Privacy notice, cookie policy, consent controls, and data-minimisation language are available before sign-up.
OrgDayTrust and compliance
Clear signals for healthcare, care, and regulated teams.
OrgDay is not an NHS service, but teams evaluating it from NHS or healthcare networks need the same basics to be obvious: privacy information, cookie choices, accessibility intent, secure access controls, and UK-first deployment options.
Session cookies are HTTP-only in the app, admin MFA is supported, and company records are checked per request.
New workspaces default to managed AWS London hosting, with private and customer-cloud options for stricter procurement.
The public pages now publish an accessibility statement and set WCAG 2.2 AA as the target baseline.
Network review readiness
Public checks now exposed
- Cookie banner includes reject optional, accept optional, and customise choices with equal prominence.
- No optional analytics cookies are active by default.
- Public privacy, cookie, accessibility, and trust pages are available without authentication.
- Security response headers are configured for transport, frame, content type, referrer, and browser permissions posture.
- The product messaging names UK hosting defaults, separated company data, MFA, and document audit history.
Network filtering decisions are controlled by the local NHS trust, ICB, or filtering supplier. If a site remains blocked, the IT team normally needs the domain, the business purpose, and these public policy pages so they can reclassify or allow-list it.