OASYS HR Management
Locally developed & maintained in-house · ISO 27001 certified

Privacy Policy

This policy explains how personal data is collected, used, and protected when you use the OASYS Human Resources Management application (the "App") and related services.

Effective date: 01 Jul 2026 Last updated: 01 Jul 2026 Version:1.0

01 Introduction

OASYS is a Human Resources Management System developed and maintained in-house by Deloitte Ltd ("we", "us", "our"). The App gives employees and administrators a single place to manage the employee lifecycle — including core HR records, leave, shifts and schedules, expenses, appraisals, training, and reporting.

We are committed to protecting your personal data and respecting your privacy in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Cyprus data protection law (Law 125(I)/2018).

Please read this policy together with any privacy notice provided by your employer, which may describe how your organisation uses your data as the primary controller.

02 Who is responsible for your data

OASYS is typically provided to your employer, who decides which personal data is processed and for what purposes. In most cases:

  • Your employer is the data controller for the employee data processed in the App.
  • Deloitte Ltd acts as a data processor, processing that data on your employer's documented instructions to operate, host, and support the App.

Where we determine the purposes of processing ourselves — for example, for platform security, service administration, or product improvement — we act as a controller for those limited activities.

Deployment models vary. OASYS can be delivered as Cloud (Azure-hosted), Deployment as a Service (Deloitte-managed end-to-end), or On-Premises (hosted in your organisation's own data centre). The hosting model may affect where your data is stored — see International transfers.

03 Scope of this policy

This policy applies to the OASYS mobile and web application and the supporting back-end services. It does not cover:

  • Third-party websites or services that may be linked from the App;
  • Your employer's own internal systems, policies, or HR processes outside OASYS;
  • Data processed by app stores (Apple App Store, Google Play) under their own privacy terms.

04 Information we collect

The exact data depends on the modules your organisation has enabled and the role assigned to you. It may include:

Identity & account data

  • Name, employee ID, work email address, and organisational role;
  • Authentication data managed through your organisation's identity provider (e.g. Microsoft Azure AD / Entra ID single sign-on). We do not store your corporate password.

HR & employment data

  • Job title, department, reporting line, and organisation chart position;
  • Leave requests and balances, shift assignments and schedules, timesheets;
  • Expenses, training records, appraisals and survey responses, and related documents you or your organisation upload.

Usage & technical data

  • Device type, operating system, app version, and language settings;
  • Log data such as access times, actions performed, IP address, and error/diagnostic information used to keep the service secure and reliable;
  • Push-notification tokens, where you have enabled notifications.
OASYS is not designed to collect special-category data (such as health or biometric data) unless your organisation explicitly configures a module that requires it and has a valid legal basis to do so.

05 How and why we use your data

We process personal data only where we have a lawful basis under the GDPR. The main purposes and bases are:

PurposeTypical legal basis
Providing core HR functionality (leave, shifts, expenses, appraisals, etc.)Performance of the employment relationship / your employer's legitimate interests, on the controller's instructions
Authentication, access control, and account managementLegitimate interests (securing the service)
Security monitoring, logging, and fraud preventionLegitimate interests; legal obligation
Providing support and resolving issuesLegitimate interests; performance of a contract
Sending operational notifications you have opted intoConsent or legitimate interests
Meeting legal, tax, and regulatory obligationsLegal obligation

We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.

06 Sharing & disclosure

We share personal data only where necessary, with:

  • Your employer and authorised administrators within your organisation;
  • Sub-processors and infrastructure providers that help us run the service — for example, cloud hosting (Microsoft Azure) for Cloud and Deployment-as-a-Service deployments — under written data-processing agreements.
  • Professional advisers and authorities where required by law, regulation, or valid legal process.

All parties who process data on our behalf are bound by confidentiality and data-protection obligations and may use the data only for the purposes we specify.

07 International transfers

Where OASYS is hosted in the cloud, data is stored in the region agreed with your organisation (typically within the on prem of employeer). For On-Premises deployments, data remains within your organisation's own infrastructure.

If any transfer of personal data outside the EEA is required, we rely on an appropriate safeguard under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses.

08 Data retention

Personal data is retained for as long as needed to provide the service and to meet your employer's retention requirements and applicable legal obligations. Retention periods are set by your organisation as the controller.

When data is no longer required, it is deleted or anonymised in line with the agreed retention schedule. 6 months

09 How we protect your data

OASYS is developed and operated under an information-security management system certified to ISO/IEC 27001. We apply technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and, for cloud deployments, encryption at rest;
  • Role-based access control and least-privilege access;
  • Single sign-on and multi-factor authentication through your organisation's identity provider;
  • Audit logging, monitoring, and regular security testing;
  • Secure development practices and access reviews for support staff.

No system can be guaranteed to be completely secure. If a personal-data breach affects your rights, we will notify your organisation and cooperate on any required notifications to individuals and the supervisory authority.

10 Your rights

Under the GDPR you have the following rights over your personal data. Because your employer is usually the controller, requests are generally handled by them; we will support your employer in responding.

RightWhat it means
AccessObtain a copy of the personal data we hold about you.
RectificationHave inaccurate or incomplete data corrected.
ErasureHave your data deleted where there is no lawful reason to keep it.
RestrictionLimit how your data is processed in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interests.
Withdraw consentWithdraw consent at any time, where processing relies on it.

You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus (dataprotection.gov.cy) or your local supervisory authority.

11 Cookies & similar technologies

The web version of OASYS uses only cookies and local storage that are necessary to run the App — for example, to keep you signed in and remember your language and settings. We do not use advertising or third-party tracking cookies.

12 Children's data

OASYS is a workplace application intended for use by employees and authorised users of an organisation. It is not directed at children and we do not knowingly collect data from anyone under the age of 18.

13 Changes to this policy

We may update this policy from time to time to reflect changes in the App, the law, or our practices. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify your organisation. Please review this page periodically.

14 Contact us

If you have questions about this policy or how your data is handled, please contact your organisation's HR or data-protection contact first. You can also reach us at:

Entity
Deloitte Ltd
Privacy contact
oasysproductmanager@deloitte.com