Data Processing Terms
How we handle the personal information your company puts into Orientra Compliance.
Effective 9 October 2026.
These terms form part of the Terms of Service between your company (the “customer”) and James Worthing, a sole proprietor carrying on business as James Worthing Safety Consulting Services (“JWSCS”), in Manitoba, Canada (“we”). They apply to the personal information the customer and its users put into the service (“customer data”). If these terms and the Terms of Service disagree about customer data, these terms apply.
1. Who is responsible for what
- The customer is the organization responsible for customer data. It decides what is collected, about whom, and why, and it is responsible for having the right to collect it and for telling its workers what the law requires.
- We are the customer's service provider. We handle customer data on the customer's behalf, to provide the service.
2. What we do with customer data
- We use customer data only to provide, secure and support the service, as the Terms of Service and the customer's own use of the product instruct, and to meet a legal obligation.
- We do not sell customer data, use it for advertising, or use it to train artificial intelligence models.
- If the law requires us to disclose customer data, we will tell the customer first unless the law forbids it.
3. Who can reach it
Access is limited to the operator, when needed to run and support the service, under a duty of confidentiality. Every read and every change the operator makes in a customer's workspace is recorded in that customer's own activity log.
4. Security
We maintain the safeguards described in section 12 of the Privacy Policy, including encryption in transit, salted password hashing, separation of each customer's records, rate-limited sign-in, and logging of access. We may change these measures as long as the overall protection does not get weaker.
5. Providers we use
The customer agrees to our use of these providers to deliver the service. Each is bound by its own contract with us to protect what it handles.
| Provider | What it does | What it can reach | Where |
|---|---|---|---|
| Railway | Hosts the application and its database | Everything stored in the product | United States |
| Cloudflare | Stores evidence files; hosts this website and our uptime monitor | Photographs, signature images, uploaded documents; requests to this website | United States and other countries where Cloudflare operates |
| Resend | Sends email | Recipient addresses and message contents | United States |
| Stripe | Takes card payments | Your card details, which you give to Stripe directly; we receive only a confirmation and a reference | United States and other countries where Stripe operates |
| Analytics | The limited usage information described under Analytics | United States and other countries where Google operates | |
| Twilio | Sends text messages, only where a company has text messaging switched on | Recipient telephone numbers and message contents | United States |
Changes. We will email the customer's administrators at least 30 days before adding or replacing a provider that handles customer data. A customer that objects may cancel before the change takes effect. We remain responsible to the customer for what our providers do with customer data.
6. Where it is stored
Customer data is stored and processed in the United States, as described in section 9 of the Privacy Policy, and may be viewed by the operator from Canada. For a customer in Canada, that means its data is held outside Canada. The customer agrees to this, and is responsible for telling its own workers where the law requires it.
7. Requests from individuals
The product lets the customer find, export and correct what is held about a person, and remove what can be removed when a worker leaves. If a person writes to us about customer data, we will pass the request to the customer and will not answer it ourselves unless the customer asks us to or the law requires it. We will give the customer reasonable help in responding.
8. United States privacy laws
Where a United States state privacy law, such as the California Consumer Privacy Act, applies to customer data, we act as the customer's service provider (or “processor”) and agree that we will:
- not sell customer data, and not share it for cross-context behavioural advertising;
- not keep, use or disclose customer data for any purpose other than providing the service to the customer, or outside our direct business relationship with the customer;
- not combine customer data with personal information we receive from anywhere else, except as that law allows a service provider to do;
- require each provider in section 5 to protect customer data to at least this standard;
- tell the customer if we decide we can no longer meet these obligations, and let the customer take reasonable steps to stop and put right any unauthorised use.
The service is not a HIPAA system. We are not a business associate, and the customer agrees not to put medical records or other information regulated by HIPAA into the service.
9. If there is a breach
If we confirm a breach of security safeguards involving customer data, we will tell the customer as soon as feasible, and will share what we know: what happened, what information was involved, and what we are doing about it. The customer is responsible for any notice it owes to its workers or to a regulator, and we will give reasonable help with it.
10. When the agreement ends
- Customer data is not deleted because a trial or subscription ended. The workspace becomes read-only and stays exportable.
- On the customer's written request we will take a final export for the customer, then delete the customer data from our live systems, aiming to finish within 30 days, and confirm when it is done. Copies in backups are overwritten as those backups expire.
- We may keep what the law requires us to keep, and nothing is deleted while a legal hold applies to it.
11. Showing that we keep to these terms
On reasonable written request, and no more than once a year, we will give the customer the information reasonably needed to confirm that we are keeping to these terms. We do not offer on-site audits.
12. Liability
The limits and exclusions in the Terms of Service apply to these terms.
Questions about these terms: info@orientracompliance.ca.