Legal & Compliance
How we collect, use, and protect your data — in plain language.
Last updated · 2026-09-26
Osolix ("we", "us", "the platform") provides a multi-tenant fixed asset management platform for finance, asset, and audit teams. This Privacy Policy explains what personal data we collect, why we collect it, how it is processed, who it is shared with, and how long we keep it. It applies to osolix.com, the Osolix web application, the Osolix mobile applications, and any Osolix API.
We act as the data processor on behalf of our customers (the tenants who licence Osolix) for everything stored inside a tenant. We act as the data controller only for the information we collect about you when you visit our marketing pages, request a demo, or sign up for our newsletter.
We share personal data only with the sub-processors we need to deliver the service: Microsoft Azure (hosting and storage), Stripe (payment processing — we never see or store full card numbers), Twilio SendGrid (email delivery) and Anthropic (AI assistance — only if your organisation switches on Online AI). Each processes data on our instructions under contractual confidentiality and data-protection commitments. We give at least 30 days' notice before adding or replacing a sub-processor. We never sell personal data and never share customer data with third parties for their own purposes.
Online AI is off unless your organisation's administrator switches it on and accepts the AI data terms. When it is on, the AI assistants send the user's question and the minimum business context needed to answer it to Anthropic, which processes it on our behalf under commercial terms that do not permit it to train its models on that data. When it is off, no data is sent to any AI provider. Administrators can switch Online AI off at any time.
Customer data is hosted in Microsoft Azure data centres in the United Arab Emirates (UAE North region). Some sub-processors listed in section 3 process limited data in other countries, including the United States — for example payment details (Stripe), email delivery (SendGrid) and, only if Online AI is switched on, AI requests (Anthropic). Where personal data leaves the UAE, the Kingdom of Saudi Arabia or the European Economic Area, we rely on the safeguards the applicable law requires, such as adequacy decisions or standard contractual clauses. Customers with specific data-residency requirements should raise them before signing so they can be agreed in writing.
You can download a copy of your personal data and request erasure of your account yourself from your profile page. For any other request, use our contact form. We respond within 30 days.
Each customer's data is logically separated: every record is tagged to the organisation that owns it and access is checked on every request, with automated tests confirming that one organisation cannot read another's data. Passwords are hashed, authenticator secrets and ERP credentials are encrypted, and application secrets are held in a managed key vault. Our controls are designed with reference to ISO/IEC 27001; we do not claim certification. We carry out regular internal security reviews and plan independent penetration testing; enterprise customers may request a summary of our current security measures.
Osolix is a B2B service and is not directed to children under 16. We do not knowingly collect personal data from children.
We will notify customers and visitors of any material change to this policy at least 30 days before it takes effect, via in-app banner and the email address on file.
Osolix · UAE · contact form
Questions about how we handle your data? Reach our privacy team through our contact form.