Legal

Privacy Notice

This Notice sets out the basis on which Oromis collects, uses, stores and processes personal information about you. It applies to our website and to our workforce compliance and training platform.

Last updated:

Not ready to publish. The Information Officer name and registered address are still blank in src/lib/privacy-notice.ts. Fill both, then delete nothing else — this banner disappears on its own.

1.Introduction

This Privacy Notice (“Notice”) sets out the basis on which Oromis collects, uses, stores and processes personal information about you. It applies to our website at www.oromis.io (the “Website”) and to our workforce compliance and training platform (the “Platform”).

Please read this Notice carefully to understand how we collect, use, protect, and otherwise handle your personal information.

Any references to “we”, “us” or “our” in this Notice refer to Oromis and, where applicable, our affiliates and subsidiaries. References to “you” or “your” refer to any individual whose personal information we process.

We are subject to and committed to compliance with the Protection of Personal Information Act 4 of 2013 (“POPIA”) in South Africa, the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) where applicable, and applicable US state data privacy laws where relevant to our operations.

Depending on the context in which we process your personal information, we may act as a Responsible Party (under POPIA) or a Controller (under applicable US law) — meaning we determine the purpose and means of processing — or we may act as an Operator or Processor — meaning we process personal information solely on the instructions of a client. This distinction is explained further in section 8 below.

2.About Oromis and our platform

Oromis is a workforce compliance and training platform. Our core functions are to —

  • generate role-specific compliance training programmes from a our client’s own policies;
  • track whether staff members have completed training modules and assessments; and
  • ingest de-identified, staff-behaviour data to surface compliance gaps and aggregate quality metrics for the facility.

Oromis is not a clinical records system. We do not store patient charts, electronic medical records, diagnoses, lab results, vital signs, or any individual patient journey data. Our Platform tracks staff behaviour against policy — not patient outcomes.

3.Who this notice applies to

This Notice applies to the following categories of individuals —

  • Website visitors: any person who visits our Website at www.oromis.io;
  • Customer contacts and administrators: client representatives and administrators at who manage accounts on the Platform;
  • Learner users: employees and staff who use the Platform to complete training and compliance programmes; and
  • Prospective clients and contacts: individuals who correspond with us, request information, or enquire about the Platform.

Our employees and contractors are covered by a separate internal privacy notice.

4.Personal information we collect

Depending on how you interact with us, we may collect and process the following categories of personal information —

  • Website visitor data: IP address, browser type, device type, pages visited, session duration, and referring URL. This technical data does not, on its own, identify you personally;
  • Customer and administrator data: name, job title, work email address, telephone number, facility name, login credentials, and Platform usage activity;
  • Learner and employee data: employee name, work email address, job role or department, facility name, training module completion status, assessment scores, and compliance event outcomes (records of whether a staff member followed a specific protocol on a given date);
  • De-identified facility operational data: aggregate, monthly statistics about facility-wide performance (for example, falls per month, hospital-acquired infection rates, medication administration error rates) and de-identified staff behavioural compliance records. This data contains no patient identifiers and is de-identified by you before it is sent to us and it is passed through our de-identification gateway on upload to the Platform (see section 9 below); and
  • Correspondence data: any personal information you provide to us in emails, support requests, or other communications.

We do not collect or store patient names, patient identifiers (including Medical Record Numbers, dates of birth, Social Security Numbers, or National Identity Numbers), clinical diagnoses, laboratory results, vital signs, or any individual patient journey data.

5.How we collect personal information

We collect personal information in the following ways —

  • Directly from you, when you visit the Website, register for an account, complete training modules or assessments, upload data files to the Platform, contact us, or submit enquiries;
  • Automatically, when you interact with our Website or Platform, through cookies, server logs, and analytics tools (see section 15 below); and
  • From your employer/client, when they provides us with your employee details (such as name, email address, and role) for the purpose of setting up your learner account on the Platform.

The supply of certain personal information is necessary to access and use the Platform. If you do not provide required information, we may not be able to create your account or deliver the applicable services to you.

