Legal

Privacy Policy

This Privacy Policy explains how Obtempera collects, uses, shares and protects personal data when you visit our website, contact us, request a demonstration or otherwise interact with us.

Effective: 29 August 2026

1. Who we are

Obtempera is a workforce and contractor compliance technology business based in Ireland. In this policy, “Obtempera”, “we”, “us” and “our” refer to Obtempera.

Where Obtempera determines why and how personal data collected through this website is processed, Obtempera acts as the data controller.

2. Scope of this policy

This policy applies to personal data collected through:

  • www.obtempera.com and related Obtempera marketing pages;
  • contact, enquiry and Book a Demo forms;
  • business communications with prospective customers, partners and suppliers;
  • events, demonstrations and product discussions; and
  • other interactions where this policy is provided or referenced.

Customer use of the Obtempera compliance platform may involve additional processing terms, including a Data Processing Agreement and customer-specific privacy information.

3. Personal data we may collect

Depending on how you interact with us, we may collect:

  • Identity and contact information: name, work email address, telephone number and job title.
  • Organisation information: employer or organisation, country, workforce size, project information and role.
  • Enquiry information: information you provide about your projects, contractor population, compliance challenges or product requirements.
  • Communications: correspondence, meeting notes and records of our communications with you.
  • Technical information: IP address, browser/device information, server logs and security information generated when you access the website.
  • Business relationship information: records relating to proposals, demonstrations, contracts, billing and customer support where applicable.

Please do not submit unnecessary sensitive or special-category personal data through our public website forms.

4. How we obtain personal data

We may obtain personal data:

  • directly from you when you submit a form or communicate with us;
  • from your employer or organisation in connection with a business enquiry;
  • from publicly available professional or business sources where appropriate; and
  • automatically through normal web-server and security logging.

5. Why we use personal data and our legal bases

PurposeTypical legal basis
Responding to enquiries and arranging demonstrationsSteps requested before entering a contract and/or legitimate interests
Managing prospective and existing customer relationshipsLegitimate interests and/or performance of a contract
Operating, securing and improving the website and servicesLegitimate interests
Providing requested marketing communicationsConsent where required, or legitimate interests where permitted by law
Meeting legal, tax, accounting, regulatory or dispute requirementsLegal obligation and/or legitimate interests

Where we rely on legitimate interests, we consider whether our interests are proportionate and whether your rights and interests require additional protection.

6. Marketing

We may contact business contacts about Obtempera where permitted by applicable law. Where consent is required, we will obtain it before sending the relevant communication. You can opt out of marketing communications at any time using the unsubscribe method provided or by contacting us.

7. Sharing personal data

We may share personal data with service providers that support our website, hosting, communications, customer relationship management, security, professional advice and business operations. Such providers should only receive the information reasonably necessary for their role and must be subject to appropriate contractual safeguards.

We may also disclose information where required by law, to protect legal rights, in connection with a corporate transaction, or with your consent.

We do not sell personal data to advertisers.

8. International transfers

Some service providers may process data outside Ireland or the European Economic Area. Where personal data is transferred to a country that does not benefit from an applicable adequacy decision, we will use an appropriate transfer mechanism where required, such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate.

9. Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including business relationship, security, legal, accounting and dispute-resolution requirements.

As an initial operational rule, routine sales enquiries that do not result in an ongoing relationship should normally be reviewed for deletion within 24 months, unless there is a legitimate reason to retain them for longer. Contract, finance and legal records may need to be retained for longer periods.

10. Security

We use organisational and technical measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. No internet-based service can guarantee absolute security.

11. Your data-protection rights

Subject to applicable law and the circumstances of the processing, you may have rights to:

  • receive information about how your personal data is processed;
  • access personal data held about you;
  • correct inaccurate or incomplete information;
  • request erasure of personal data in appropriate circumstances;
  • restrict processing in appropriate circumstances;
  • object to certain processing, including direct marketing;
  • receive certain data in a portable format; and
  • withdraw consent where processing is based on consent.

To exercise a right, contact us through the Contact page. We may need to verify your identity before acting on a request.

12. Complaints

If you have concerns, we encourage you to contact us first so that we can try to resolve them. You also have the right to lodge a complaint with the Irish Data Protection Commission or another competent supervisory authority.

Irish Data Protection Commission: www.dataprotection.ie

13. Obtempera as a compliance platform

When a customer uses the Obtempera platform to manage worker, contractor or project compliance data, the customer will generally determine why that information is processed and will normally act as controller for that processing. Obtempera will generally act as processor on the customer's documented instructions, subject to the applicable customer agreement and Data Processing Agreement.

Obtempera may act as an independent controller for limited data processed for its own purposes, such as customer account administration, billing, security, fraud prevention and legal compliance.

14. Automated decision-making and AI

The public Obtempera website does not currently make decisions producing legal or similarly significant effects about visitors using solely automated processing.

Any future AI-assisted compliance features within the Obtempera product are intended as decision-support tools and will be described separately in applicable product terms, customer documentation and privacy information.

15. Cookies and similar technologies

Our use of cookies and similar technologies is described in our Cookie Policy.

16. Changes to this policy

We may update this Privacy Policy as Obtempera develops, our processing activities change or legal requirements evolve. The effective date shown above will be updated when material changes are made.

17. Contact

Privacy questions and requests can be submitted through the Obtempera Contact page.