ORUSLegal
ORUS · Legal · Eight Hours Group Ltd

Privacy policy

Last updated 7 September 2026Version 3.0Questions: hello@orus.uk

This policy explains what personal data we collect, why, what we do with it, and the rights you have over it. We have written it to be readable and to describe the product as it is built today. The law behind it is the UK GDPR and the Data Protection Act 2018.

The short version: we do not sell your data, we do not run targeted advertising, and the health information you log in the app, or read from Apple Health, is there only because you switched it on and can be deleted by you at any time.

It sits alongside our Customer Terms of Service, Site Terms of Service, Booking Terms, App Terms of Service, Community Guidelines and Advisor Terms.

1. Who we are

ORUS is a trading name of Eight Hours Group Ltd, registered in England and Wales, company number 17031572, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

Eight Hours Group Ltd is the data controller for the personal data described in this policy, except where we say otherwise in sections 4.3 and 8.

We are registered with the Information Commissioner’s Office under registration reference ZC181817.

Contact: hello@orus.uk

2. Where this policy applies

This policy covers orus.uk, the ORUS app, our events, and our communications with you. Where we operate a store for another market, that store links to its own version of this policy, and the differences are set out in section 12.

3. What we collect

3.1 Account and profile

Email address, password (stored as a salted hash by our authentication provider), display name, and any profile details you add, including a photograph if you upload one.

3.2 Orders and payments

What you ordered, delivery address, order history, and returns. We never see or store your full card details. Payment is handled by our payment providers, who send us only a confirmation and the last four digits.

3.3 Wellness profile

Age range, sleep window, primary disruptors, exercise frequency, caffeine cut-off, goals and any free-text notes. Voluntary.

3.4 Health and wellbeing data (special category)

If you switch on the relevant features, our servers hold:

  • Training sessions, plans, schedules, check-ins, soreness, body goals, and your training thresholds and zones (FTP, threshold heart rate, threshold pace) where you or a coach set them
  • Meals logged, protein, energy, plant and portion counts, water, targets, any meal plan, recipe or supplement a coach prescribes, and a coach's comments on meals you have shared with them
  • Weight, body measurements, progress entries and progress photographs
  • Sleep schedule, declared bedtime and wake times, sleep check-ins and wind-down routines
  • Journal entries, symptom tags, habits and weekly check-ins
  • Your wellness profile: age range, sleep window, disruptors, exercise frequency, caffeine cut-off, goals and notes
  • What you have chosen to share with a coach, your intake form and health questionnaire, coaching check-ins, and the record of what a coach looked at

Some health data never reaches our servers at all and is kept only on your phone:

  • Apple Health readings (see the connected sources above)
  • WHOOP readings, which pass through our server to the phone and are not stored on it
  • The supplement list and reminder times you keep for yourself
  • Menstrual cycle tracking, which is off by default

This is special category data under Article 9 of the UK GDPR and we treat it accordingly. Sections 4.2 and 4.3 explain our lawful basis.

3.5 Advisor conversations and memory

Your messages to ORUS Advisor, its responses, and the durable “memory facts” it derives from your conversations. You can view, edit and delete every memory fact and wipe conversations at any time.

3.6 Community and social

Clubs you belong to and follow, posts and comments, people you follow, messages you send, and what you have chosen to share.

3.7 Bookings

Which practitioner, venue, class, event or course you booked, when, what you paid, and whether you were checked in.

3.8 Recommendations from a coach

Where a coach you work with recommends a product to you through ORUS, we record that the recommendation was made, and the note they wrote with it. We never tell a brand who recommended its product.

3.9 Reviews

Rating, review text, photos and the display name attributed to the review.

3.10 Technical

IP address, device and browser type, app version, and error diagnostics collected by our error monitoring tool. Used to keep the service working and secure.

3.11 Cookies and similar technologies

See section 10.

