Data processing agreement
Version 2.0. Effective 22 September 2026.
These terms form part of the agreement between the customer (the controller) and Oberon (the processor) and apply whenever we process personal data on the customer's behalf.
1. Roles
The customer is the controller of workspace data, including records about their staff, their contractors and visitors who sign in at their sites. Oberon is the processor and acts only on documented instructions, including on international transfers, unless the law requires otherwise. Giving the people concerned a privacy notice is the controller's duty; we provide a worker notice template and gate wording they can use.
2. Confidentiality
Everyone we allow near customer data is bound by confidentiality and is given access only where their job needs it.
3. Security
We keep the measures set out in Annex B, appropriate to the risk, and review them as the service changes.
4. Subprocessors
The customer gives general authorisation to the subprocessors in Annex C. We give at least thirty days' notice before adding or replacing one, and the customer may object on reasonable data protection grounds. Each subprocessor is bound by terms no weaker than these.
5. Helping the controller
We assist with data subject requests, data protection impact assessments and consultations with the regulator, taking account of the information available to us. A one-step per-person export is built into the product for subject access requests.
6. Breach notification
We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the facts we have and what we are doing about it.
7. Deletion and return
The customer can export everything at any time from the workspace. On termination, data is deleted after the retention window in Annex D, except where law requires us to keep it.
8. Audit
We make available the information needed to show compliance and will answer a reasonable annual security questionnaire.
A. Annex A: processing details
Subject matter: provision of health and safety management software. Duration: the term of the agreement. Nature and purpose: hosting, storage and processing of safety records. Data subjects: the customer's staff, contractors and site visitors.
Categories: identity and contact details; employment, training and induction records; documents the customer uploads to their own company library; site attendance and gate sign-in records, including the name of a manager who authorises an entry by exception; approximate location captured at the moment of a signature; photographs taken as evidence against a task, check or incident; incident details; hand-arm vibration and noise exposure readings; and health data where the customer records it after an accident or exposure. The last two categories are special-category data and the customer determines the condition for processing them, which is normally their obligations under health and safety law.
B. Annex B: security measures
Encryption in transit and at rest. Organisation-level isolation enforced in the database. Role-based access within a workspace. Audit logging of significant actions and of any support access. Daily backups with rehearsed restores. Least-privilege administration and password hashing. Entries captured with no signal are held on the capturing device only until it reconnects, then uploaded and cleared from the device queue.
C. Annex C: subprocessors
Hosting and database platform (EU). Payment processing. Transactional and marketing email delivery. AI model provider, used for drafting and answering features; request content is not used to train the provider's general models. Web analytics, only where the visitor has accepted cookies. The current named list is provided on request and with the procurement pack, and changes carry at least thirty days' notice.
D. Annex D: retention
Active workspace: for as long as the customer keeps the workspace. Trial that is not converted: the workspace locks, stays exportable for 30 days, then is erased. After termination of a paid subscription: available for export for 30 days, then deleted within a further 60 days. Backups age out on their normal rolling cycle. Accounting records are kept for six years.
Exposure readings, health surveillance entries and accident records are not aged out on a schedule of ours while the workspace is active, because the duties they support run for decades after the exposure. The customer decides when to delete them, and deletion of the workspace deletes them with it.
E. Annex E: demonstration environments
Demonstration and presentation workspaces contain invented records only. Customer personal data is never copied into them, and they are excluded from reporting, billing and exports.
Data processing agreement, version 2.0, effective 22 September 2026. Questions: hello@oberoncompliance.com