Data controller
We act as a data controller when we process data to operate and manage the customer relationship with readywhen. This includes account management, billing, integration configuration, technical logging, and security.
How readywhen, a product owned and operated by Oliva Health Ltd (“we”, “us” or “our”), collects, uses, discloses, and protects personal data when you use the Service available at readywhen.ai (the “Service”).
Depending on the situation, we can act either as a data processor on behalf of your organisation, or as a data controller for information required to operate and secure the service. This notice explains both roles clearly.
Depending on the context, we act either as a data controller or a data processor.
Data controller
We act as a data controller when we process data to operate and manage the customer relationship with readywhen. This includes account management, billing, integration configuration, technical logging, and security.
Data processor
We act as a data processor when we process workspace data from connected tools such as Slack, Google Calendar, Google Docs, and Gmail. In these situations, we process data only on behalf of the organisation using the service and according to its instructions.
When our B2B customers (“organisations”) connect their tools, we process some workspace data in order to deliver the service.
Across these integrations, we may process names, work email addresses, job titles, communication content, meeting participation, timestamps, and interaction metadata.
We never create, edit, delete, search, or browse any Google content. Access is limited to authorised data required to provide the service.
As readywhen is a data processor for this type of processing, the organisation is responsible for determining the appropriate lawful basis for their employee data.
In the course of providing our services, we may share limited personal data with carefully selected third-party service providers who support our infrastructure, analytics, and processing capabilities. We only share information where it is necessary for specific purposes, and we ensure that appropriate safeguards are in place to protect your data.
No other third parties receive Google user data.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including providing our services, maintaining security, and complying with legal and regulatory obligations. When personal data is no longer required, we delete or anonymise it in accordance with applicable data protection laws.
As a user, you can authorise access to the data via OAuth 2.0 when connecting integrations. You can also revoke access at any time by disconnecting your Google account or other integrations within the service. Once access is revoked, the service immediately stops retrieving data from those sources.
We apply access controls, logging, and regular security reviews to protect data.
Additional information about our security can be found in the “Extra steps we take to protect your data” section below, or in our Trust Centre.
When we act as a controller (for customer relationship and service provision), we collect and process personal data necessary to manage customer accounts and deliver our services, including:
When we act as a controller, we use customer relationship and service data to:
Where required, we rely on legal bases such as legitimate interests, or compliance with legal obligations. We do not use personal data for automated decision-making that produces legal or similarly significant effects.
We share personal data with third parties only where this is necessary to provide our services, maintain system reliability, or comply with legal obligations. When acting as a processor on behalf of our customers, we share data only in accordance with our customers’ instructions and applicable data protection laws. When acting as a controller for customer relationship management and service provision data, we determine the purposes and means of processing and ensure appropriate safeguards are in place.
Third parties may include:
All third-party providers are subject to contractual data protection obligations, including confidentiality, security requirements, and restrictions on using data for their own purposes. Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are implemented, such as Standard Contractual Clauses or equivalent lawful transfer mechanisms.
A full list of our data processors is included in our Trust Centre.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including providing the service, maintaining customer relationships, and complying with legal obligations.
When we act as a controller, we retain:
Once retention periods expire, personal data is securely deleted or anonymised. Backup copies are overwritten according to our backup lifecycle schedules.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. Data is stored in secure cloud infrastructure operated by reputable providers that comply with industry security standards. Access to personal data is limited to authorised personnel who require it to perform their duties. We also maintain incident response procedures to detect, investigate, and respond to potential security events.
Sprinto is a trust management platform that helps centralise security for organisations.
Oliva uses Sprinto for governance purposes in relation to ISO 27001 and the GDPR. Our Sprinto documentation and risk posture is regularly reviewed and updated by our business owners, and reports on our compliance are discussed at our quarterly Management Review meetings.
Please visit our Trust Centre for further information about our security governance.
We understand that having independent validation of our security program is important to our customers and users, which is why we are taking continuous steps to assess and improve our security posture and provide assurances to our customers through certifications.
We’ve already successfully passed the following:
You can find additional information about our security governance in our Trust Centre, or read our Security FAQs.
For information about the cookies we use on our website, please visit our Cookie Notice.
Your personal data is yours, and your rights in relation to it granted by the GDPR and UK GDPR include:
You have the right to be informed about the collection and use of your personal data, why it’s being processed, how long it’ll be stored for, and who it’ll be shared with.
You have the right to ask us for copies of the data we store about you.
You have the right to ask us to rectify personal information you think is inaccurate, or to complete information you think is incomplete.
You have the right to ask us to erase your personal information in some circumstances.
You have the right to ask us to restrict processing your personal information for a duration of time, in some circumstances.
You have the right to ask us to transfer your personal information to another organisation, or to someone else, in some circumstances.
When readywhen acts as a data processor, most workspace data is processed on behalf of your organisation. In these cases, you should contact your employer or organisation to exercise your rights — they determine the purpose and lawful basis for processing. We will assist them where required.
When readywhen acts as a data controller, you may contact us directly to exercise your rights in relation to account data, technical logs, and support communications. You can do so by emailing data.protection@readywhen.ai, or by writing to us at Oliva Health Ltd, 3rd Floor, 86–90 Paul Street, London, Greater London, England, EC2A 4NE. We’ll acknowledge your request as soon as possible and aim to provide the information requested within one month.
Our Data Protection Officer (DPO) is Cristina Patru, Data Privacy Counsel. You can contact Cristina at data.protection@readywhen.ai.
You also have the right to lodge a complaint with your local data protection authority if you believe your data has been handled improperly.
If you have any concerns about our use of your personal information, let us know by writing to us at data.protection@readywhen.ai. If you’re not satisfied with our response, or you’re unhappy with how we have used your data, you can complain to the Supervisory Authority available in your location.