Last updated: 21 September 2026
This English version is a translation provided for convenience only. In the event of any discrepancy between the two versions, the French version prevails.
This policy describes how OREXIS, publisher of the OpusRH service, processes personal data, in accordance with Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act (Law no. 78-17 of 6 January 1978, as amended).
For the processing operations described in section 3, the data controller is:
OREXIS, a French simplified joint-stock company (SAS) with share capital of €1,000
322 rue des Rameaux, 07430 Davézieux, France
Registered with the Aubenas Trade and Companies Register under no. 991 715 210
Personal data contact: rgpd@jhm-it.fr
The OpusRH service involves two distinct situations under the GDPR:
a. Contact requests (form on www.opusrh.com).
Data: company name, requester's first and last name, email address, telephone number, SIREN company number, company headcount, content of the message.
Purpose: to answer the request and, where applicable, establish a business relationship.
Legal basis: pre-contractual steps taken at the person's request (Art. 6(1)(b)) and OREXIS's legitimate interest in developing its business (Art. 6(1)(f)).
Messages are forwarded to OREXIS by email; their content is not stored in the platform, which keeps only a technical record of the sending (date and subject line, which includes the company name). The sender's IP address is used only transiently, to limit abusive submissions, and is not retained.
b. Customer relationship management, invoicing and reseller programme.
OREXIS sells its licences directly to the customer company, including when that company is assisted by a reseller. The reseller is a partner of OREXIS, paid a commission on the subscriptions of the customers it assists; it does not resell licences. The data subjects are the representatives and contacts of customers and resellers.
Data: identity and contact details of the customer and its representative, subscription and payment information, invoices; for the reseller: identity and contact details, bank details (IBAN, BIC), commissions, commission statements and invoices.
Purpose: entering into and performing the contract, invoicing, calculating and paying commissions, compliance with accounting and tax obligations.
Legal basis: performance of the contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)).
To verify the invoicing identity, the SIREN number is sent to the French State's public "Recherche d'entreprises" API, and the intra-Community VAT number to the European Commission's VIES service.
Payments are processed by Stripe (see sections 4 and 6): the payment module is loaded directly from Stripe's servers, and OREXIS does not keep bank card numbers.
c. Direct marketing (B2B).
Data: professional contact details (name, position, professional email, company).
Purpose: direct marketing to professionals by electronic means.
Legal basis: legitimate interest (Art. 6(1)(f)). Every communication includes a simple way to object to further messages.
d. Support and assistance.
Data: contact details and content of the exchanges.
Purpose: to handle assistance and support requests.
Legal basis: performance of the contract (Art. 6(1)(b)) or legitimate interest (Art. 6(1)(f)).
e. Security and logging.
Data: IP address and device (browser) information recorded when users sign in to accounts or attempt to, when an account is activated, when a password reset is requested, when the data processing agreement is accepted and when sensitive actions are performed on the platform (security log). The action log specific to each customer's workspace is, for its part, among the data processed on the customer's behalf (section 5).
Purpose: to secure access, prevent fraudulent access (temporary blocking of addresses responsible for repeated attempts), ensure traceability and keep evidence of contractual commitments.
Legal basis: legitimate interest (Art. 6(1)(f)).
Note: the measurement agent installed on workstations neither collects nor transmits the workstation's IP address. As with any connection, however, the originating IP address is recorded in the security log when a workstation enrolment is refused and when an employee accesses their personal task management space.
f. Audience measurement on www.opusrh.com.
Data: pages viewed, referring site (domain name only), browser language, screen dimensions, device type, a visitor identifier kept for 13 months in the browser's local storage and a 30-minute session identifier. The IP address is not recorded with this data.
Purpose: to measure traffic on the website and improve its content. This data is used only to produce statistics and is not combined with any other data.
Details of cookies and local storage are given on the Privacy & cookies page.
Data is neither sold nor assigned to third parties. It is accessible to authorised persons at OREXIS and to the following technical processors:
| Processor | Role | Location |
|---|---|---|
| OVH SAS | Hosting | France (EU) |
| Gandi SAS | Email delivery (SMTP), including the reports and alerts sent to customers' users | European Union |
| Stripe | Payment processing | Ireland (EU) with transfer to the United States — see section 6 |
Where a customer is assisted by a reseller (section 5), that reseller accesses the customer's workspace — including employees' activity data and invoicing data — under the same conditions as one of the customer's administrators.
For platform data (user accounts, employees' activity), OREXIS acts solely on the instructions of the customer, as data controller, does not use the data for any other purpose, implements appropriate security measures and governs the use of any sub-processors. The settings made by the customer in the console and its written requests constitute those instructions; any audit or advisory service that OREXIS might carry out using the data of a workspace is performed only at the customer's written request and solely on its behalf. Data subjects (employees) exercise their rights with their employer, the data controller.
