Privacy notice

How Jusoor collects, uses, and protects your personal data.

Privacy

Staff & Consultant Privacy Notice

Effective July 9, 2026 · Last updated August 5, 2026 · Version 2.0

This notice explains what personal data Jusoor holds about you in Jusoor OS, why we hold it, who can see it, how long we keep it, and the rights you have over it. It applies to everyone we employ or engage.

1. Who we are

Jusoor (“Jusoor”, “we”, “us”) is a non-profit organization, 501(c)(3), registered in California, USA. We decide how and why your personal data is handled in Jusoor OS, which makes us the data controller for it.

  • Privacy questions and requests: mydata@jusoor.ngo
  • Postal address: 501 Crescent Way, Apt 5311, San Francisco, California 94134, USA

2. What this notice covers

Jusoor OS is our internal People and Operations platform. It is used only by Jusoor staff and consultants and is not open to the public. It covers:

  • People and organization directory, including your profile and reporting line
  • Time off: balances, requests and the shared team calendar
  • Reimbursements: claims and receipts
  • Bill payments and vendors, which are mostly organizational but can involve you
  • Payroll: your payment method, monthly invoices and payment statements
  • Documents: official letters such as proof of employment and compensation certificates
  • Performance reviews
  • Surveys, with the anonymity rules described in Section 7
  • Tasks and notices you acknowledge or complete
  • Employee assets: your email signature and digital ID card
  • A resource directory of links, which holds no personal data
  • Google Workspace integration, described in Section 5

We already hold most of this information as your employer or engager. Some of it was migrated from the HR system we used before Jusoor OS. Using this platform gives us no new rights over your data.

3. The personal data we hold

We collect what we need to employ or engage you and to run normal HR, finance and operations.

Identity and profile. Your preferred name and legal name, work email, a personal email address, a profile number, an optional photo, job title, department, teams, level, country, time zone, employment type, work time, start date and reporting line.

Personal information you enter. Personal phone number, date of birth, gender, nationality, home address, dietary requirements and emergency contacts.

Private information. Passport or national ID number and a passport photo, your payment method including bank details, and your compensation. These are held only where genuinely needed and are treated as described in Sections 7 and 10.

Work records. Time-off balances and requests including any reason you write, reimbursement claims and receipts, salary invoices and payment statements, bills and vendor records where you are involved, performance review content about you and reviews you write, survey responses, tasks and notices sent to you with your acknowledgements, and documents uploaded by you or by HR such as contracts and signed letters.

Account and activity. Your login through Google sign-in, a record of the devices you sign in from so we can alert you to an unrecognized one, and an audit log of meaningful actions. The audit log records what was done and by whom, never the sensitive values themselves.

We do not use this platform for tracking, advertising or selling data of any kind.

4. Why we use it, and our lawful basis

We use your data to maintain an accurate directory and org structure, administer time off, pay, reimbursements and expenses, run performance reviews, meet our legal, tax and accounting obligations, and keep the platform secure.

Where GDPR or UK GDPR applies, our lawful bases are:

  • Performance of your contract. Most processing is necessary to employ or engage you, and to pay and manage you.
  • Legal obligation. Some records, such as pay and tax records, must be kept by law.
  • Legitimate interests. Routine HR and operations administration, and securing the platform, in a way that does not override your rights.

We do not rely on consent for core HR processing, we do not sell your personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.

5. Service providers and the Google Workspace integration

We run Jusoor OS using a small number of established providers who process data on our behalf, under our instructions and under Data Processing Agreements:

  • Supabase hosts our database, file storage and login system. Region: EU West 1, Ireland.
  • Cloudflare hosts the application, DNS and network security across its global edge network.
  • Resend sends system email, including the one-time account details we send when you join. Those details are never stored by the platform.
  • Google Workspace provides sign-in and 2-Step Verification, and the integration below.

Because Jusoor runs on Google Workspace, Jusoor OS also manages parts of your Jusoor Google account on the organization’s behalf:

  • Creating your @jusoor.ngo account when you join and suspending it when you leave. The platform cannot delete a Google account.
  • Adding you to the Google Groups that match your role, department or team.
  • Showing approved time off in your Google Calendar and on a shared team calendar as a neutral “Out of office” entry. The type of leave is never shown to colleagues.
  • Setting your Gmail auto-reply for the dates you are away, only if you ask for it when requesting the time off.
  • Setting the organization-wide email signature on your Gmail account.
  • Adding the day and month of your birthday to a shared birthdays and public holidays calendar that colleagues can see. The year is never published. Tell HR if you would rather it was not shown.
  • Reading a shared invoices mailbox so emailed supplier invoices become draft bills. This is an organizational mailbox. No personal mailbox is ever read.
  • When you leave, transferring the files and calendar events in your work Google account to a colleague and removing personal recovery details from that work account. This covers your Jusoor account only, never a personal Google account.
  • Storing platform backups in the organization’s own Google Drive. Passport, ID and bank details stay encrypted or masked there. Payroll amounts appear in readable form, so access to that folder is limited to the platform’s own service account.

