Skip to main content
← Privacy

Privacy notice - data processor

Drafted: ·Updated:

1. Introduction

Gosoft Oy ("we", "Gosoft") provides Gosoft Connect - AI chat, live chat, lead-capture forms, and conversion analytics that our customers ("Customer") embed on their own websites and offer to their visitors ("you"). When you use these tools on a Customer's website, Gosoft acts as a data processor and the Customer is the data controller who decides why your data is collected. This notice explains, transparently, what we process on the Customer's behalf.

For data Gosoft collects as a controller - for example visitors to our own site gosoft.fi, or our customer relationships - see our separate privacy notice for data controller.

2. No cookies

Gosoft Connect sets no cookies - there is no cookie banner and nothing to consent to on that basis. To work, the widget keeps a small amount of strictly-necessary data in your browser's local storage (described in section 3). Unlike cookies, local storage is not sent automatically with every request; it stays in your browser until it expires or you clear it.

3. Data kept in your browser

So the chat can keep its place across page loads, the widget stores the following in your browser's local storage, namespaced per Customer site (the same browser on two different Customer sites is not linked):

  • A visitor record - a random visitor identifier (not your name), a security token, and a secret used to authenticate your own data requests (section 7).
  • Your current conversation - the messages in your open chat and anything you typed into in-chat forms, so the thread survives a reload.
  • Small preference flags - e.g. that you dismissed a proactive message, or that a one-time pop-up has already been shown.

Most of these expire automatically once you have left the website - 30 minutes (by default; set by the Customer) after your last visit or interaction - and are erased together. While you keep a tab of the website open, the session stays active and the timer starts when you leave or close it. A one-time-pop-up marker may persist until you clear your browser. You can clear everything at any time from the chat's "Delete my data" option or your browser settings. (If the Customer uses the optional "remember my language" setting, your chosen language code is also stored; by default it is not.)

4. Data we store on our servers

On the Customer's behalf we may store:

  • Conversations and messages - the text you exchange with the chat. This is free text and may contain anything you choose to type, including contact details or other personal information.
  • Form submissions - what you enter into lead-capture or other forms, including any files you upload (kept on our servers, separate from the database).
  • Leads - contact details (name, email, phone, message) you explicitly provide so the Customer can follow up.
  • A visitor profile - only if the Customer has switched it on (off by default); see section 8.
  • Analytics events - page views, clicks, dwell time and conversions, with the page URL, referrer, language and browser type, linked to the visitor identifier in your browser. This analytics is pseudonymous, not anonymous: it is keyed to that identifier, so it can be associated with you within the Customer's site - and you can access or erase it (section 7).
  • AI usage records - for each AI reply, the model, token counts and cost. These contain no message content and are kept as financial records (section 6).

We do not store your IP address. Your IP is used only momentarily to rate-limit abuse and is never written to our analytics or conversation records.

5. AI processing and sub-processors

When you use the AI chat, your message - together with relevant content from the Customer's own knowledge base and the recent conversation - is sent to OpenAI Ireland Ltd (Ireland), our AI sub-processor, to generate a reply (default model: GPT-4o mini). Every message is also sent to OpenAI's content-moderation service to screen for unsafe content. OpenAI processes this data under its API terms and under the data-processing addendum we have executed with it, under which API data is not used to train OpenAI's models. Where OpenAI transfers data outside the EU/EEA to its affiliates, those transfers rely on appropriate safeguards (Standard Contractual Clauses or an adequacy decision).

Searching and ranking the Customer's knowledge base runs locally on our own infrastructure - no third party is involved in that step. We use no third-party advertising or analytics trackers (no Google Analytics, no advertising pixels, no session-replay). Other sub-processors (such as hosting infrastructure) are engaged under data-processing agreements, and our primary data store is located within the EU/EEA.

6. Retention

Retention periods are set by the Customer (the controller). By default:

  • Conversations, messages, form submissions, uploaded files and visitor profiles - 90 days from your last activity.
  • Analytics events - 365 days.
  • Leads - 365 days.

After these periods the data is deleted automatically. AI usage records (model, token counts and cost - no message content) are kept longer as accounting records, on the basis of our legal obligation to retain financial information (GDPR Art. 17(3)(e)).

7. Your rights - access and erasure

You can exercise the main rights directly from the chat widget:

  • Access (Art. 15) - "Download my data" returns what we hold for you on that Customer's site: your conversations and messages, form submissions, leads, profile (if any), and recent analytics (the most recent 500 events).
  • Erasure (Art. 17) - "Delete my data" erases your conversations and messages, form submissions and uploaded files, leads, visitor profile, and analytics for that Customer's site.

Both are authenticated by a secret kept in your browser, so only you can make the request. If you clear your browser storage or your session expires, that secret is gone and you can no longer self-authenticate. In that case, contact the Customer - the operator of the website where you used the chat. They are the controller and decide on your request; Gosoft, as their processor, acts on the Customer's instructions. You can also write to privacy@gosoft.fi and we will pass your request to the relevant Customer. (Note: data that is only ever pseudonymous to us - such as analytics keyed to an in-browser identifier - can only be located with that identifier, i.e. via the in-page tool; without it we may be unable to identify which records are yours.)

You also have the right to rectification, restriction of processing, objection, and data portability. Direct these to the Customer (the controller); where you contact Gosoft as processor (privacy@gosoft.fi) we forward the request to, and act on the instructions of, the Customer.

8. Automated visitor profiling (optional, off by default)

If - and only if - the Customer switches it on, Gosoft Connect builds an automated profile of a visitor from the chat conversation. It uses an LLM (OpenAI) to infer fields such as name, contact details, company, role, interests, language and likely intent, plus a short free-text summary for the Customer's sales or support team. This is automated profiling: where it is enabled, the Customer is the controller responsible for it. The profile is kept on the same default 90-day window and is removed by "Delete my data".

9. Security

We apply technical and organisational measures to protect personal data. Note that data kept in your browser's local storage is readable by any script running on the Customer's own website (it is not a protected store); the per-visitor erasure secret is stored on our servers only as a one-way hash, never in plain text.

10. Cooperation with authorities

Where necessary we cooperate with the data-protection authorities to ensure compliance with the law.

11. Changes to this notice

We may update this notice, for example after legal or product changes. The current version is always published here.

12. Contact

Gosoft Oy - privacy@gosoft.fi