Privacy Policy
Effective 7 August 2026 · Version 1.0
ISETT is a private management platform operated by Rock Solid Group for the staff of RSG group companies. It is not a consumer product and it is not open to the public. This policy explains what personal data the platform holds, why, for how long, and what you can ask us to do about it.
The short version. We hold the least we can get away with. We have never sold personal data and never will. There are no ads, no trackers, no cookies, and no third party watching you use this. Your data is not used to train AI. Everything below is the same promise written out at length, with the exceptions named rather than hidden.
- 1. Who we are
- 2. Who this policy applies to
- 3. What we collect
- 4. What we do not collect
- 5. Where it comes from
- 6. Why we process it
- 7. The Cypher assistant
- 8. Who we share it with
- 9. How long we keep it
- 10. How we protect it
- 11. Your rights
- 12. Account deletion
- 13. Children
- 14. Changes
- 15. Contact us
1.Who we are
Rock Solid Group (“RSG”, “we”, “us”) operates the ISETT platform, reachable on the web at isett.rsg.one and through the ISETT mobile app for iOS and Android. For the purposes of the Saudi Personal Data Protection Law, RSG is the controller of the personal data described here.
Questions about this policy go to info@rsg.one or through the contact form.
2.Who this policy applies to
Two different groups of people appear in ISETT, and they are not the same group.
People who use ISETT. Staff of RSG group companies who have been given an account by an administrator. There is no public sign-up: an account exists because someone at RSG created it.
People whose information appears inside ISETT. ISETT displays data drawn from RSG's existing business systems — human resources, sales, and project records. Employees and contacts whose details appear in those systems therefore appear in ISETT, whether or not they personally use it. Sections 5, 6 and 11 apply to you as well.
3.What we collect
Account information
Your name, work email address, and a one-way hash of your password — we never store the password itself. Alongside it we keep your display preferences: theme, company and module ordering, pinned dashboards, and saved chart choices.
Sign-in and security records
Each sign-in records the time and the IP address it came from. Active sessions record a device label (on mobile, the phone's brand and model, for example “Apple iPhone15,2”), the browser or app user agent, and when the session was last used, so that you can see and revoke your own sessions. We also keep an audit trail of security-relevant actions — signing in and out, password and permission changes, administrative changes, and access to sensitive figures — recording who did what, when, from which address.
Usage information
ISETT records which pages you open, when, for which company, and roughly how long you stay, together with which client you used. This is first-party product analytics held in our own database. It is used to understand which parts of the platform earn their place and to support the platform, and it is visible to RSG administrators.
Things you write
Conversations with the Cypher assistant, and anything you submit through the public forms on this site.
Business data from RSG systems
ISETT reads from RSG's operational systems and displays the results. That data includes personal data about employees — names, employee numbers, job titles, divisions, nationalities, joining and leaving dates, employment status, leave, and document expiry — and business contact details for people at customer and supplier organisations. ISETT is a reporting surface over those systems; it is not the origin of that data and, with the exception of the project-progress module, does not write back to them.
4.What we do not collect, and what we will not do
Stated plainly, because a lot of it is what people actually want to know:
- We never sell, rent, or licence personal data. Not to advertisers, not to data brokers, not to anyone, in any form, for any price.
- No advertising anywhere in the product. ISETT carries no ads and no advertising technology, and nothing in it is funded by attention.
- No third-party analytics or tracking. The platform carries no Google Analytics, no Meta pixel, no advertising or attribution SDK, and no third-party crash-reporting service. Usage analytics are first-party and stay in our own database.
- No tracking cookies. ISETT sets no cookies at all — not even “essential” ones. Your session is held in your browser's local storage, and on mobile in the operating system's secure storage. That is why you have never seen a cookie banner here.
- No location data. The mobile app never requests location permission. An IP address in our security log implies a rough region, and nothing finer.
- No access to your contacts, photos, camera, calendar, or health data. The mobile app does not request these permissions. The one device permission ISETT ever asks for is the microphone, on the web only, and only when you press the dictate button in the assistant to speak a question instead of typing it. The recording is sent once to our model provider to be turned into text, is not stored by us, and nothing listens until you press that button — see section 7.
- No device identifiers for tracking. No advertising ID, no IDFA, no fingerprinting.
- No biometric data. If you unlock the app with a fingerprint or face, that check happens on your device and the biometric never reaches us.
- No session recording. No screen replay, no heatmaps, no keystroke capture. We record that a page was opened, not what you did on it.
- No profiling, and no automated decisions about you. We do not build behavioural profiles and nothing in ISETT decides anything about a person automatically.
