Privacy Policy
Last updated: 27 April 2026
1. Who We Are
ORM Systems UK Ltd is a company registered in England and Wales with company number 10416934. wfc360.com is a product of ORM Systems UK Ltd and provides workforce management, staff vetting, and compliance software services to UK companies.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, ORM Systems UK Ltd is the data controller for personal data collected through this website.
ICO Registration Number: ZA906000
Data Protection contact: [email protected]
2. What Data We Collect
We collect the following categories of personal data:
- Contact information — name, email address, phone number, company name (when you submit a demo request or contact form).
- Usage data — pages visited, time on site, browser type, IP address, referral source (collected via analytics cookies, with your consent).
- Cookie data — see Section 5 for full details of cookies used.
- Communications — any information you provide when contacting our support or sales team.
3. How We Use Your Data
We use your personal data for the following purposes:
- To respond to demo requests, enquiries, and support tickets.
- To provide and improve our software products and website.
- To send you product updates and marketing communications (only with your explicit consent).
- To analyse website traffic and user behaviour to improve our content and services (only with your analytics consent).
- To comply with our legal obligations.
4. Legal Basis for Processing
Under UK GDPR, we rely on the following legal bases:
- Consent — for analytics and marketing cookies, and for sending marketing emails.
- Legitimate interests — for responding to enquiries and improving our website.
- Contract — for processing data necessary to deliver our services to customers.
- Legal obligation — where we are required to process data by law.
5. Cookies
We use cookies and similar tracking technologies on our website. Cookies are small text files placed on your device. We use the following categories of cookies:
Strictly Necessary Cookies
Essential for the website to function. Cannot be disabled. These include session management and security cookies.
Analytics Cookies
Used to understand how visitors interact with our website (e.g. Google Analytics via Google Tag Manager). Only set with your consent. Data is aggregated and anonymised where possible.
Marketing Cookies
Used to deliver relevant advertising and track campaign performance. Only set with your consent.
You can manage your cookie preferences at any time using our cookie consent tool (the banner shown on your first visit) or by clicking "Manage Cookie Preferences" in the footer.
6. Third-Party Services
We use the following third-party services that may process your data:
- Google Tag Manager / Google Analytics — website analytics (with your consent). Data may be transferred to the USA under Google's Standard Contractual Clauses.
- Email service providers — for transactional and marketing emails.
7. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, or as required by law. Contact form submissions are retained for up to 2 years. Analytics data is retained in accordance with Google Analytics' default retention settings (26 months).
8. Your Rights
Under UK GDPR and (where applicable) CCPA, you have the following rights:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate data.
- Right to erasure — request deletion of your personal data ("right to be forgotten").
- Right to restrict processing — request that we limit how we use your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent — withdraw consent at any time where processing is based on consent.
- CCPA rights (California residents) — right to know, right to delete, right to opt-out of sale of personal information, and right to non-discrimination.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. All data transmitted to and from our website is encrypted using TLS. Our software products use AES-256 encryption at rest.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page will reflect any changes. We encourage you to review this page periodically.
11. Contact & Complaints
If you have questions about this policy or how we handle your data, contact us at [email protected].
If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.