Privacy notice
Version 2.0. Effective 22 September 2026.
1. Who this covers
This notice covers people who visit this website, people who sign up for an Oberon workspace, and people whose details are entered into a workspace by their employer. Where an employer puts worker, contractor or visitor records into Oberon, that employer is the data controller and we are the processor acting on their instructions. If your details are in an employer's workspace, their own privacy notice governs them and this one explains what we do with them on their behalf.
2. What we collect
Account details (name, work email, phone, employer, role). Usage records needed to run the service (sign-in times, audit entries, device and browser information). Billing details, held by our payment processor rather than by us. Anything you type into an enquiry or demo request.
Inside a workspace, employers record safety information about their people: training, inductions, permits, checks, incidents, tasks and corrective actions, documents they upload to their own company library, photographs taken as evidence that a job was done, hand-arm vibration and noise exposure readings, sign-ons with an approximate location, and health information where the employer chooses to record it after an accident or an exposure. We handle all of that on their behalf.
3. Photographs, exposure readings and other sensitive records
Where a manager requires photo evidence, the photograph and who took it are stored with that record and appear in the record and in evidence packs. People can appear in those photographs. The purpose is to evidence the work, not to watch a person, and the photograph lives and dies with the record it belongs to.
Vibration and noise exposure readings, and health information recorded after an accident, are special-category data. The employer decides the lawful basis, which is normally their duties under health and safety law. A worker sees twelve months of their own exposure record; the employer keeps the full history, because health surveillance duties run for many years after the exposure that caused them. We do not age those records out on a schedule of our own.
4. Location and devices
When someone signs a document or signs on to a site, the device may offer an approximate location, coarse to about a kilometre, which is stored with that signature so the employer can show it was given on site. A person can refuse and the signature still stands. Location is captured at the moment of a sign-on and at no other time: there is no live map, no history between signatures and no tracking of anybody's movements.
Where there is no signal, entries and photographs wait on the device that captured them until it reconnects, then upload and clear from the queue. On a personal phone that means workspace data sits on that phone in the meantime.
5. Visitors and contractors at the gate
Site kiosks collect a name, company, times in and out, briefing acknowledgements and, where entry was allowed by exception, the name of the manager who authorised it. That register belongs to the site occupier, who is the controller for it. We hold it for them and do not use it for anything else.
6. AI features
Where someone uses the drafting features or asks Chief a question, the text of that request is sent to our AI provider so an answer can be produced. Worker records are not sent wholesale, the provider does not use the content to train its general models, and drafts come back into the workspace as the customer's own document. Everything the AI produces is a draft for a person to review.
7. Why we hold it
To provide the service you asked for (contract), to keep it secure and working (legitimate interests), to send service messages you need, and to meet our own legal duties such as tax records. Marketing email is sent only where you asked for it, and every message can unsubscribe.
8. Who we share it with
A small set of processors: our hosting and database platform, our payment processor, our email sender, our AI provider, and our analytics provider where you accepted cookies. Each is bound by contract and the current list is an annex to the data processing agreement. We give customers at least thirty days' notice before adding or replacing one. We do not sell personal data.
9. Where it is held
The service runs on infrastructure in the European Union. Where a processor operates outside the UK or EU, transfers rely on approved safeguards.
10. How long we keep it
Workspace data is kept while the workspace is active. If a trial ends without a plan being chosen, the workspace locks, everything stays exportable for thirty days and is then erased. When a paid subscription ends, the export stays available for thirty days and the data is erased within a further sixty days, with backups ageing out on their normal rolling cycle. Enquiry records are kept for two years. Accounting records are kept for six years because we must.
11. Demonstration workspaces
Our demonstration and presentation environments contain invented records only. Real customer data is never copied into them.
12. Your rights
You can ask for a copy of your data, correction, deletion, restriction or objection, and you can complain to the Information Commissioner's Office. If your details are in an employer's workspace, ask them first, since it is their record. Write to hello@oberoncompliance.com and we will respond within one month.
13. Security
Access is separated by organisation and enforced in the database. Support access to a workspace is logged and visible to the customer. Passwords are never stored in readable form.
Privacy notice, version 2.0, effective 22 September 2026. Questions: hello@oberoncompliance.com