- No training AI on your data. Neither we nor our model provider use your questions, your conversations, or the business data in ISETT to train or improve any AI model. See section 7.
These are commitments, not descriptions of the current build that we might quietly walk back. If any of them ever has to change, it changes here first, with the effective date moved and a notice in the platform — see section 14.
5.Where it comes from
- From you — when you sign in, change a preference, ask the assistant something, or use a form on this site.
- From your device automatically — IP address, user agent, and the device model used as a session label.
- From RSG's business systems — the HR, sales and project databases the platform reports on. Where the data concerns you as an employee, its original collection is governed by your employer's own handling of employee records, not by this platform.
6.Why we process it
| Purpose | Data used | Basis under the PDPL |
|---|---|---|
| Giving you access to the platform | Account information, session records | Necessary to perform the employment or service relationship |
| Keeping accounts secure and investigating misuse | Sign-in records, audit trail, IP, user agent | Legitimate interest in protecting confidential business information |
| Showing you the reports you are entitled to see | Business data from RSG systems | Legitimate interest in managing the group's operations |
| Supporting and improving the platform | Usage information, support enquiries | Legitimate interest in operating and maintaining our own system |
| Answering your questions in the assistant | The text you send, and the reports you are entitled to see | Necessary to provide the feature you asked for |
| Meeting legal, audit and regulatory obligations | Audit trail, account records | Compliance with an applicable legal obligation |
We do not use your personal data to make automated decisions that produce legal effects for you.
7.The Cypher assistant
ISETT includes an assistant called Cypher that answers questions about the data you already have access to. Cypher is available on the web platform only — the mobile app does not include it, so nothing in this section applies to you if the app is all you use. It works by sending your question, the conversation so far, and the results it retrieves to a large language model operated by a third party, which returns the answer. Text you type into Cypher, and business data it retrieves to answer you, therefore leaves our servers and is processed by that provider. We would rather say that in the first paragraph than bury it.
Our current model provider is Google (the Gemini models), used under a paid business agreement. Under the terms of that agreement:
- Your data is not used to train or improve any model — not Google's, not ours.
- It is not retained by the provider beyond what is needed to return the answer, and it is not reviewed by human beings.
- It is not shared onward, and it is not used to build a profile of you or of RSG.
If we ever change model provider, this section is updated before the change goes live, and the same three conditions are a requirement of any provider we would move to.
Speaking to it, and it speaking back. You can dictate a question instead of typing it, and you can ask for an answer to be read aloud. Both go to the same provider under the same three conditions above. Recording starts only when you press the microphone button and stops when you press it again; the clip is sent once, turned into text you can correct before you send it, and is not kept by us afterwards. Reading an answer aloud sends only the wording of that answer — never your question, never the assistant's working, and never the contents of a table or a query on screen.
What the assistant can reach is limited to what your own account is permitted to see; it cannot read a company or a module you have not been granted, and asking it to does not widen your access. Conversations are stored against your account so you can return to them, and are deleted when you delete the conversation. We record what the assistant did — which tools it ran and how many rows came back — but the retrieved rows themselves are not stored in the conversation history.
One practical note. The assistant is a reporting tool over data you already hold, so there is rarely a reason to type anything into it that is not already in the platform — and never a reason to type a password. Answers can also be wrong; check anything you are about to act on.
8.Who we share it with
We do not sell personal data, and we do not share it for anyone else's marketing. The complete list of parties outside RSG that ever touch it is short, and it is this:
| Who | What they do | What they get |
|---|---|---|
| Our hosting provider | Runs the servers the platform operates on | Everything stored, at rest on their infrastructure — encrypted, and never accessed by them in the ordinary course |
| Google (Gemini) | Answers assistant questions (section 7) | Only the text of that conversation and the rows retrieved for it, and only when you use the assistant |
| Authorities, regulators, advisers | Where disclosure is legally required, or to establish or defend a legal claim | Only what the specific obligation requires |
Nobody else. There is no fourth row hidden in a phrase like “trusted partners”. Every provider above is bound by a written agreement that limits them to processing on our instructions, and we add a new one to this table before it starts, not after.
Inside RSG, administrators and authorised colleagues see data according to the permissions they hold, granted per company and per module. Our own engineers reach production data only where support or a fault requires it, and those actions are recorded in the audit trail like anyone else's.
Some of these providers operate outside Saudi Arabia, so personal data may be transferred abroad in the course of running the platform. Where that happens we rely on the transfer conditions permitted by the PDPL and its implementing regulations.
