Privacy Policy
Last updated: July 2026
How data is handled in the OHS workspace — plainly, and in line with the GDPR.
1. Roles
For the data your company enters (employees, health-check records, assessments), your company is the controller and we are the processor — a data processing agreement is available self-serve. For your account and billing data, we are the controller.
2. What we process
Account details (email, name, language), your company's employee register, statutory role assignments, health-check dates, status decisions and optionally the hosted decision document, assessments, and an append-only audit log. Structured fields never hold diagnoses or medical detail.
3. Where it lives
All processing happens in the EU: database and files in EU data centers, transactional email with EU data residency. Files such as certificates and health documents live in private storage and are served through short-lived signed links.
4. Retention and deletion
Records are kept while your company uses the service. Leavers in the employee register are deactivated, never silently deleted, so statutory history survives. Deleting your company purges its rows and files after a 30-day grace period. Full data export (JSON/CSV plus files) is self-serve.
5. Your rights
You can access, correct, export, and delete your data. Employees can always see their own records through their secure link. Requests: support@ohs.ee — we answer within 30 days.
6. Cookies
The app uses only cookies that sign you in and remember your choices. Our marketing site uses cookieless analytics.