Orgma Shared privacy notice

Version shared-2026-09-25-v1

# Orgma Shared privacy notice Version 1.0, approved 25 September 2026. Applies to Orgma Shared when the service is activated and this version is presented to the customer. ## Who is responsible Triton Safety Limited trading as Orgma is the controller for information used to administer accounts, subscriptions, enquiries, support and service security. Company number 11602941. Registered office: 7 Bournemouth Road, Chandler's Ford, Eastleigh, SO53 3DA, United Kingdom. Contact support@getorgma.com for privacy questions. The organisation using a Shared workspace controls the workforce records it uploads. Orgma processes that information on its instructions under the Shared data processing agreement. If your employer or contracting organisation holds your training record in Shared, contact that organisation first about access, correction or deletion. We will assist it with requests where appropriate. ## Information and purposes Account information includes your name, work email, organisation, role, sign-in and authentication records. We use it to provide access, apply permissions, help with recovery and protect the service. Account security can require an authenticator. We do not use a certificate photograph to recognise a person's face. Subscription information includes the organisation's chosen plan, payment status, billing references and the authorised representative's agreement record. Stripe processes payments. Orgma does not need your full card number or security code in a support message. Enquiries and support messages include the contact details and information you choose to send, our replies and related follow-up notes. Please send only what is necessary. Do not email passwords, complete backups or unredacted employee certificates. We will agree a suitable route if evidence is needed. Service and security information includes necessary access events, workspace identifiers, usage totals and diagnostic information. We use it to maintain service reliability, investigate misuse, manage allowances and resolve support issues. Customer workforce information is not made available to other customer organisations. Processing usage records include page counts, request status, model and token costs, and document fingerprints used to prevent duplicate charges or allowance use. A fingerprint is a technical digest, not a copy of the certificate. These records are not a reason to retain certificate images, extracted fields or unnecessary personal details for Orgma's own accounting. ## Lawful bases for our controller activities We rely on legitimate interests in operating a business service, communicating with business representatives, preventing misuse and maintaining service security, balanced against people's rights. Where an individual is directly party to a contract with us, necessary contract administration can rely on performance of that contract. Tax, accounting and legally required records are processed to meet legal obligations. Accepting service terms is not consent to unrelated marketing. The customer organisation determines the lawful basis and notices for its workforce information. It must avoid unnecessary personal information and assess any sensitive information before uploading it. ## Providers and processing locations Shared uses Supabase for account authentication, its database and evidence storage in the configured Ireland region, and Netlify for website hosting and server functions. Customer server functions currently run in Ohio, United States. Where enabled, assisted certificate extraction uses the configured OpenAI route through Netlify's gateway. Private encrypted evidence recovery copies and recovery inventories use Backblaze B2 in the selected EU Central region. Account email uses Resend, operated by Plus Five Five, Inc. Stripe handles subscriptions and payments under its applicable privacy information and agreements. The customer data processing schedule identifies the providers, purposes and applicable transfer arrangements. A hosting region does not mean that all support, email, billing or AI processing stays in that region. We do not promise UK-only processing or zero provider retention. The AI request's store:false setting alone does not establish zero retention. ## Keeping information We keep information for the purpose for which it is needed, under the retention schedule below, statutory duties and proportionate records needed to establish or defend claims. Cancelling renewal does not itself request workspace deletion. Customer exports and portable backups remain under the customer's control and may retain data removed from the live workspace. | Record | Retention | | --- | --- | | Account profile and access membership | While needed for an active workspace; remove within 30 days after the last applicable workspace is closed, unless a specific security or legal need applies. Retain only the separate minimal records below. | | Routine enquiries and support correspondence | 12 months after the enquiry or case closes. Remove temporary diagnostic attachments within 30 days of closure, or sooner when no longer needed. | | Routine security and diagnostic records controlled by Orgma | Up to 90 days. Extract only necessary evidence for a specific incident or claim and document its separate review date. Provider logs follow their applicable security and delivery schedules. | | Processing allowances and duplicate prevention records | Keep necessary workspace usage totals and document fingerprints while the workspace remains available, then remove request details and personal links within 30 days after closure. Remove individual actor identifiers within 90 days unless a documented incident or claim requires them. Retain only minimal totals needed for accounting under the separate accounting rule. | | Agreement acceptance and material contract/dispute records | Service term and six years after the relationship ends, subject to review for a specific continuing claim. | | Company accounting records | Six years from the end of the last company financial year to which they relate, with longer retention where required. This does not justify retaining workforce certificates. | | Workforce records and originals | The customer's instructions and the processing agreement govern these. Paid access for viewing/export lasts at least 90 days after editing ends; scheduled deletion review begins no earlier than then, with at least 30 days after notice delivery. Free inactivity review follows 12 months without authorised use and at least 30 days after notice delivery. Scoped live erasure then requires at least 24 hours of quarantine. Earlier requests are individually reviewed and their scope and timing confirmed. | | Database recovery copies | Daily backups retained for seven days under the configured database service. After live erasure, recovery copies remain restricted to necessary recovery until expiry; erased records must not be returned to ordinary use. | | Evidence recovery copies and inventories | Current evidence remains backed up. Removed or superseded versions have at least seven days from first observed absence, extended where a retained recovery inventory needs them. Inventories can remain for approximately 14 days. Scheduled cleanup removes eligible versions; failures or backlog can extend expiry and require attention. Orgma provides the applicable expected completion date when handling an erasure request. | | Provider security and delivery logs | The applicable provider schedule, separately from database and evidence recovery copies. Customer exports remain under customer control. | The company accounting period follows [GOV.UK record guidance](https://www.gov.uk/running-a-limited-company/company-and-accounting-records). The other periods reflect the service and records concerned. A specific legal hold must have a recorded reason, restricted access and a review date. It does not permit indefinite routine retention. ## Your rights and complaints Depending on the processing and applicable law, you can ask to access, correct or erase personal information, restrict its use, object to processing based on legitimate interests, or receive portable information where that right applies. Where processing relies on consent, you can withdraw it without affecting earlier lawful processing. Some information must be retained to meet legal obligations or applicable exceptions. Contact support@getorgma.com. We may need proportionate information to verify a requester's identity. For workforce records, we will refer the request to the responsible customer organisation and assist it under the processing agreement. Requests to exercise information rights are handled under their applicable legal deadlines; the complaints process below does not replace or extend those deadlines. You can also raise a data protection complaint by emailing support@getorgma.com or writing to our registered office. Tell us what happened and what you would like us to investigate; no special form or legal wording is required. We will acknowledge a complaint within 30 days of receipt, investigate and take appropriate steps without undue delay, keep you informed and explain the outcome without undue delay. Where your complaint concerns workforce processing controlled by a customer, we will promptly refer that part to the customer and assist it, while investigating any part about our own responsibilities. You can complain to the Information Commissioner's Office at https://ico.org.uk/make-a-complaint/. ## Account storage and changes The application uses necessary browser storage for authentication, preferences and operation. Acceptance of the agreement is not consent to advertising cookies. Any optional tracking will be explained separately and used with consent where required. We identify published notices by version and retain the documents associated with recorded customer agreement versions. Material changes will be communicated appropriately. Processing prepares information for customer review; it does not make an automated decision about a person's employment, competence or access to a worksite.