9.How long we keep it
| Record | Kept for |
|---|---|
| Account and preferences | While the account exists, then as set out in section 12 |
| Sessions and refresh tokens | Until they expire or you revoke them |
| Detailed page-view events | 12 months, then deleted automatically |
| Aggregated daily usage counts | Retained for long-term trend reporting |
| Security audit trail | Retained as a security and compliance record |
| Assistant conversations | Until you delete them, or the account is removed |
| Requests sent through this site | 24 months from the date we handle them, then deleted |
| Business data from RSG systems | Governed by the source system, not by ISETT |
Retention here is a ceiling we enforce, not an intention. We would rather hold less: where a shorter period does the same job, we take the shorter period, and we do not keep a record simply because storage is cheap.
10.How we protect it
- Passwords are stored only as salted one-way hashes. We could not tell you your password if we wanted to, and nobody at RSG will ever ask you for it.
- Encrypted in transit and at rest. All traffic runs over HTTPS with modern cipher suites and HTTP Strict Transport Security; the database and its backups are encrypted on disk.
- Sessions use short-lived access tokens with rotating refresh tokens. Reuse of a retired token invalidates the whole chain, and you can see and revoke every active session from your profile.
- Access is default-deny. An account sees a company or a module only where a grant has been recorded; every route in the platform is classified and enforced centrally, so a page cannot be shipped without an access rule attached to it.
- Sensitive commercial figures are masked for accounts without an explicit exemption, and the masking is applied before the number reaches the browser — not hidden in the interface.
- Least privilege internally. Credentials live in a secret store rather than in code or configuration files, connections to source systems are read-only wherever the platform only needs to read, and staff access to production is limited to the people whose job requires it.
- Everything sensitive is recorded. Administrative actions, permission changes, and access to masked figures are written to an audit trail that the platform itself cannot edit.
- Repeated failed sign-ins lock an account, and the public forms on this site are rate-limited.
- Dependencies are kept current and security updates are applied promptly.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting personal data we will notify the Saudi Data & Artificial Intelligence Authority within 72 hours of becoming aware of it, and tell affected individuals without undue delay, as the PDPL requires.
If you believe you have found a security vulnerability in ISETT, please report it to info@rsg.one. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
11.Your rights
Under the Saudi Personal Data Protection Law you have the right to:
- Be informed of the legal basis and purpose of collecting your personal data — which is what this document is for.
- Access your personal data held by us.
- Request a copy of it in a readable, portable format.
- Correct data that is inaccurate, incomplete, or out of date.
- Request deletion of your personal data where we no longer need it for the purpose it was collected for.
- Withdraw consent where our processing rests on consent.
Ask through the contact form or at info@rsg.one. We will respond within 30 days, and we do not charge for any of it. A request for a copy comes back as a machine-readable file, not a screenshot of a screen.
There are limits, and they are the honest kind: we cannot delete records we are required by law to keep, or a security audit trail whose entire purpose is that it cannot be edited, and we may need to verify who you are before acting on a request — because a rights process that hands your data to whoever asks is a data breach with paperwork. If you are unhappy with our response you may complain to the Saudi Data & Artificial Intelligence Authority (SDAIA).
If your details appear in ISETT because you are an employee of an RSG company rather than a user of the platform, a correction is usually best made in the originating HR or business system, because ISETT reflects what that system holds. Contact us and we will point you to the right place.
12.Account deletion
You can request deletion of your ISETT account at any time, without signing in, using the account deletion request form.
ISETT accounts are issued by an administrator against a working relationship with an RSG company, so an account is not deleted the instant a form is submitted — the request goes to the administrators who own that decision. On approval we delete your account record, your preferences, your saved dashboards and pinned pages, your assistant conversations, and your sessions. We retain the security audit trail of actions taken on the account, because a tamper-proof security log that can be erased on request is not a security log; those entries are retained as a compliance record and are not used for any other purpose.
Business records in RSG's HR and operational systems are not affected by deleting an ISETT account — those are your employer's records and are governed by their own retention rules.
13.Children
ISETT is a workplace tool for adults. It is not directed at children, and we do not knowingly hold personal data about anyone under 18 other than as it may appear in employment records lawfully held by an RSG company.
14.Changes
If we change this policy we will update the effective date at the top and, where the change materially affects you, tell you in the platform. Continuing to use ISETT after a change means the updated policy applies to you.
15.Contact us
Privacy questions, data rights requests, and anything else: info@rsg.one, or the contact form.
Rock Solid Group
Al Kindi Plaza, Diplomatic Quarter, Riyadh
Kingdom of Saudi Arabia
+966 54 812 4638