Governance
Data Policy
Last updated: 5 August 2026. How SongaOne governs community data.
1. Tenant and workspace isolation
Every tenant and workspace has its own data boundary. Row-level security, role checks and workspace membership enforce this isolation at the database level.
2. Audit
Every status change, edit and access is recorded in an audit log. Logs include the user, timestamp and before/after values where applicable. Audit logs are retained according to the workspace plan.
3. Data exports
Workspace administrators can export community data, project records and reports in standard formats. Exports respect the user’s role and the workspace retention settings.
4. Deletion
Users can request deletion of personal data. Some records may need to be retained for legal, audit or public transparency reasons; in those cases data is anonymised where possible.
5. Public snapshots
Only approved, published snapshots and reports are visible to the public. The workspace controls what is published and can withdraw or expire public content.
6. Data location
Data is stored with our cloud provider in encrypted form. Backups are encrypted, regularly tested and retained according to our disaster-recovery plan.