DecideAct typical implementation process:
Initial Consultation: The implementation begins with a discovery session where DecideAct’s team works closely with the client to understand strategic goals, existing processes, and organizational structure.
Solution Configuration: Based on requirements, DecideAct configures the platform—customizing strategic frameworks, dashboards, KPIs, and access privileges tailored to the client’s needs.
Data Import and Migration: Existing strategy content, milestones, and historical performance data are migrated into DecideAct, either through automated tools or manual input as needed.
User Onboarding and Training: Key users and stakeholders receive hands-on training and onboarding with DecideAct’s customer success team, ensuring smooth user adoption and familiarity with features.
Pilot and Feedback: Organizations often launch with a pilot phase to test workflows, gather user feedback, and refine configurations or permissions before full rollout.
DecideAct can be customized extensively across frameworks, data, workflows, roles, and integrations to fit specific business needs.
Strategic frameworks: Use pre-defined models (e.g., OKRs, BSC, pillars) or build fully custom frameworks, including custom terminology and structure to mirror internal methods.
Goal/KPI modeling: Define custom objectives, targets, KPIs, and status monitors with configurable cadence, thresholds, and portfolio roll-ups for different business units.
Dashboards and reporting: Configure real-time dashboards, analytics, and reports for role-specific views and leadership oversight, with organization-wide alignment and visibility.
Workflow customization: Adapt workflows to unique processes, including initiative lifecycles, approvals, and governance checkpoints for accountability and auditability.
Role-based access: Set granular permissions and hierarchical access by team, function, or management layer to enforce data governance and selective visibility.
Data import/export: Import existing strategy artifacts and performance data; export structured data for external analysis and board reporting as needed.
Integrations and APIs: Integrate with ERP/CRM/BI tools (e.g., Power BI, Grafana, Tableau, SAP) via open GraphQL API for bidirectional data sync of KPIs and initiatives.
Multi-organization setups: Support multi-entity accounts and organizational hierarchies to standardize strategy across subsidiaries while allowing local customization.
ESG frameworks: Configure standard or custom ESG/CSRD/SDG frameworks and indicators to align sustainability goals with operational strategy.
Terminology/localization: Customize labels, categories, and strategic taxonomies to match internal language and stakeholder expectations across departments.
Alerts and nudges: Tailor reminder cadence, escalation rules, and notification audiences to ensure timely updates and follow-ups without overload.
Portfolio governance: Configure portfolio criteria, risk-confidence scoring, remediation fields, and cross-functional workgroups to reflect governance models.
Enterprise options: Customize SSO, security controls, data migration scope, and module-level configurations with dedicated customer success support.
Implementation tailoring: Onboarding and setup are tailored to organizational needs, including mapping existing strategic processes into DecideAct’s models.
DecideAct lists a Professional plan at 25 EUR per user per month billed annually (4-user minimum) or 31.25 EUR per user when billed monthly, and an Enterprise plan with custom pricing; the page emphasizes simple, transparent pricing with an available free trial. Maintenance, including patches, fixes, and new software version releases, is provided at no additional cost by default, though custom functionality or programming is excluded unless otherwise agreed. Standard help and support is included (8/5 support noted on the Professional tier), while Enterprise adds a dedicated Customer Success Manager, SSO, and enhanced security as part of the package; scope and service levels scale with the chosen plan rather than appearing as separate mandatory fees. Public materials do not indicate a universal setup or implementation fee; onboarding and configuration are typically included within plan scope, with any bespoke customizations, advanced integrations, or expanded services handled on a case-by-case commercial basis. Third-party listings corroborate subscription-based pricing and bundled support options, with entry points and totals varying by users and modules.
DecideAct provides structured onboarding, customer success guidance, and ongoing support to help new users adopt the platform quickly and effectively.
Onboarding and setup: Tailored implementation that maps your existing strategy process into DecideAct, with guided configuration of frameworks, KPIs, dashboards, and governance.
Customer Success team: Dedicated experts who lead onboarding, change management, best-practice coaching, and adoption programs to ensure measurable outcomes.
Training: Role-based enablement for executives, strategy owners, and contributors, including hands-on sessions focused on planning, execution workflows, KPI management, and reporting.
Resources: Access to digital onboarding materials, product guidance, and investor-documented proof of “highly effective onboardings” with strong satisfaction scores.
Support availability: Standard support bundled with subscriptions, with enhanced service levels and a dedicated Customer Success Manager on enterprise plans.
DecideAct protects customer data through a combination of third‑party audited certifications, strong identity controls, encryption, availability commitments, and documented secure development practices.
Certifications and audits: ISO 27001:2022 and SOC 2 Type II certifications, with regular independent audits and a Trust Center for controlled access to security documentation.
Identity and access management: Single Sign-On with SAML (Okta, Azure AD), Auth0-backed authentication, role-based access control, and optional multi‑factor authentication for hardened sign-ins.
