Privacy Policy
Wassl OÜ (trading as Oumré) · Last updated: 8 August 2026
Wassl OÜ (trading as Oumré, “Oumré”) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
Data we collect
We collect account information (name, email), booking details, intake form responses (encrypted at rest), post-session reflections, payment processor references (not card numbers), age verification status (yes/no, not document data), and technical log data.
What we do not collect
We do not record or store live session video or audio. Recording is disabled at the infrastructure level. We do not store your ID document — age verification is handled by third-party providers who return only a pass/fail signal.
Billing discretion
Transactions with Oumré appear on your billing statement as “OUMRE HEALTH” or similar neutral descriptor. We do not share your identity with practitioners beyond the display name you choose.
Data sharing
We share data only with: (1) the practitioner you have booked, (2) authorised payment processors, (3) age verification providers (minimal data), (4) regulators when required by law, and (5) our infrastructure providers under data processing agreements.
Intake form data
Intake form responses are encrypted at rest using Supabase Vault. They are accessible only to you and the practitioner you booked. Oumré staff cannot read intake form content in the ordinary course.
Retention
Booking records are retained for 7 years for financial and legal compliance. Age verification records are retained for the minimum period required by law in your jurisdiction. You may request deletion of other data at any time.
Your rights
EU and UK residents have rights under GDPR / UK GDPR including access, rectification, erasure, portability, and objection. To exercise rights:
Data controller
Wassl OÜ (trading as Oumré), Tallinn, Estonia. EU representative appointed per Article 27 GDPR.