ISETT Rock Solid Group

Privacy Policy

Effective 7 August 2026 · Version 1.0

ISETT is a private management platform operated by Rock Solid Group for the staff of RSG group companies. It is not a consumer product and it is not open to the public. This policy explains what personal data the platform holds, why, for how long, and what you can ask us to do about it.

The short version. We hold the least we can get away with. We have never sold personal data and never will. There are no ads, no trackers, no cookies, and no third party watching you use this. Your data is not used to train AI. Everything below is the same promise written out at length, with the exceptions named rather than hidden.

1.Who we are

Rock Solid Group (“RSG”, “we”, “us”) operates the ISETT platform, reachable on the web at isett.rsg.one and through the ISETT mobile app for iOS and Android. For the purposes of the Saudi Personal Data Protection Law, RSG is the controller of the personal data described here.

Questions about this policy go to info@rsg.one or through the contact form.

2.Who this policy applies to

Two different groups of people appear in ISETT, and they are not the same group.

People who use ISETT. Staff of RSG group companies who have been given an account by an administrator. There is no public sign-up: an account exists because someone at RSG created it.

People whose information appears inside ISETT. ISETT displays data drawn from RSG's existing business systems — human resources, sales, and project records. Employees and contacts whose details appear in those systems therefore appear in ISETT, whether or not they personally use it. Sections 5, 6 and 11 apply to you as well.

3.What we collect

Account information

Your name, work email address, and a one-way hash of your password — we never store the password itself. Alongside it we keep your display preferences: theme, company and module ordering, pinned dashboards, and saved chart choices.

Sign-in and security records

Each sign-in records the time and the IP address it came from. Active sessions record a device label (on mobile, the phone's brand and model, for example “Apple iPhone15,2”), the browser or app user agent, and when the session was last used, so that you can see and revoke your own sessions. We also keep an audit trail of security-relevant actions — signing in and out, password and permission changes, administrative changes, and access to sensitive figures — recording who did what, when, from which address.

Usage information

ISETT records which pages you open, when, for which company, and roughly how long you stay, together with which client you used. This is first-party product analytics held in our own database. It is used to understand which parts of the platform earn their place and to support the platform, and it is visible to RSG administrators.

Things you write

Conversations with the Cypher assistant, and anything you submit through the public forms on this site.

Business data from RSG systems

ISETT reads from RSG's operational systems and displays the results. That data includes personal data about employees — names, employee numbers, job titles, divisions, nationalities, joining and leaving dates, employment status, leave, and document expiry — and business contact details for people at customer and supplier organisations. ISETT is a reporting surface over those systems; it is not the origin of that data and, with the exception of the project-progress module, does not write back to them.

4.What we do not collect, and what we will not do

Stated plainly, because a lot of it is what people actually want to know:

These are commitments, not descriptions of the current build that we might quietly walk back. If any of them ever has to change, it changes here first, with the effective date moved and a notice in the platform — see section 14.

5.Where it comes from

6.Why we process it

PurposeData usedBasis under the PDPL
Giving you access to the platformAccount information, session recordsNecessary to perform the employment or service relationship
Keeping accounts secure and investigating misuseSign-in records, audit trail, IP, user agentLegitimate interest in protecting confidential business information
Showing you the reports you are entitled to seeBusiness data from RSG systemsLegitimate interest in managing the group's operations
Supporting and improving the platformUsage information, support enquiriesLegitimate interest in operating and maintaining our own system
Answering your questions in the assistantThe text you send, and the reports you are entitled to seeNecessary to provide the feature you asked for
Meeting legal, audit and regulatory obligationsAudit trail, account recordsCompliance with an applicable legal obligation

We do not use your personal data to make automated decisions that produce legal effects for you.

7.The Cypher assistant

ISETT includes an assistant called Cypher that answers questions about the data you already have access to. Cypher is available on the web platform only — the mobile app does not include it, so nothing in this section applies to you if the app is all you use. It works by sending your question, the conversation so far, and the results it retrieves to a large language model operated by a third party, which returns the answer. Text you type into Cypher, and business data it retrieves to answer you, therefore leaves our servers and is processed by that provider. We would rather say that in the first paragraph than bury it.

Our current model provider is Google (the Gemini models), used under a paid business agreement. Under the terms of that agreement:

If we ever change model provider, this section is updated before the change goes live, and the same three conditions are a requirement of any provider we would move to.

Speaking to it, and it speaking back. You can dictate a question instead of typing it, and you can ask for an answer to be read aloud. Both go to the same provider under the same three conditions above. Recording starts only when you press the microphone button and stops when you press it again; the clip is sent once, turned into text you can correct before you send it, and is not kept by us afterwards. Reading an answer aloud sends only the wording of that answer — never your question, never the assistant's working, and never the contents of a table or a query on screen.