6.Purpose of processing and lawful basis

We process personal information for the following purposes and on the following lawful bases —

  • Website visitors: to operate and improve the Website, monitor security, and respond to enquiries. Lawful basis: our legitimate interests in operating a secure and functional website (section 11(1)(f) of POPIA; legitimate business interests under applicable US law);
  • Customer contacts and administrators: to manage your account, deliver the Platform, provide support, process payments, and fulfil our contractual obligations. Lawful basis: necessary for the performance of a contract (section 11(1)(b) of POPIA) and our legitimate business interests;
  • Learner users (processed on behalf of the client): to deliver training modules, track completion, record compliance outcomes, and generate compliance reports for the facility. We process this data as Operator or Processor acting solely on the facility’s instructions. The client (as Responsible Party or Controller) determines the lawful basis for this processing;
  • De-identified facility operational data: to generate compliance gap analysis, quality metrics reporting, and AI-assisted training recommendations for the facility. This data is de-identified by your employer/facility prior to ingestion and is processed to support the facility’s own regulatory and operational compliance obligations. However, it does also pass through our de-identification gateway for additional control; and
  • Legal and compliance obligations: where processing is required by applicable law, regulation, or court order. Lawful basis: compliance with a legal obligation (section 11(1)(c) of POPIA).

We will only use your personal information for the purposes set out above, or for a compatible purpose of which we will notify you.

7.Special personal information

We do not intentionally collect Special Personal Information as defined under POPIA (being information about race, ethnic origin, political opinion, religion, trade union membership, biometric information, criminal record, health, or sex life), or Sensitive Personal Information as defined under applicable US state privacy laws.

To the limited extent that compliance event records relating to healthcare staff (for example, a record that a staff member reported a bloodborne exposure incident) could be characterised as health-related information, we process such records solely in our capacity as Operator acting on the instructions of the healthcare facility, which processes such records pursuant to its own statutory obligations under applicable healthcare legislation.

We do not process patient health information. Our Platform does not store, receive, or analyse any Protected Health Information (“PHI”) as defined under HIPAA.

8.Our role as Operator or Processor for clients

Where we process personal information on behalf of a client, we act as an Operator under POPIA or a Service Provider or Processor under applicable US data privacy law. In these circumstances, the client is the Responsible Party or Controller of the personal information of its employees and learners.

We process learner personal information only —

  • on the documented written instructions of the client, as set out in the Data Processing Agreement (“DPA”) between us and the facility;
  • for the purpose of delivering the contracted training and compliance Platform services; and
  • subject to equivalent data protection obligations imposed on all sub-processors we engage.

We do not use learner personal information for our own commercial purposes, for marketing, or for training third-party AI models. Where such third-party AI models have the capacity to do so we enable settings to prohibit same. In any event, we only submit data which has been de-identified to these models.

If you are an employee whose personal information has been provided to the Platform by your employer, your employer (as Responsible Party or Controller) is primarily responsible for ensuring you are informed of your rights. You should contact your employer’s privacy or HR officer in the first instance with any data subject rights requests. We will promptly assist your employer in responding to any such requests directed to us.

9.Patient data and HIPAA compliance (United States)

Our Platform is architecturally designed not to receive Protected Health Information (PHI) as defined under HIPAA (45 CFR Part 160 and Subparts A and E of Part 164).

We apply technical and procedural controls to ensure that any data derived from health facility operations is de-identified before it is transmitted to or stored on Oromis infrastructure. Our de-identification approach is designed to align with the HIPAA Safe Harbor standard under 45 CFR §164.514(b)(2).

We maintain an audit record of every data import to the Platform. Actual PHI values are not recorded in those logs.

Your healthcare facility, as the HIPAA Covered Entity, remains responsible for ensuring that all data submitted to the Platform has been appropriately de-identified prior to transmission. Oromis operates as a further safeguard, not as a substitute for the facility's own obligations.

10.AI features and AI sub-processors

Our Platform uses artificial intelligence tools to generate training content tailored to each client’s own compliance policies. These AI capabilities are provided by third-party technology providers.

