Privacy Policy
v0.1 · Last updated 2026-07-22 · Draft — pending final legal review
Who we are
Gogins (www.gogins.ai) is an AI governance service operated by Nevari International Limited, a company registered in England and Wales (Company No. 16018299), registered office: Nevari HQ, The Summit, Church Lane, Guiting Power, Cheltenham, England, GL54 5TX. VAT: GB 516689652.
Nevari International Limited is the controller of the personal data described in this policy. Our privacy contact is [email protected]. For general product support, use [email protected].
What this policy covers — and what it doesn't
This policy covers the personal data we process as controller to operate Gogins: your account and team identity, the operational records the service creates, and the technical data involved in signing in and using the product.
Content your organisation puts into Gogins — including files uploaded to the evidence library — is your organisation's data. We process it as processor, on your organisation's instructions, under the Data Processing Agreement that forms part of your organisation's contract with us. If you want to know how your organisation uses Gogins, ask your organisation's administrator.
The personal data we process
Account and team identity. When you're invited to a Gogins workspace or sign in, we hold your email address, your sign-in identifier from our identity provider, and your role and status in your organisation's workspace.
Operational records. Gogins keeps an audit trail of actions taken in the service. Where you take an action — creating an API key, generating an auditor export, accepting a risk, requesting an escalation or reclassification, uploading evidence — the record includes your identity as the person who did it. Our own operations staff appear in these records in the same way when they act on your account.
Content you choose to add. Free-text fields (such as an agent's owner label or a note) contain whatever you type. Files uploaded to the evidence library are stored as you provide them; we do not inspect the contents of uploaded files.
Sign-in and technical data. Signing in produces diagnostic records in our hosting provider's logs, which include your email address and sign-in identifier. We use exactly four first-party cookies: three strictly necessary — a session cookie (7 days), a sign-in state cookie (10 minutes), and a return-destination cookie (10 minutes) — and one functional preference cookie that remembers the light or dark theme you choose (up to 1 year). We use no analytics, advertising, or tracking cookies, which is why you don't see a cookie banner.
Usage metering. We meter service usage (for example, tokens observed across your governed agents). Metering records are counts and hashed references — they do not contain message content or personal data beyond attribution to your workspace.
What we deliberately do not collect
When Gogins scans your connected systems (such as n8n or Make), it reads workflow structure only — the shape of your automations, the models and connections they reference by name, their triggers. It does not read prompt text, data passing through your workflows, or credential values, and it does not store your raw workflows. Gogins does not process personal data about your organisation's own customers or end users through scanning.
We do not use your personal data for advertising, and we do not sell it.
Why we process it, and on what basis
We process the data above to provide and operate the service your organisation has contracted for — authentication, workspace and seat management, the agent inventory and its classification, findings and evidence, usage metering, and auditor exports (performance of a contract). We maintain audit records and sign-in diagnostics for security, accountability, and the integrity of the compliance record the product exists to provide (our legitimate interests, and your organisation's). We'll contact you about the service itself — such as an invitation to a workspace — as part of operating it.
Where your data lives, and international transfers
Your data is stored in Frankfurt, Germany (EU) with our database and storage provider, and our application compute runs in the Frankfurt region of our hosting provider.
Some of our providers are US companies: our hosting provider (which also holds the sign-in diagnostic logs described above), our identity provider (which handles sign-in and sends invitation and sign-in emails), and our background-job provider (which receives only internal identifiers, never personal content). Where data is transferred outside the UK/EEA, it is safeguarded under those providers' data processing agreements, using recognised transfer mechanisms (Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework). Our current sub-processors, what each one receives, and the applicable mechanism are listed on our Data Protection page, which we keep up to date.
How long we keep it
We keep your personal data for the life of your organisation's account. We do not currently apply automatic time-based deletion. Personal data is removed when a validated erasure request is fulfilled or when your organisation's account is closed and offboarded.
One deliberate exception: audit records are redacted, not deleted. When your personal data is erased, your identifiers in the audit trail are replaced with redacted values while the record of what happened is preserved — because a compliance product's audit trail must survive the people in it. The redacted records no longer identify you.
Your rights
Under UK and EU data protection law you have the right to access your personal data, to correct it, to have it erased, to restrict or object to its processing, and to data portability, in each case where the law provides for it.
To exercise any of these rights, email [email protected]. We will verify your identity and respond within one month. If you are unhappy with how we handle your data, you can complain to the UK Information Commissioner's Office (ico.org.uk) or, if you are in the EEA, to your local supervisory authority.
What erasure does. A fulfilled erasure request removes your membership record, revokes any pending invitations, redacts your identifiers throughout the operational and audit records, and adds a suppression marker (a one-way hash of your email — not the address itself) so you are not silently re-invited afterwards. One honest limit: the contents of files manually uploaded to the evidence library are stored opaquely and cannot be searched by person. Erasure removes the record of you as an uploader; for the file contents themselves, contact your organisation's administrator, who controls that content.
Security
Sign-in is passwordless, handled by our identity provider, with multi-factor authentication enforced at sign-in. Connection credentials your organisation provides for scanning are encrypted at rest, and access to stored data is restricted to server-side service paths — customer sessions can only read their own workspace's data. Evidence files are held in private storage and are only ever accessible through short-lived, individually generated links.
Changes to this policy
We'll post any material changes to this page and update the effective date. If a change meaningfully affects your rights, we'll take reasonable steps to bring it to your organisation's attention.
Nevari International Limited · Company No. 16018299 · Nevari HQ, The Summit, Church Lane, Guiting Power, Cheltenham, GL54 5TX, England · [email protected]