4. Why we use it, and our lawful basis

4.1 Ordinary personal data

What we doLawful basis
Create and run your accountPerformance of a contract
Process orders, deliveries, returns and refundsPerformance of a contract
Take bookings and pass details to the providerPerformance of a contract
Run ORUS Credit and referralsPerformance of a contract
Send transactional emails (orders, password resets, booking confirmations)Performance of a contract
Provide community features and messagingPerformance of a contract
Keep the service secure and prevent fraudLegitimate interests: protecting our users and our business
Understand which products and content work, in aggregateLegitimate interests: improving what we offer
Measure how the site is used with Google AnalyticsConsent, given through the cookie banner
Handle complaints, disputes and legal claimsLegitimate interests, and legal obligation where applicable
Meet tax, accounting and consumer law obligationsLegal obligation
Send marketing emailsConsent, or the soft opt-in for existing customers. Unsubscribe any time

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can object at any time. See section 9.

Important. The bases in this table are our Article 6 bases for ordinary personal data. Health and wellbeing data, including anything read from Apple Health, is special category data and needs a second condition under Article 9. For that we rely only on your explicit consent, never on legitimate interests. Sections 4.2 and 4.3 explain this.

4.2 Health and wellbeing data

For everything listed in section 3.4, our condition for processing special category data is your explicit consent under Article 9(2)(a) of the UK GDPR.

That means:

  • Each health feature stays off until you turn it on and give clear, specific consent.
  • Consent is separate per feature. Turning on nutrition logging does not turn on cycle tracking, and connecting Apple Health does not share anything with a coach.
  • You can withdraw consent at any time from Consent and data in the app, without affecting anything we did before you withdrew it.
  • Withdrawing consent for a feature means we stop processing that data and delete it, unless we are required to keep something by law.
  • We do not rely on legitimate interests for health data, and we will not use it for marketing, profiling for advertising, or automated decisions that produce legal or similarly significant effects.

We have carried out a Data Protection Impact Assessment covering these features. See section 12A.

4.3 The sources you can connect: Apple Health and WHOOP

The app can read from Apple Health on your iPhone so that it can show and interpret your own readings, and it can connect directly to a WHOOP account (section 4.3A). Those are the only two sources today. If we add another, this policy is updated before it goes live, the list below changes, and you are asked to consent to that source separately. Connecting is optional, and separate from every other health feature.

What the app asks to read, each one a separate line on the iOS permission screen that you can allow or refuse individually:

  • sleep, including stages and time in bed
  • heart rate variability
  • resting heart rate
  • respiratory rate
  • sleeping wrist temperature
  • steps
  • active energy
  • workouts
  • weight
  • blood pressure (systolic)
  • blood pressure (diastolic)

What the app writes: a workout you log in ORUS, only if you allowed writing. Nothing else is written.

Where the readings live: On your phone. Readings are kept in a daily record on the device and are not uploaded to our servers as a stream. The home-screen widget reads the same record. iOS may wake the app in the background when a new sleep, heart or workout reading arrives so that record stays current; that refresh also stays on the phone. There is no table of Apple Health readings in our database. Apple does not tell an app which read permissions were refused; a refused type simply returns nothing.

The one time a summary leaves the phone. When you send a message to ORUS Advisor, the app attaches a summary of your latest readings so the Advisor can answer against your own baseline rather than a general average: your readiness score; last night’s sleep hours, stages, efficiency and sleep debt; heart rate variability, resting heart rate and respiratory rate, each with your recent baseline and the change against it; the direction of your sleeping wrist temperature against its baseline; active energy and steps with their change; today’s workouts as type, duration and energy; the last seven days beside the seven before them as averages of those same readings (sleep hours, readiness, heart rate variability, resting heart rate and workout minutes, with how many nights were recorded); and when the readings were last synced. That summary is used to build the reply and is sent to our AI provider under section 7. It is not stored with the conversation; the words you typed are. You can use every health feature without ever writing to the Advisor.

Coaches see none of it by default. Connecting Apple Health shares nothing with any coach, club or practitioner. Sharing a stream with a coach is a separate switch per stream on the Your coach screen, off until you turn it on, and each change is written to a consent ledger you can read.

Disconnecting is on the Wearables screen in the app. It stops the app reading Apple Health and clears the record held on your phone. Because nothing from Apple Health is held on our servers, there is no keep-or-delete question to answer. A summary already inside a stored Advisor reply stays until you wipe that conversation.

Who controls what. Apple Health is Apple’s, on your phone, under Apple’s terms with you. We do not control what it records or how accurate it is. What the app reads becomes a copy on the device that we are responsible for, under this policy. We do not use Apple Health data for advertising or marketing, we do not share it with third parties for their own purposes, we do not use it to train AI models, and we do not sell it. This is required by Apple and it is also our own policy.

