Privacy Policy
Wassl OÜ (trading as Oumré) · Last updated: 31 August 2026
This policy explains what Oumré does with personal data, why, and what you can ask us to do about it. Wassl OÜ, trading as Oumré, is the data controller.
What we hold, and why we are allowed to
Account details — name, email address, display name, and the country you are in. We hold these to run your account, on the legal basis that we need them to perform our contract with you.
Booking and payment records — what you booked, when, what it cost, and a reference from our payment provider. We never see or store your card number. We hold these to deliver and account for the booking (contract), and to meet Estonian bookkeeping and tax law (legal obligation).
Intake responses, check-ins and reflections — what you tell a practitioner before a session and what you record afterwards. In substance this is often health data, so we treat it as a special category under Article 9 and process it on the basis of your explicit consent, given when you complete the form. Your answers are encrypted before they are stored, and the key that unlocks them is held outside the database, so a copy of the database on its own does not reveal them. They are shown to you and to the practitioner you booked, and Oumré staff do not read them in the ordinary course of running the platform.
Intake comes after booking, not before, and you can withdraw your consent at any time. Some practitioners ask for an intake form before a first session because they prepare from it. If you would rather not complete one, say so — to the practitioner or to us — and we will sort it out with you — including a refund if that is what you want — rather than leave you stuck between a form you do not want to fill in and a session you have already paid for.
Age and identity verification — where verification is required, it runs through our provider. Depending on where you are, that is either a check of a government-issued document or an estimate of your age from a photograph of your face. The provider carries out the check and returns a pass or fail result and the date. Oumré does not receive or store the document or the photograph. What we hold is the result, the provider's reference for the check, and the country and region worked out from your IP address at the time — we hold these because the law in certain jurisdictions requires the check and requires us to be able to show it happened (legal obligation).
Practitioner application material — if you apply to practise on Oumré, we hold what you send us: your professional history, a government-issued identity document, and any certificates, professional body membership or insurance you choose to provide. The identity document is held encrypted and is reachable only by the staff who review applications and by our payment providers, who require verified identity before anyone can be paid. We hold this to enter into and perform our contract with you, and to meet the anti-money-laundering and identity checks our payment providers impose. None of it is published on your profile; only the resulting badge is.
Technical logs — IP address, device and browser information, error reports. We hold these to keep the platform running and secure, on the basis of our legitimate interest in a working, non-abusable service.
What we do not do
Live sessions are not recorded. Recording is disabled at the infrastructure level, so no recording of a session exists on Oumré. We do not sell personal data, we do not use it to train machine-learning models, and we do not use intake or reflection content for marketing.
Billing
Transactions appear on your statement under a neutral descriptor rather than a description of what you booked. Practitioners see the display name you choose and nothing more.
Who else processes your data
We use a small number of providers, each limited to what their function requires: Vercel (hosting and delivery of the site itself), Supabase (database, authentication and file storage), Stripe (payments), Daily.co (live video), Mux (video hosting and delivery), Resend (transactional email), Sentry (error monitoring), Upstash (rate limiting), Umami (cookieless analytics, loaded in production only), and Didit (age and identity verification). Each processes data under a data processing agreement, which for these providers forms part of the terms we accepted when we signed up with them. We also share data with a practitioner you have booked, and with regulators or law enforcement where we are legally required to.
Your practitioner's role
Practitioners are independent professionals, not our employees, so it is worth being clear about who is responsible for what.
For your intake form, we decide this together. The practitioner writes the questions for their own session types; we provide the form, encrypt the answers and store them. That makes us joint controllers for that step under Article 26 GDPR. Our side of it is building and securing the form, storing the responses, and answering you if you ask about your data. The practitioner's side is deciding what to ask, reading the answers, and using them only to prepare for your session.
For notes a practitioner writes after a session, and for anything you arrange with them outside Oumré, the practitioner is the controller on their own and we are not involved.
You do not need to work out which is which before you ask for something. Write to us at support@oumre.com about any of it and we will either handle it or put it to the practitioner. Article 26 gives you the right to exercise your rights against either of us, and we are not going to make you go round in a circle to do it.
Where your data goes
Some of these providers are based outside the European Economic Area, chiefly in the United States. Where data is transferred there, it is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision, and we assess each transfer before relying on it.