Encryption: Strong encryption of data in transit and at rest as a core platform control, alongside VPN and traffic filtering to protect network flows.
Availability and reliability: Service availability commitment of 99.99% measured over rolling three‑month periods for hosted solutions.
Policies and governance: Extensive internal security and privacy policies applied across the organization to enforce standards and operational discipline.
Secure SDLC: Static code analysis, coding convention governance, automated tests, and PCI DSS–inspired security requirements embedded throughout development and deployment.
Access governance: Fine‑grained authorization layers, per‑account roles from Admin to Reader, ensuring least‑privilege data access and auditable actions.
DecideAct releases software updates on a regular and continuous basis, following the standard SaaS model where improvements, patches, and new features are rolled out automatically to all customers as part of ongoing service delivery. There is no set interval publicly disclosed (e.g., weekly, monthly), but the platform emphasizes "automatic updates" to keep all users on the latest version and quickly address evolving needs, security issues, and feature enhancements. Update management is fully managed by DecideAct—customers do not need to perform manual installs, as updates happen seamlessly in the cloud environment, with advanced notification and support provided for any significant changes that might impact user workflows. Service level agreements confirm ongoing maintenance and support are included by default, ensuring reliability, fast issue resolution, and consistent innovation.
DecideAct’s policy on data ownership and portability ensures that customer data remains the property of the customer at all times, even as the platform and its associated intellectual property rights belong solely to DecideAct. Customers retain full legal ownership over any data they create or own within the DecideAct software environment, and DecideAct may not claim rights to customer-contributed data, whether developed internally or by third parties for the customer’s benefit.
In terms of data portability, DecideAct commits to providing mechanisms in line with GDPR and industry best practices. Customers have the right to export their data at any time, typically in standardized, machine-readable formats, and can request data transfers as required for compliance or operational reasons. The platform maintains a Data Processing Agreement (DPA) that details how personal and project data is processed, stored, and accessed, with strict guarantees on not transferring personal data outside the EU/EEA without explicit customer consent unless certified safeguards are in place.
DecideAct offers subscription flexibility to allow scaling up or down as organizational needs change, in line with typical SaaS best practices. Customers can increase or decrease the number of user licenses (seats) or add/remove modules at contract renewal periods or by agreement with the company during the contract term.
If a customer wants to scale up—by adding users, new teams, or additional modules—DecideAct will adjust the subscription and billing accordingly, often with proration depending on the date of change versus the billing cycle. For scaling down, such as reducing user count or removing modules, customers must usually provide notice before their next renewal (often 30 days before the contract renews), as subscription terms and invoicing are typically locked for the current period once started.
DecideAct’s contract renewal and cancellation terms are structured to support flexible, subscription-based engagement with clear guidelines for notice periods, automatic renewals, and fee obligations. Agreements generally operate on an annual or monthly basis, with subscriptions automatically renewing for successive periods unless explicitly cancelled by the customer before the end of the current term.
The policy requires clients to provide written notice of non-renewal or cancellation before the conclusion of their current agreement period, with the standard notice period typically set at 30 days. If notice is not received within that window, the contract renews for another equivalent term—either monthly or yearly, depending on the chosen subscription. Early termination by the client does not normally result in a refund of prepaid fees, and the user remains liable for all due costs for the full period of the current term.
On cancellation, DecideAct retains the customer’s right to data export for a set period after effective cancellation, ensuring compliance with data portability and record retention requirements. However, unless otherwise agreed, access to the platform will be suspended at the end of the paid term, and any remaining data is subject to deletion under GDPR-compliant data destruction timelines.
Pricing, service tier, and contract length may be renegotiated at renewal; any such amendments must be expressly agreed to in writing. Changes in pricing or terms are communicated in advance of renewal, allowing clients to adjust or opt out in line with their operational needs. For enterprise customers, custom terms regarding renewal, auto-termination for breach, or force majeure may apply as outlined in individual service agreements.
DecideAct meets several leading compliance standards critical for enterprise strategy and data management. The platform is certified for ISO 27001:2022, which sets the international benchmark for information security management, ensuring robust controls across its operations, data handling, and technology environment. DecideAct has also achieved SOC 2 Type II certification, validated by regular independent audits, confirming strong controls over security, availability, processing integrity, confidentiality, and privacy of customer data—especially important for clients operating in regulated industries or with stringent data security requirements.
DecideAct provides a detailed Data Processing Agreement and ensures processes are compliant with the General Data Protection Regulation (GDPR), safeguarding users’ rights to privacy, data ownership, and portability in line with EU/EEA mandates. These guarantees are delivered alongside committed adherence to organizational-level security governance, making DecideAct a fit for enterprises, the public sector, and any organization needing formal, externally verified compliance postures.