Privacy Policy

Last updated: 3 August 2026

goiso is the Living Compliance platform: we turn your daily operations into audit evidence. This document explains which data passes through us, why, where it goes, and when it is erased. It was written to be read by an auditor, not signed unread.

Who operates goiso

goiso is built and operated by Oten Middle East, in partnership with Al-Emtyaz Facility Management: Oten builds and runs the platform, while Al-Emtyaz grounds its operational content in field experience in facility and occupational-safety management. Responsibility for the processing described in this document rests with Oten Middle East as the platform operator. For any privacy matter, use the WhatsApp button at the foot of this page.

1. Scope

This policy covers three surfaces: the public site (goiso.co, its blog and its chat assistant), the platform application behind sign-in, and the mobile app where your facility uses it.

It does not cover third-party sites we link to, nor the systems of certification and audit bodies to which you may hand your own reports.

2. Two different roles — and who answers for what

The distinction below is essential to the rest of this document, and it is the same one any auditor will ask about:

  • Operational data your facility uploads — employees, sites, assets, inspections, incidents, work permits, evidence and documents — belongs to your facility. It decides what is collected and why; we process it on its behalf and under its instructions.
  • Account and usage data — subscriber details, sign-in records, the audit trail, subscription billing — is data we determine, as the platform operator.
  • Public visitor data — whoever reads our blog or talks to our assistant before becoming a customer — is our responsibility.

In practice this means an employee at a subscribing facility addresses any request — access, correction, deletion — to their organisation first; we support the organisation in carrying it out, and we do not act on its data on our own initiative except on its instructions or under a legal obligation.

3. The data we process

We keep to what the service genuinely needs. We do not buy data and we do not import it from brokers.

  • Account data: name, email address, phone number where provided, role and permissions, the linked organisation and site. Passwords are stored as one-way hashes and cannot be read by anyone — ourselves included.
  • Operational data uploaded by your facility: employee records, competencies and training, inspections, maintenance and work permits, incidents and injuries and their investigations, assets and sites, and files uploaded as evidence (photos, PDFs, certificates). Some of it is sensitive by nature — the details of an occupational injury, for instance — and the lawfulness of collecting and uploading it rests with your facility.
  • Technical and audit-trail data: IP address, timestamps, browser type, and a record of who did what and when on sensitive records. That trail is not a luxury: it is what makes your evidence defensible before an auditor, which is why it is retained and does not vanish when the underlying record is deleted.
  • Public assistant conversations: the text of your messages to the site assistant and the IP address that opened the thread, used to curb abuse and measure cost. We do not ask who you are to start a conversation — so do not type into it anything you would not want stored.
  • Mobile notifications: the device token, once you install our app and enable notifications — for delivery, nothing more.
  • Subscription data: plan, term, quotas and AI credit consumption. We neither receive nor store card numbers — there is no payment gateway on the platform today, and collection happens outside it by invoice.

4. Cookies and tracking

We use no advertising cookies, no tracking pixels and no third-party analytics. The cookies we do set are strictly necessary to run the service:

Because we set nothing that requires consent, you will not see a cookie banner on this site. We also self-host our fonts rather than pulling them from an external provider — a decision taken for two reasons: so the site opens from regions where some delivery networks are blocked, and so your address does not leak to a third party merely because you read a page.

  • Session cookie: keeps you signed in.
  • CSRF cookie: prevents another site from issuing requests in your name.
  • Language preference: remembers your choice between Arabic and English.

5. Why we process it

  • Performance of the contract: running your account, computing your readiness, generating your reports, delivering your notifications.
  • Legitimate interests: platform security, abuse prevention and rate limiting, fault diagnosis, and measuring operating cost.
  • Legal obligation or defence of a right: retaining the audit trail and billing records to the extent required.
  • Your consent: where it is genuinely required — enabling mobile notifications, or messaging us on WhatsApp.

We do not sell, rent or trade your data, and we never use one tenant's data to serve another — not in a report, not in a benchmark, not to train a model.

