Skip to main content

Privacy Policy

Last updated: July 2026

1. Who we are

Grewing Mirko D.I. (an Italian sole trader / Ditta Individuale, trading as ObligoBoard) is the data controller for your personal data. Registered office: Via delle Casine 19, Firenze, Italia. VAT number (P.IVA): IT07214970480.

Data protection contact: privacy@obligoboard.com

2. What data we collect

Account data

  • Name, email address, and password (stored as a bcrypt hash — we never store your password in plain text)

Organisation data

  • Organisation name, country, and currency preference
  • Organisation risk profile: size, business type, data categories processed, international transfer status, and privacy documentation status

Usage data

  • Tasks, notes, evidence files, and activity logs you create while using ObligoBoard
  • Assessment wizard answers and resulting compliance risk scores
  • Document generation history (document type, template version, locale, generation date)

Security data

  • Failed login attempts, account lockout timestamps, and IP addresses recorded in security event and activity logs

Contact and support requests

  • Name, email address, and message content when you use our contact form
  • When you send a support request from inside the app while signed in: your name, account email address, your organisation, the page you were on when you opened the form, the app version, and your message content

Invitations

  • Email addresses of people you invite to join your organisation

Public compliance self-assessment

  • Your email address, the answers you give in our free public GDPR self-assessment, and the resulting compliance score
  • A record of each consent you gave (report delivery, marketing, and any other subscription you separately confirmed) and the version of the consent wording you agreed to

3. How we use your data

We process your data to:

  • Provide, maintain, and improve ObligoBoard (legal basis: contract performance)
  • Authenticate your identity and protect your account (legal basis: contract performance and legitimate interest)
  • Process payments and manage your subscription (legal basis: contract performance)
  • Send transactional emails — welcome messages, password resets, team invitations, task reminders (overdue and due-soon digests), and trial expiry reminders (legal basis: contract performance)
  • Respond to your support enquiries (legal basis: contract performance)
  • Detect and prevent fraud and security incidents (legal basis: legitimate interest)

Automated processing

ObligoBoard calculates a compliance risk score for your organisation based on your organisation profile (size, business type, data categories, international transfers, documentation status) and obligation completion state. This score is advisory only — it is not used to restrict your access to any features or make decisions about your account. You can view the factors contributing to your score on the dashboard and update your profile at any time to recalculate it.

We do not use your data for advertising or marketing profiling.

Marketing communications

If you opt in during signup or via your notification settings, we may send you product updates, compliance tips, and news about ObligoBoard. These emails are separate from transactional communications (such as account notifications, password resets, and compliance reminders) which are necessary for the service to function.

Legal basis: Your explicit consent (GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)).

Withdrawal: You can withdraw your consent at any time by:

Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

We use Resend as our email service provider. Your email address and name are shared with Resend for the purpose of delivering emails. Resend's privacy policy is available at resend.com/legal/privacy-policy.

Public compliance self-assessment (lead capture)

Our website offers a free, public GDPR compliance self-assessment. When you ask us to email you your report, we collect and store your email address, your assessment answers, the resulting compliance score, a record of each consent you gave, and the version of the consent wording you agreed to.

We use this data to:

  • Send you the compliance report you requested (legal basis: your consent, GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)).
  • Send you occasional product updates and compliance tips — only if you separately opt in to marketing (legal basis: your consent, GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)). This opt-in is off by default. If you do not give it, we never add you to any marketing list.
  • Send you any email subscription you have separately confirmed — for example, alerts about changes to regulatory deadlines (legal basis: your consent, GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)). Each subscription is optional, off by default, independent of the others and of the marketing opt-in, and is only activated once you confirm it by clicking the link in a confirmation email we send you. The subscriptions on offer are named at the point where you give the consent, and each one tells you what it covers before you agree to it.

Your email address is shared with Resend, our email processor, to deliver the report and — where you separately opted in — our newsletter or any subscription you confirmed. Resend may process this data in the United States under Standard Contractual Clauses (SCCs); see sections 5 and 6 below.