We access these AI services on their commercial / API tiers. We do not permit these providers to use the content we submit to train their own models. Where a provider's commercial terms prohibit such training by default, we rely on those terms; where a provider instead offers a setting or election to prevent it, we enable that setting on every request. In all cases, the content we submit consists only of de-identified, facility-level policy and training material and aggregate compliance data — we take the reasonable steps in clause 6.1.4 above to submit no patient data and no learner personal information.

11.Sharing of personal information

We will not share your personal information with third parties except as set out in this Notice or as required by applicable law.

We share personal information with the following categories of sub-processors and service providers, each of whom is bound by appropriate data protection obligations —

  • Database and infrastructure (European Union);
  • AI content generation (United States);
  • Email delivery (United States);
  • Web hosting and content delivery (United States).

We may also disclose personal information where required to comply with applicable law, a court order, subpoena, or lawful government or regulatory demand; to protect and defend our rights or property; or to protect the safety of our staff, clients, or the public.

We do not sell your personal information to third parties.

12.International transfers of personal information

Several of our sub-processors are located in the United States. Where personal information is transferred to a country that does not have an adequacy finding or equivalent data protection legislation, we ensure that appropriate safeguards are in place to protect your personal information.

South African data subjects: Transfers of personal information about South African data subjects to recipients outside South Africa (including to US-based sub-processors) are subject to the requirements of section 72 of POPIA. We ensure that all such recipients are either located in a country that provides an adequate level of protection to POPIA or they are contractually bound, by way of binding data transfer agreements, to provide at least the same level of protection as required under POPIA.

US data subjects: Where personal information of US residents is transferred to sub-processors in other countries, we ensure that appropriate contractual and technical safeguards are in place.

You may contact us using the details in section 22 below to request further information about the specific safeguards applicable to the transfer of your personal information.

13.Data retention

We retain personal information only for as long as is necessary for the purposes described in this Notice and to comply with our legal and regulatory obligations. Our standard retention periods are —

  • Customer account and administrator data: for the duration of the contract, plus three (3) years after termination, to comply with applicable statutory limitation periods;
  • Learner training and compliance records: as instructed by the client, and typically for a period of six (6) years from the date of training completion, to support the client’s own regulatory compliance obligations subject to individual client instructions;
  • Audit logs and import records: Audit logs are retained for two (2) years from creation whereas import logs are retained for twelve (12) months from creation;
  • Website analytics data: Twelve (12) months from collection; and
  • Email and correspondence records: three (3) years from the date of last contact.

When personal information is no longer required, it is securely deleted or irreversibly anonymised. If you have questions about the retention of your records, please contact us using the details in section 22 below.

14.Protection of your personal information

We are committed to protecting your personal information. We have implemented appropriate technical and organisational security measures, including —

  • data partitioned at database level by customer organisation so that no customer can access another customer’s data;
  • role-based access controls;
  • audit trails recording all data access and modifications;
  • de-identification architecture applied before operational data reaches our servers; and
  • encryption of personal information in transit and at rest.

We have procedures to detect, investigate, and respond to suspected personal information security breaches. In the event of a breach that triggers notification obligations under applicable law (including the 72-hour notification requirement to the South African Information Regulator under POPIA, and applicable HIPAA breach notification requirements). Where we act as the Responsible Party we will notify the relevant regulator and, where required, affected individuals without undue delay. Where we act as the Operator we will inform the Responsible Party and act in terms of the DPA between us.

While we use best-practice security measures, the transmission of information via the internet is not completely secure, and any transmission of personal information to our Website or Platform is at your own risk.

15.Cookies and tracking technologies

We use cookies and similar tracking technologies on our Website to operate the Website correctly, improve your experience, store session authentication, and understand how users engage with our content. “Cookies” are small text files transferred by a web server to your device and thereafter stored on your device.

We use cookies to —

  • ensure the Website and Platform function correctly and securely;
  • store your session authentication and preferences; and
  • collect anonymised, aggregate analytics data to understand Website usage and improve our services.

You may configure your browser to decline cookies or to alert you when cookies are being set. Declining certain cookies may limit your access to, or the functionality of, our Website and Platform. Where required by applicable law, we will seek your consent before placing non-essential cookies on your device.

