# Orgma Shared data processing schedule
Version 1.0, approved 25 September 2026.
Applies to Orgma Shared when the service is activated and this version is presented to the customer.
## Parties, scope and instructions
The customer is controller of the workforce information it places in Shared.
Triton Safety Limited trading as Orgma acts as processor for that information.
Orgma separately acts as controller for its own account administration,
billing, security and legal records; those purposes require a separate privacy
notice and are not an unrestricted right to reuse workforce data.
Processing covers hosting, organising, extracting proposed certificate fields,
storing originals, presenting records to authorised colleagues, exporting,
backing up and deleting data on documented instructions. It lasts for the
service and the agreed return/deletion period. Instructions consist of the
agreement and authorised actions within the service. Orgma will notify the
customer if an instruction appears to infringe applicable data protection law.
Data subjects include employees, subcontractors and authorised account users.
Data may include names, company and employee references, induction numbers,
roles, qualifications, issue and expiry dates, certificate numbers, certificate
photographs and signatures, review notes and access/audit records. Do not treat
portrait processing as facial recognition. Special category information is not
part of the intended routine service; its inclusion needs an explicit assessment
of necessity, lawful conditions and safeguards.
## Processor commitments
Orgma will:
1. Process personal data only on documented instructions, including transfers,
unless law requires otherwise; give notice of that requirement where lawful.
2. Bind personnel with authorised access to confidentiality obligations.
3. Maintain appropriate technical and organisational measures proportionate to
risk, documented in the security schedule below.
4. Obtain the customer's general written authorisation for listed subprocessors
and their disclosed onward processing. For a new or replacement provider
appointed directly by Orgma, give at least 30 days' advance notice. For a
change to an existing provider's onward subprocessors, pass on the available
advance notice promptly and give a meaningful opportunity to object before
the change applies to the customer's data. That provider's notice period may
be shorter than 30 days. An objection must have reasonable data protection
grounds. If sufficient advance notice or required safeguards cannot be
secured, Orgma will prevent the affected new processing or suspend that
route while resolving the issue, preserving safe return and export options.
Impose equivalent applicable processing obligations and remain responsible
for subprocessors' performance of those obligations. The parties will seek
an appropriate alternative following an objection. If none is available,
the customer may terminate the affected service and receive a proportionate
refund of prepaid fees for the unused affected service.
5. Assist the customer with data subject requests, data protection complaints
and its security, breach,
impact assessment and regulator consultation obligations, taking account of
the nature of processing and information available. Forward workforce data
requests and complaints to the customer promptly, while handling any part
concerning Orgma's own controller activities through its complaints process.
6. Notify the customer without undue delay after becoming aware of a personal
data breach, providing available facts and subsequent updates. Do not make
the customer's regulatory notification decision on its behalf.
7. At the end of services, return or delete data at the customer's choice and
delete copies unless law requires retention, under the final agreed timetable.
8. Make compliance information available and permit proportionate audits and
inspections, subject to appropriate confidentiality and security arrangements.
## Provider and transfer schedule
| Provider | Processing function |
| --- | --- |
| Supabase Pte. Ltd | Account authentication, organisation database and original evidence storage. The configured data region is Ireland. |
| Backblaze, Inc. | Private encrypted recovery copies of original evidence and file inventories in the selected EU Central region. Support and other processing can occur outside that region. |
| Netlify, Inc. | Website hosting, server functions and gateway routing where AI assistance is enabled. Customer server functions run in Ohio, United States. |
| OpenAI through Netlify AI Gateway | Where enabled and used, certificate images are processed to propose fields for human review. This is an onward service through Netlify, not a representation of a direct customer contract with OpenAI. |
| Plus Five Five, Inc., trading as Resend | Transactional account emails containing recipient addresses and account access content. |
Stripe processes subscription and payment information under the applicable
payment agreements. Orgma uses it for its own billing activities; this does not
make every Stripe activity subprocessing of customer workforce information.
A selected hosting region does not mean that all delivery, support, email or
AI processing remains in that region. Orgma will use applicable adequacy
arrangements or appropriate contractual safeguards for restricted international
transfers, including the relevant UK transfer addendum where required, and
provide information about the relied-on safeguards on request. Orgma will not
activate a processing route before the applicable arrangements are established.