How long we keep it. We keep your assessment answers and compliance score for up to 12 months, after which they are erased (see section 7). If you have not confirmed any email subscription, your whole record — including your email address — is deleted at the same point. If you have confirmed a subscription, we keep your email address, and the record of the consent you gave for it, for as long as that subscription lasts: until you unsubscribe, or until we discontinue the subscription, whichever happens first. Your assessment answers and score are still erased at 12 months either way. If we discontinue a subscription, we delete the email addresses we were holding for it. Once your last subscription ends, your record returns to the ordinary deletion path described above. Where you unsubscribe, we may keep a minimal suppression record — your email address and the date — for no more than 36 months, solely so that we do not contact you again (legal basis: our legitimate interest in honouring your withdrawal and evidencing that we did so, GDPR Article 6(1)(f)). You can withdraw any consent, or ask us to delete your data, at any time by emailing privacy@obligoboard.com.

4. Cookies

We use three essential cookies only. No analytics cookies, no advertising cookies, no tracking cookies. For full details see our Cookie Policy.

5. Third-party services

We share data with the following service providers, solely to operate ObligoBoard. Each processes data under a data processing agreement (DPA) where applicable.

ServicePurposeData location
VercelHosting, blob storage, privacy-friendly analytics (cookieless)EU (Frankfurt)
NeonPostgreSQL databaseEU (Frankfurt, eu-central-1)
StripePayment processing and subscriptionsEU data processing (Stripe infrastructure)
ResendTransactional email deliveryUS
Font AwesomeIcon library (CDN — receives visitor IP addresses)CDN
RailwayExecutes automated cookie/tracker scans of customer websites on the operator's behalfEU (Amsterdam, Netherlands — europe-west4)
Vercel BlobStorage of user-uploaded evidence files and system-generated PDF documents (privacy policy, DPA, and assessment-report exports)EU (Frankfurt)

For the full sub-processor list with transfer-mechanism details (used in our Data Processing Agreement Annex III) see obligoboard.com/sub-processors.

Vercel Analytics is used for basic page-view metrics. It is cookieless and does not track individual users. No personal data is collected.

Google Fonts (IBM Plex Sans & IBM Plex Mono) is self-hosted via Next.js — no data is sent to Google at runtime.

We do not use Google Analytics, advertising pixels, chat widgets, or error-tracking services.

6. International data transfers

Your database and file storage are located in the EU (Frankfurt). Some service providers (Resend, Stripe, Font Awesome) may process data in the United States under appropriate safeguards, including Standard Contractual Clauses (SCCs) and data processing agreements.

7. Data retention

PurposeDataRetention periodWhat ends it
Running your accountAll account, organisation and usage dataFor as long as your account is activeAccount cancellation
Winding down a cancelled accountAll account, organisation and usage data90 days after cancellationThe 90 days elapse
Compliance scoring and audit historyRisk scores, obligation and audit historyFor as long as your organisation existsDeletion of the organisation
Proving which documents you generatedGenerated-document metadata (type, version, date)For as long as your organisation existsDeletion of the organisation
Delivering and supporting your self-assessment reportPublic self-assessment answers and compliance scoreUp to 12 months from collectionThe 12 months elapse — regardless of any subscription you hold
Sending you a subscription you confirmedThe email address you gave with the self-assessment, and the record of the consent you gave for itUntil the subscription ends; if you confirm none, deleted with your answers and score at 12 monthsYou unsubscribe, or we discontinue the subscription — in which case we delete the email addresses we held for it
Making sure we do not email you again after you unsubscribeYour email address and the date you unsubscribedNo more than 36 monthsThe period elapses
Security monitoringSecurity logs (failed logins, lockouts, IP addresses)12 monthsThe 12 months elapse

Where two rows cover the same record, the shorter period governs each field independently: your assessment answers and score are erased at 12 months even where your email address is lawfully retained for a subscription beyond that point.

