Legal
Privacy Policy
Last updated: 22 August 2026
This Privacy Policy explains how TrustOS (“we”, “us”) collects, uses and protects personal data when you use the TrustOS website and application (the “Service”). It applies to our customers and their users, to supplier contacts who receive a confirmation request, and to visitors of our website. We process personal data in accordance with the Israeli Protection of Privacy Law, 5741-1981 and its regulations and, where applicable, the EU/UK General Data Protection Regulation (“GDPR”).
1. Who is responsible
For data you submit on behalf of your organisation (emails, invoices, supplier details), your organisation is the controller and we act as its processor. For account, billing, website and security data, TrustOS is the controller. Contact: alex3352alex@gmail.com.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account & company data | Name, work email, role, company name and domain, plan | You |
| Supplier Vault data | Supplier name, domain, trusted contact email and phone, country, bank country | You |
| Bank account identifiers | One-way hash of the account number and its last four characters (never the full number) | You / submitted documents |
| Verification content | Text of payment requests and invoices you paste, extracted fields (amount, invoice number, sender email), risk scores and signals | You |
| Supplier responses | Whether a confirmation link was confirmed or rejected, and when | Supplier contact |
| Audit & technical logs | Actions taken in the Service, timestamps, IP address, browser type, error diagnostics | Automatically |
We do not knowingly collect data about children, special categories of personal data, or full payment-card numbers. Please do not paste more personal data than is needed for a verification.
3. Why we use it (and legal bases)
- Providing the Service — analysing requests, producing risk scores, sending supplier confirmation links, maintaining your Supplier Vault and history (performance of a contract).
- Security and fraud prevention — protecting the Service, our customers and supplier contacts from abuse (legitimate interests).
- Improving the Service — understanding which signals are useful, fixing errors (legitimate interests). We do not use Customer Data to train third-party AI models.
- Communications and billing — service notices, invoices, support (contract / legal obligation).
- Legal compliance — responding to lawful requests and keeping records we are required to keep.
4. Supplier contacts
If you received a confirmation request from TrustOS, a customer of ours entered your business contact details as a trusted contact for their supplier. We process your email address and your confirm/reject response only to deliver that request and record the outcome for the customer. We do not use your details for marketing. You can ask the requesting company or us to remove your details at any time.
5. Who we share data with
We do not sell personal data. We share it only with service providers that help us run the Service:
- Vercel — application hosting and content delivery (USA/EU).
- Neon — managed PostgreSQL database hosting.
- Resend — delivery of supplier confirmation emails (when enabled).
- OpenAI — extraction of fields from pasted text (only when AI extraction is enabled; data sent under API terms that prohibit training on it).
We may also disclose data where required by law, to protect rights and safety, or as part of a merger or acquisition (with notice to you). Where data leaves Israel or the EEA, we rely on adequacy decisions or standard contractual clauses.
6. Retention
Verification records, signals and audit logs are kept for as long as your account is active so that you have an evidentiary trail, and deleted within 90 days after account closure unless we must keep them by law. Supplier confirmation tokens expire once answered. Technical logs are kept for up to 12 months.
7. Security
All traffic is encrypted in transit (TLS). Bank account numbers are stored only as one-way cryptographic hashes plus the last four characters. Access to production systems is restricted and logged. The Service is currently offered as a private preview behind an access password; no method of storage is 100% secure, and we will notify affected customers and authorities of a data breach as required by law.
8. Your rights
Subject to applicable law you may request access to, correction or deletion of your personal data, restrict or object to its processing, receive a copy in a portable format, and withdraw consent where processing is based on consent. Israeli residents also have the right to inspect and correct data held in a database under the Protection of Privacy Law. To exercise these rights email alex3352alex@gmail.com; we respond within 30 days. If your data was submitted by one of our customers, we may refer your request to them. You may also lodge a complaint with your supervisory authority (in Israel, the Privacy Protection Authority).
9. Cookies
The Service uses a single strictly necessary cookie (trustos_gate) to remember that you entered the access password; it contains no personal data and expires after 30 days. We do not use advertising or third-party analytics cookies. Because only essential cookies are used, no consent banner is shown; you can delete the cookie at any time in your browser.
10. Changes
We may update this policy from time to time. We will post the new version here with a new “last updated” date and, for material changes, notify customers by email or in the Service.
11. Contact
TrustOS — alex3352alex@gmail.com. See also our Terms of Service.