OrgHealthLab Back to site
Legal · Privacy

Privacy Policy

Effective: March 2026

1. Overview

OrgHealthLab is a platform for organisational health diagnostics used by HR professionals and business leaders. This Privacy Policy explains what personal data we collect, why we collect it, and how we protect it.

By using OrgHealthLab, you agree to the practices described in this policy. If you do not agree, please do not use the platform.

2. Data We Collect

We collect the following categories of data:

  • Account data — your name, work email address, job title, and organisation name provided at signup.
  • Diagnostic inputs — workforce metrics, organisational data, and other HR inputs you enter when running a diagnostic module.
  • Report outputs — the analysis and recommendations generated by the platform, stored against your account.
  • Usage data — pages visited, features used, and session metadata collected to improve the platform.
  • Communications — messages you send to support.

We do not collect payment card data. Billing is handled by third-party processors under their own privacy policies.

3. How We Use Your Data

We use your data to operate the platform, generate and store reports, authenticate your account, respond to support requests, send service-related communications, and improve the product through aggregate anonymised usage analysis.

We do not sell your personal data or diagnostic inputs. We do not use your data to train AI or machine learning models without your explicit consent.

4. Data Storage and Security

Your data is stored on secure cloud infrastructure with encryption in transit and at rest. Access is restricted to authorised personnel and systems only.

  • TLS encryption for all data in transit.
  • Row-level security policies to restrict report access.
  • Authenticated access controls with session management.
  • Regular security reviews of infrastructure.

5. Data Retention

We retain your account data for as long as your account is active. Diagnostic reports are retained until you delete them or close your account. If you close your account, we will delete your personal data within 30 days except where retention is legally required.

6. Third-Party Services

OrgHealthLab uses Supabase for authentication and database hosting and AI providers to process diagnostic inputs and generate reports under their applicable processing terms.

7. Your Rights

You may request access, correction, deletion, portability, or objection to specific uses of your data.

To exercise these rights, contact support@orghealthlab.com. We aim to respond within 30 days.

8. Cookies

OrgHealthLab uses only essential cookies and session tokens required for login and security. We do not use advertising cookies.

9. Children's Privacy

OrgHealthLab is intended for professional adult use and does not knowingly collect data from anyone under 18.

10. Changes to This Policy

We may update this policy from time to time. When material changes occur, we will notify users by email or in-product notice in advance.

11. Contact

support@orghealthlab.com