Orgma Shared data processing agreement

Version shared-2026-09-25-v1

# Orgma Shared data processing schedule Version 1.0, approved 25 September 2026. Applies to Orgma Shared when the service is activated and this version is presented to the customer. ## Parties, scope and instructions The customer is controller of the workforce information it places in Shared. Triton Safety Limited trading as Orgma acts as processor for that information. Orgma separately acts as controller for its own account administration, billing, security and legal records; those purposes require a separate privacy notice and are not an unrestricted right to reuse workforce data. Processing covers hosting, organising, extracting proposed certificate fields, storing originals, presenting records to authorised colleagues, exporting, backing up and deleting data on documented instructions. It lasts for the service and the agreed return/deletion period. Instructions consist of the agreement and authorised actions within the service. Orgma will notify the customer if an instruction appears to infringe applicable data protection law. Data subjects include employees, subcontractors and authorised account users. Data may include names, company and employee references, induction numbers, roles, qualifications, issue and expiry dates, certificate numbers, certificate photographs and signatures, review notes and access/audit records. Do not treat portrait processing as facial recognition. Special category information is not part of the intended routine service; its inclusion needs an explicit assessment of necessity, lawful conditions and safeguards. ## Processor commitments Orgma will: 1. Process personal data only on documented instructions, including transfers, unless law requires otherwise; give notice of that requirement where lawful. 2. Bind personnel with authorised access to confidentiality obligations. 3. Maintain appropriate technical and organisational measures proportionate to risk, documented in the security schedule below. 4. Obtain the customer's general written authorisation for listed subprocessors and their disclosed onward processing. For a new or replacement provider appointed directly by Orgma, give at least 30 days' advance notice. For a change to an existing provider's onward subprocessors, pass on the available advance notice promptly and give a meaningful opportunity to object before the change applies to the customer's data. That provider's notice period may be shorter than 30 days. An objection must have reasonable data protection grounds. If sufficient advance notice or required safeguards cannot be secured, Orgma will prevent the affected new processing or suspend that route while resolving the issue, preserving safe return and export options. Impose equivalent applicable processing obligations and remain responsible for subprocessors' performance of those obligations. The parties will seek an appropriate alternative following an objection. If none is available, the customer may terminate the affected service and receive a proportionate refund of prepaid fees for the unused affected service. 5. Assist the customer with data subject requests, data protection complaints and its security, breach, impact assessment and regulator consultation obligations, taking account of the nature of processing and information available. Forward workforce data requests and complaints to the customer promptly, while handling any part concerning Orgma's own controller activities through its complaints process. 6. Notify the customer without undue delay after becoming aware of a personal data breach, providing available facts and subsequent updates. Do not make the customer's regulatory notification decision on its behalf. 7. At the end of services, return or delete data at the customer's choice and delete copies unless law requires retention, under the final agreed timetable. 8. Make compliance information available and permit proportionate audits and inspections, subject to appropriate confidentiality and security arrangements. ## Provider and transfer schedule | Provider | Processing function | | --- | --- | | Supabase Pte. Ltd | Account authentication, organisation database and original evidence storage. The configured data region is Ireland. | | Backblaze, Inc. | Private encrypted recovery copies of original evidence and file inventories in the selected EU Central region. Support and other processing can occur outside that region. | | Netlify, Inc. | Website hosting, server functions and gateway routing where AI assistance is enabled. Customer server functions run in Ohio, United States. | | OpenAI through Netlify AI Gateway | Where enabled and used, certificate images are processed to propose fields for human review. This is an onward service through Netlify, not a representation of a direct customer contract with OpenAI. | | Plus Five Five, Inc., trading as Resend | Transactional account emails containing recipient addresses and account access content. | Stripe processes subscription and payment information under the applicable payment agreements. Orgma uses it for its own billing activities; this does not make every Stripe activity subprocessing of customer workforce information. A selected hosting region does not mean that all delivery, support, email or AI processing remains in that region. Orgma will use applicable adequacy arrangements or appropriate contractual safeguards for restricted international transfers, including