms of Use (EULA), and Website Terms & Conditions. In the event of a conflict between this Policy and the EULA, the EULA prevails to the extent of the inconsistency.

2. Definitions

For the purposes of this Policy:

"Connected System" means any third-party booking, accounting, payment, or messaging service that a customer authorises the Platform to access.

"Customer Data" means data that a customer connects to, or generates within, the Platform, including booking and customer records, product information, operational signals, conversation history, and sales and channel performance data.

"Authorised User" means an individual permitted by a customer to access the Platform under that customer's account.

"Processing" has the meaning given under applicable data protection laws.

3. Scope of Data Access and Use

3.1 The Platform accesses only the data reasonably necessary to deliver the services a customer has enabled. Depending on the Connected Systems authorised, this may include:

  • booking and customer records;
  • tour and product information;
  • operational status and readiness signals;
  • customer conversation history (where inbox functionality is enabled); and
  • sales and channel performance signals.

3.2 We Process Customer Data solely to provide and improve the contracted services, including to monitor business performance, detect anomalies, respond to in-platform user queries, draft customer responses (Customer Support Inbox), and surface recommendations.

3.3 We do not:

  • sell Customer Data;
  • modify a customer's booking system without that customer's prior approval;
  • make undisclosed or silent changes to Connected Systems; or
  • share customer information with third parties for advertising purposes.

3.4 Where a customer disconnects a Connected System, the Platform's access to data from that system ceases.

4. Access Control

4.1 The Platform enforces role-based access control ("RBAC") so that Authorised Users are granted access only to the data and functions appropriate to their role. Standard role tiers include:

  • Support Teams: access to the inbox and customer conversations;
  • Operations Teams: access to readiness and departures data;
  • Commercial Teams: access to sales and reseller performance data; and
  • Owners: oversight access across all functions.

4.2 Customers are responsible for assigning and reviewing the roles granted to their Authorised Users.

5. Data Security Measures

5.1 Security controls are integrated into the design and operation of the Platform, including:

  • Secured connections: all connections to Connected Systems are authenticated and secured;
  • Encryption: Customer Data is encrypted in transit and, where applicable, at rest;
  • Access controls: strict, permission-based access to production systems; and
  • Monitoring: continuous monitoring and secure operational practices.

5.2 We maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Data against unauthorised access, disclosure, alteration, and destruction.

6. Accountability and Auditability

6.1 The Platform is designed to provide a traceable record of activity, including:

  • a record of actions and events within the Platform;
  • source attribution for signals and recommendations;
  • visibility into actions taken by Authorised Users; and
  • an audit trail across Platform activity.

7. Certifications and Compliance

7.1 Google Cloud Application Security Assessment (CASA). Dazhboards has completed Google's Cloud Application Security Assessment (CASA), conducted under the App Defense Alliance framework. CASA verifies that applications accessing Google API scopes meet defined application security requirements.

7.2 SOC 2. Dazhboards is currently undergoing the System and Organization Controls 2 (SOC 2) certification process. This work is ongoing, and we will update this Policy upon completion. Customers requiring information on the current status of our SOC 2 program may contact us at the address in Section 12.

7.3 We are committed to maintaining and expanding our security and compliance posture in line with the evolving needs of our customers.

8. Responsible and Reviewable AI

8.1 The Platform's AI functionality is designed to be grounded in connected data rather than generated without context. Specifically:

  • responses are sourced from a customer's live, connected business systems;
  • outputs are contextual to the customer's specific business; and
  • human review is supported where appropriate.

8.2 By way of illustration, the Customer Support Inbox drafts responses that may be reviewed before sending, the in-platform query feature provides explanations based on connected signals, and recommendations are designed to be actionable and traceable. AI supports decisions; final control rests with the customer.

9. Privacy and Data Handling

9.1 The Platform is designed around responsible data handling. Customers control which systems are connected and which Authorised Users may access them.

9.2 Customer Data is used to deliver product value and is not used for advertising. We do not sell Customer Data. Further detail is set out in our Privacy Policy.

10. Reliability and Availability

10.1 The Platform is engineered for consistent availability and performance, including during peak periods, and is designed to scale with a customer's message and booking volume.

10.2 High-volume operators may engage with us to agree specific reliability requirements.

11. Procurement and Security Reviews

11.1 We support customer procurement and security review processes. Customers requiring a security questionnaire, documentation, or a security walkthrough may contact us using the details in Section 12.

12. Contact

Questions regarding this Policy, or requests for security documentation, may be directed to:

Dazhboards Pty Ltd

security@dazhboards.ai

South Melbourne, Victoria, Australia

13. Changes to this Policy

13.1 We may update this Policy from time to time to reflect changes to our practices, certifications, or legal obligations. The "Last updated" date above indicates when this Policy was most recently revised. Material changes will be communicated through the Platform or by other reasonable means.

Free capacity audit

See the Revenue You're Leaving on the Table

Read-only connection to your booking system. Within a few days you get back a plain report on your unsold seats, weekday demand pattern and lead-time curve. Nothing installed, nothing changed, nothing to uninstall.

What comes back
  • Seats that went out empty in the last 90 days, by product and departure
  • Where your weekday demand actually sits versus where you're pricing it
  • How far out guests book, so you know when a seat is really lost
  • Which of the five leaks is costing you the most bookings