Privacy Policy
Placeholder draft · Last updated 6 July 2026
Placeholder draft — this document has not yet completed legal review and is not legal advice. Final text must be reviewed before client contracting.
1. Who we are
OgmaQ ("OgmaQ", "we", "us") provides operational escalation support software as a service for GMP-adjacent manufacturing teams — one structured workflow to capture, triage, track and close operational escalations. Contact routes are listed in the Contact section below.
2. Role under data protection law
Pending legal review. The customer organisation is expected to act as the controller of its workspace content.
OgmaQ expects to act as a processor for customer workspace content submitted by customer users, and as a controller for its own business, account administration, security, support and contracting data. This allocation is pending legal review and will be reflected in the applicable Data Processing Agreement.
3. What data the app processes
- Account and profile data — name, work email address, and role, site and department assignments set up by your organisation's administrator.
- Workspace content — the escalation records, triage notes, comments, decisions and related content that the customer's users enter into their workspace. The customer controls what is entered.
- Operational logs — sign-in events, audit-support trail entries and technical logs needed to run, secure and support the service.
Customer workspace content is controlled by the customer. Users should avoid entering unnecessary personal data or sensitive data into escalation records, comments, descriptions and attachments. Unless separately agreed in writing, OgmaQ is not intended for patient data, protected health information (PHI) or special-category personal data — see the Acceptable Use Policy. Requests that affect customer workspace records may need to be handled with the customer as controller.
Where the customer enables published data links, a link exposes a read-only operational data feed drawn from the customer's own workspace. Personnel columns (such as owner or reporter names) are included in a feed only when the customer explicitly enables them for that link; otherwise the feed carries no personnel names. Access to a link is logged as metadata only — the outcome, timestamp, feed format and row count — and OgmaQ does not store the raw IP address of link consumers.
4. Purposes
We process this data to provide and operate the service, authenticate users and keep accounts secure, maintain the audit-support trail that the product exists to provide, respond to support requests, and improve the reliability and safety of the service. Where the customer enables published data links, we also process the scoped workspace data to serve the read-only operational data feed to the holders of a link URL at the customer's instruction.
5. Legal bases
The legal bases relied on for each processing activity are pending legal review. The table below sets out the expected allocation.
| Processing activity | Expected legal basis (to be confirmed) |
|---|---|
| Providing and operating the service | Performance of a contract |
| Account administration and support | Performance of a contract / legitimate interests |
| Security, the audit-support trail and abuse prevention | Legitimate interests, and legal obligations where applicable |
| Public website and any marketing communications | Consent where required |
The final allocation will be confirmed during legal review.
6. Where data is stored and international transfers
Customer workspace data is stored in a Supabase-hosted PostgreSQL database, and the application is served through Cloudflare. See the subprocessor list for the vendors involved and their data locations.
The primary Supabase project region is EU (eu-central-1, Frankfurt). Where personal data is transferred internationally — for example to a subprocessor outside the EU — the transfer mechanisms relied on (such as the EU Standard Contractual Clauses) will be assessed and documented during legal review.
7. Retention
Retention is governed by customer-controlled retention settings per workspace. Historical audit-support records may be retained for record integrity, since removing them would undermine the traceability the service provides. See the Data Retention Policy.
8. Your rights and requests
You can raise a privacy request — access, export, correction or deletion — through the in-app privacy request workflow or by contacting the privacy contact below. Requests that affect audit-support records or another organisation's workspace are reviewed with the workspace's controller before action is taken.
For customer workspace content, OgmaQ expects to act as a processor: requests that affect a customer workspace are coordinated with that customer as the controller, and OgmaQ supports the customer in responding rather than deciding unilaterally.
9. Data Processing Agreement
A placeholder Data Processing Agreement scaffold is published at ogmaq.com/dpa. It is not legally final and is intended for later use as part of customer contracting, once reviewed and finalised by qualified legal counsel.
10. Subprocessors
The third-party vendors that process data on our behalf are listed at ogmaq.com/subprocessors.
11. Language and localisation
English is the primary operating language of OgmaQ. Interface localisation may be available for supported languages, and any translation applies to the application's own interface text only.
Customer-entered records remain exactly as entered — OgmaQ does not automatically translate customer-entered information. No third-party translation service currently processes customer-entered content, and no customer data is transmitted to external translation providers. Any future automatic-translation capability will be introduced as an optional feature and accompanied by updated legal documentation and privacy disclosures before release.
12. Contact
Use the route that matches your request:
- General — [email protected]
- Privacy & data subject requests — [email protected]
- Security & vulnerability reports — [email protected]
- Legal, contracts & subprocessors — [email protected]
These role-based aliases route to the OgmaQ team. [email protected] is the general contact if you are unsure which to use.