Legal
Privacy policy
Written to be read. If anything here is unclear, ask us and we will clarify it in the document rather than in an email.
Last updated 30 July 2026
Obcend processes personal data in two distinct capacities: as a controller for our own website and business contacts, and as a processor when carrying out audits on behalf of a customer. The sections below distinguish between the two wherever the treatment differs.
1. Scope
This policy covers personal data processed through the Obcend website and through audit engagements carried out on behalf of a customer organisation.
Where Obcend processes data on a customer's instruction as part of an audit, the customer is the controller and Obcend acts as processor under a separate data processing agreement.
2. Data we collect
Website: information you submit through contact and demo forms — name, work email, organisation, and the content of your message. We do not use advertising trackers or third-party analytics profiling on this site.
Engagements: credentials supplied for authenticated crawls, contact details of nominated personnel, and any personal data incidentally present in captured page content.
3. How we use it
To respond to your enquiry, to scope and deliver an audit, and to meet legal and contractual obligations.
We do not sell personal data. We do not use customer content or captured artifacts to train machine learning models, and we do not share them between customers under any circumstances.
4. Retention
Enquiry records are retained for 24 months. Audit artifacts follow the retention schedule published on our security page, and shorter periods can be agreed per engagement.
Deletion requests are actioned across primary storage and backups within the window stated in the applicable agreement.
6. Your rights
Depending on your jurisdiction you may have rights of access, rectification, erasure, restriction, portability, and objection. Requests can be made through the contact page and are answered within one month.
If you are dissatisfied with our response you may complain to your local supervisory authority.
7. Security
Data is encrypted in transit and at rest. Internal access is role-based, logged, and limited to personnel supporting the relevant engagement. Credentials supplied for authenticated crawls are stored encrypted and are revocable at any time.
8. Changes
Material changes to this policy are notified to active customers before they take effect. The date at the top of this page reflects the most recent revision.