Privacy Policy

When using Giosg.com Ltd’s ("us", "we", or "our") Services (“Services”), we receive and process information as described in this privacy policy. We automatically collect and store certain information as described below. Please take the time to carefully read this Privacy Policy.

Giosg.com Ltd (giosg.com Oy), business ID 2388009-8, Valimotie 21, 00380 Helsinki, Finland. This Privacy Policy also covers the email features of the giosg platform, which let business users of our Customers, such as agents and administrators, connect a Google (Gmail) account; see section 12, "Google User Data".

This Privacy Policy is also intended to serve as a Data Processing Agreement between us and those Customers with whom we do not have a separate DPA in place.

1. Data Processing

The data collected by the Services is split into two categories:

Customer Data is data processed by us on behalf of the Customer using the Services. Customer data contains personal data, such as full ip addresses and the contents of chat conversations. Most of this data is provided by the visitor themselves during a chat conversation. The purpose of the processing of this data is the provision of customer engagement and analytics tools on the Customer website.

The Customer Data is owned by the Customer. In regard to Customer Data the Customer is the data controller and giosg the data processor in the meaning of the EU data protection legislation.

When a Customer's user connects a Google account, Customer Data also includes email data from that account. Emails may contain personal data of third parties, such as senders and recipients. The Customer is the data controller of this data and giosg the data processor.

The Customer Data categories are fully listed in the table below:

Customer Data
1. Web Analytics Data (per visitor)
  • Customer-specific cookie identifier (CID)
  • IP address
  • Visited URLs
  • Referrer URL
  • Timestamp
  • Operating system
  • Device Browser
2. Chat operator data (registered user)
  • Name
  • Phone number
  • Email address
  • Additional user-provided information
  • Time online
  • Profile picture, if uploaded
3. Chat related data
  • Content of the conversations
  • Operator of each chat
  • References to web analytics data
  • Blacklisted users (per cookie/IP address)
4. Additional data provided by
  • Customer Data provided through the API
5. Email data (connected Google accounts)
  • Google account email address and name, email messages (subject, body, sender, recipients, dates, headers), attachments, labels, threads and read status. See section 12.

 

2. Cookies

Our Services use cookies, including unique cookie identifiers, as well as similar local storage technologies such as browser web storage and application data caches.

Cookies are used for tracking visitors and their browsing patterns. Cookies allow us to identify, profile and track computers which are used to visit our website or those websites which use giosg Services. By accessing our website or websites which use giosg Services, you accept the use of cookies and tracking.

Most browsers accept cookies automatically. However, you can change the settings of your browser to erase cookies or prevent them. In that case, we cannot guarantee that our website or Services will be able to provide you with the intended user experience.

Third Party Cookies

On our own website we also use third party cookies from the following Service providers to help us analyze trends and for tracking purposes, and to gather general information about our visitor base:

DoubleClick collects data on visitor responses to advertising and the effectiveness of advertising.

Facebook collects data and analytics regarding traffic flows to/from Facebook and displays ads.

Google Analytics collects data and analytics regarding the visitor base and traffic of the website.

Google Adwords is used for showing ads in connection with google search results.

HubSpot is used for email tracking and analytics of website traffic and visitor data.

Linkedin Marketing Solutions collects data and analytics regarding traffic flows to/from Linkedin and displays ads.

These third-party cookies are used on our own website only. Data from connected Google
accounts is never shared with these services or used for advertising.

 

3. Visitor Consents

When using the giosg Service on any website, the Customer is responsible for acquiring all applicable consents (regarding for example the processing of personal data and cookies) from the website visitors as necessary for the delivery of the Service.

 

4. Servers and Data Storage

All Data is physically stored within the European Union. The servers are provided through credible subcontracters.

 

5. Duration of Data Processing

Unless otherwise agreed, we store Customer Data for 5 years.

A custom chat data deletion tool can be activated for the manager user account, allowing for the Customer to schedule the deletion time of chats themselves.

 

6. Technical and Organizational Measures

We hereby confirm that we have the appropriate technical and organizational measures in place to meet the data processing requirements of the General Data Protection Regulation. Giosg is ISO27001 certified.

We have appointed a Data Protection Officer.

The Services are TLS protected. At rest-data encryption, IP access controls and high-security password controls are provided as a separate security tool.  Google user data and OAuth tokens are always encrypted at rest, regardless of the separate security tool.

 

7. Sub-Processors

Credible third-party subcontractors may be engaged in the data processing process for data storage purposes (rented servers).

For AI features, content, including email content, may be processed by AI service providers acting as our sub-processors in the EU/EEA. They do not store the content beyond processing and do not use it to train their models.

We will provide Customers with a written notice before engaging sub-processors for other purposes.

 

8. Confidentiality

We confirm that all persons we have authorised to process personal data of the Customer are bound with a written undertaking of confidentiality.

 

9. Data Breach Notices

In case we become aware of a data security breach affecting personal data we will report this to the Customer within a time frame of 48 hours. In such case we will coordinate and assist the Customer in minimising any damage and provide the Customer with the required information about the breach.

 

10. Data Subject Rights

We are committed to assisting our Customers with their responsibilities regarding the data subject rights. Our contact for this type of requests is support@giosg.com.

In cases where such assistance causes us a substantial amount of work, we reserve the right to invoice such work in accordance with our standard hourly fees.

 

11. Right to Audit

Our Customers are welcome to perform data protection/security audits on us as long as they compensate for all costs involved.

For audits causing us a substantial amount of work, we reserve the right to invoice such work in accordance with our standard hourly fees.

 

12. Google User Data

This section applies when a business user of a Customer connects a Google account to Giosg Email Integration app. giosg processes this data on behalf of the Customer as described in section 1, and in addition follows the commitments below.

Data we access. Using Google OAuth, we access the data listed in section 1, category 5. 

How we use it. We use Google user data only to provide and improve the user-facing features of Giosg Email Integration app: showing, searching and organising the user's emails, and generating AI summaries and draft replies. We do not use it for any other purpose.

AI/ML. We do not use Google user data to develop, improve or train generalised or non-personalised AI/ML models.

Sharing. We do not sell Google user data or use or transfer it for advertising, including retargeting and personalised or interest-based ads, or to determine creditworthiness or for lending. Google user data is available only to the connecting user and to other users of the same Customer account who have been given access to it in the platform, and to the sub-processors described in section 7. We disclose it to others only when required by law.

Human access. Our personnel do not read email content unless (a) the user gives explicit consent for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is required by law, or (d) the data has been aggregated and anonymised for internal operations.

Storage, retention and deletion. Google user data is stored encrypted in the EU. Unlike the default in section 5, we keep it only while the Google account is connected. Users can disconnect at any time in application settings or at myaccount.google.com/permissions, after which we revoke our tokens and delete stored Google user data within 30 days. Deletion can also be requested at support@giosg.com.

Changes. If we change how we access, use, store or share Google user data, we will notify affected users in the app or by email before the change takes effect.

Limited Use. giosg's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

 

13. Contact

For questions regarding privacy, please contact: support@giosg.com.

 

(Policy last modified: 28 September 2026)