1. Who we are
Grewing Mirko D.I. (an Italian sole trader / Ditta Individuale, trading as ObligoBoard) is the data controller for your personal data. Registered office: Via delle Casine 19, Firenze, Italia. VAT number (P.IVA): IT07214970480.
Data protection contact: privacy@obligoboard.com
2. What data we collect
Account data
- Name, email address, and password (stored as a bcrypt hash — we never store your password in plain text)
Organisation data
- Organisation name, country, and currency preference
- Organisation risk profile: size, business type, data categories processed, international transfer status, and privacy documentation status
Usage data
- Tasks, notes, evidence files, and activity logs you create while using ObligoBoard
- Assessment wizard answers and resulting compliance risk scores
- Document generation history (document type, template version, locale, generation date)
Security data
- Failed login attempts, account lockout timestamps, and IP addresses recorded in security event and activity logs
Contact and support requests
- Name, email address, and message content when you use our contact form
- When you send a support request from inside the app while signed in: your name, account email address, your organisation, the page you were on when you opened the form, the app version, and your message content
Invitations
- Email addresses of people you invite to join your organisation
Public compliance self-assessment
- Your email address, the answers you give in our free public GDPR self-assessment, and the resulting compliance score
- A record of each consent you gave (report delivery, marketing, and any other subscription you separately confirmed) and the version of the consent wording you agreed to
3. How we use your data
We process your data to:
- Provide, maintain, and improve ObligoBoard (legal basis: contract performance)
- Authenticate your identity and protect your account (legal basis: contract performance and legitimate interest)
- Process payments and manage your subscription (legal basis: contract performance)
- Send transactional emails — welcome messages, password resets, team invitations, task reminders (overdue and due-soon digests), and trial expiry reminders (legal basis: contract performance)
- Respond to your support enquiries (legal basis: contract performance)
- Detect and prevent fraud and security incidents (legal basis: legitimate interest)
Automated processing
ObligoBoard calculates a compliance risk score for your organisation based on your organisation profile (size, business type, data categories, international transfers, documentation status) and obligation completion state. This score is advisory only — it is not used to restrict your access to any features or make decisions about your account. You can view the factors contributing to your score on the dashboard and update your profile at any time to recalculate it.
We do not use your data for advertising or marketing profiling.
Marketing communications
If you opt in during signup or via your notification settings, we may send you product updates, compliance tips, and news about ObligoBoard. These emails are separate from transactional communications (such as account notifications, password resets, and compliance reminders) which are necessary for the service to function.
Legal basis: Your explicit consent (GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)).
Withdrawal: You can withdraw your consent at any time by:
- Clicking the "Unsubscribe" link in any newsletter email
- Disabling the "Newsletter" toggle in Settings → Notifications
Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
We use Resend as our email service provider. Your email address and name are shared with Resend for the purpose of delivering emails. Resend's privacy policy is available at resend.com/legal/privacy-policy.
Public compliance self-assessment (lead capture)
Our website offers a free, public GDPR compliance self-assessment. When you ask us to email you your report, we collect and store your email address, your assessment answers, the resulting compliance score, a record of each consent you gave, and the version of the consent wording you agreed to.
We use this data to:
- Send you the compliance report you requested (legal basis: your consent, GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)).
- Send you occasional product updates and compliance tips — only if you separately opt in to marketing (legal basis: your consent, GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)). This opt-in is off by default. If you do not give it, we never add you to any marketing list.
- Send you any email subscription you have separately confirmed — for example, alerts about changes to regulatory deadlines (legal basis: your consent, GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)). Each subscription is optional, off by default, independent of the others and of the marketing opt-in, and is only activated once you confirm it by clicking the link in a confirmation email we send you. The subscriptions on offer are named at the point where you give the consent, and each one tells you what it covers before you agree to it.
Your email address is shared with Resend, our email processor, to deliver the report and — where you separately opted in — our newsletter or any subscription you confirmed. Resend may process this data in the United States under Standard Contractual Clauses (SCCs); see sections 5 and 6 below.