How long we keep it
Booking and payment records are kept for seven years, which Estonian accounting law requires. Intake responses and reflections are kept while your account is open, and removed when you close it or ask us to. Where a practitioner or our team raises an actual safeguarding concern about a session, the record of that concern is kept for longer and separately from your identity, for the reason explained below. Technical logs are kept according to each system we use — typically from a day up to a few months, depending on the vendor.
Closing a client account works in two steps, once anything outstanding is settled. An upcoming confirmed session, a payment still being processed, an open dispute or an active subscription each has to be dealt with first, and we tell you which of them applies when you ask. After that: from the moment you ask, you are signed out and cannot sign back in, and anything of yours that was publicly visible, such as a review you wrote, no longer shows your name. We keep the account for 30 days after that, in case it was a mistake or a dispute needs it, then everything is erased, with two exceptions.
The first is booking and payment records: the amounts, dates and practitioner side stay, with your identity removed from them, because the seven-year accounting requirement above still applies to the transaction even after the account it belonged to is gone.
The second is a safeguarding record. Every session ends with a routine note from your practitioner, and that note is erased along with everything else, whether or not anything happened in the session. But if a practitioner or our team actually raised a safeguarding concern about a session, that record is kept: what was raised and when, with your identity removed from it, for up to ten years. Removing your identity from a record is not the same as making it anonymous. The practitioner, the date and the substance of what was raised all stay; only the link back to you is gone. Ten years is the longest period under Estonian law in which someone could still bring a claim connected to a session, and the record may be what answers one. That is also why we do not keep it forever: once that period has passed, it is deleted too.
Closing a practitioner account is not automatic. A request goes to a person, because clients, payouts and published content have to be dealt with first; the account stays active until that is done, and we come back to you within 30 days.
Practitioner documents work differently, and the distinction matters. We keep two things: the document you sent us, and the record of what we checked. The document is held for as long as you practise here and removed when your account is closed, because evidence of a check should not outlive the relationship it supports, and should not be destroyed while that relationship is live. The record of the check itself — what was verified, when, by whom, and when it expires — is kept longer. It is how we can show that the verification behind your public badges actually happened, and removing it would erase our own accountability rather than protect your privacy.
If you apply and we do not take the application forward, the documents you sent are removed after a short review window, and only the record of the decision remains.
Anonymous information about sessions
Separately from everything above, we keep anonymous, aggregated information about what happens in a session: a broad category of practice rather than the practitioner, whether it was one-to-one or group, a price range and a duration range rather than the exact figures, the month rather than the date, a wellbeing score before and after where one was given, whether you said you would return, a general goal category, and whether a concern was raised, as a yes or no rather than what was said. This is written once a session is complete, alongside your check-in.
We call this anonymous rather than pseudonymised deliberately, and the difference matters: nothing on this record identifies you, points back to your booking, or can be joined to anything else we hold to work out who you are. No name, no booking reference, no practitioner, no exact date or amount. That is a design choice, not a promise on top of one: each figure above is rounded or bucketed for that reason, and the record is built that way from the moment it is written, not turned anonymous later. Because it never identifies you, closing your account and asking us to delete your data does not touch it: there is nothing on it to trace back to you in the first place.
Cookies
We set the cookies needed to keep you signed in and to keep the site secure. Our analytics provider is cookieless and does not track you across sites. We do not run advertising or profiling cookies, so there is no consent banner to click through.
Automated decisions
No decision that significantly affects you is made by automated means alone. Applications are read by a person, and a decision to restrict or end a listing is made by a person, with reasons given.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to processing we base on legitimate interest, or ask for it in a portable format. Where we rely on your consent, you can withdraw it at any time, and doing so does not affect what was done before.
If you have a client account, the fastest way to do either of the first two is directly in Account settings: “Download my data” gives you a JSON copy of your bookings, intake answers, journal entries and more, and “Delete my account” starts the closure described above. Safeguarding and session-note records are not in the automatic download; write to us for those, and for anything else on this list. If you have a practitioner account, both of these are handled by a person — write to us and we will do it.
Write to support@oumre.com and we will respond within one month. If you are not satisfied, you can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or to the supervisory authority where you live.
If something goes wrong
If there is a breach affecting your personal data, we will notify the Estonian Data Protection Inspectorate within 72 hours of becoming aware of it, and we will tell you directly without undue delay where the breach is likely to put your rights at risk.
Who we are
Wassl OÜ, trading as Oumré, registry code 17343721, Sakala tn 7-2, 10141 Tallinn, Estonia. We are established in the European Union, so questions about this policy come to us directly at support@oumre.com.
See also our Terms of Service and Community Standards.