What the assistant can reach is limited to what your own account is permitted to see; it cannot read a company or a module you have not been granted, and asking it to does not widen your access. Conversations are stored against your account so you can return to them, and are deleted when you delete the conversation. We record what the assistant did — which tools it ran and how many rows came back — but the retrieved rows themselves are not stored in the conversation history.

One practical note. The assistant is a reporting tool over data you already hold, so there is rarely a reason to type anything into it that is not already in the platform — and never a reason to type a password. Answers can also be wrong; check anything you are about to act on.

8.Who we share it with

We do not sell personal data, and we do not share it for anyone else's marketing. The complete list of parties outside RSG that ever touch it is short, and it is this:

WhoWhat they doWhat they get
Our hosting providerRuns the servers the platform operates onEverything stored, at rest on their infrastructure — encrypted, and never accessed by them in the ordinary course
Google (Gemini)Answers assistant questions (section 7)Only the text of that conversation and the rows retrieved for it, and only when you use the assistant
Authorities, regulators, advisersWhere disclosure is legally required, or to establish or defend a legal claimOnly what the specific obligation requires

Nobody else. There is no fourth row hidden in a phrase like “trusted partners”. Every provider above is bound by a written agreement that limits them to processing on our instructions, and we add a new one to this table before it starts, not after.

Inside RSG, administrators and authorised colleagues see data according to the permissions they hold, granted per company and per module. Our own engineers reach production data only where support or a fault requires it, and those actions are recorded in the audit trail like anyone else's.

Some of these providers operate outside Saudi Arabia, so personal data may be transferred abroad in the course of running the platform. Where that happens we rely on the transfer conditions permitted by the PDPL and its implementing regulations.

9.How long we keep it

RecordKept for
Account and preferencesWhile the account exists, then as set out in section 12
Sessions and refresh tokensUntil they expire or you revoke them
Detailed page-view events12 months, then deleted automatically
Aggregated daily usage countsRetained for long-term trend reporting
Security audit trailRetained as a security and compliance record
Assistant conversationsUntil you delete them, or the account is removed
Requests sent through this site24 months from the date we handle them, then deleted
Business data from RSG systemsGoverned by the source system, not by ISETT

Retention here is a ceiling we enforce, not an intention. We would rather hold less: where a shorter period does the same job, we take the shorter period, and we do not keep a record simply because storage is cheap.

10.How we protect it

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting personal data we will notify the Saudi Data & Artificial Intelligence Authority within 72 hours of becoming aware of it, and tell affected individuals without undue delay, as the PDPL requires.

If you believe you have found a security vulnerability in ISETT, please report it to info@rsg.one. We will not pursue anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.

11.Your rights

Under the Saudi Personal Data Protection Law you have the right to:

Ask through the contact form or at info@rsg.one. We will respond within 30 days, and we do not charge for any of it. A request for a copy comes back as a machine-readable file, not a screenshot of a screen.

There are limits, and they are the honest kind: we cannot delete records we are required by law to keep, or a security audit trail whose entire purpose is that it cannot be edited, and we may need to verify who you are before acting on a request — because a rights process that hands your data to whoever asks is a data breach with paperwork. If you are unhappy with our response you may complain to the Saudi Data & Artificial Intelligence Authority (SDAIA).

If your details appear in ISETT because you are an employee of an RSG company rather than a user of the platform, a correction is usually best made in the originating HR or business system, because ISETT reflects what that system holds. Contact us and we will point you to the right place.

12.Account deletion

You can request deletion of your ISETT account at any time, without signing in, using the account deletion request form.

ISETT accounts are issued by an administrator against a working relationship with an RSG company, so an account is not deleted the instant a form is submitted — the request goes to the administrators who own that decision. On approval we delete your account record, your preferences, your saved dashboards and pinned pages, your assistant conversations, and your sessions. We retain the security audit trail of actions taken on the account, because a tamper-proof security log that can be erased on request is not a security log; those entries are retained as a compliance record and are not used for any other purpose.

Business records in RSG's HR and operational systems are not affected by deleting an ISETT account — those are your employer's records and are governed by their own retention rules.

13.Children

ISETT is a workplace tool for adults. It is not directed at children, and we do not knowingly hold personal data about anyone under 18 other than as it may appear in employment records lawfully held by an RSG company.

14.Changes

If we change this policy we will update the effective date at the top and, where the change materially affects you, tell you in the platform. Continuing to use ISETT after a change means the updated policy applies to you.

15.Contact us

Privacy questions, data rights requests, and anything else: info@rsg.one, or the contact form.

Rock Solid Group
Al Kindi Plaza, Diplomatic Quarter, Riyadh
Kingdom of Saudi Arabia
+966 54 812 4638