8. Security

Passwords are hashed with bcrypt. Sessions use signed JWT tokens that expire after 24 hours of inactivity. Password reset tokens expire after 60 minutes. We log security events (failed logins, lockouts) and enforce account lockout after repeated failed attempts.

9. Your rights

Under the EU GDPR and UK GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase your data ("right to be forgotten")
  • Port your data to another service
  • Restrict processing
  • Object to processing

To exercise any of these rights, email privacy@obligoboard.com. We will respond within 30 days.

10. Supervisory authorities

If you believe we have not handled your data correctly, you have the right to lodge a complaint with a supervisory authority:

  • EU users: contact your national Data Protection Authority (DPA).
  • UK users: contact the Information Commissioner's Office (ICO) at ico.org.uk.

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. The "Last updated" date at the top of this page reflects the most recent revision.

12. Contact

For any privacy-related questions, email privacy@obligoboard.com.

Grewing Mirko D.I.Trading as ObligoBoard

Privacy Policy

Version 2026-07-26 · Effective 26 JUL 2026 · Exported — from the current organisation profile

1. Who we are

Grewing Mirko D.I. (an Italian sole trader / Ditta Individuale, trading as ObligoBoard) is the data controller for your personal data. Registered office: Via delle Casine 19, Firenze, Italia. VAT number (P.IVA): IT07214970480.

Data protection contact: privacy@obligoboard.com

2. What data we collect

Account data

  • Name, email address, and password (stored as a bcrypt hash — we never store your password in plain text)

Organisation data

  • Organisation name, country, and currency preference
  • Organisation risk profile: size, business type, data categories processed, international transfer status, and privacy documentation status

Usage data

  • Tasks, notes, evidence files, and activity logs you create while using ObligoBoard
  • Assessment wizard answers and resulting compliance risk scores
  • Document generation history (document type, template version, locale, generation date)

Security data

  • Failed login attempts, account lockout timestamps, and IP addresses recorded in security event and activity logs

Contact form

  • Name, email address, and message content when you use our contact form

Invitations

  • Email addresses of people you invite to join your organisation

Public compliance self-assessment

  • Your email address, the answers you give in our free public GDPR self-assessment, and the resulting compliance score
  • A record of the consent you gave (report consent, and whether you separately opted in to marketing) and the version of the consent wording you agreed to

3. How we use your data

We process your data for the purposes below. The lawful basis for each purpose is set out in the table that follows.

PurposeLawful basisReference
Providing, maintaining and improving ObligoBoardContract performanceArt. 6(1)(b)
Authenticating your identity and protecting your accountContract performance & legitimate interestArt. 6(1)(b), 6(1)(f)
Processing payments and managing your subscriptionContract performanceArt. 6(1)(b)
Sending transactional emails (welcome, password resets, invitations, task and trial reminders)Contract performanceArt. 6(1)(b)
Responding to your support enquiriesContract performanceArt. 6(1)(b)
Detecting and preventing fraud and security incidentsLegitimate interestArt. 6(1)(f)
Marketing communications (only where you opt in)ConsentArt. 6(1)(a)
Public compliance self-assessment — sending your requested report and, where you have separately confirmed one, any email subscription offered alongside itConsentArt. 6(1)(a)

Automated processing. ObligoBoard calculates a compliance risk score for your organisation based on your organisation profile (size, business type, data categories, international transfers, documentation status) and obligation completion state. This score is advisory only — it is not used to restrict your access to any features or make decisions about your account. You can view the factors contributing to your score on the dashboard and update your profile at any time to recalculate it.

We do not use your data for advertising or marketing profiling.

Marketing communications. If you opt in during signup or via your notification settings, we may send you product updates, compliance tips, and news about ObligoBoard. These emails are separate from transactional communications (such as account notifications, password resets, and compliance reminders) which are necessary for the service to function. Legal basis: your explicit consent (GDPR Article 6(1)(a) / UK GDPR Article 6(1)(a)).

