Draft for review. Tti Labs hasn't approved this text yet, and the parts in brackets are still to be confirmed.

Privacy notice

What personal data Greening OS holds about the people who use it, why, who else handles it, how long it is kept, and what you can ask of us.

Version 1.0 · in force from [date, to be confirmed]

1.Who is responsible

  • For an organisation's data, the organisation decides what is recorded and who sees it. Tti Labs ([Tti Labs' registered name, to be confirmed]) holds and processes it on the organisation's behalf.
  • For the accounts people sign in with, Tti Labs is responsible.

2.What we hold

  • Your account: your name, email address, the organisations you belong to, your role in each, and until when.
  • Signing in: your password, stored only as a one-way hash by our sign-in provider; your two-step sign-in factors; and your sessions, with the browser, device and IP address each was started from, so you can see them and end them under Account security, and so we can tell you when a new device signs in. When you create your account from an invitation link, we log the IP address it came from, for security, and delete that log after 90 days.
  • What you do: every change to an organisation's data is recorded with who made it and when, in a tamper-evident audit trail. Verifiers rely on it, so it can't be edited.
  • What you record: mostly figures about an organisation's activity, which aren't personal data, and the files attached to them, such as bills and certificates. Supplier contacts (a name and an email address) are kept where an organisation asks a supplier for data. Commuting is recorded as totals, never per employee.
  • Emails we send you: invitations, sign-in and security notices, and the reminders your organisation turns on.

We don't collect payment card details, sensitive personal data, or anything for advertising.

3.Why we use it

  • To run Greening OS for your organisation and for you: the reason the organisation has an agreement with Tti Labs.
  • To keep it secure, and its records trustworthy: sessions, sign-in notices and the audit trail.
  • To meet legal obligations, where a law requires us to keep or hand over information.

We don't sell personal data, profile people, or use it for marketing.

4.Cookies and browser storage

Greening OS uses only what it needs to work, so it doesn't ask for cookie consent:

  • sign-in cookies that keep you signed in;
  • a random device id (gos_device) and a mark that this session has been noted (gos_noted), for the new-device notice and the session list;
  • the unit you last chose on This month, and in your browser's own storage, the pages you opened recently, the last source you entered and whether you chose the light or dark look, so you can carry on where you were;
  • on a phone used without a connection, the readings and bill photos you entered, kept on the device until they are sent, and the This month pages you opened, so they work offline. Signing out clears the pages. Unsent readings stay on the device until they are sent or discarded, shown only to the person who entered them, so nothing typed offline is lost.

There are no analytics, advertising or third-party tracking cookies.

5.Who else handles it, and where

These companies process data for us, under contracts that bind them to use it only for that:

CompanyWhereWhat for
Hetzner Online GmbHGermanyRuns the application server.
Supabase Inc.European Union (Frankfurt)Hosts the database, sign-in and stored files (bills, certificates, reports).
Amazon Web Services (Amazon SES)European UnionSends the app's emails: invitations, sign-in links, reminders and notices.
Anthropic PBCUnited StatesOnly when used: reads a bill image someone asks it to read, and answers the copilot's questions where an owner has turned the copilot on.
  • So your data is stored outside Pakistan, in the European Union. If an organisation needs it held in Pakistan, its agreement can provide for that.
  • Anthropic receives data only when the AI features are used: the bill image someone asks it to read, with whatever is printed on it (often the account holder's name and address), and, where an owner has turned the copilot on, the questions asked and the figures read to answer them. The copilot's figures go without who did what: no names of who entered, approved or owns something, and no email addresses, sessions or keys. Notes and reasons are sent as they were written. Anthropic doesn't use this data to train its models.

6.How long we keep it

  • An organisation's data, files and audit trail are kept while the organisation is open.
  • When an owner closes it, they stay readable for 30 days (7 if a second owner agrees), then are deleted for good. We keep only a record that the organisation was closed: who asked, why, and when.
  • When someone leaves an organisation, their access ends, but their name stays in its audit trail beside what they did, because those records must stay complete.
  • Some records are deleted on a schedule, every night:
    • records of calls made with API keys, the app's readings of uploaded bills, and the logs of scheduled jobs after 90 days;
    • notifications after a year;
    • the devices you sign in from once unused for 400 days;
    • records of views of shared report links after two years.
  • Backups are overwritten after [the backup period, to be confirmed].
  • Your account is kept until you ask us to delete it. We act on that within 30 days: the account is closed so it can no longer sign in, and what isn't needed to keep the organisations' records complete is removed. Your name stays beside what you did in their audit trails.

7.How we protect it

  • Every connection is encrypted, and so are the database and the stored files at rest.
  • Each organisation's data is kept apart by the database itself, so a request on behalf of one organisation can't read another's.
  • Two-step sign-in is available to everyone, and required for owners, admins, managers and verifiers.
  • The audit trail is chained, so a change made outside the app would show.

8.Your rights

You can ask us to show you the personal data we hold about you, correct it, delete it, stop using it for a purpose, or give it to you in a form you can take elsewhere. For data your organisation recorded, we pass the request to its owners, who decide. We answer within 30 days.

Pakistan's law, and the EU's and UK's data protection law where they apply to you, may give you further rights, including complaining to a regulator.

9.Changes and contact

When this notice changes in a way that matters, we say so in the app or by email before the change takes effect. Questions and requests: [contact email, to be confirmed].