Privacy Policy

Gochi — a product of Tellurium Technologies (Pty) Ltd

Effective 27 July 2026

1. Who we are

Gochi (gochi.tech) is a business management platform for managed service providers and their clients, developed and operated by Tellurium Technologies (Pty) Ltd, a company registered in South Africa (“Tellurium”, “we”, “us”). Registered address: Unit 11, APD Industrial Park, Elsecar St, Kya Sand, Randburg, 2163, South Africa. Privacy contact: welcome@gochi.tech.

Under the Protection of Personal Information Act, 2013 (POPIA), Tellurium is the responsible party for personal information we collect about our own customers and website visitors, and acts as an operator (processor) for personal information our customers store in Gochi about their own clients and end users. Where the EU or UK General Data Protection Regulation applies, the equivalent roles are controller and processor respectively.

Our Information Officer, as required by POPIA, can be reached at welcome@gochi.tech.

EU and UK representatives. Tellurium is established in South Africa and serves customers internationally. We have no office or establishment in the European Union or the United Kingdom. Where Article 27 of the GDPR or of the UK GDPR requires us to designate a representative in those territories, we will do so and name them here. Wherever you are, you can reach us directly at welcome@gochi.tech, and we will honour the rights described in this policy regardless of which law gives them to you.

2. Information we collect

Account information
Name, email address, phone number, password (stored as a salted hash), and multi-factor authentication settings.
Customer relationship data
Contacts, companies, deals, tickets, contracts and related records that our customers create or import into Gochi about their own clients. Tellurium processes this data on the customer's instructions.
Email data
Where a customer connects a mailbox (e.g. Microsoft 365 or IMAP), Gochi ingests message headers and content in order to display, thread and link email to customer records.
Device telemetry
Where a customer installs the Gochi infrastructure agent on a device, the agent reports the hostname, hardware and operating system details, resource metrics (CPU, memory, disk), network addresses, the username of the person signed in to the device, and an inventory of installed software, for monitoring and remote support. Installation requires explicit consent on the device at install time.
Remote support sessions
Where a technician starts a remote desktop or terminal session to a managed device, we record that a session took place, who started it, and when. A visible notice is shown on the device at the start and end of each session.
Documents and signatures
Documents generated or uploaded for approval and electronic signature, including signature data, and an audit trail of who signed and when. Signed documents are encrypted at rest.
Connected platform tokens
Where a customer connects a third-party account (for example a social media or advertising account), we store the access tokens needed to act on the customer's instructions. Tokens are encrypted at rest and can be disconnected at any time.
Marketing campaign data
Where a customer sends an email campaign through Gochi, we record deliveries, bounces, unsubscribes, and whether a message was opened or a link clicked, so the customer can measure the campaign and honour opt-outs.
Usage and log data
Sign-in events, audit records of actions taken in the platform, IP addresses, and basic analytics about how the product is used.
Cookies
Gochi sets a single cookie, used to keep you signed in. It is strictly necessary to provide the service you have asked for. We do not use analytics cookies, advertising cookies, or third-party trackers on this website, so no cookie consent banner is needed. Your theme preference is stored locally in your browser and is never sent to us.
Website analytics we provide to customers
Customers can place a Gochi analytics snippet on their own website. It records the page visited, an approximate country derived from the request, and whether the device is a desktop, tablet or phone. It sets no cookies and does not store the visitor's IP address. The customer is the responsible party for that data and for any notice they must give their own visitors.

3. How we use information

  • To provide, operate and secure the Gochi platform.
  • To act on our customers' instructions — e.g. sending an email campaign, generating a document, monitoring a device, or publishing content to a platform the customer has connected.
  • To provide support, investigate incidents, and maintain audit trails.
  • To improve the product, using aggregated or de-identified usage data.
  • To meet legal obligations.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use customer data to train artificial-intelligence models.

4. Our lawful basis for processing

Where the GDPR applies, we rely on the following bases. POPIA recognises equivalent grounds of justification.

Performance of a contract
Providing the platform to the customer who has subscribed to it, including hosting their data and carrying out the actions they request.
Legitimate interests
Securing the service, preventing abuse, maintaining audit trails, and improving the product using aggregated or de-identified data. We balance these against your rights and interests.
Consent
Installing the device agent on a machine, and connecting a third-party account. Consent can be withdrawn at any time — by uninstalling the agent or disconnecting the account.
Legal obligation
Retaining records and responding to lawful requests where the law requires it.

Where we act as an operator or processor for a customer, that customer determines the purpose and lawful basis for the data they store about their own clients.

5. Third-party platforms you connect

Customers may connect third-party accounts (such as Microsoft 365, Google, Meta, LinkedIn or TikTok) to Gochi. When you connect an account, you authorise Gochi to access that account only to the extent of the permissions shown on the platform's consent screen, and only to carry out the actions you request in Gochi. You can revoke this access at any time, either in Gochi or in the third-party platform's own security settings, and we will delete the stored tokens.

What we access from each platform, and why:

Facebook Pages and Instagram
The name and identifier of the Page or professional account you select, so we can show you which account is linked; permission to publish the posts you schedule; and the engagement figures the platform returns for those posts (impressions, reach, likes, comments, shares) so you can measure them. We do not read your personal profile, your friends, your inbox, or any Page content we did not publish.
LinkedIn
Your name and profile identifier, or the identifier of a company page you administer, so we can show which account is linked and publish the posts you schedule. We do not read your connections, your feed or your messages.
TikTok
Your account name and the creator information TikTok requires us to display before posting (such as your nickname and whether your daily posting limit is reached), and permission to upload or publish the content you submit. We do not read your videos, your followers or your messages.
Google and YouTube
The channel name and identifier, so we can show which channel is linked, and permission to upload the videos you submit. We do not read your other Google data, your Gmail, your Drive or your viewing history.
Microsoft 365
Where you connect a mailbox, the messages in it, so Gochi can display, thread and link email to your customer records.

