GO-180 Trust Center

LEGAL & COMPLIANCE

For legal, privacy, and procurement teams: what data GO-180 processes, who processes it, how long we keep it, and the rights you can exercise.

HIPAA-alignedGDPRCCPA / CPRAFAR / NIST 800-171PCI SAQ-A

Compliance posture

GO-180 is built to handle the sensitive data of U.S. military veterans, and our controls are mapped to the regulatory frameworks that govern that data.

  • HIPAA Security Rule–aligned safeguards for health-adjacent data
  • GDPR and CCPA/CPRA data-subject rights honored
  • FAR / NIST SP 800-171 control families mapped
  • PCI-DSS SAQ-A — no card data on our servers
  • Documented risk assessment and incident response
  • Automated, category-based data retention

This page is provided for transparency and does not constitute legal advice. Framework alignment describes the controls we implement; certification status is available on request.

Regulatory alignment

Frameworks we map to

Each framework below governs a different slice of the data GO-180 handles. The right-hand column summarizes the controls we implement to address it.

FrameworkWhat it coversHow we address it
HIPAA Security RuleSafeguards for health-adjacent data such as TRICARE and insurance assessments.Document encryption, access controls, 15-minute automatic logoff, minimum-necessary redaction, audit controls, and a documented risk-assessment and incident-response program aligned to the Security Rule.
GDPR (EU/UK)Processing of personal data and data-subject rights.Lawful-basis and consent logging, data access and portability, erasure, and rectification, plus breach-notification procedures.
CCPA / CPRACalifornia consumer privacy rights.Right to know, delete, and opt out of sale; a published “Do Not Sell” path; and non-discrimination for exercising your rights.
FAR 52.204-21 / NIST SP 800-171Safeguarding information handled on federal contracts.Access control, identification and authentication, audit and accountability, and system/communications protection mapped to the 800-171 control families.
PCI-DSSPayment card data.Card entry is delegated to Stripe; our scope is SAQ-A and no card numbers are stored on GO-180 systems.

Data inventory

What we process

We collect only what is needed to deliver transition support. Sensitive categories receive the strongest protections, including encryption and minimum-necessary access.

ACCOUNT & IDENTITY

Name, email, phone, and date of birth used to create and secure your account.

MILITARY SERVICE

Branch, rank, service dates, and MOS used to tailor transition guidance.

EMPLOYMENT

Skills, work history, applications, and mentorship activity.

FINANCIAL

Budgets, goals, and debts you choose to track. No bank credentials are stored.

HOUSING & RELOCATION

VA-loan and relocation assessments, including eligibility inputs.

INSURANCE & HEALTH-ADJACENT

TRICARE and insurance assessments — treated as our most sensitive data.

DOCUMENTS

Files you upload (e.g., DD-214, pay stubs), encrypted with AES-256-GCM.

COMMUNICATIONS

Support messages, feedback, and notification preferences.

Service providers

Subprocessors

We engage the service providers below to operate the platform. Contact us for our current subprocessor list and the applicable data-processing terms.

ProviderPurposeData shared
StripePayment processingBilling identifiers (no card numbers stored by us)
CloudinaryEncrypted document storageEncrypted files and URLs
OpenAIAI assistant featuresPrompt content you submit to AI tools
MailjetTransactional emailEmail address and message content
TwilioSMS / WhatsApp and one-time codesPhone number and message content
SentryError monitoringDiagnostic data (personal data disabled)

Your rights

Exercising your privacy rights

Wherever you live, you can access, correct, export, or delete your data. Residents of the EU/UK and California have additional rights under GDPR and CCPA/CPRA.

ACCESS & PORTABILITY

Export a machine-readable copy of your data at any time.

ERASURE

Request deletion. We soft-delete with a 30-day grace window, then permanently purge.

RECTIFICATION

Correct or update your information directly in account settings.

OPT-OUT & DO-NOT-SELL

Unsubscribe from non-essential messages; we do not sell your personal information.

WITHDRAW CONSENT

Withdraw consent for optional processing such as marketing communications.

To exercise any of these rights, email privacy@go180.ai or use the data tools in your account settings. We respond within the timelines required by applicable law.

Retention

How long we keep data

Account data

Until you delete it — soft-deleted with a 30-day grace window, then purged.

Auth & system audit logs

30 to 365 days, by category.

Administrative action logs

Up to 7 years.

Generated exports (CSV/PDF)

About 7 days, then automatically removed.

Billing records

Retained as required for financial and audit compliance.

Incidents

Breach notification

In the event of a qualifying security incident, GO-180 follows a documented incident-response plan. Where required by HIPAA, GDPR (Articles 33–34), or applicable state law, we notify the relevant regulators and affected individuals within 72 hours, followed by a root-cause investigation and remediation.

Report a suspected vulnerability or incident to security@go180.ai.