4.3A WHOOP, connected directly

On the Wearables screen you can connect a WHOOP account. You are sent to WHOOP's own sign-in page, where WHOOP asks you to allow ORUS access; you can refuse, and you can revoke it later from either side.

What we ask WHOOP for, each a separate permission on WHOOP's screen:

  • sleep: hours asleep, efficiency and respiratory rate
  • recovery: WHOOP's recovery score, heart rate variability and resting heart rate
  • daily strain and energy
  • workouts: the sport and how long
  • your WHOOP user id, so WHOOP's change notices can be matched to your account

What our server holds: the connection itself, meaning an access token, a refresh token and your WHOOP user id, in a table no app or website session can read. Where the readings live: On your phone. Our server holds the connection and fetches readings only when your phone asks, handing them straight to the phone's daily record; no reading is kept on the server. When a record changes, WHOOP sends our server a notice carrying only the record's id and kind; our server then asks your phone to fetch the latest, and the readings still go to the phone alone.

Disconnecting is on the same Wearables screen. It asks WHOOP to revoke our access and deletes the connection from our server. Because no reading is held on the server, there is nothing else to delete there; the copy on your phone clears with the rest of your health record.

Who controls what. WHOOP is WHOOP's, under WHOOP's terms with you. What the app fetches becomes a copy on your device that we are responsible for, under this policy, and everything said above about Apple Health data applies to it: no advertising, no third parties for their own purposes, no model training, no sale.

5. ORUS Advisor and automated processing

The Advisor uses your messages, and any wellness profile and memory facts you have given it, to generate responses and suggest products and content. The Advisor Terms describe it in full.

  • Your messages are sent to our AI provider to generate a response, and to a second provider that turns each message into a numerical form so the right products and answers can be found. See section 7.
  • Where you have enabled health features or connected Apple Health, the Advisor may include the summary described in section 4.3 in the context it sends to our AI provider, so that it can answer against your own baseline rather than a general average. You can use the health features without using the Advisor.
  • The Advisor produces suggestions, not decisions. We have assessed it against Article 22 of the UK GDPR and concluded it does not carry out solely automated decision-making producing legal or similarly significant effects: it recommends content and products, a human is never bound by its output, and it is not used to assess your health, set prices for you, price risk, or determine eligibility for anything.
  • Prices are never personalised. Everyone sees the same price for the same item in the same market.
  • The Advisor is not a clinician. Its output is not medical advice.
  • You can delete individual memory facts, or all of them, and wipe your conversation history.

If you have not enabled health features or connected Apple Health, the Advisor does not have access to health data.

6. When we share your data

We never sell your personal data. We do not share it with advertisers. We do not run targeted advertising.

We share it in these situations only:

  • With service providers who process it on our behalf under contract. See section 7.
  • With practitioners, venues and course providers you book with. See section 8.
  • With brands who fulfil your order, limited to the name, delivery address and item needed to ship it. Brands are independent controllers of that limited data and are contractually barred from using it for marketing or adding you to any list. We are the seller; the brand is only the shipper.
  • With other users, where you have chosen to share: community posts, reviews, messages and anything you share with a coach.
  • Where the law requires it, or to establish, exercise or defend legal claims.
  • On a business sale or reorganisation, in which case we would tell you.

We do not share your health data with Apple. Data flows from Apple Health to the app, and the only thing passing back is a workout you log, if you allowed writing. See section 4.3.

7. Our service providers

Everyone who handles data on our behalf, or receives your IP address when a page loads, as the code stands today. This table is generated from the same register our build checks against the code, so a provider cannot be added to the product without appearing here.

