Ask Osolix — instant answers

Legal & Compliance

Privacy Policy

How we collect, use, and protect your data — in plain language.

GDPRUAE PDPLISO 27001-aligned

Last updated · 2026-09-26

Osolix ("we", "us", "the platform") provides a multi-tenant fixed asset management platform for finance, asset, and audit teams. This Privacy Policy explains what personal data we collect, why we collect it, how it is processed, who it is shared with, and how long we keep it. It applies to osolix.com, the Osolix web application, the Osolix mobile applications, and any Osolix API.

We act as the data processor on behalf of our customers (the tenants who licence Osolix) for everything stored inside a tenant. We act as the data controller only for the information we collect about you when you visit our marketing pages, request a demo, or sign up for our newsletter.

1Data we collect

  • Account & identity: name, email, phone, job title, employer, language, time zone.
  • Authentication: hashed password, single sign-on (SSO) claims, encrypted authenticator (MFA) secrets and single-use recovery codes, session cookies.
  • Usage telemetry: page visits, feature interactions, error reports and AI feature usage (recorded without the text of your questions) — used to operate and improve the product. We do not sell this data.
  • Tenant data: the asset, financial, maintenance, custodian and document data your employer uploads. We never access tenant data except for support tickets you raise, legal compulsion, or as required to operate the platform.
  • Marketing-page data: if you submit a demo request, we collect what you give us — name, email, company, phone, message — and a marketing-attribution cookie.

2Lawful basis (GDPR Art. 6 / UAE PDPL Art. 5)

  • Contract: we process account, identity and tenant data to deliver the service you contracted with us for.
  • Legitimate interest: we process telemetry to improve the platform.
  • Consent: we use cookies and email marketing only with your consent (you can withdraw at any time).
  • Legal obligation: we retain audit logs and financial transaction records to meet tax, accounting, and audit obligations.

3How we share data

We share personal data only with the sub-processors we need to deliver the service: Microsoft Azure (hosting and storage), Stripe (payment processing — we never see or store full card numbers), Twilio SendGrid (email delivery) and Anthropic (AI assistance — only if your organisation switches on Online AI). Each processes data on our instructions under contractual confidentiality and data-protection commitments. We give at least 30 days' notice before adding or replacing a sub-processor. We never sell personal data and never share customer data with third parties for their own purposes.

Online AI is off unless your organisation's administrator switches it on and accepts the AI data terms. When it is on, the AI assistants send the user's question and the minimum business context needed to answer it to Anthropic, which processes it on our behalf under commercial terms that do not permit it to train its models on that data. When it is off, no data is sent to any AI provider. Administrators can switch Online AI off at any time.

4International transfers

Customer data is hosted in Microsoft Azure data centres in the United Arab Emirates (UAE North region). Some sub-processors listed in section 3 process limited data in other countries, including the United States — for example payment details (Stripe), email delivery (SendGrid) and, only if Online AI is switched on, AI requests (Anthropic). Where personal data leaves the UAE, the Kingdom of Saudi Arabia or the European Economic Area, we rely on the safeguards the applicable law requires, such as adequacy decisions or standard contractual clauses. Customers with specific data-residency requirements should raise them before signing so they can be agreed in writing.

5Retention

  • Account data: kept while your organisation's subscription is active. You can ask for your own account to be erased at any time (see section 6): sign-in stops immediately and your personal details are permanently removed after 30 days. Personal data held for an organisation is deleted 90 days after its subscription ends.
  • Audit logs and financial records: kept for as long as audit, tax and accounting obligations require — typically up to 7 years. If a person's account is erased, their name is removed from these records but the record that the action happened is kept.
  • Telemetry: 13 months rolling.
  • Marketing leads: 24 months from last interaction, then deleted unless you have opted in to a longer relationship.

6Your rights

  • Access your personal data and obtain a copy.
  • Rectify inaccurate data.
  • Request erasure (subject to retention obligations).
  • Object to or restrict processing.
  • Withdraw consent for marketing at any time.
  • Lodge a complaint with your local data protection authority.

You can download a copy of your personal data and request erasure of your account yourself from your profile page. For any other request, use our contact form. We respond within 30 days.

7Security

Each customer's data is logically separated: every record is tagged to the organisation that owns it and access is checked on every request, with automated tests confirming that one organisation cannot read another's data. Passwords are hashed, authenticator secrets and ERP credentials are encrypted, and application secrets are held in a managed key vault. Our controls are designed with reference to ISO/IEC 27001; we do not claim certification. We carry out regular internal security reviews and plan independent penetration testing; enterprise customers may request a summary of our current security measures.

8Children

Osolix is a B2B service and is not directed to children under 16. We do not knowingly collect personal data from children.

9Changes

We will notify customers and visitors of any material change to this policy at least 30 days before it takes effect, via in-app banner and the email address on file.

10Contact

Osolix · UAE · contact form

Questions about how we handle your data? Reach our privacy team through our contact form.