6. The AI advisor — full disclosure

Several platform capabilities — the advisor, its free chat, importing a standard from a document, and on-demand summarisation — rely on a language model operated by a third party, Anthropic. Because this is the single point most scrutinised in an information-security audit, we spell it out:

  • What is sent: the text of your question and the specific excerpt of the clause or document the request concerns. Your organisation's database and files are not shipped wholesale, and nothing about another tenant is ever sent.
  • How it is sent: over an encrypted connection (HTTPS) from our server directly to the provider's API; it does not pass through your browser or any intermediary.
  • Training: the provider does not use what reaches it through this API to train its models.
  • What we keep: consumption and cost counters, and the result summary needed to show you the outcome and bill it — we do not build a conversation archive behind your back.
  • An automatic nightly pass: besides what you request yourself, the advisor passes nightly over your new evidence to propose verifications and to compose your daily digest. This pass is enabled by default for every organisation and runs under exactly the limits described above: an excerpt of your own data, no training, and no crossing between tenants.
  • Switching it off: the whole capability — the button and the nightly pass alike — is disabled for your organisation by a single switch, after which nothing is sent to the provider on its behalf. The self-service toggle in the owner's dashboard is under construction; until it ships we disable it on your request within one business day. Exhausting your credit stops only this feature, not the rest of the platform.
  • Limits of reliance: advisor output is advisory input to a decision, never the decision. Your readiness colours and figures are computed deterministically from your own data, not from a model's opinion.

7. Who we share with — and no one else

We rely on a small set of providers, each for a single purpose, under confidentiality terms:

  • Hosting provider: servers, database and file storage — located in Germany.
  • Backup provider: encrypted copies held off the live server — in the United States.
  • Anthropic: the advisor capabilities described above.
  • Resend: transactional email (invitations, password recovery, alerts).
  • Google Firebase: delivery of mobile push notifications, where enabled.
  • WhatsApp: when you choose to message us there — that conversation is also governed by its operator's policies.
  • A competent judicial or regulatory authority: on a legally binding request, only to the extent required, and with notice to you unless the law forbids it.

If we add a material new provider that processes tenant data, we update this list and notify account owners before the switch.

8. Where your data lives

The live copy — database and uploaded files — resides on servers in Germany. Encrypted backups are held with a provider in the United States, satisfying a three-copies-in-two-locations rule; transfers between them are encrypted in transit.

If your country mandates local data residency, tell us before contracting — we would rather say so plainly than promise what we do not have today.

9. How we protect it

  • Encryption in transit (HTTPS) across every public and authenticated surface.
  • One-way password hashing, with rate limiting on sign-in and recovery against guessing.
  • A mandatory tenant fence enforced at the data-model layer rather than the interface alone — a query cannot read a row that does not belong to your organisation.
  • Per-organisation file path separation, and time-limited signed download links for packages instead of permanent public URLs.
  • Granular roles and permissions controlled by the account owner, and an audit trail attributing every sensitive action to its actor.
  • Regular backups and automated health monitoring.

No system is absolutely secure and we will not claim otherwise. If a breach affects your data, we notify the affected account owners without undue delay, with an honest account of what happened, what we did, and what we advise you to do.

10. Retention and deletion

Your data is kept for as long as your subscription is active. After it lapses, three windows follow — all announced in advance, none a surprise:

  • Read-only grace (around 30 days): you sign in, read, export a complete package yourself, and renew at your inherited price.
  • Dormancy: access closes and the data is preserved; you return by an administrative restore on your request.
  • Permanent deletion (around 90 days after lapse): irreversible erasure of your data and files.
  • Export packages you generate remain downloadable for a short window (about 14 days) and are then erased automatically.
  • The audit trail and billing records are kept longer, to the extent needed to defend a right or meet an obligation.

Ahead of each window we send a dated, multi-channel notice chain ending in a final warning. If that last message bounces or cannot be delivered, automatic deletion halts and the case is reviewed by hand — a message to a dead address is not a notice. Deletion can also be suspended on a documented legal hold.

11. Your rights

You may request access to your data, its correction, its portability, its deletion, and you may object to or restrict a particular processing activity.

Because we process operational data on behalf of your facility, the fastest route is your organisation's account owner: they hold a self-service export of the complete package in two formats, and can amend or delete what concerns you. Where that is not possible, or where your request concerns the account data we hold directly or a conversation on our public site, contact us and we will respond within 30 days at the latest, once we have verified your identity.

12. Children

goiso is a service for organisations, not individuals. It is not directed at anyone under 18 and we do not knowingly collect their data. Where a minor's data is uploaded as a trainee or employee, the processing and its legal basis remain the responsibility of their facility.

13. Changes to this policy

We may update this document as the platform evolves. A material change — adding a provider that processes tenant data, or changing where we host — is communicated to account owners before it takes effect, and the date at the top is updated. Continued use after that date constitutes acceptance of the updated version.

14. Contact

For any privacy question or request, or to report a security vulnerability, reach us on WhatsApp via the button below. We handle vulnerability reports in good faith and do not pursue those who disclose responsibly.

Message us on WhatsApp

Last updated: 3 August 2026