Privacy Policy
OvateAccess is a private identity and secure-messaging platform used by organizations. Accounts are created by invitation for members and stakeholders of a participating organization (the tenant). This notice explains what personal data is processed and your rights under the applicable data protection law.
Who controls your data
The organization (tenant) that invited you is the data controller for your account and the records you create within it. The platform operator processes personal data on the organization's behalf and as the operator of the shared infrastructure.
What we collect
We process only what is needed to run the service:
- Account identity: username, email address, and a securely hashed password.
- Profile details you provide: name, contact numbers, address, avatar, and preferences.
- Device and session data used for trust and security: device names, IP addresses, and browser/agent information.
- Security and audit events: sign-ins, approvals, and device changes.
- Secure messaging: message content and attachments are end-to-end encrypted and are not readable by the platform; only routing metadata (participants, timing, size) is visible to the server.
Why we process it, and our legal basis
We process your data to provide and secure the service and to support your relationship with the organization that invited you. The legal bases are the performance of that membership/employment relationship, the organization's legitimate interests in operating and securing the platform, compliance with legal obligations, and — where indicated — your consent (which you may withdraw).
Who we share it with
We do not sell personal data. Limited data is shared with service providers strictly to operate the platform — for example, delivery of push notifications and email, and abuse prevention. Each provider processes data only as needed for that function.
Where your data is stored
Primary personal data is held on the operator's own servers. Where a supporting service processes data outside the country in which the organization operates, such transfers are made only under a lawful transfer mechanism as required by the applicable data protection law. (Hosting region is being finalized — see the draft notice above.)
How long we keep it
We keep personal data for as long as your account is active with the organization, and afterwards only as needed to meet legal obligations, resolve disputes, and preserve the integrity of business records you created or managed. Where continued identification is no longer necessary but records must be retained, we pseudonymize your data rather than keep it identifiable.
Your rights
Subject to the PDPL, you may request access to your data, correction of inaccurate data, and — where no overriding legal or business-record obligation applies — deletion or pseudonymization. Ending your relationship with the organization does not by itself erase records that must be retained; those are minimized and pseudonymized instead. To exercise a right, contact your organization's administrator or the operator (below).
How we protect it
Passwords are stored only as one-way hashes; secure-messaging content is end-to-end encrypted so the server cannot read it; trusted-device approval and (where enabled) passkeys protect sign-in. Security events are logged for accountability.
Contact
For privacy questions or to exercise a right, contact your organization's administrator, or the platform operator's data-protection contact. (Contact details to be completed before launch.)