Privacy Policy

The short version: companies provide their own documents and employee details. We use that information to format and deliver their training material, track completion, and run the service.

Last updated August 17, 2026

Core customer documents and training records are stored in Toronto, with background processing in Toronto and Montréal. Some supporting providers may process limited information elsewhere.

1. How the service works

Companies bring their own workplace documents to OHS.training. The service formats those documents into reusable modules, knowledge checks, assignments, and completion records. The company chooses what to upload, who receives it, and how it is used.

For employee information entered by a company, OHS.training works on that company's instructions. The company remains responsible for its source documents and its own employee privacy practices.

2. Information we keep

We keep the information needed to run the service. This can include:

  • names, email addresses, account roles, and sign-in records;
  • company and workspace details;
  • documents uploaded by a company and the modules made from them;
  • assignments, answers, attempts, scores, progress, and completion records;
  • billing status and Stripe customer references; and
  • basic technical records used to keep accounts secure and email invitations or reminders.

Stripe collects card details directly. OHS.training does not store full payment card numbers. We use necessary browser storage for sign-in, security, theme preferences, and basic service operation. We do not use employee training results for advertising or sell personal information.

3. How we use it

We use this information to run workspaces, format company documents, create and deliver modules, save progress, show completion records, manage subscriptions, send service emails, provide support, and protect the service from misuse.

4. Who can see it

A company's administrators can see the people, assignments, scores, and completion records in their workspace. Employees can see only their own assigned material and records. Workspaces are kept separate from one another.

We use a small number of service providers to operate OHS.training: Google Cloud and Firebase for core infrastructure, OpenAI for document processing and the workspace assistant, Vercel for the web app, Stripe for payments, and Resend for service emails. We may also disclose information if the law requires it or if it is needed to protect the service and its users.

5. Canadian data residency

Core workspace records, uploaded documents, generated modules, assignments, answers, and completion records are stored in Toronto. Core background jobs run in Toronto and Montréal. Google Cloud lists both regions as Low CO₂ regions.

Some supporting services may process limited information outside Canada. For example, a company document is sent to OpenAI when the company asks OHS.training to format it. Our OpenAI requests are set not to store reusable responses, and OpenAI says API data is not used to train its models by default. Other providers may keep limited service, security, billing, or delivery records under their own terms.

OHS.training is designed with Canadian privacy requirements in mind. Depending on the customer and where information moves, BC PIPA, PIPEDA, or another provincial privacy law may apply. PIPEDA is a law, not a government certification.

6. Retention and security

We keep workspace information while it is needed to provide the service and maintain the records requested by the company. Some billing, audit, backup, and security records may be kept longer where needed for legal or operational reasons.

We use account roles, workspace checks, restricted database and file access, short-lived upload permissions, protected server operations, and encrypted network connections. No online service can promise zero risk, so customers also need to protect their accounts and remove access when a user leaves.

7. Questions and requests

People may ask to see or correct personal information about them, subject to the rules that apply. If you use OHS.training through your employer, contact that employer first because it controls your workplace information. OHS.training will help the company respond.

The OHS.training privacy contact can be reached at support@ohs.training. We may need to confirm identity before acting on a request.

We may update this policy when the service or its providers change. The current version and date will always appear on this page. See our Terms of Service for the rules that apply when using OHS.training.