16.Direct marketing

We may use your personal information to contact you about Oromis products and services where you are an existing client of ours, or where you have given us consent to do so.

Where you are an existing client, we will only use personal information obtained through the provision of our services to you, and only to market similar products and services.

You may opt out of direct marketing communications at any time by clicking the unsubscribe link in any marketing email, or by contacting us at the address in section 22. We will not send you marketing communications if you have objected to receiving them.

17.Your rights in relation to your personal information

Subject to applicable law and certain exceptions, you have the following rights in relation to your personal information —

  • Right of access: to request a copy of the personal information we hold about you;
  • Right to rectification: to request that we correct inaccurate or incomplete personal information;
  • Right to erasure or destruction: to request that we delete your personal information in certain circumstances and subject to applicable legal retention obligations;
  • Right to object or restrict processing: to object to, or request restriction of, certain processing of your personal information;
  • Right to withdraw consent: where processing is based on your consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal;
  • Right to data portability: to request that we transmit your personal information to another party in a structured, machine-readable format, where technically feasible;
  • Right not to be subject to automated decision-making: to object to decisions based solely on automated processing that produce legal or similarly significant effects; and
  • Right to lodge a complaint: to lodge a complaint with the applicable data protection regulator (see section 21 below).

South African data subjects enjoy the rights conferred by sections 23 to 25 of POPIA, including the right to request access to records held by us as contemplated in section 23. To exercise any right under POPIA, please contact our Information Officer using the details in section 22 below.

California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information is collected about them, the right to opt out of the sale or sharing of personal information (we do not sell personal information), and the right not to be discriminated against for exercising their privacy rights.

To exercise any of the above rights, please contact us using the details in section 22. We may request reasonable proof of identity before processing your request. We will respond within the timeframes required by applicable law.

18.Automated decision-making

We use AI-assisted tools to generate training content recommendations and to identify compliance gaps from aggregated facility data. These tools do not make automated decisions about individual employees that would produce legal or similarly significant effects without human review by the client.

Individual training completion records and compliance outcomes are presented to the client’s own management for review and action. Oromis does not make, and has no role in, employment decisions, disciplinary proceedings, or any other decision with legal effect in respect of individual employees.

19.Children

Our Platform and Website are not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children under 16. If you become aware that a child has provided us with personal information without appropriate parental or guardian consent, please contact us immediately using the details in section 22 and we will take steps to delete that information.

20.Third-party links

Our Website may contain links to third-party websites. If you click on such links, you will leave our Website. We are not responsible for the content of those third-party websites or for the security of your personal information when you use them. We recommend that you review the privacy policy of any third-party website you visit.

21.Complaints

You have the right to lodge a complaint with the applicable data protection regulator if you believe we have not complied with applicable data protection law. We encourage you to contact us first so that we have the opportunity to address your concern directly.

In the Republic of South Africa:

In the United States:

  • Depending on your state of residence, you may contact your state’s Attorney General’s office or the applicable state data protection authority. For example, California residents may contact the California Privacy Protection Agency (CPPA) at: cppa.ca.gov/.

22.How to contact us

If you have any questions, comments, or requests about this Privacy Notice, or wish to exercise any of your data subject rights, please contact us at privacy@oromis.io with “Privacy Notice” in the subject line.

In South Africa, our appointed Information Officer responsible for compliance with POPIA is Rudolf Gremels, who is contactable by email at privacy@oromis.io.

Our registered address is: [Oromis registered address].

23.General

You warrant that all personal information you provide to us is accurate, truthful, and current, and that you will not impersonate or misrepresent any person or entity.

It is not intended that any provision of this Privacy Notice contravenes any provision of data protection legislation applicable in your jurisdiction. All provisions of this Privacy Notice must be treated as qualified, to the extent necessary, to ensure compliance with applicable data protection legislation.

24.Changes to this privacy notice

We reserve the right to update this Privacy Notice from time to time to reflect changes in our data practices, applicable law, or our services. We will publish the updated Notice on our Website with a revised effective date. Where changes are material, we will notify affected clients and users by email. Your continued use of the Platform after the effective date of any updated Notice constitutes your acceptance of the updated terms.