ProviderWhat they doWhereTransfer basis
SupabaseAuthentication and the database, including the health data you log in the app.EUWithin adequacy
ShopifyThe storefront, checkout, card payments and order fulfilment for products.US / globalIDTA with transfer risk assessment
VercelHosting for the site and the app's server, plus aggregate, cookieless measurement of page speed and how many people visit each page.US / global edgeIDTA with transfer risk assessment
AnthropicGenerates the ORUS Advisor's replies from your messages, and the console assistant's drafts for club owners.USIDTA with transfer risk assessment
Voyage AITurns each Advisor message into a numerical form so the Advisor can find the right products and answers. Receives the text of the message.USIDTA with transfer risk assessment
OpenAITurns the Advisor's reply into speech, only when you switch Spoken replies on in the app. Receives the reply text, never your message.USIDTA with transfer risk assessment
StripePayments and payouts for bookings, tickets, courses and clubs, and the identity verification of hosts who take money.US / EUIDTA with transfer risk assessment
MuxHosts course videos. When you play a lesson, Mux receives your IP address and a playback token tied to your enrolment.USIDTA with transfer risk assessment
ResendSends our transactional email: orders, bookings, club invitations and account messages.USIDTA with transfer risk assessment
KlaviyoHolds the newsletter list: the email address you give the newsletter form, and nothing else.USIDTA with transfer risk assessment
Google AnalyticsMeasures how the site is used, only if you accept cookies. Paid orders are reported with an order id and value, and linked to your visit only if you accepted.USIDTA with transfer risk assessment
WHOOPIf you connect a WHOOP, our server holds the connection to your WHOOP account (an access token and your WHOOP user id) and fetches your recovery, sleep, strain and workout records from WHOOP when your phone asks, passing them to the phone without storing them. WHOOP also tells our server when one of those records changes, by id only.USIDTA with transfer risk assessment
ExpoDelivers push notifications to the app: the device token and the text of the notification.USIDTA with transfer risk assessment
Your browser's push serviceCarries web notifications you turn on, through Apple, Google or Mozilla depending on your browser.US / globalIDTA with transfer risk assessment
AppleDistributes the app through TestFlight and the App Store, and carries app notifications.US / globalIDTA with transfer risk assessment
SentryError monitoring and diagnostics, which may include an IP address.US / EUIDTA with transfer risk assessment
Google WorkspaceOur business email.EU / USIDTA with transfer risk assessment
Royal Mail and carriersDeliver orders.UKN/A
OpenStreetMapThe map on a class or event page loads from openstreetmap.org, which receives your IP address when the map loads.UKN/A
FontshareThe site's typeface loads from api.fontshare.com, which receives your IP address.GlobalIDTA with transfer risk assessment
UnsplashCover photographs on some journal articles load from images.unsplash.com, which receives your IP address. No personal data is sent.USN/A
postcodes.ioTurns a club venue's postcode into map coordinates. A venue's address, never a member's.UKN/A
Spotify, YouTube and Apple PodcastsA podcast episode embedded in a community post plays through their players, under their terms, when you press play.US / globalN/A

Anthropic. Your messages to the Advisor are processed to generate a response. Under our agreement, Anthropic does not retain them beyond the request lifecycle and does not use them to train models. Where you have connected Apple Health, this may include the summary described in section 4.3.

Each processes data on our instructions under a written contract with confidentiality and security obligations.

International transfers. Some providers are outside the UK. Where that happens we rely on UK adequacy regulations, or on Standard Contractual Clauses with the UK International Data Transfer Addendum, together with a transfer risk assessment. You can ask us for details.

8. Practitioners, venues and course providers

When you book a class, session or consultation, we pass the provider the information they need to deliver it: your name, what you booked and when, and anything you choose to tell them. Reaching you is done through ORUS messaging; we do not hand a host your email address or phone number.

From that point the provider is a data controller in their own right for the information you give them and anything they record about you, including any health information you share as part of their service. Their own privacy policy applies to that, not ours. If you want to know how a practitioner handles your data, ask them directly.

There is a narrow exception. Where a provider records something into ORUS systems on our instructions and for our purposes, completing a booking record for example, they act as our processor for that step, under written terms that meet Article 28 of the UK GDPR.

At the moment of booking itself, we and the provider may determine purposes together. Where that is so, we are joint controllers for that step within the meaning of Article 26, and the essence of our arrangement is this: we are responsible for telling you what happens at booking and for handling requests about our booking records; the provider is responsible for everything they record in delivering the service. Either of us will help you reach the other. You may exercise your rights against either of us.

We require providers to comply with data protection law, but we do not control what they do with the information you give them.

Connecting Apple Health does not give any coach, club or practitioner access to it. Where you work with a coach through ORUS they see only what you choose to share with them, stream by stream, and you can withdraw that at any time.

