Privacy Policy

Last updated: July 2026

How data is handled in the OHS workspace — plainly, and in line with the GDPR.

1. Roles

For the data your company enters (employees, health-check records, assessments), your company is the controller and we are the processor — a data processing agreement is available self-serve. For your account and billing data, we are the controller.

2. What we process

Account details (email, name, language), your company's employee register, statutory role assignments, health-check dates, status decisions and optionally the hosted decision document, assessments, and an append-only audit log. Structured fields never hold diagnoses or medical detail.

3. Where it lives

All processing happens in the EU: database and files in EU data centers, transactional email with EU data residency. Files such as certificates and health documents live in private storage and are served through short-lived signed links.

4. Retention and deletion

Records are kept while your company uses the service. Leavers in the employee register are deactivated, never silently deleted, so statutory history survives. Deleting your company purges its rows and files after a 30-day grace period. Full data export (JSON/CSV plus files) is self-serve.

5. Your rights

You can access, correct, export, and delete your data. Employees can always see their own records through their secure link. Requests: support@ohs.ee — we answer within 30 days.

6. Cookies

The app uses only cookies that sign you in and remember your choices. Our marketing site uses cookieless analytics.