Withdrawal. You can withdraw your consent at any time by clicking the “Unsubscribe” link in any newsletter email, or by disabling the “Newsletter” toggle in Settings → Notifications. Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.

We use Resend as our email service provider. Your email address and name are shared with Resend for the purpose of delivering emails. Resend’s privacy policy is available at resend.com/legal/privacy-policy.

Public compliance self-assessment (lead capture). When you ask us to email you your report, we collect and store your email address, your assessment answers, the resulting compliance score, a record of each consent you gave, and the version of the consent wording you agreed to. The optional marketing opt-in and any email subscription offered alongside the assessment are off by default and independent of each other; if you do not opt in, we never add you to that list. A subscription is only activated once you confirm it by clicking the link in a confirmation email, and each subscription is named and described at the point where you give the consent. Your email address is shared with Resend to deliver the report and — where you separately opted in — our newsletter or any subscription you confirmed. We keep the assessment answers and compliance score for up to 12 months, after which they are erased (see section 7). If you confirmed no subscription, your email address is deleted at the same point. If you confirmed one, we keep your email address for as long as that subscription lasts — until you unsubscribe, or until we discontinue the subscription, whichever happens first; if we discontinue a subscription, we delete the email addresses we were holding for it. Where you unsubscribe, we may keep a minimal suppression record (your email address and the date) for no more than 36 months, solely so that we do not contact you again. You can withdraw any consent or ask us to delete your data at any time by emailing privacy@obligoboard.com.

4. Cookies

We use three essential cookies only. No analytics cookies, no advertising cookies, no tracking cookies. For full details see our Cookie Policy.

5. Third-party services

We share data with the following service providers, solely to operate ObligoBoard. Each processes data under a data processing agreement (DPA) where applicable.

ServicePurposeData location
VercelHosting, blob storage, privacy-friendly analytics (cookieless)EU (Frankfurt)
NeonPostgreSQL databaseEU (Frankfurt, eu-central-1)
StripePayment processing and subscriptionsEU data processing (Stripe infrastructure)
ResendTransactional email deliveryUS
Font AwesomeIcon library (CDN — receives visitor IP addresses)CDN
RailwayExecutes automated cookie/tracker scans of customer websites on the operator's behalfEU (Amsterdam, Netherlands — europe-west4)
Vercel BlobStorage of user-uploaded evidence files and system-generated PDF documents (privacy policy, DPA, and assessment-report exports)EU (Frankfurt)

For the full sub-processor list with transfer-mechanism details (used in our Data Processing Agreement Annex III) see obligoboard.com/sub-processors.

Vercel Analytics is used for basic page-view metrics. It is cookieless and does not track individual users. No personal data is collected.

Google Fonts (IBM Plex Sans & IBM Plex Mono) is self-hosted via Next.js — no data is sent to Google at runtime.

We do not use Google Analytics, advertising pixels, chat widgets, or error-tracking services.

6. International data transfers

Your database and file storage are located in the EU (Frankfurt). Some service providers (Resend, Stripe, Font Awesome) may process data in the United States under appropriate safeguards, including Standard Contractual Clauses (SCCs) and data processing agreements.

7. Data retention

8. Security

Passwords are hashed with bcrypt. Sessions use signed JWT tokens that expire after 24 hours of inactivity. Password reset tokens expire after 60 minutes. We log security events (failed logins, lockouts) and enforce account lockout after repeated failed attempts.

9. Your rights

Under the EU GDPR and UK GDPR, you have the right to:

To exercise any of these rights, email privacy@obligoboard.com. We will respond within 30 days.

10. Supervisory authorities

If you believe we have not handled your data correctly, you have the right to lodge a complaint with a supervisory authority:

11. Changes to this policy

We may update this policy from time to time. Material changes will be communicated via email or an in-app notice. The version stamp at the top of this document reflects the most recent revision.

12. Contact

For any privacy-related questions, email privacy@obligoboard.com.