9. Your rights

You have the right to:

  • Access a copy of the data we hold about you
  • Rectify anything inaccurate
  • Erase your data (the “right to be forgotten”)
  • Restrict how we use it
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Portability: receive your data in a machine-readable format
  • Withdraw consent at any time, including for any health feature or for Apple Health
  • Not be subject to solely automated decisions with legal or similarly significant effects

Several of these are built into the product rather than requiring a request:

  • Advisor memory: review, edit or delete any individual memory fact at /me/advisor
  • Advisor conversations: wipe your entire history at /me
  • Health data: export a diary or delete it by area from the Consent and data screen in the app, without deleting your account
  • Apple Health: connect or disconnect, and see which types the app reads, from the Connected devices screen in the app
  • Sharing with a coach: switch each stream on or off from the Your coach screen
  • Account closure: from the app (Account, then Delete account, reversible for 30 days), or by emailing us

For anything else, email hello@orus.uk. We respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk or 0303 123 1113. We would rather you came to us first.

10. Cookies and similar technologies

  • Strictly necessary: Supabase authentication tokens and Shopify cart cookies, plus security. The site cannot work without these and they do not require consent.
  • Functional: your consent preference (orus_consent and its date), region and currency selection, referral attribution (orus_ref), and the campaign you first arrived from (orus_utm), used only to attribute your own order.
  • Analytics, only if you accept: Google Analytics sets its cookies (_ga and _ga_*) to measure how the site is used. Decline and no analytics script loads and no analytics cookie is set. Paid orders are reported to Google Analytics with an order id and value from our server; they are linked to your visit only if you accepted cookies.
  • Aggregate measurement without cookies: Vercel counts page views and measures page speed without identifying you and without setting a cookie.
  • We do not use advertising cookies or third-party tracking pixels.
  • Error monitoring collects technical diagnostics, which may include an IP address.

You can change your choice by clearing the orus_consent cookie in your browser, after which the banner asks again, and you can control cookies generally in your browser.

11. How long we keep things

DataRetention
Account dataUntil you close your account, then deleted within 30 days
Health and wellbeing data on our serversUntil you delete it, or until you withdraw consent for that feature
Apple Health readingsOn your phone only, until you disconnect or delete the app
Advisor conversations and memoryUntil you delete them, or account closure
Order and transaction records6 years from the end of the financial year of the sale (tax law)
Booking records6 years, for tax and to defend claims
ReviewsWhile your account is active, or until you ask us to remove one. Removed on account closure unless the review is anonymised
Community posts and messagesUntil you delete them or close your account; content you posted is then attributed to a deleted account rather than to you
Credit ledger6 years from the end of the financial year of the transaction
Coach recommendation recordsWhile the coaching relationship is active, then 12 months
Complaints and disputes6 years from resolution
Marketing consent records6 years from withdrawal, as evidence of consent
Consent records for health features and coach sharing6 years from withdrawal, as evidence of explicit consent
Error diagnostics90 days

Where we must keep a record for tax purposes we keep the minimum needed and restrict access to it.

12. Other markets

Where we sell into a market outside the United Kingdom, local data protection law may give you additional or different rights. Each market we operate in has its own annex at the end of this policy, setting out who the controller is there, which law applies, who your local contact is, how breaches and complaints are handled, and the basis on which data leaves that country. Where an annex conflicts with the main policy, the annex applies for that market.

Markets with an annex today: Malaysia. Where you deal with more than one ORUS store, the annex for each market applies to the data collected by that store.

12A. Data Protection Impact Assessment

We have carried out a Data Protection Impact Assessment covering the health features, the Apple Health connection described in section 4.3, the ORUS Advisor, and sharing with a coach, because each involves either special category data or profiling. We review it when we materially change any of those features, and before adding a new connected source.

13. Security

  • Traffic between your device and our servers is encrypted with TLS.
  • The database is encrypted at rest.
  • Health data you log is stored on EU-hosted Supabase servers and isolated per user by row-level security, so your rows cannot be read by another account.
  • Apple Health readings never reach our servers, so there is no server copy to secure; the copy on your phone sits inside the app’s own protected storage.
  • Access by our staff is limited to those who need it, and health data access is restricted further.
  • We use a managed authentication provider rather than building our own password handling.

No system is perfectly secure.

