GO-180 Trust Center
LEGAL & COMPLIANCE
For legal, privacy, and procurement teams: what data GO-180 processes, who processes it, how long we keep it, and the rights you can exercise.
Compliance posture
GO-180 is built to handle the sensitive data of U.S. military veterans, and our controls are mapped to the regulatory frameworks that govern that data.
- HIPAA Security Rule–aligned safeguards for health-adjacent data
- GDPR and CCPA/CPRA data-subject rights honored
- FAR / NIST SP 800-171 control families mapped
- PCI-DSS SAQ-A — no card data on our servers
- Documented risk assessment and incident response
- Automated, category-based data retention
This page is provided for transparency and does not constitute legal advice. Framework alignment describes the controls we implement; certification status is available on request.
Regulatory alignment
Frameworks we map to
Each framework below governs a different slice of the data GO-180 handles. The right-hand column summarizes the controls we implement to address it.
| Framework | What it covers | How we address it |
|---|---|---|
| HIPAA Security Rule | Safeguards for health-adjacent data such as TRICARE and insurance assessments. | Document encryption, access controls, 15-minute automatic logoff, minimum-necessary redaction, audit controls, and a documented risk-assessment and incident-response program aligned to the Security Rule. |
| GDPR (EU/UK) | Processing of personal data and data-subject rights. | Lawful-basis and consent logging, data access and portability, erasure, and rectification, plus breach-notification procedures. |
| CCPA / CPRA | California consumer privacy rights. | Right to know, delete, and opt out of sale; a published “Do Not Sell” path; and non-discrimination for exercising your rights. |
| FAR 52.204-21 / NIST SP 800-171 | Safeguarding information handled on federal contracts. | Access control, identification and authentication, audit and accountability, and system/communications protection mapped to the 800-171 control families. |
| PCI-DSS | Payment card data. | Card entry is delegated to Stripe; our scope is SAQ-A and no card numbers are stored on GO-180 systems. |
Data inventory
What we process
We collect only what is needed to deliver transition support. Sensitive categories receive the strongest protections, including encryption and minimum-necessary access.
ACCOUNT & IDENTITY
Name, email, phone, and date of birth used to create and secure your account.
MILITARY SERVICE
Branch, rank, service dates, and MOS used to tailor transition guidance.
EMPLOYMENT
Skills, work history, applications, and mentorship activity.
FINANCIAL
Budgets, goals, and debts you choose to track. No bank credentials are stored.
HOUSING & RELOCATION
VA-loan and relocation assessments, including eligibility inputs.
INSURANCE & HEALTH-ADJACENT
TRICARE and insurance assessments — treated as our most sensitive data.
DOCUMENTS
Files you upload (e.g., DD-214, pay stubs), encrypted with AES-256-GCM.
COMMUNICATIONS
Support messages, feedback, and notification preferences.
Service providers
Subprocessors
We engage the service providers below to operate the platform. Contact us for our current subprocessor list and the applicable data-processing terms.
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Payment processing | Billing identifiers (no card numbers stored by us) |
| Cloudinary | Encrypted document storage | Encrypted files and URLs |
| OpenAI | AI assistant features | Prompt content you submit to AI tools |
| Mailjet | Transactional email | Email address and message content |
| Twilio | SMS / WhatsApp and one-time codes | Phone number and message content |
| Sentry | Error monitoring | Diagnostic data (personal data disabled) |
Your rights
Exercising your privacy rights
Wherever you live, you can access, correct, export, or delete your data. Residents of the EU/UK and California have additional rights under GDPR and CCPA/CPRA.
ACCESS & PORTABILITY
Export a machine-readable copy of your data at any time.
ERASURE
Request deletion. We soft-delete with a 30-day grace window, then permanently purge.
RECTIFICATION
Correct or update your information directly in account settings.
OPT-OUT & DO-NOT-SELL
Unsubscribe from non-essential messages; we do not sell your personal information.
WITHDRAW CONSENT
Withdraw consent for optional processing such as marketing communications.
To exercise any of these rights, email privacy@go180.ai or use the data tools in your account settings. We respond within the timelines required by applicable law.
Retention
How long we keep data
Account data
Until you delete it — soft-deleted with a 30-day grace window, then purged.
Auth & system audit logs
30 to 365 days, by category.
Administrative action logs
Up to 7 years.
Generated exports (CSV/PDF)
About 7 days, then automatically removed.
Billing records
Retained as required for financial and audit compliance.
Incidents
Breach notification
In the event of a qualifying security incident, GO-180 follows a documented incident-response plan. Where required by HIPAA, GDPR (Articles 33–34), or applicable state law, we notify the relevant regulators and affected individuals within 72 hours, followed by a root-cause investigation and remediation.
Report a suspected vulnerability or incident to security@go180.ai.
Related
TRUST OVERVIEW
Plain-English summary of how we protect your data and what's new.
ExploreSECURITY ARCHITECTURE
Control-by-control technical detail with data-flow diagrams.
ExplorePRIVACY POLICY
The full privacy policy and your detailed data rights.
ExploreFor a Data Processing Agreement, security questionnaire, or our current subprocessor list, contact legal@go180.ai. This page is informational and not legal advice.