Skip to main content

Security and data protection

Drafted: ·Updated:

Gosoft Connect is used on websites that belong to other companies, which makes almost everything it touches somebody else's data. This page describes what we do about that, in enough detail to be checked rather than taken on trust.

Where we act on a customer's behalf we are a processor and they are the controller. Our processor privacy notice and our Data Processing Agreement set out that relationship in full.

Data protection by design

No cookies. Gosoft Connect sets none, on any customer site. There is no cookie banner because there is nothing to consent to on that basis. What the widget needs to function is held in the browser's local storage, scoped to that one site, and cleared when the session expires or the visitor asks.

No visitor IP addresses are stored. An IP is held in memory only long enough to rate-limit abusive traffic, and is never written to our database or to any application log. We keep no web access logs at all - the usual line-per-request record of who visited what is switched off, not merely rotated. Web-server error logs may still record a client address for request-level failures such as timeouts; those are operational logs kept 14 days. We do store the IP of a logged-in portal user for audit, DPA acceptance and password resets - staff and customer personnel, never a website visitor.

No third-party trackers. No advertising pixels, no third-party analytics, no session replay. Knowledge-base search runs on our own infrastructure.

Automated profiling is off unless switched on. The feature that derives attributes from a conversation is disabled by default and requires a deliberate per-workspace decision.

Encryption

In transit - TLS on every connection between visitors, customers, our services and our sub-processors.

Backups - encrypted with public-key cryptography before they touch disk. The server running the platform holds only the public half, so it can create backups and cannot read any of them back. The private half lives on a separate backup host that runs no public services. Someone who compromised our application server would obtain encrypted archives and no means of opening them.

Data in the live database is protected by the access controls and infrastructure security described below rather than by full-disk encryption. We would rather state that plainly than imply a control we do not operate.

Access control

Access is invite-only - there is no open self-service registration. Every request is scoped to an organisation and a workspace and re-checked on the server; workspace ownership is verified per call, so an administrator of one organisation cannot reach another's data by guessing identifiers. Passwords are hashed with argon2id. Administrative AI endpoints bind to loopback only and refuse any request that arrived through a public proxy.

Audit logging

Portal reads of customer personal data are recorded: who accessed what category of data, in which workspace, when, and from where. The log holds no message content. Covered today: opening a conversation, exporting a transcript, listing form submissions, and opening the moderation queue.

Not covered, so you know the edges: aggregate dashboard previews, and direct database access by an administrator with shell access to the server. The second is bounded by limiting production access to named administrators rather than by logging, and we would rather say so than imply a completeness we cannot deliver.

Customers can retrieve their own access trail at any time through the portal API. Verifying who has looked at your data should not require asking us.

Resilience

Backups run nightly, are verified when created, and are replicated to a separate server in a different country, where they are retained for thirty days. That backup host has no public IPv4 address, denies all inbound traffic at the provider firewall, and is reachable only over a private network.

Automated health checks run every three minutes and alert on service failure, certificate expiry, and on backups that stop arriving, go stale, or are written without encryption.

Sub-processors

Sub-processor Role Established in Data located in
Hetzner Online GmbH Hosting and infrastructure Germany (EU) Finland (Helsinki); backups in Germany (Falkenstein)
OpenAI Ireland Ltd AI model inference and content moderation Ireland (EU) EU/EEA

Both are engaged under data processing agreements imposing obligations equivalent to those we owe our customers, and we remain liable to the customer for their performance. Our agreement with OpenAI includes Standard Contractual Clauses. Data sent through the API is not used to train OpenAI's models.

We notify customers before adding or replacing a sub-processor, with a period to object on reasonable grounds.

Data centre certification

Both data centres holding your data - Helsinki for the platform, Falkenstein for backups - fall within the scope of Hetzner's ISO/IEC 27001 certification, valid to September 2028, and Hetzner holds a BSI C5 Type 2 attestation. Their technical and organisational measures were inspected on site by TUV Rheinland i-sec, whose most recent report records no deviations. Hetzner publishes the measures themselves at hetzner.com/AV/TOM_en.pdf, which is the document to read if you want the detail. We hold our own Article 28 agreement with Hetzner and their audit report; both are marked confidential by Hetzner, so we share them under a non-disclosure agreement rather than publish them.

To be precise about what this covers: these are our hosting provider's certifications, covering their data centres and hosting services. Gosoft Oy is not itself ISO 27001 certified, and we do not claim to be. The measures described on this page are our own, and are stated so you can verify them rather than take a badge on trust.

Retention

Data Default Set by customer
Conversations, messages, submissions, uploaded files 90 days from last activity On request
Analytics events and leads 365 days On request
AI usage records - model, tokens, cost, no message content Longer, as accounting records No

Deletion is automated, not on request. The sweep runs every day at 03:00 in your workspace's own timezone and issues a real delete, not a hidden flag. A separate hourly pass closes idle conversations and clears expired tokens.

Retention windows are defaults enforced in code. We will set a different window for your workspaces on request; there is no self-service control for it yet, so the table says "on request" rather than implying a setting you would go looking for.

Rights of website visitors

Visitors can download or delete their own data directly from the chat widget, authenticated by a secret held in their own browser. Erasure removes conversations, messages, form submissions, uploaded files, leads, any profile, and analytics events - verified end to end, including the files on disk.

Where a visitor has lost that secret, the request goes to the website operator as controller, and we act on their instruction.

Where we are

Gosoft Oy is a Finnish company, Business ID 3454099-6, registered in Helsinki. Our primary data storage is in the EU/EEA. Our agreements are governed by Finnish law.

Asking us questions

Security questionnaires, audit requests under Article 28(3)(h), and requests for our Article 30 processing record all go to privacy@gosoft.fi. We would rather answer a specific question than send a generic pack.