01 Introduction
OASYS is a Human Resources Management System developed and maintained in-house by Deloitte Ltd ("we", "us", "our"). The App gives employees and administrators a single place to manage the employee lifecycle — including core HR records, leave, shifts and schedules, expenses, appraisals, training, and reporting.
We are committed to protecting your personal data and respecting your privacy in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Cyprus data protection law (Law 125(I)/2018).
02 Who is responsible for your data
OASYS is typically provided to your employer, who decides which personal data is processed and for what purposes. In most cases:
- Your employer is the data controller for the employee data processed in the App.
- Deloitte Ltd acts as a data processor, processing that data on your employer's documented instructions to operate, host, and support the App.
Where we determine the purposes of processing ourselves — for example, for platform security, service administration, or product improvement — we act as a controller for those limited activities.
03 Scope of this policy
This policy applies to the OASYS mobile and web application and the supporting back-end services. It does not cover:
- Third-party websites or services that may be linked from the App;
- Your employer's own internal systems, policies, or HR processes outside OASYS;
- Data processed by app stores (Apple App Store, Google Play) under their own privacy terms.
04 Information we collect
The exact data depends on the modules your organisation has enabled and the role assigned to you. It may include:
Identity & account data
- Name, employee ID, work email address, and organisational role;
- Authentication data managed through your organisation's identity provider (e.g. Microsoft Azure AD / Entra ID single sign-on). We do not store your corporate password.
HR & employment data
- Job title, department, reporting line, and organisation chart position;
- Leave requests and balances, shift assignments and schedules, timesheets;
- Expenses, training records, appraisals and survey responses, and related documents you or your organisation upload.
Usage & technical data
- Device type, operating system, app version, and language settings;
- Log data such as access times, actions performed, IP address, and error/diagnostic information used to keep the service secure and reliable;
- Push-notification tokens, where you have enabled notifications.
05 How and why we use your data
We process personal data only where we have a lawful basis under the GDPR. The main purposes and bases are:
| Purpose | Typical legal basis |
|---|---|
| Providing core HR functionality (leave, shifts, expenses, appraisals, etc.) | Performance of the employment relationship / your employer's legitimate interests, on the controller's instructions |
| Authentication, access control, and account management | Legitimate interests (securing the service) |
| Security monitoring, logging, and fraud prevention | Legitimate interests; legal obligation |
| Providing support and resolving issues | Legitimate interests; performance of a contract |
| Sending operational notifications you have opted into | Consent or legitimate interests |
| Meeting legal, tax, and regulatory obligations | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.
06 Sharing & disclosure
We share personal data only where necessary, with:
- Your employer and authorised administrators within your organisation;
- Sub-processors and infrastructure providers that help us run the service — for example, cloud hosting (Microsoft Azure) for Cloud and Deployment-as-a-Service deployments — under written data-processing agreements.
- Professional advisers and authorities where required by law, regulation, or valid legal process.
All parties who process data on our behalf are bound by confidentiality and data-protection obligations and may use the data only for the purposes we specify.
07 International transfers
Where OASYS is hosted in the cloud, data is stored in the region agreed with your organisation (typically within the on prem of employeer). For On-Premises deployments, data remains within your organisation's own infrastructure.
If any transfer of personal data outside the EEA is required, we rely on an appropriate safeguard under the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses.
08 Data retention
Personal data is retained for as long as needed to provide the service and to meet your employer's retention requirements and applicable legal obligations. Retention periods are set by your organisation as the controller.
When data is no longer required, it is deleted or anonymised in line with the agreed retention schedule. 6 months
09 How we protect your data
OASYS is developed and operated under an information-security management system certified to ISO/IEC 27001. We apply technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and, for cloud deployments, encryption at rest;
- Role-based access control and least-privilege access;
- Single sign-on and multi-factor authentication through your organisation's identity provider;
- Audit logging, monitoring, and regular security testing;
- Secure development practices and access reviews for support staff.
No system can be guaranteed to be completely secure. If a personal-data breach affects your rights, we will notify your organisation and cooperate on any required notifications to individuals and the supervisory authority.
10 Your rights
Under the GDPR you have the following rights over your personal data. Because your employer is usually the controller, requests are generally handled by them; we will support your employer in responding.
| Right | What it means |
|---|---|
| Access | Obtain a copy of the personal data we hold about you. |
| Rectification | Have inaccurate or incomplete data corrected. |
| Erasure | Have your data deleted where there is no lawful reason to keep it. |
| Restriction | Limit how your data is processed in certain circumstances. |
| Portability | Receive your data in a structured, machine-readable format. |
| Objection | Object to processing based on legitimate interests. |
| Withdraw consent | Withdraw consent at any time, where processing relies on it. |
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus (dataprotection.gov.cy) or your local supervisory authority.
11 Cookies & similar technologies
The web version of OASYS uses only cookies and local storage that are necessary to run the App — for example, to keep you signed in and remember your language and settings. We do not use advertising or third-party tracking cookies.
12 Children's data
OASYS is a workplace application intended for use by employees and authorised users of an organisation. It is not directed at children and we do not knowingly collect data from anyone under the age of 18.
13 Changes to this policy
We may update this policy from time to time to reflect changes in the App, the law, or our practices. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify your organisation. Please review this page periodically.
14 Contact us
If you have questions about this policy or how your data is handled, please contact your organisation's HR or data-protection contact first. You can also reach us at: