Privacy Policy
What Orientra Compliance collects, why, who else handles it, and the rights you have over it.
Effective 9 October 2026.
1. Who we are
Orientra Compliance is operated by James Worthing, a sole proprietor carrying on business as James Worthing Safety Consulting Services (“JWSCS”), in Manitoba, Canada. James Worthing is the person accountable for privacy (our privacy officer). Questions, requests and complaints go to info@orientracompliance.ca.
We are a Canadian business and follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) for all the personal information we handle, wherever the person it is about lives. The service is offered to businesses in Canada and the United States; section 15 sets out what applies in the United States in addition.
2. Whose information this is, and who is responsible for it
Our customers are companies, and we handle personal information in two different roles:
- Information a customer puts into its workspace. Most of the personal information in Orientra is about a customer's own workers, and it is put there by that company, which decides what is recorded and why. That company is responsible for it. We handle it only on the company's behalf and on its instructions, under the Data Processing Terms.
- Information we collect for ourselves. Account and billing details, what is typed into our website forms, and usage analytics. We are responsible for this.
If you are a worker and want to see or correct what your employer has recorded about you, ask your employer first — they control those records. If that does not work, write to us and we will help.
3. What the product stores
About the people who sign in
- Name and email address
- A hash of the password (never the password itself), and, if two-step sign-in is switched on, its secret in encrypted form
- Sign-in sessions, including the IP address and browser they came from
About workers
- Name, job title, employment status, start and end dates, email address and telephone number
- Training records, certificates, competency assessments and their expiry dates
- Signatures drawn on a screen
About injuries and incidents
An incident record can name the person involved, say what happened, which part of the body was injured, whether first aid or medical aid was given, how many working days were lost, and whether the incident is reportable to the Workers Compensation Board. This is health information and we treat it as the most sensitive data in the product. It is recorded by the employer, for the employer's own health and safety obligations.
About a customer's own customers
- Business names, site addresses, contact names, telephone numbers and email addresses
- A signature from a customer's representative when a job is completed
Files
Photographs taken on site, uploaded documents and signature images. A fingerprint (a SHA-256 digest) of each file is recorded so it can be shown later that the file has not been altered. A form may record a location if the person filling it in chooses to give one.
Records of use
- An activity log of who changed what, and when
- A log of who opened datasets that contain personal information, by day
4. What this website collects
- The demo request form. What you type into it — name, company, email address, and anything optional you add — is stored in the Orientra application's database and emailed to us so we can reply. We do not sell it or use it for anything else.
- Signing up for a trial. Company name, your name, your work email address, a password (stored only as a hash) and the number of workers you tell us.
- Buying a plan. Stripe collects your payment details directly, and we pass it the email address of the person paying. Stripe also asks for your billing address, and a business tax number if you choose to give one, so that the right tax can be calculated. We receive a confirmation, a payment reference and the amount of tax charged. Your card details never reach us.
- Analytics, described in section 6.
5. Why we use it
We collect only what these purposes need, and we do not use personal information for anything else without asking.
| Purpose | What we use | Basis |
|---|---|---|
| Providing the service to a customer | Everything in the customer's workspace | Our contract with the customer, on its instructions |
| Creating and securing accounts | Name, email address, password hash, sessions, IP address | Needed to provide the service you asked for, and to keep it secure |
| Billing | The email address of the person paying, the plan, payment references | Our contract; tax and accounting law |
| Replying to an enquiry | What you typed into the form | Your consent, given by sending it |
| Service messages (receipts, security notices, changes to these documents) | Email address | Needed to provide the service |
| Understanding how the site and product are used | The limited analytics in section 6 | Your consent, which you can withhold (section 6) |
| Meeting legal obligations and protecting people's safety | Whatever the obligation requires | The law |
We do not sell personal information. We do not use it for advertising. We do not use customer records to train artificial intelligence models.
Marketing email. We send marketing email only to people who have agreed to receive it, and every message has a working unsubscribe link, as Canada's anti-spam law and the United States CAN-SPAM Act require.