How long we keep it. We keep your assessment answers and compliance score for up to 12 months, after which they are erased (see section 7). If you have not confirmed any email subscription, your whole record — including your email address — is deleted at the same point. If you have confirmed a subscription, we keep your email address, and the record of the consent you gave for it, for as long as that subscription lasts: until you unsubscribe, or until we discontinue the subscription, whichever happens first. Your assessment answers and score are still erased at 12 months either way. If we discontinue a subscription, we delete the email addresses we were holding for it. Once your last subscription ends, your record returns to the ordinary deletion path described above. Where you unsubscribe, we may keep a minimal suppression record — your email address and the date — for no more than 36 months, solely so that we do not contact you again (legal basis: our legitimate interest in honouring your withdrawal and evidencing that we did so, GDPR Article 6(1)(f)). You can withdraw any consent, or ask us to delete your data, at any time by emailing privacy@obligoboard.com.
4. Cookies
We use three essential cookies only. No analytics cookies, no advertising cookies, no tracking cookies. For full details see our Cookie Policy.
5. Third-party services
We share data with the following service providers, solely to operate ObligoBoard. Each processes data under a data processing agreement (DPA) where applicable.
| Service | Purpose | Data location |
|---|---|---|
| Vercel | Hosting, blob storage, privacy-friendly analytics (cookieless) | EU (Frankfurt) |
| Neon | PostgreSQL database | EU (Frankfurt, eu-central-1) |
| Stripe | Payment processing and subscriptions | EU data processing (Stripe infrastructure) |
| Resend | Transactional email delivery | US |
| Font Awesome | Icon library (CDN — receives visitor IP addresses) | CDN |
| Railway | Executes automated cookie/tracker scans of customer websites on the operator's behalf | EU (Amsterdam, Netherlands — europe-west4) |
| Vercel Blob | Storage of user-uploaded evidence files and system-generated PDF documents (privacy policy, DPA, and assessment-report exports) | EU (Frankfurt) |
For the full sub-processor list with transfer-mechanism details (used in our Data Processing Agreement Annex III) see obligoboard.com/sub-processors.
Vercel Analytics is used for basic page-view metrics. It is cookieless and does not track individual users. No personal data is collected.
Google Fonts (IBM Plex Sans & IBM Plex Mono) is self-hosted via Next.js — no data is sent to Google at runtime.
We do not use Google Analytics, advertising pixels, chat widgets, or error-tracking services.
6. International data transfers
Your database and file storage are located in the EU (Frankfurt). Some service providers (Resend, Stripe, Font Awesome) may process data in the United States under appropriate safeguards, including Standard Contractual Clauses (SCCs) and data processing agreements.
7. Data retention
| Purpose | Data | Retention period | What ends it |
|---|---|---|---|
| Running your account | All account, organisation and usage data | For as long as your account is active | Account cancellation |
| Winding down a cancelled account | All account, organisation and usage data | 90 days after cancellation | The 90 days elapse |
| Compliance scoring and audit history | Risk scores, obligation and audit history | For as long as your organisation exists | Deletion of the organisation |
| Proving which documents you generated | Generated-document metadata (type, version, date) | For as long as your organisation exists | Deletion of the organisation |
| Delivering and supporting your self-assessment report | Public self-assessment answers and compliance score | Up to 12 months from collection | The 12 months elapse — regardless of any subscription you hold |
| Sending you a subscription you confirmed | The email address you gave with the self-assessment, and the record of the consent you gave for it | Until the subscription ends; if you confirm none, deleted with your answers and score at 12 months | You unsubscribe, or we discontinue the subscription — in which case we delete the email addresses we held for it |
| Making sure we do not email you again after you unsubscribe | Your email address and the date you unsubscribed | No more than 36 months | The period elapses |
| Security monitoring | Security logs (failed logins, lockouts, IP addresses) | 12 months | The 12 months elapse |
Where two rows cover the same record, the shorter period governs each field independently: your assessment answers and score are erased at 12 months even where your email address is lawfully retained for a subscription beyond that point.
8. Security
Passwords are hashed with bcrypt. Sessions use signed JWT tokens that expire after 24 hours of inactivity. Password reset tokens expire after 60 minutes. We log security events (failed logins, lockouts) and enforce account lockout after repeated failed attempts.
9. Your rights
Under the EU GDPR and UK GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Port your data to another service
- Restrict processing
- Object to processing
To exercise any of these rights, email privacy@obligoboard.com. We will respond within 30 days.
10. Supervisory authorities
If you believe we have not handled your data correctly, you have the right to lodge a complaint with a supervisory authority:
- EU users: contact your national Data Protection Authority (DPA).
- UK users: contact the Information Commissioner's Office (ICO) at ico.org.uk.
11. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For any privacy-related questions, email privacy@obligoboard.com.