Resellers. A customer may be assisted by an OpusRH reseller: its IT service provider, its integrator or its adviser. That reseller is a service provider to the customer. It takes part in administering the OpusRH workspace on the customer's behalf and on the customer's instructions: deploying the agent on workstations, configuration, assistance, help in answering requests to exercise rights. For that purpose it has, within the platform, the same access as one of the customer's administrators, limited to the workspaces of the customers attached to it; its sign-ins to the platform are logged (section 3.e).
At the customer's request, the reseller may also draw on the data of that workspace to provide the customer with audit or advisory services (work organisation, use of tools, deployment support). Those services are performed solely on the customer's behalf, under the contract between them; the reseller is not authorised to make any other use of that data.
The reseller does not act as a processor on behalf of OREXIS. It is for the customer, as data controller, to govern its relationship with the reseller (Art. 28 GDPR) and to inform its employees of the reseller's involvement. The customer may ask OREXIS at any time to withdraw a reseller's access to its workspace.
Hosting (OVH) and email delivery (Gandi) take place within the European Union.
Payment processing by Stripe involves a transfer of data to the United States (Stripe, LLC). That transfer is governed by the safeguards provided for in Chapter V of the GDPR: Stripe is certified under the EU-U.S. Data Privacy Framework and implements the European Commission's standard contractual clauses. No other transfer outside the EU takes place.
| Data | Period |
|---|---|
| Employees' activity data, flags, declared absences, completed tasks and the action log of the customer workspace | Period set by the customer: 160 days by default, between 90 days and 10 years; automatically deleted beyond that |
| Employee identity and directory identifiers | Until the employee is anonymised by the customer (possible 30 days after their last activity) or the workspace is deleted |
| The agent's local log, on the employee's workstation | 60 days by default; measurements that could not yet be sent to the service are kept for up to four times that period |
| Customer workspace after termination, suspension or non-payment | Employee-related data (activity, identity, workstations, groups, tasks, flags) deleted after 365 days, following prior notice to the customer; the customer account, its users' accounts and the workspace action log are kept, as are invoicing records to meet accounting obligations |
| Workspace left in trial with no subscription | Deleted in full 60 days after the end of the trial, following prior notice |
| Security log (sign-ins, IP addresses, sensitive actions) | 2 years (730 days) |
| Technical log of the service (system log) | 90 days |
| Sign-in sessions, account activation and password reset requests (IP address, device) | For as long as the account exists |
| Evidence of acceptance of the data processing agreement (date, version, IP address, device) | For as long as the customer workspace exists |
| Invoicing and accounting data | 10 years (legal obligation) |
| Contact requests / direct marketing | 3 years from the last contact |
| Website audience measurement | Visitor identifier: 13 months; visit data: 25 months |
OREXIS implements technical and organisational measures to protect data: encrypted communications (HTTPS), passwords stored as salted hashes, two-step verification by one-time code (enabled by default on every account, and can be disabled by its holder), segregation of data by customer, logging of access and of sensitive actions.
In accordance with Articles 15 to 22 of the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability regarding your data, as well as the right under French law to give instructions about what happens to it after your death.
To exercise them, write to rgpd@jhm-it.fr. (For data relating to employees' activity, the request must be sent to the employer, as data controller.)
You also have the right to lodge a complaint with the French data protection authority, the Commission nationale de l'informatique et des libertés (CNIL) — 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — www.cnil.fr.
The simulated presence detection feature produces flags and automatically recalculates the activity rate displayed, deducting the flagged periods from it. This feature constitutes profiling within the meaning of Article 4(4) of the GDPR: it automatically evaluates an aspect of behaviour at work from workstation usage data. These are indicators made available to the customer's authorised managers: on their own they trigger no blocking, no sanction and no measure of any kind against the employee.
The service does not by itself take any decision regarding an employee. Any follow-up is a human decision of the employer, as data controller, who is responsible for reviewing each flag before drawing any consequence from it, and for ensuring that no decision producing legal effects or significantly affecting an employee is based solely on these indicators (Art. 22 GDPR).
Data protection matters are handled directly by the President of OREXIS, the company's legal representative; the company has no employees. OREXIS has not appointed a data protection officer (DPO).
For any question, or to exercise your rights, write to rgpd@jhm-it.fr. This is also the address to which customers send the written requests provided for in the data processing agreement.
This policy may be updated. The applicable version is the one published on the website on the date it is consulted.