1. Who operates the application
Cooper Nooraye Workspace Assistant (“the Assistant”) is a private automation tool operated under the Nooraye Software trading identity by Insight Software Solutions CC (“we”, “us” or “the operator”) in South Africa.
The Assistant is configured for a limited, authorised user base and is not offered as a public consumer service.
2. Scope of this policy
This policy applies to Google user data accessed through the Assistant’s OAuth connection and to information submitted through the public pages at cooper.frontofficecloud.com. The public site contains no account-registration form, advertising technology or analytics script.
3. Google data the Assistant may access
The exact access available depends on the permissions granted by the user. The current integration may access:
| Service | Data | Purpose |
|---|---|---|
| Gmail | Message content and metadata, threads and labels | Review authorised mail, organise messages and labels, and compose or send mail when directed. |
| Google Calendar | Calendars, events and event details | Review schedules and manage events when authorised. |
| Google Drive | File and folder content and metadata | Find, read, create, upload, organise, share or remove files when authorised. |
| Google Docs | Document content and structure | Read, create and edit documents when requested. |
| Google Sheets | Spreadsheet content and structure | Read, create and update spreadsheets when requested. |
| Google Contacts | Names, email addresses and phone numbers | Provide authorised contact context. The configured contact access is read-only. |
The Assistant does not obtain a user’s Google password. Google issues OAuth credentials after the user reviews and approves the requested permissions.
4. How Google data is used
Google user data is used only to provide or improve the user-facing functions requested by the authorised operator. Typical uses include answering a question about authorised content, locating information, preparing a draft, organising material, or carrying out an approved Workspace action.
We do not use Google user data for advertising, credit decisions, surveillance, sale to data brokers, or the development or training of generalised or non-personalised artificial-intelligence models.
5. AI processing and service providers
The Assistant uses an AI model to interpret requests and produce responses. Information necessary to fulfil an authorised request may therefore be sent to the configured AI service provider for processing. The current deployment uses OpenAI services.
Only information relevant to the requested function should be supplied to the provider. Provider processing is subject to the applicable service agreement and data controls. The operator remains responsible for configuring and using the Assistant consistently with this policy.
Cloudflare may process routine web-request information, such as IP address, browser information and security logs, when serving these public policy pages. The public site does not send Google Workspace content to Cloudflare.
6. Storage and retention
- OAuth credentials are stored locally in the Cooper Hermes profile on an operator-controlled computer.
- Relevant Google content or generated results may remain in local agent-session history or in project files when required to complete or document an authorised task.
- OAuth credentials are retained until access is revoked, credentials are deleted, or the integration is reconfigured.
- Task content is retained only for as long as reasonably necessary for the authorised operational purpose, record-keeping requirement or legal obligation.
7. Disclosure and sharing
We do not sell Google user data. We disclose it only:
- to the authorised user through the Assistant;
- to configured service providers where necessary to perform the requested function;
- when the user explicitly directs an external action, such as sending an email or sharing a file; or
- when required by applicable law or necessary to protect legal rights and security.
8. Security
We use proportionate administrative and technical safeguards, including profile-scoped credential storage, restricted machine access, least-privilege permissions where practical, and human approval controls for consequential actions. No system can guarantee absolute security.
9. User control, access and deletion
The authorised user may revoke the Assistant’s Google access at any time through the third-party connections or permissions area of their Google Account. Revocation prevents future API access but does not automatically remove information already retained in local records.
Requests to access, correct or delete locally retained information may be sent to noorayesoftware@gmail.com. We will respond subject to identity verification, technical feasibility and applicable legal obligations.
10. Google API Services User Data Policy
The Assistant’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11. South African privacy rights
Where the Protection of Personal Information Act, 2013 (“POPIA”) applies, personal information will be processed lawfully and for a defined purpose. A data subject may contact us to exercise applicable rights or raise a concern.
12. Changes to this policy
We may update this policy when the Assistant’s permissions, providers or processing practices change. The effective date above will be updated when material changes are made.
13. Contact
Nooraye Software
Operated by Insight Software Solutions CC
South Africa
noorayesoftware@gmail.com