We keep an up-to-date list of these providers. We do not share your personal data with anyone else except where required by law or at your direction.

6. International transfers

Our team is spread across many countries and our providers operate internationally, so your data may be processed outside your own country. Our primary hosting region is EU West 1, Ireland. Where data moves between regions we rely on our providers’ transfer safeguards, such as Standard Contractual Clauses.

7. Who can see your data inside Jusoor OS

Access is restricted by role and by need, and is enforced in the software:

  • You can see and manage your own profile, personal information, private details, documents, time off, reimbursements and pay.
  • Your manager, and anyone above them in your reporting line, can see your role and organizational information, your time off, and your contract details including compensation and contract documents. They can view your phone number on request. Every reveal of compensation or of your phone number is logged. They cannot see your passport or ID, or your bank details.
  • HR administrators can see and manage people records for HR purposes. Sensitive fields are masked by default, revealed only with permission, and every reveal is logged.
  • Finance can see the finance data they process: bills, reimbursements, vendor records, and the payroll information needed to pay you.
  • Performance reviews follow strict separation of duties. Only the designated performance administrator can see everyone’s results. Platform administrators cannot see other people’s review results, only their own and their reporting line’s. Within a review, each question is configured so that what a reviewer writes reaches you with their name, anonymously, or not at all, and the platform enforces that setting.
  • Surveys. When a survey is anonymous the link between you and your answers is never recorded, so nobody can see who said what, including the survey’s creator and administrators. Results appear only once enough people have responded that answers cannot be traced back to individuals. The platform records that you completed an anonymous survey so that reminders stop, never what you answered. Named surveys say so before you respond.

Passport and ID numbers, bank details and compensation are encrypted, shown masked by default, and audited every time they are revealed.

8. Your rights

You can ask us to:

  • Access a copy of the personal data we hold about you.
  • Correct data that is wrong or out of date. You can edit much of this yourself in your profile.
  • Delete your data where we no longer have a lawful reason to keep it.
  • Restrict or object to certain processing.
  • Receive certain data in a portable format.

To exercise any of these, contact mydata@jusoor.ngo. We will respond within 60 days, or tell you if we need more time or more information to verify your identity. Some data may need to be kept for legal or tax reasons even after you leave. See Section 9.

9. How long we keep your data

We keep your data while you are employed or engaged, and for up to 7 years after your last working day. After that your record becomes eligible for permanent erasure.

This period is set to meet tax and employment record-keeping requirements across the countries our team members live in, including the United States, Canada, the United Kingdom, the Netherlands and the European Union, where those periods commonly range from four to ten years. Where local law requires a different period, we follow it.

After the retention period, or on a valid erasure request where no legal reason to keep the data remains, we permanently delete your personal data from the platform, including your files and your login. We keep a minimal record that an erasure happened, showing your name and reference number only.

Erasure removes your data. It does not rewrite the organization’s own records. Where you acted in an organizational capacity, for example approving a colleague’s leave or a payment, that record keeps your name as plain text with no link to any profile. Survey answers you gave are kept in de-identified form. Bookkeeping about the organization’s decisions survives; your personal data does not.

10. How we protect your data

  • Encryption of passport and ID numbers, bank details and compensation, shown masked by default and revealed only with permission.
  • Role-based access control that denies by default, enforced in the software.
  • Sign-in through Google with 2-Step Verification, and an alert to you when your account signs in from an unrecognized device.
  • Audit logging of meaningful actions.
  • Encrypted, access-restricted backups.
  • Security review before real data goes in, and after significant changes.

No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong. If a breach affects your personal data and is likely to create a risk to you, we will notify you and any regulator as required by law.

11. Data minimization

We aim to collect only what we use. If you think we hold data we do not need for your role, tell us and we will review it.

12. Changes to this notice

We may update this notice as the platform or the law changes. We will tell staff and consultants about material changes and update the date above.

13. Contact

  • Email: mydata@jusoor.ngo
  • Postal address: 501 Crescent Way, Apt 5311, San Francisco, California 94134, USA

Internal platform for Jusoor staff and consultants.