Privacy policy
Last updated 27 September 2026
This policy is incomplete: it does not yet state who the controller is, a contact address, a data protection contact. Those details belong to the business operating GarnetOS. It should not be relied on, or submitted to Google for verification, until they are filled in.
Who is responsible for your data
GarnetOS is operated by [Name of the business or trader — not yet supplied] in the United Kingdom, at [Contact address — not yet supplied]. The business is not currently a registered company, so it has no Companies House number; this page will say so when that changes.
For the records a business keeps in GarnetOS about its own staff, that business is the data controller and GarnetOS is a processor acting on its instructions. For the account you use to sign in — your name, email address and sign-in history — GarnetOS is the controller.
Questions, or a request to see or delete your data, go to [Data protection contact address — not yet supplied].
What is collected, and why
- Your account
- Name, work email address, a hashed password, and — if you turn it on — a second-factor secret. Used to sign you in and to show colleagues who took an action. Sign-in attempts, IP address and browser are recorded so an account takeover can be investigated.
- Employment records
- Whatever your employer records about you: contact details, job title, working pattern, pay where they use that feature, leave and attendance, and documents such as contracts and right-to-work evidence. Your employer decides what to keep and for how long.
- Documents you upload
- Held in encrypted storage and scanned for malware before anybody can open them. A file that fails a scan is never served to anyone, including the person who uploaded it.
- What you did in the system
- Reading somebody’s personal details, downloading a document, changing a permission and approving leave are each recorded with your name and the time. This is the audit trail, and it cannot be edited or switched off — it is the evidence your employer may need to produce.
The legal basis for each of these
Different data is held for different reasons, and the reason matters — it decides what you can ask us to stop doing.
- Your account — to perform a contract
- We cannot give you an account without holding your name and email address. If you object to this, the only remedy is to close the account.
- Sign-in and security records — legitimate interests
- Recording failed sign-ins, IP address and browser is how an account takeover is spotted and investigated. The interest is keeping other people’s employment records out of the wrong hands, which we think outweighs the modest privacy cost of keeping them. You can object, and we will consider it against that.
- Employment records — your employer’s basis, not ours
- Your employer decides why they hold your records and on what basis, usually their employment contract with you and their own legal obligations. GarnetOS processes those records only on their written instructions. Questions about why something is held belong to them.
- The audit trail — legal obligation and legitimate interests
- Being able to show who read a record and when is what makes the rest defensible, both for your employer and for you. It is the one thing nobody can switch off or edit, including us.
- Calendar access — your consent
- Asked for separately, given by you and nobody else, and withdrawable at any time from your own settings without affecting anything else. Withdrawing deletes the tokens.
Google and Microsoft calendar access
Connecting a calendar is optional, per person, and can be disconnected at any time from your own settings. Nobody can connect or disconnect a calendar on your behalf.
When you connect a Google account, GarnetOS asks only for https://www.googleapis.com/auth/calendar.events, together with your email address and a sign-in identifier. It is used for one purpose: to write your own approved leave into your own calendar, and to remove those entries if the leave is cancelled.
GarnetOS does not read your existing calendar entries, does not create or delete calendars, does not touch anybody else’s calendar, and never shows your calendar contents to your employer or to anyone else. The broader auth/calendar scope, which can delete whole calendars, is deliberately not requested — an automated test fails the build if it ever is.
The tokens Google issues are encrypted before storage and are used only by the background job that writes those events. Disconnecting deletes them. GarnetOS does not sell this data, does not use it for advertising, does not use it to train models, and does not transfer it to third parties. Its use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft 365 connections work the same way, using Calendars.ReadWrite, which is the narrowest permission Microsoft Graph offers that can write an event.
Cookies
GarnetOS sets five cookies and every one of them is needed to sign you in and keep you signed in: bos_session, bos_refresh, bos_csrf, bos_pending during two-step sign-in, and bos_platform for GarnetOS staff. They are set only after you sign in, and clearing them signs you out.
There are no analytics cookies, no advertising cookies, and no third-party scripts that could set one. Nothing here tracks you between sites or builds a profile of you. That is also why there is no cookie banner: consent is required for the cookies GarnetOS does not use, and asking for it anyway would be theatre.
Where it is held
In the United Kingdom. The database and document storage are in Amazon Web Services’ London region (eu-west-2), encrypted at rest with keys GarnetOS controls. One company’s records are separated from another’s by the database itself, not only by application code.
Email is sent through Brevo, which may process the recipient address and message outside the UK. Calendar entries go to Google or Microsoft only where somebody has connected an account. Those are the sub-processors; there are no others.
How long it is kept
Employment records are kept for as long as your employer decides, and GarnetOS applies the retention rules they configure — a document past its retention period is destroyed unless somebody has placed a hold on it. When a company closes its account its data is deleted.
The audit trail is kept longer than the records it describes, because its value is being able to show what happened after the fact.
Your rights
You can ask to see, correct, or delete the personal data held about you, to object to processing, or to receive it in a portable form. Because your employer is the controller of your employment records, ask them first — GarnetOS will help them answer. For your sign-in account, ask us directly at [Data protection contact address — not yet supplied].
Some details you can change yourself, immediately, from My details. Others need your employer to apply them, because a change of legal name or address on an employment record is something they have to be able to evidence.
If you think your data has been mishandled you can complain to the Information Commissioner’s Office at ico.org.uk.
Changes
Material changes will be told to account holders by email before they take effect. The date at the top of this page is when it last changed.