6. Analytics
This website and the Orientra application use Google Analytics 4 to count visits and to measure how many people start a trial and go on to buy. What is sent to Google is deliberately limited:
- Page views. In the application, every identifier is removed from the address first, so Google receives a page type such as
/company/:id/incidentsand never which company or which record. - A small number of events: a demo being requested, signing up, a trial starting, a checkout being opened, and a purchase. A checkout or purchase event carries the plan size and the price.
- Never a name, an email address, a company name, or anything a person typed into a record.
- Google's advertising features and ad personalisation are switched off.
Google Analytics sets cookies in your browser to tell visits apart. If your browser sends a Global Privacy Control or Do Not Track signal, analytics is not loaded. You can also block these cookies in your browser without affecting how the product works.
7. Cookies
- A sign-in cookie in the application, which keeps you signed in. It cannot be read by scripts and is needed for the product to work.
- A remembered-browser cookie, only if you choose to have a browser remembered for two-step sign-in.
- Google Analytics cookies, as described above.
We use no advertising cookies and no third-party tracking beyond the analytics described.
8. Who else handles the information
We use these service providers to run Orientra. Each handles only what its job needs, under its own contract with us:
| Provider | What it does | What it can reach | Where |
|---|---|---|---|
| Railway | Hosts the application and its database | Everything stored in the product | United States |
| Cloudflare | Stores evidence files; hosts this website and our uptime monitor | Photographs, signature images, uploaded documents; requests to this website | United States and other countries where Cloudflare operates |
| Resend | Sends email | Recipient addresses and message contents | United States |
| Stripe | Takes card payments | Your card details, which you give to Stripe directly; we receive only a confirmation and a reference | United States and other countries where Stripe operates |
| Analytics | The limited usage information described under Analytics | United States and other countries where Google operates | |
| Twilio | Sends text messages, only where a company has text messaging switched on | Recipient telephone numbers and message contents | United States |
We do not sell personal information, and we do not share it with anyone else, except:
- with a safety consultant, where a customer has granted that consultant access to its own workspace;
- where the law requires it, or to respond to a valid court order or lawful demand;
- where it is needed to protect a person's life, health or safety;
- with a successor, if the business is transferred — who must keep to this policy.
9. Where the information is stored
Personal information in Orientra is stored and processed in the United States. The application and its database are hosted in the United States. Evidence files are held by Cloudflare, which may store them in the United States or in another country where it operates. Our email, payment, analytics and text-message providers are also based in the United States.
For customers in Canada, that means your information is held outside Canada. While information is in another country it is subject to that country's laws, and courts, law enforcement and national security authorities there may be able to obtain access to it. If your company's own policies or contracts require Canadian storage, do not put that information into the service.
We operate the service from Canada, so the operator may view information from Canada when running and supporting it. We remain responsible for information we have sent to a provider, and we require each provider to protect it.
10. How long records are kept
A company can set its own retention periods. Where it has not, the product uses these defaults:
| Records | Default |
|---|---|
| Incidents and investigations | 10 years |
| Training, competency and certificates | 7 years |
| Photographs, signatures and uploaded files | 7 years |
| Inspections and completed forms | 5 years |
| Document acknowledgements | 5 years |
| Work orders, time, materials and invoices | 7 years |
| A worker's contact details after they leave | 2 years |
These are the product's defaults, not legal advice about how long your company must keep anything.
When a trial or a subscription ends, nothing is deleted: the workspace becomes read-only and stays exportable. A company's records are removed only on that company's written request, after a final export, and we aim to complete the removal within 30 days. Enquiries sent through the website are kept for as long as needed to deal with them, and are deleted if you ask. Billing records are kept for as long as tax law requires.
11. Your rights
You have the right to ask what personal information is held about you, to see it, to have it corrected, to withdraw a consent you gave, and to complain about how it has been handled.
- If the information is in an employer's workspace, ask the employer. A company can produce a copy of what is held about one of its workers, and correct it, from inside the product. If your employer does not respond, write to us and we will pass the request on and help.
- If it is information we collected ourselves — your account, a form you sent us, billing — write to info@orientracompliance.ca. We will answer within 30 days, at no charge.
- What can be removed. When a worker leaves, their contact details, sign-in credentials and drawn signature image can be removed.
- What cannot be removed, and why. The fact that a person signed something, their typed name, what they were shown and when are kept, as is who an incident record is about. Removing them would falsify a safety record that the law expects an employer to keep, and that record usually protects the worker it names.
