Privacy
Staff & Contractor Privacy Notice
Effective July 9, 2026 · Last updated July 20, 2026 · Version 1.1
This notice explains what personal data Jusoor holds about you in the Jusoor OS platform, why we hold it, who can see it, how long we keep it, and the rights you have over it. It applies to everyone whose data we hold in Jusoor OS — employees and contractors.
1. Who we are (the data controller)
Jusoor (“Jusoor”, “we”, “us”) is a non-profit organization (501(c)(3)) registered in California, USA. We decide how and why your personal data is handled in Jusoor OS, which makes us the data controller for that data.
- Contact for privacy questions and requests: mydata@jusoor.ngo
- Postal address: 501 Crescent Way, Apt 5311, San Francisco, California 94134, USA
If you have a question about your data or want to exercise any of your rights (Section 8), contact us at the address above.
2. What this notice covers
Jusoor OS is our internal People & Operations platform, used only by Jusoor staff and contractors — it is not open to the public. It brings together:
- People & organization directory (your profile and org information)
- Time Off (leave balances and requests)
- Expense reimbursement (expense reports and receipts)
- Bill Pay & Vendors (paying invoices — mostly organizational, but can include you)
- Performance reviews
- Surveys (staff feedback — see Section 7 for the anonymity rules)
- Tasks & notices (organizational announcements you acknowledge or complete)
- Employee assets (your organizational email signature and digital ID card)
- Google Workspace integration (your Jusoor Google account, calendar, and Gmail settings — see Section 5)
We already hold most of this information as your employer or engager. Using Jusoor OS does not give us new rights over your data — it is a more secure, organized place to keep and use the data we already need to work with you.
3. The personal data we hold
We collect only what we need to employ or engage you and to run normal HR, finance, and operations:
Identity & profile: your preferred name and legal name, work email, a personal email address (used to send you your account details when you join, and kept as a contact route), a profile number, photo (optional), job title, department, team(s), level/seniority, country, employment type (employee/contractor), work-time (e.g. full-time/part-time), start date, and your manager/reporting line.
Personal information (entered by you): personal phone number, date of birth, gender, home address, dietary requirements, and emergency contact(s).
Sensitive / private information (held only where genuinely needed): passport or national ID number and a passport photo; bank / payout details (to pay you); and compensation / pay information.
Work records: time-off balances and requests (including any reason you enter); expense reports and receipts; bills or vendor/payout records where you are involved; performance-review content about you (and reviews you give — see Section 7); survey responses you submit (see Section 7 for how anonymity works); tasks and notices sent to you and your acknowledgements; and documents you or HR upload (e.g. contracts).
Account & activity: your login (via Google sign-in); a record of the devices you sign in from (a cookie recognizes each device, and a sign-in from an unrecognized device triggers a security alert to you); and an audit log recording meaningful actions (who did what, and when) for security and accountability. The audit log records the action and the people involved by name, never the sensitive values themselves.
We do not use this platform for tracking, advertising, or selling data of any kind.
4. Why we use it, and our lawful basis
We use your data to maintain an accurate directory and org structure; administer time off, pay, expenses, and reimbursements; run performance reviews; meet our legal, tax, and accounting obligations; and keep the platform and your data secure.
Our lawful bases for this (relevant where GDPR / UK GDPR applies) are:
- Performance of your contract — most processing is necessary to employ or engage you and to pay and manage you.
- Legal obligation — some records (e.g. pay and tax records) must be kept by law.
- Legitimate interests — routine HR and operations administration, and securing the platform, in a way that doesn’t override your rights.
We do not rely on consent for core HR processing, we do not sell your personal data, and we do not use it for automated decision-making that has legal or similarly significant effects on you.
5. The service providers we use (sub-processors)
We run Jusoor OS using a small number of reputable providers who process data on our behalf and under our instructions, under Data Processing Agreements:
- Supabase — hosts our database, file storage, and login system (this is where your data lives). Region: EU West 1 (Ireland).
- Cloudflare — hosts the app front-end, DNS, and network security/CDN, across its global edge network (default region).
- Resend — sends system emails (notifications, reminders, and your one-time account details when you join — sent to your personal email address and never stored by the platform), in its default region.
- Google (Google Workspace) — sign-in (“Sign in with Google”) and 2-Step Verification, plus the workplace integration described below, on Google infrastructure.
Because Jusoor runs on Google Workspace, Jusoor OS also manages parts of your Jusoor Google account on the organization’s behalf:
- Creating your @jusoor.ngo account when you join, and suspending it when you leave (the platform can never delete a Google account).
- Adding you to the Google Groups (mailing lists) that match your role, department, or team.
- Approved time off appears in your Google Calendar and on a shared team calendar as a neutral “Out of office” entry — the type of leave is never shown to colleagues.
- Optionally setting your Gmail auto-reply for the dates you are away (only if you choose this when requesting time off).
- Setting the organization-wide email signature on your Gmail account.
