Privacy notice
What personal data Greening OS holds about the people who use it, why, who else handles it, how long it is kept, and what you can ask of us.
Version 1.0 · in force from [date, to be confirmed]
1.Who is responsible
- For an organisation's data, the organisation decides what is recorded and who sees it. Tti Labs ([Tti Labs' registered name, to be confirmed]) holds and processes it on the organisation's behalf.
- For the accounts people sign in with, Tti Labs is responsible.
2.What we hold
- Your account: your name, email address, the organisations you belong to, your role in each, and until when.
- Signing in: your password, stored only as a one-way hash by our sign-in provider; your two-step sign-in factors; and your sessions, with the browser, device and IP address each was started from, so you can see them and end them under Account security, and so we can tell you when a new device signs in. When you create your account from an invitation link, we log the IP address it came from, for security, and delete that log after 90 days.
- What you do: every change to an organisation's data is recorded with who made it and when, in a tamper-evident audit trail. Verifiers rely on it, so it can't be edited.
- What you record: mostly figures about an organisation's activity, which aren't personal data, and the files attached to them, such as bills and certificates. Supplier contacts (a name and an email address) are kept where an organisation asks a supplier for data. Commuting is recorded as totals, never per employee.
- Emails we send you: invitations, sign-in and security notices, and the reminders your organisation turns on.
We don't collect payment card details, sensitive personal data, or anything for advertising.
3.Why we use it
- To run Greening OS for your organisation and for you: the reason the organisation has an agreement with Tti Labs.
- To keep it secure, and its records trustworthy: sessions, sign-in notices and the audit trail.
- To meet legal obligations, where a law requires us to keep or hand over information.
We don't sell personal data, profile people, or use it for marketing.
5.Who else handles it, and where
These companies process data for us, under contracts that bind them to use it only for that:
| Company | Where | What for |
|---|---|---|
| Hetzner Online GmbH | Germany | Runs the application server. |
| Supabase Inc. | European Union (Frankfurt) | Hosts the database, sign-in and stored files (bills, certificates, reports). |
| Amazon Web Services (Amazon SES) | European Union | Sends the app's emails: invitations, sign-in links, reminders and notices. |
| Anthropic PBC | United States | Only when used: reads a bill image someone asks it to read, and answers the copilot's questions where an owner has turned the copilot on. |
- So your data is stored outside Pakistan, in the European Union. If an organisation needs it held in Pakistan, its agreement can provide for that.
- Anthropic receives data only when the AI features are used: the bill image someone asks it to read, with whatever is printed on it (often the account holder's name and address), and, where an owner has turned the copilot on, the questions asked and the figures read to answer them. The copilot's figures go without who did what: no names of who entered, approved or owns something, and no email addresses, sessions or keys. Notes and reasons are sent as they were written. Anthropic doesn't use this data to train its models.
6.How long we keep it
- An organisation's data, files and audit trail are kept while the organisation is open.
- When an owner closes it, they stay readable for 30 days (7 if a second owner agrees), then are deleted for good. We keep only a record that the organisation was closed: who asked, why, and when.
- When someone leaves an organisation, their access ends, but their name stays in its audit trail beside what they did, because those records must stay complete.
- Some records are deleted on a schedule, every night:
- records of calls made with API keys, the app's readings of uploaded bills, and the logs of scheduled jobs after 90 days;
- notifications after a year;
- the devices you sign in from once unused for 400 days;
- records of views of shared report links after two years.
- Backups are overwritten after [the backup period, to be confirmed].
- Your account is kept until you ask us to delete it. We act on that within 30 days: the account is closed so it can no longer sign in, and what isn't needed to keep the organisations' records complete is removed. Your name stays beside what you did in their audit trails.
7.How we protect it
- Every connection is encrypted, and so are the database and the stored files at rest.
- Each organisation's data is kept apart by the database itself, so a request on behalf of one organisation can't read another's.
- Two-step sign-in is available to everyone, and required for owners, admins, managers and verifiers.
- The audit trail is chained, so a change made outside the app would show.
8.Your rights
You can ask us to show you the personal data we hold about you, correct it, delete it, stop using it for a purpose, or give it to you in a form you can take elsewhere. For data your organisation recorded, we pass the request to its owners, who decide. We answer within 30 days.
Pakistan's law, and the EU's and UK's data protection law where they apply to you, may give you further rights, including complaining to a regulator.
9.Changes and contact
When this notice changes in a way that matters, we say so in the app or by email before the change takes effect. Questions and requests: [contact email, to be confirmed].