How GearLogs collects, uses, protects, and shares data.
This policy is being finalized ahead of RAQIOM’s registration in Israel; an effective date will be added when it takes effect. It explains what data GearLogs handles, why, where it lives, and your rights — covering both account data we collect from you and operational data your organization enters into the Service.
Two categories. Account & authentication data — email, name, organization, and login and security metadata. Operational data your organization enters — equipment records, and personnel names, roles, and custody assignments. Personnel data is entered by the customer organization, not collected by us directly from those individuals.
We process account data to operate and secure your access, and operational data to provide the accountability and inventory service you use. For users in the EU, our legal bases are performance of a contract (Art. 6(1)(b)) and our legitimate interest in securing and improving the Service (Art. 6(1)(f)).
We use a small, named set of providers:
We maintain this as a living, named list and will notify material changes. We do not sell your data or share it for advertising.
Your primary database is hosted in the EU (Frankfurt). Content delivery, bot-protection, and payment processing may involve providers operating in other regions. Where processing occurs outside the EU or an adequate jurisdiction, an appropriate safeguard (such as Standard Contractual Clauses or the provider’s equivalent) applies. Israel holds EU adequacy status, which supports transfers between Israel and the EU.
We retain Customer Data for as long as your organization’s access is active, and for a limited window after termination (to allow export) — after which it is deleted or anonymized, except where law requires retention. We do not keep operational data indefinitely.
Support conversations and notification records inside the app, and enquiries sent through the website form, are kept for 12 months from their last activity and then deleted.
We apply appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation so one organization’s data is not accessible to another, optional two-factor authentication, and role-based access controls. No system is perfectly secure, and this description of our measures does not diminish our underlying duty to protect data.
If you believe you have found a security vulnerability, report it to [email protected] or via the contact named in /.well-known/security.txt; a person reads and responds to every report. We do not pursue legal action against good-faith security research conducted under this policy.
Subject to applicable law, you may request access to, correction of, deletion of, or a portable export of your personal data, and (for EU users) may object to or ask us to restrict certain processing. To exercise these, contact [email protected]; we aim to respond within 30 days. Where your organization is the controller of personnel data, some requests may be directed to it.
We use only essential cookies needed for authentication and security (for example, session cookies and Cloudflare’s bot-protection). We do not use advertising or cross-site tracking cookies.
GearLogs is intended for organizational and professional use and is not directed to individuals under 18. Responsibility for lawful entry of any personnel data, including any minor’s, rests with the customer organization (see Terms clause 4).
If a data breach affects your data, we will notify you without undue delay and, where required, notify the Israeli Privacy Protection Authority or the relevant EU supervisory authority.
We may update this policy and will post the effective date and notify material changes. Continued use after the effective date constitutes acknowledgment.
The controller is RAQIOM, a sole proprietorship registered in Israel (registered address to be published on registration). Privacy questions: [email protected]. Where your organization determines how personnel data it enters is used, it is the controller and GearLogs is the processor; a Data Processing Addendum governs that relationship and can be provided on request.