- Setting your Google profile photo from your Jusoor OS photo (framed in Jusoor’s style) — you can opt out of this on your profile.
- When you leave, the organization may transfer the files and calendar events in your work Google account to a colleague, and remove personal recovery details from the work account — this covers your Jusoor account only, never any personal Google account.
- Platform backups (with the most sensitive fields kept encrypted, and identity documents/bank details masked in the readable copies) are also stored in the organization’s own Google Drive.
We keep an up-to-date list of these sub-processors. We do not share your personal data with anyone else except where required by law, or at your direction.
6. International transfers
Our team members are located all over the world, and our providers operate internationally, so your data may be processed outside your own country. Our primary hosting region (the database) is EU West 1 (Ireland). Where data moves between regions, we rely on our providers’ safeguards for such transfers (for example, Standard Contractual Clauses and their data-transfer terms).
7. Who can see your data inside Jusoor OS
Access is restricted by role and by need, enforced in the software (not just by policy):
- You can see and manage your own profile, personal information, private details (passport/bank), documents, time off, and expenses.
- Your manager — and anyone further up your reporting line — can see your role and organizational information, your time off, and your contract details (including compensation and contract documents). On request they can also view your phone number. Reveals of compensation and of your phone number are logged. They cannot see your passport or national ID or your bank details, which remain limited to you, HR, and the Director.
- HR administrators can see and manage people records for HR purposes; sensitive fields are masked by default and only revealed with permission, and every reveal is logged.
- Finance can see finance data (bills, expenses, vendor/payout information) for the payments they process.
- Performance reviews follow strict separation-of-duties rules: only a designated performance administrator (the role the platform shows as “Board Member HR”) can see everyone’s results; even Platform Admins cannot see other people’s review results (only their own and their reporting line’s). Within a review, what a reviewer writes can be shared with you with the reviewer’s name, anonymously, or kept private, exactly as configured for that question — and the platform enforces this.
- Surveys: when a survey is anonymous, the link between you and your answers is never stored — nobody, including the survey’s creator and administrators, can see who said what, and results are only shown once enough people have responded that answers can’t be traced back to individuals. The platform records only that you completed an anonymous survey (so reminders stop), never what you answered. Named surveys say so before you respond.
Sensitive fields (passport/ID, bank details, compensation) are encrypted and shown masked by default; access is minimized and audited.
8. Your rights
You can ask us to:
- Access — get a copy of the personal data we hold about you.
- Correct — fix data that is wrong or out of date (you can edit much of this yourself in your profile).
- Delete / erase — have your data permanently deleted where we no longer have a lawful reason to keep it.
- Restrict or object to certain processing.
- Data portability — receive certain data in a portable format.
To exercise any of these, contact mydata@jusoor.ngo. We will respond within 60 days, or tell you if we need more time or more information to verify your identity. Some data may need to be retained for legal or tax reasons even after you leave (see Section 9).
9. How long we keep your data
We keep your data while you are employed or engaged, and for up to 7 years after your last working day, after which your record becomes eligible for permanent erasure.
This period is intended to meet common tax and employment record-keeping requirements across the countries our team members live in — including the United States, Canada, the United Kingdom, the Netherlands, and major European Union countries — where retention periods for pay, tax, and employment records commonly range from about 4 to 10 years. Where a specific local law requires a different period, we follow that.
After the retention period, or on a valid erasure request where no legal reason to keep the data remains, we permanently delete your personal data from the platform (including files and your login). We keep a minimal audit record that an erasure happened — your name and reference number only, never the deleted content — as a record of accountability.
Erasure removes yourdata; it does not rewrite the organization’s own records. Where you acted in an organizational capacity — for example, approving a colleague’s leave or a payment — that record keeps your name as plain text, no longer connected to any profile or personal data. Survey answers you gave are kept in de-identified form (no longer linked to you), the same way anonymous responses are stored. This is a deliberate records-retention practice: bookkeeping about the organization’s decisions survives, your personal data does not.
10. How we protect your data
- Encryption of the most sensitive fields (passport/ID, bank details, compensation), shown masked by default and revealed only with permission.
- Strict, role-based access control, deny-by-default, enforced in the software.
- Secure login via Google sign-in with 2-Step Verification, and an alert to you when your account signs in from an unrecognized device.
- Audit logging of meaningful actions.
- Encrypted, access-restricted backups.
- A security review before real data goes in.
No system is perfectly secure, but we work to protect your data and to respond quickly if something goes wrong. If a data breach affects your personal data and is likely to create a risk to you, we will notify you and any regulator as required by law.
11. Data minimization (our commitment)
We aim to collect only what we actually use. If you think we’re holding data we don’t need for your role, tell us and we’ll review it.
12. Changes to this notice
We may update this notice as the platform or the law changes. We’ll tell staff and contractors about material changes and update the “Last updated” date above.
13. Contact
Questions, concerns, or requests about your data:
- Email: mydata@jusoor.ngo
- Postal address: 501 Crescent Way, Apt 5311, San Francisco, California 94134, USA