We use data from these platforms only to provide the features you asked for. We do not sell it, we do not transfer it to anyone except as needed to provide the service at your instruction, we do not use it for advertising, and we do not use it to train artificial-intelligence models. Access tokens are encrypted at rest and are deleted when you disconnect the account.

Gochi's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

To disconnect an account or have the data we hold from it deleted, follow the steps at gochi.tech/data-deletion.

6. Sharing

We share personal information only with: (a) service providers who host and operate our infrastructure; (b) third-party platforms, when and only because a customer has connected them and instructed an action; and (c) authorities where the law requires it. We require operators processing data on our behalf to protect it to the standards required by POPIA and, where applicable, to be bound by terms meeting Article 28 of the GDPR.

Our current sub-processors are published at gochi.tech/subprocessors, with what each one does and where it is located. Before adding or replacing a sub-processor we update that page and notify account holders at least 30 days in advance, and you may object within 30 days — the process and consequences are set out there. We remain fully liable for our sub-processors' performance under Article 28(4) of the GDPR.

7. Security

We use appropriate technical and organisational measures, including encryption in transit (TLS), encryption at rest, role-based access control, tenant isolation, audit logging, multi-factor authentication, and hardened remote-access controls. Passwords are stored only as salted hashes and are never recoverable.

Stored credentials, third-party access tokens and signed documents saved from July 2026 onward are encrypted with AES-256-GCM. A small number of older records predate that change: signed documents from before it use an earlier encryption scheme, and some credentials stored before encryption was introduced remain unencrypted until they are next saved. We are migrating both.

No system is perfectly secure. Under POPIA we notify the Information Regulator and every affected data subject of any security compromise, as soon as reasonably possible after discovering it — POPIA sets no risk threshold and no exemption for encrypted data, so this applies to all qualifying incidents.

Where the GDPR or UK GDPR applies and we are acting as controller, we notify the relevant supervisory authority without undue delay and within 72 hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to people's rights and freedoms, and we tell affected individuals where the risk to them is high. Where we act as a processor for a customer, we notify that customer without undue delay so they can meet their own deadlines.

8. Retention and deletion

We keep personal information for as long as the customer account it belongs to is active. After an account is closed we delete or de-identify personal information within 90 days, unless the law requires us to keep it longer.

When you delete a record inside the platform it is immediately removed from view and from every list, report and search — it can be restored during a short grace period, and is then permanently erased by an automated job that runs daily and removes anything deleted more than 7 days ago. Copies held in encrypted backups age out on our normal backup rotation. Audit and security logs are kept longer than ordinary records, because we need them to investigate incidents and to meet our accountability obligations.

To request deletion of your data, email welcome@gochi.tech — this includes data obtained from connected third-party platforms.

9. Your rights

Under POPIA you may request access to, correction of, or deletion of your personal information, and you may object to processing. Where the GDPR or UK GDPR applies, you also have the right to restrict processing, to receive your data in a portable format, and to withdraw consent at any time without affecting processing already carried out.

We do not make decisions producing legal or similarly significant effects about you by solely automated means, and we do not carry out profiling of that kind.

Where our customer is the responsible party for data about you (for example, you are a client of a business that uses Gochi), we will refer your request to them and assist them in responding. You may lodge a complaint with the Information Regulator (South Africa) at inforegulator.org.za, or, if you are in the EU or UK, with your local supervisory authority.

10. International transfers

Gochi is hosted in South Africa, with Domains.co.za. Where a customer connects an international third-party platform, data flows to that platform under its own terms.

South Africa has not been designated by the European Commission or the UK as providing an adequate level of protection. Where personal information reaches us from the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), using Module Two where our customer is the controller and we act as processor. For transfers from the United Kingdom we use the same clauses together with the ICO's International Data Transfer Addendum, and we carry out and document the transfer risk assessment (the “data protection test”) that UK law requires. We apply supplementary measures where an assessment shows they are needed.

Where we transfer personal information out of South Africa ourselves — for example to a sub-processor — we do so only on conditions meeting section 72 of POPIA, including binding terms that carry equivalent protection through to any onward transfer.

11. United States

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act as amended by the CPRA. Because we do neither, we do not provide a “Do Not Sell or Share My Personal Information” link, and we do not act on opt-out preference signals for those purposes.

Where a US business uses Gochi to process personal information about its own customers or staff, we act as that business's service provider (or the equivalent term in other state laws). We use that information only to provide the service under our contract, never for our own purposes, and we delete it on the business's instruction.

Residents of US states with comprehensive privacy laws may have rights to know what personal information we hold about them, to correct or delete it, to obtain a copy, and to appeal a refused request. If a business is the controller of data about you, we will refer your request to them and help them respond. Otherwise, contact welcome@gochi.tech. We will not discriminate against you for exercising any of these rights.

12. Children

Gochi is a business tool and is not directed at children. We do not knowingly collect personal information from children.

13. Changes

We will post any changes to this policy on this page and update the effective date. Material changes will be notified to account holders.

14. Contact

Tellurium Technologies (Pty) Ltd · Unit 11, APD Industrial Park, Elsecar St, Kya Sand, Randburg, 2163, South Africa · welcome@gochi.tech

See also our Terms of Service.