Where contractual safeguards are relied on, Orgma will document the applicable
transfer risk assessment and any additional protections needed to meet the UK
data protection test. Reliance on an adequacy arrangement requires checking its
scope and the recipient's current eligibility.
No UK-only processing or zero provider retention is promised.
## Security schedule
Orgma will maintain organisation membership and role checks, database row access
policies, private evidence storage and protected network connections. Privileged
credentials are held on the server and are not supplied to the browser.
Certificate assistance uses permission and workspace checks, bounded inputs and
server usage controls. Its proposed fields remain subject to human review.
Orgma will restrict support access to the purpose and personnel needed, record
material administrative actions and review privileged access regularly.
Orgma will maintain documented incident response, vulnerability handling,
credential rotation and recovery procedures proportionate to the service.
Recovery arrangements must cover both database records and original evidence;
a database-only backup is not represented as a backup of certificate files.
The configured database backup schedule is daily with seven days of retained
backups. Original evidence is backed up separately on an hourly schedule to
private storage encrypted with provider-managed keys. New file copies are
retrieved and checked against their original size and SHA-256 checksum before
a complete recovery inventory is recorded. The database and files are separate
snapshots, so a recovery must check their consistency and apply recorded erasures.
Monitoring records failures and the time of the last complete file backup;
these schedules do not guarantee a maximum data loss or recovery time.
Portable customer backups use a customer-chosen passphrase. Orgma cannot recover
a forgotten passphrase. No independent security certification or guaranteed
recovery time is represented unless expressly agreed in a signed order.
## Retention and return
After paid editing entitlement ends, the customer has at least 90 days to view
and export the workspace unless an earlier verified and lawful instruction is
separately assessed and confirmed. Orgma gives notice by day 60. Scheduled
deletion review starts no earlier than day 90; later notice moves review to at
least 30 days after actual delivery. A further quarantine of at least 24 hours
precedes completion of scoped live erasure. Reactivation or an agreed Free transfer cancels
scheduled closure. A Free workspace may be closed after 12 months without
authorised use, followed by at least 30 days' notice and an opportunity to retain
or export it.
The customer may choose return or deletion at the end of the service. Orgma will
verify the instruction and provide the supported export route. The scheduled
processor erasure removes that tenant's workforce register and original evidence
files, evidence metadata and pending object operations, while preserving other
organisations and shared account identities. Separate account, agreement,
billing, security and necessary processing usage records follow the controller
purposes and retention periods in the privacy notice. This is not permission to
retain certificate contents or unnecessary personal links as accounting data.
Remaining request details, account links and support copies containing workforce
information require
separate review and removal through the appropriate support process. An earlier
deletion instruction is assessed individually and is not automatically run by
the scheduled erasure tool. Lawfully retained exceptions will be identified,
access restricted and reviewed.
Where immediate deletion from a recovery copy is not technically possible,
the data will be put beyond ordinary use, restricted to necessary recovery and
deleted at the next applicable secure expiry cycle. Orgma will identify the
applicable cycle and expected completion date when confirming a deletion
request, and will not retain recovery copies indefinitely. If a restore recovers
erased records, their deletion must be reapplied before ordinary service resumes.
Current evidence copies remain protected while their originals are referenced
by the live workspace. A removed or superseded file version is retained for at
least seven days from the backup service's first observation that it is no
longer current, and longer if a retained recovery inventory still needs it.
Expired versions are removed by the scheduled job once those checks pass.
Recovery inventories can remain for approximately 14 days. A failed job or
backlog can extend these periods and requires operator attention. This is not
a promise that every copy disappears exactly seven days after live erasure.
Provider security logs and customer-held exports have separate retention rules.
Customer-held exports and backups remain under the customer's control.
## Acceptance and evidence
The final agreement must identify the parties, processing purpose and duration,
data types and subjects, controller rights and obligations, subprocessors and
security/return arrangements. Record the accepted document version with the
organisation and authorised representative. Maintain a history of changes.