If a personal data breach occurs, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it where the breach is likely to result in a risk to people’s rights and freedoms. Where the breach is likely to result in a high risk to you, we will tell you directly and without undue delay, and explain what happened, what we are doing about it, and what you can do to protect yourself.

14. Children

ORUS is for adults. You must be 18 or over to hold an account. We do not knowingly collect data from anyone under 18. If you believe we have, contact hello@orus.uk and we will delete it.

15. Changes to this policy

The current version is always at this URL with the date it was last updated. If we make a material change, particularly to how we handle health data or Apple Health, or add a new service that handles your data or a new source you can connect, we will tell you by email or in the app before it takes effect, and where the change requires it we will ask for fresh consent.

16. Contact

Eight Hours Group Ltd (trading as ORUS) · Company number 17031572 · 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ · Email: hello@orus.uk · Account deletion: same address, subject “Account deletion request”

Annex MY: Malaysia

This annex applies to personal data collected through the ORUS Malaysia store, the app where you use it as a person in Malaysia, and ORUS classes, events and bookings taking place in Malaysia. Malaysia’s Personal Data Protection Act 2010, as amended by the Personal Data Protection (Amendment) Act 2024, applies to that data rather than the UK GDPR.

MY.1 Who the controller is

Until a Malaysian operating company is incorporated and named in this annex, Eight Hours Group Ltd is the data controller for the Malaysia market, at the address in section 16. When a Malaysian operating company takes over that role we will update this annex and tell affected users before the change takes effect.

MY.2 How the law differs from the UK

  • The Act is consent-led. There is no general “legitimate interests” basis, so where the main policy relies on legitimate interests we rely instead on your consent or on a specific ground in the Act.
  • Sensitive personal data, which includes health data and anything read from Apple Health, requires your explicit consent. This matches how we already treat it.
  • The Act uses the term “data controller”, which replaced “data user” under the 2024 Amendment Act.
  • Your rights of access, correction, withdrawal of consent, and to limit processing come from the Act. The rights listed in section 9 are given effect in Malaysia through the equivalent provisions.

MY.3 Your local contact and our Data Protection Officer

Where the Act requires it, we appoint a Data Protection Officer who is resident in Malaysia or readily contactable there, and who is proficient in Bahasa Melayu and English. Their contact details are published on the Malaysia store and notified to the Commissioner as required. Until that appointment is published, contact hello@orus.uk, marked for the attention of the Malaysia data protection contact.

We keep the appointment under review against the thresholds in the Act, which include processing the personal data of a large number of people, processing sensitive personal data at scale, and carrying out regular and systematic monitoring. Continuous health tracking is capable of meeting the last of these.

MY.4 Data breaches

Where a breach affecting Malaysian personal data causes or is likely to cause significant harm, or affects a large number of people, we notify the Commissioner as soon as possible and in any event within the period the Act requires, and we notify affected individuals where the Act requires it. This is a separate route from the UK notification described in section 13, and where a breach affects both markets we make both notifications.

MY.5 Data leaving Malaysia

Our infrastructure is hosted outside Malaysia: the database in the EU, and some providers in the United States, as set out in section 7. Before transferring Malaysian personal data we carry out a transfer impact assessment and rely on the grounds available under the Act, including your consent where required, and contractual protections with each recipient equivalent to those described in section 7.

MY.6 Apple Health

Section 4.3 applies in Malaysia, with two differences: your explicit consent is required for the sensitive personal data read, and the transfer of the Advisor summary outside Malaysia is covered by MY.5. Apple remains an independent party in the sense described in section 4.3, under its own terms with you.

MY.7 Complaints

Raise anything with us first at hello@orus.uk. If you are not satisfied, you may complain to the Personal Data Protection Commissioner (Jabatan Perlindungan Data Peribadi), whose contact details are at pdp.gov.my. The Information Commissioner’s Office in the United Kingdom does not supervise processing carried out under this annex.

MY.8 Language

This policy is provided in English. Where we publish a Bahasa Melayu translation and there is a conflict, the English version governs, except where Malaysian law requires otherwise.

Version 3.0 · Effective 7 September 2026 · Eight Hours Group Ltd, trading as ORUS · The current version of this policy is always at this address. Previous versions are available on request from hello@orus.uk.