the relevant UK transfer addendum where required, and provide information about the relied-on safeguards on request. Orgma will not activate a processing route before the applicable arrangements are established. Where contractual safeguards are relied on, Orgma will document the applicable transfer risk assessment and any additional protections needed to meet the UK data protection test. Reliance on an adequacy arrangement requires checking its scope and the recipient's current eligibility. No UK-only processing or zero provider retention is promised. ## Security schedule Orgma will maintain organisation membership and role checks, database row access policies, private evidence storage and protected network connections. Privileged credentials are held on the server and are not supplied to the browser. Certificate assistance uses permission and workspace checks, bounded inputs and server usage controls. Its proposed fields remain subject to human review. Orgma will restrict support access to the purpose and personnel needed, record material administrative actions and review privileged access regularly. Orgma will maintain documented incident response, vulnerability handling, credential rotation and recovery procedures proportionate to the service. Recovery arrangements must cover both database records and original evidence; a database-only backup is not represented as a backup of certificate files. The configured database backup schedule is daily with seven days of retained backups. Original evidence is backed up separately on an hourly schedule to private storage encrypted with provider-managed keys. New file copies are retrieved and checked against their original size and SHA-256 checksum before a complete recovery inventory is recorded. The database and files are separate snapshots, so a recovery must check their consistency and apply recorded erasures. Monitoring records failures and the time of the last complete file backup; these schedules do not guarantee a maximum data loss or recovery time. Portable customer backups use a customer-chosen passphrase. Orgma cannot recover a forgotten passphrase. No independent security certification or guaranteed recovery time is represented unless expressly agreed in a signed order. ## Retention and return After paid editing entitlement ends, the customer has at least 90 days to view and export the workspace unless an earlier verified and lawful instruction is separately assessed and confirmed. Orgma gives notice by day 60. Scheduled deletion review starts no earlier than day 90; later notice moves review to at least 30 days after actual delivery. A further quarantine of at least 24 hours precedes completion of scoped live erasure. Reactivation or an agreed Free transfer cancels scheduled closure. A Free workspace may be closed after 12 months without authorised use, followed by at least 30 days' notice and an opportunity to retain or export it. The customer may choose return or deletion at the end of the service. Orgma will verify the instruction and provide the supported export route. The scheduled processor erasure removes that tenant's workforce register and original evidence files, evidence metadata and pending object operations, while preserving other organisations and shared account identities. Separate account, agreement, billing, security and necessary processing usage records follow the controller purposes and retention periods in the privacy notice. This is not permission to retain certificate contents or unnecessary personal links as accounting data. Remaining request details, account links and support copies containing workforce information require separate review and removal through the appropriate support process. An earlier deletion instruction is assessed individually and is not automatically run by the scheduled erasure tool. Lawfully retained exceptions will be identified, access restricted and reviewed. Where immediate deletion from a recovery copy is not technically possible, the data will be put beyond ordinary use, restricted to necessary recovery and deleted at the next applicable secure expiry cycle. Orgma will identify the applicable cycle and expected completion date when confirming a deletion request, and will not retain recovery copies indefinitely. If a restore recovers erased records, their deletion must be reapplied before ordinary service resumes. Current evidence copies remain protected while their originals are referenced by the live workspace. A removed or superseded file version is retained for at least seven days from the backup service's first observation that it is no longer current, and longer if a retained recovery inventory still needs it. Expired versions are removed by the scheduled job once those checks pass. Recovery inventories can remain for approximately 14 days. A failed job or backlog can extend these periods and requires operator attention. This is not a promise that every copy disappears exactly seven days after live erasure. Provider security logs and customer-held exports have separate retention rules. Customer-held exports and backups remain under the customer's control. ## Acceptance and evidence The final agreement must identify the parties, processing purpose and duration, data types and subjects, controller rights and obligations, subprocessors and security/return arrangements. Record the accepted document version with the organisation and authorised representative. Maintain a history of changes.