- Withdrawing consent to analytics is done in your browser (section 6). Withdrawing consent to something the service needs in order to work means we can no longer provide it to you.
12. How it is protected
- Connections to the application are encrypted (HTTPS).
- Passwords are stored only as salted hashes. Two-step sign-in is available to every account and required for accounts that can reach more than one company.
- Each company's records are separated from every other company's, and that separation is tested automatically.
- Sign-in attempts are rate-limited, and sessions can be reviewed and revoked.
- Access to personal information by the operator is recorded in the customer's own activity log.
- We keep a register of security incidents.
No system is perfectly secure, and we cannot guarantee that information will never be accessed, lost or altered without authority.
13. If something goes wrong
If we confirm a breach of security safeguards involving personal information:
- we will tell each affected customer as soon as feasible, with what we know about what happened, what information was involved and what we are doing about it, so that the customer can meet its own obligations to its workers;
- where the breach involves information we are responsible for and creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify the people affected, as PIPEDA requires;
- we will keep a record of the breach.
14. Children
Orientra Compliance is a business product. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. An account may be held only by a person aged 18 or over. An employer may lawfully employ a young worker and record that worker's training and safety information; the employer is responsible for doing so properly. If you believe a child under 13 has given us personal information, write to info@orientracompliance.ca and we will delete it.
15. If you are in the United States
This section adds to the rest of this policy for people in the United States. It is written to meet the California Consumer Privacy Act as amended (CCPA/CPRA), and we apply it to residents of every state.
What we collect, in the law's categories
| Category | Examples in Orientra | Where it comes from |
|---|---|---|
| Identifiers | Name, email address, telephone number, IP address | You, or your employer |
| Professional or employment information | Job title, employment dates, training, certificates, competency records | Your employer |
| Sensitive personal information | Health information in an incident record; account sign-in credentials; a precise location, if one is added to a form | Your employer; you |
| Commercial information | The plan a company bought and its payment references | The customer; Stripe |
| Internet or network activity | Sign-in sessions; the limited analytics in section 6 | Your browser |
| Visual and electronic information | Photographs taken on site; signatures drawn on a screen | You, or your employer |
Why we use each of these is set out in section 5, who receives it in section 8, and how long it is kept in section 10.
What we do not do
- We do not sell personal information, and have not done so in the past twelve months.
- We do not share personal information for cross-context behavioural advertising.
- We use sensitive personal information only to provide the service — never to infer characteristics about a person.
- We disclose personal information only to the service providers in section 8, for the business purposes in section 5.
- We honour Global Privacy Control signals.
Your rights
- To know what personal information we hold about you, and to receive a copy.
- To have it corrected.
- To have it deleted, subject to the limits in section 11 and to records the law requires to be kept.
- Not to be treated differently for using any of these rights.
How to use them. If the information is in your employer's workspace, your employer is the business responsible for it and we act as its service provider: ask your employer, and we will help it respond. For information we collected ourselves, write to info@orientracompliance.ca. We will confirm who you are using information we already hold, and answer within 45 days. Someone you have authorised in writing may make the request for you.
Health information and HIPAA. Orientra is a workplace safety record system used by employers. It is not a medical records system, we are not a “business associate” under HIPAA, and the service must not be used to store medical records or other information regulated by HIPAA.
16. If you are anywhere else
The service is offered only to businesses in Canada and the United States, and we do not market it elsewhere. We nevertheless apply the same standard to everyone whose information we hold.
European Economic Area and United Kingdom (GDPR). We do not offer the service there. If we hold your personal information, you may ask us for access to it, to correct it, to delete it, to restrict or object to its use, or to receive a copy, and we will respond within 30 days. Section 5 sets out why we use information and on what basis.
17. Changes to this policy
If we change this policy in a way that matters, we will email the administrators of each customer at least 30 days beforehand and show the new effective date at the top of this page.
18. Questions and complaints
Write to our privacy officer, James Worthing, at info@orientracompliance.ca. We will acknowledge a complaint, look into it, and answer within 30 days.
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1-800-282-1376). If you are in the United States, you may also contact your state's attorney general.
This page is published at www.orientracompliance.ca. The application itself is at orientracompliance.ca.