Skip to content

Legal

Privacy policy

Written to be read. If anything here is unclear, ask us and we will clarify it in the document rather than in an email.

Last updated 30 July 2026

Obcend processes personal data in two distinct capacities: as a controller for our own website and business contacts, and as a processor when carrying out audits on behalf of a customer. The sections below distinguish between the two wherever the treatment differs.

1. Scope

This policy covers personal data processed through the Obcend website and through audit engagements carried out on behalf of a customer organisation.

Where Obcend processes data on a customer's instruction as part of an audit, the customer is the controller and Obcend acts as processor under a separate data processing agreement.

2. Data we collect

Website: information you submit through contact and demo forms — name, work email, organisation, and the content of your message. We do not use advertising trackers or third-party analytics profiling on this site.

Engagements: credentials supplied for authenticated crawls, contact details of nominated personnel, and any personal data incidentally present in captured page content.

3. How we use it

To respond to your enquiry, to scope and deliver an audit, and to meet legal and contractual obligations.

We do not sell personal data. We do not use customer content or captured artifacts to train machine learning models, and we do not share them between customers under any circumstances.

4. Retention

Enquiry records are retained for 24 months. Audit artifacts follow the retention schedule published on our security page, and shorter periods can be agreed per engagement.

Deletion requests are actioned across primary storage and backups within the window stated in the applicable agreement.

5. Sharing and subprocessors

We use a limited set of infrastructure subprocessors for hosting, storage, and email delivery. A current list is available on request and forms part of our data processing agreement.

We disclose personal data to authorities only where legally compelled, and we notify the affected customer unless prohibited from doing so.

6. Your rights

Depending on your jurisdiction you may have rights of access, rectification, erasure, restriction, portability, and objection. Requests can be made through the contact page and are answered within one month.

If you are dissatisfied with our response you may complain to your local supervisory authority.

7. Security

Data is encrypted in transit and at rest. Internal access is role-based, logged, and limited to personnel supporting the relevant engagement. Credentials supplied for authenticated crawls are stored encrypted and are revocable at any time.

8. Changes

Material changes to this policy are notified to active customers before they take effect. The date at the top of this page reflects the most recent revision.