
Office Management Operating System by The Office Management Group
PRIVACY POLICY
Version 1.0 · 12 August 2026
1. Who We Are
The Office Management Group Limited ("we", "us", "our") are committed to protecting and respecting your privacy.
This Privacy Policy explains how we collect, use, store and protect your personal data when you use OMOS — the Office Management Operating System — available at useomos.com and app.useomos.com (together "the Platform").
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is:
The Office Management Group Limited
Company number: 10284254
Victoria House, 50 Alexandra Street, Southend-on-Sea, Essex, SS1 1BN
Email: [email protected]
Website: useomos.com
2. What Data We Collect
We collect and process the following categories of personal data:
2.1 Account and registration data
When you create an OMOS account or are added as a user by your organisation, we collect:
• Full name
• Work email address
• Job title and department
• Organisation name
• Password (stored in encrypted form — we cannot read it)
• Account access level and permissions
• Date of account creation
2.2 Data you enter into the platform
OMOS is an operational platform. The data you enter into the system is your organisation's operational data. This may include:
• Staff records — names, job titles, departments, start dates, employment type
• Visitor records — names, companies, visit times, host details
• Health and safety records — compliance items, training records, walkround logs
• Asset records — asset details, locations, valuations, depreciation data
• Supplier and contractor records — company details, contract terms, compliance documents
• Facilities management records — PPM schedules, FM tickets, EET records
• Lease and premises data — lease terms, costs, notice periods
• Budget and financial data — budget categories, actual spend, variance
• Time tracking records — activities, categories, hours logged
• Document uploads — PDFs, certificates, RAMS documents, images
This operational data is owned by you (the customer organisation). We process it on your behalf as a data processor, in accordance with our Data Processing Agreement.
2.3 Technical and usage data
When you use the platform, we automatically collect:
• IP address and browser type
• Pages visited and features used
• Login timestamps and session data
• Device type and operating system
• Error logs and performance data
2.4 Communications data
If you contact us by email or through the platform, we collect:
• Your name and email address
• The content of your message
• Any attachments you send
2.5 Payment data
Payment transactions are processed by Stripe. We do not store your full card details. We retain:
• Your billing name and email
• Subscription tier and payment status
• Invoice history
For full details of how Stripe handles your payment data, please see stripe.com/privacy.
3. How We Use Your Data
We use your personal data only for the purposes described below. We will never sell your data to third parties.

4. Data Controller and Data Processor
OMOS operates a two-layer data relationship:

A Data Processing Agreement (DPA) is available at useomos.com/dpa and governs how we handle your operational data as processor. Enterprise customers will receive a signed DPA as part of their contract.
5. Data Storage and Security
5.1 Where your data is stored
All OMOS data is stored on servers located in the European Union (EU West region). We use Supabase as our database infrastructure provider. Data does not leave the EU/EEA without appropriate safeguards in place.
5.2 Data isolation
Each OMOS customer organisation's data is completely isolated from all other organisations using Row Level Security (RLS) at the database level. It is technically impossible for one customer to access another customer's data through the platform.
5.3 Access controls
Access to your data within OMOS is controlled by the permissions you set. Only users you have granted access to can view your organisation's data. The Office Management Group staff do not have routine access to your operational data. In the event that support access is required, it will only be granted with your explicit consent, will be logged, and will be time-limited.
5.4 Encryption
All data transmitted to and from OMOS is encrypted in transit using TLS (HTTPS). Data is encrypted at rest within our database infrastructure.
5.5 Passwords
Passwords are hashed and salted using industry-standard encryption. We cannot read your password. If you forget your password, you must reset it — we cannot retrieve it for you.
5.6 Security incidents
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware, and will notify affected customers without undue delay.
6. Data Retention
We retain your data only for as long as necessary for the purposes for which it was collected.

When your subscription ends, you have 30 days to export your data before it is permanently deleted from our systems. We will send you a reminder before deletion occurs.
7. Sharing Your Data
We do not sell your data. We share your data only in the following circumstances:
7.1 Sub-processors
We use the following trusted third-party services to operate OMOS. Each is bound by data processing agreements and GDPR-compliant terms:

7.2 Legal requirements
We may disclose your data where required to do so by law, regulation or court order, or where necessary to protect the rights, property or safety of The Office Management Group, our customers or others.
7.3 Business transfer
In the event that The Office Management Group Limited or the OMOS platform is acquired by or merged with another organisation, your data may be transferred to the new owner. We will notify you before this occurs and you will have the right to delete your account.
7.4 Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.
If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
8. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data. To exercise any of these rights, contact us at [email protected]. We will respond within one month.

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
No fee usually required
You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data. This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
9. Cookies
OMOS uses cookies to operate the platform, maintain your session, and improve performance. We do not use cookies for advertising or tracking across third-party websites. us understand how the platfo

For full details see our Cookie Policy at useomos.com/cookies.
10. International Data Transfers
We store all primary data within the EU. Some of our sub-processors (Stripe, Anthropic) are based in the United States. Where data is transferred outside the UK/EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
If you require data to be stored in a specific jurisdiction (for example, Saudi Arabia for ZATCA compliance), please contact us to discuss your requirements before signing up.
11. Children's Data
OMOS is a professional business platform intended for use by adults in a workplace setting. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child's data has been entered into the platform, please contact us immediately at [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology or legal requirements. When we make material changes, we will notify you by email and update the version number and date at the top of this document. The current version is always available at useomos.com/privacy.
13. Contact Us
For any questions, requests or concerns about this Privacy Policy or how we handle your data, please contact us:
