Office Management Operating System by The Office Management Group

PRIVACY POLICY

Version 1.0  ·  12 August 2026

1. Who We Are

The Office Management Group Limited ("we", "us", "our") are committed to protecting and respecting your privacy.

This Privacy Policy explains how we collect, use, store and protect your personal data when you use OMOS — the Office Management Operating System — available at useomos.com and app.useomos.com (together "the Platform").

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is:

 

The Office Management Group Limited

Company number: 10284254

Victoria House, 50 Alexandra Street, Southend-on-Sea, Essex, SS1 1BN

Email: [email protected]

Website: useomos.com

 

2. What Data We Collect

We collect and process the following categories of personal data:

 

2.1 Account and registration data

When you create an OMOS account or are added as a user by your organisation, we collect:

    Full name

    Work email address

    Job title and department

    Organisation name

    Password (stored in encrypted form — we cannot read it)

    Account access level and permissions

    Date of account creation

 

2.2 Data you enter into the platform

OMOS is an operational platform. The data you enter into the system is your organisation's operational data. This may include:

    Staff records — names, job titles, departments, start dates, employment type

    Visitor records — names, companies, visit times, host details

    Health and safety records — compliance items, training records, walkround logs

    Asset records — asset details, locations, valuations, depreciation data

    Supplier and contractor records — company details, contract terms, compliance documents

    Facilities management records — PPM schedules, FM tickets, EET records

    Lease and premises data — lease terms, costs, notice periods

    Budget and financial data — budget categories, actual spend, variance

    Time tracking records — activities, categories, hours logged

    Document uploads — PDFs, certificates, RAMS documents, images

 

This operational data is owned by you (the customer organisation). We process it on your behalf as a data processor, in accordance with our Data Processing Agreement.

 

2.3 Technical and usage data

When you use the platform, we automatically collect:

    IP address and browser type

    Pages visited and features used

    Login timestamps and session data

    Device type and operating system

    Error logs and performance data

 

2.4 Communications data

If you contact us by email or through the platform, we collect:

    Your name and email address

    The content of your message

    Any attachments you send

 

2.5 Payment data

Payment transactions are processed by Stripe. We do not store your full card details. We retain:

    Your billing name and email

    Subscription tier and payment status

    Invoice history

For full details of how Stripe handles your payment data, please see stripe.com/privacy.

 

3. How We Use Your Data

We use your personal data only for the purposes described below. We will never sell your data to third parties.

4. Data Controller and Data Processor

OMOS operates a two-layer data relationship:

A Data Processing Agreement (DPA) is available at useomos.com/dpa and governs how we handle your operational data as processor. Enterprise customers will receive a signed DPA as part of their contract.

5. Data Storage and Security

5.1 Where your data is stored

All OMOS data is stored on servers located in the European Union (EU West region). We use Supabase as our database infrastructure provider. Data does not leave the EU/EEA without appropriate safeguards in place.

 

5.2 Data isolation

Each OMOS customer organisation's data is completely isolated from all other organisations using Row Level Security (RLS) at the database level. It is technically impossible for one customer to access another customer's data through the platform.

 

5.3 Access controls

Access to your data within OMOS is controlled by the permissions you set. Only users you have granted access to can view your organisation's data. The Office Management Group staff do not have routine access to your operational data. In the event that support access is required, it will only be granted with your explicit consent, will be logged, and will be time-limited.

 

5.4 Encryption

All data transmitted to and from OMOS is encrypted in transit using TLS (HTTPS). Data is encrypted at rest within our database infrastructure.

 

5.5 Passwords

Passwords are hashed and salted using industry-standard encryption. We cannot read your password. If you forget your password, you must reset it — we cannot retrieve it for you.

 

5.6 Security incidents

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, and will notify affected customers without undue delay.

 

 

6. Data Retention

We retain your data only for as long as necessary for the purposes for which it was collected.

When your subscription ends, you have 30 days to export your data before it is permanently deleted from our systems. We will send you a reminder before deletion occurs.

7. Sharing Your Data

We do not sell your data. We share your data only in the following circumstances:

 

7.1 Sub-processors

We use the following trusted third-party services to operate OMOS. Each is bound by data processing agreements and GDPR-compliant terms:

 7.2 Legal requirements

We may disclose your data where required to do so by law, regulation or court order, or where necessary to protect the rights, property or safety of The Office Management Group, our customers or others.

 

7.3 Business transfer

In the event that The Office Management Group Limited or the OMOS platform is acquired by or merged with another organisation, your data may be transferred to the new owner. We will notify you before this occurs and you will have the right to delete your account.

 

7.4 Change of purpose

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

 

8. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, contact us at [email protected]. We will respond within one month.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

 

No fee usually required

You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

 

What we may need from you

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request to speed up our response.

 

Time limit to respond

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

 

9. Cookies

OMOS uses cookies to operate the platform, maintain your session, and improve performance. We do not use cookies for advertising or tracking across third-party websites. us understand how the platfo

For full details see our Cookie Policy at useomos.com/cookies.

 

10. International Data Transfers

We store all primary data within the EU. Some of our sub-processors (Stripe, Anthropic) are based in the United States. Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

If you require data to be stored in a specific jurisdiction (for example, Saudi Arabia for ZATCA compliance), please contact us to discuss your requirements before signing up.

 

11. Children's Data

OMOS is a professional business platform intended for use by adults in a workplace setting. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child's data has been entered into the platform, please contact us immediately at [email protected].

 

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, technology or legal requirements. When we make material changes, we will notify you by email and update the version number and date at the top of this document. The current version is always available at useomos.com/privacy.

  

13. Contact Us

For any questions, requests or concerns about this Privacy Policy or how we handle your data, please contact us: