1Who we are

1.1oboloo Limited is a company registered in England and Wales under company number 12420854, with its registered office at 7 Bell Yard, London, WC2A 2JR (“oboloo”, “we”, “us”).

1.2This policy covers oboloo.com, oboloo.app and every Customer subdomain, the Supplier Portal, help.oboloo.com, academy.oboloo.com and our other subdomains (together the “websites”), and the services we provide through them (the “Services”).

1.3Questions, requests and complaints about personal data should be sent to support@oboloo.app with the subject line “Privacy”, or by post to the address above.

Back to top

2Our two roles

We are the controller forWe are a processor for
Visitors to our websites. People who contact us, book a demo or sign up for marketing. Registration, login, security and billing details of people who use oboloo through a customer account. Support tickets. Product usage and analytics. oboloo Academy learners. Login and security data of Supplier Users.Everything a customer and its suppliers put into oboloo: supplier records and contacts, questionnaires, certificates, documents, contracts, sourcing responses and savings records. The customer decides why and how this data is used. Our Data Processing Agreement at oboloo.com/dpa governs it.

If you want to exercise your rights over data a customer holds in oboloo, contact that customer first. We will help them respond.

Back to top

3Personal data we collect

CategoryExamplesWhere it comes from
Identity and contactName, job title, employer, work email address, work telephone numberYou, your employer, Microsoft single sign-on
Account and securityUsername, hashed password, two-factor authentication settings, SSO identifiers, role and permissions, login times, IP address, device and browser, session and new-device sign-in events, change logsYou, and automatically when you use the Services
BillingBilling contact details, invoices, VAT number, card type and last four digits. We never see or store full card numbers; our payment provider Stripe does.You, Stripe
Usage and analyticsPages and features used, clicks, performance data, session replays (which can capture what was on screen)Automatically when you use the Services
SupportThe content of tickets, emails and chats, and any screenshots you sendYou
Marketing and salesEmail engagement, demo bookings, event sign-ups, notes in our CRM, interactions with our social mediaYou, publicly available business sources, our CRM
Supplier PortalName, email address, employer, authentication codes issued and used, submission timesThe customer that invites you, and you
oboloo AcademyName, email address, course progress, quiz results, certificates issuedYou
Website visitorsIP address, cookie identifiers, pages visited, referring site, device and browserAutomatically, through cookies (section 11)

We do not ask for, and you should not give us, special category data (such as health, ethnicity or trade union membership) or criminal offence data.

Back to top

4How we use personal data and our lawful bases

PurposeLawful basis
Creating and running your account, providing the Services, support and billingPerformance of our contract with you or your organisation; our legitimate interest in serving the organisation you work for
Keeping the Services secure, preventing fraud and abuse, enforcing our Acceptable Use PolicyLegitimate interests; legal obligation
Understanding how the Services are used so we can fix problems and improve themLegitimate interests. We aggregate and anonymise wherever we can
Sending service messages such as invoices, renewal notices, security alerts and changes to our termsPerformance of contract; legitimate interests
Responding to enquiries and demo requestsLegitimate interests; steps taken at your request before a contract
Sending marketing about oboloo to business contactsLegitimate interests, and consent where the law requires it. You can opt out at any time (section 5)
Running oboloo Academy and issuing certificatesPerformance of contract; legitimate interests
Complying with law, including tax, accounting and regulatory requestsLegal obligation
Establishing, exercising or defending legal claimsLegitimate interests
A sale, merger or reorganisation of our businessLegitimate interests

Where we rely on legitimate interests we have balanced them against your rights and interests. You can object to any processing based on legitimate interests (section 9).

Back to top

5Who we share personal data with

5.1Service providers that process data on our instructions. These include: IONOS (application and database hosting); Amazon Web Services (document storage); Cloudflare (network security); Stripe (payments); Twilio SendGrid (email delivery); ThriveDesk (help centre and support tickets); Mixpanel (product analytics, EU region); HubSpot (CRM and marketing email); Candu (in-app guides); Microsoft (single sign-on and our own email); Webflow (website hosting); and OpenAI and Anthropic (AI features, as described at oboloo.com/ai). Each is bound by a contract that limits what it can do with the data.

5.2Your organisation. If you use oboloo through a customer account, your organisation's administrators can see your account details, role and activity in the Services.

5.3The customer that invited you. If you are a Supplier User, the customer that invited you sees what you submit through the Supplier Portal.

5.4Professional advisers, insurers and auditors, under confidentiality.

5.5Regulators, courts, law enforcement and other authorities where the law requires or allows it.

5.6A buyer or investor, and their advisers, if we sell, merge or reorganise all or part of our business, under confidentiality. Your data would continue to be used in line with this policy.

5.7We do not sell personal data and we do not share it with third parties for their own marketing. To stop marketing from us, use the unsubscribe link in any email or write to support@oboloo.app. We will still send you service messages about your account.

Back to top

6International transfers

We are based in the United Kingdom. Some of the service providers in section 5 are in the United States or process data there. When personal data leaves the UK or the European Economic Area we rely on an adequacy decision, the UK extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, as applicable. Transfers between the UK and the EEA are covered by adequacy decisions for as long as they remain in force. You can ask for a copy of the relevant safeguards at support@oboloo.app.

Back to top

7How long we keep personal data

Account details of customer users and Supplier Users
While the account is active, then deleted within six months of the account closing
Data we hold as a processor for a customer
As set out in the Data Processing Agreement: deleted within six months of the customer's subscription ending
Billing records and invoices
Six years after the end of the financial year they relate to, for tax and accounting law
Support tickets
Three years after the ticket is closed
Marketing contacts
Until you opt out, or 24 months after your last engagement with us
Security and audit logs
12 months
oboloo Academy records
While you are enrolled, and certificate records for three years so certificates can be verified
Website analytics
For the cookie lifetimes in section 11, then in aggregated form only
Backups
Overwritten in our normal backup rotation after deletion from live systems

We keep data for longer where the law requires it or where it is needed for a legal claim.

Back to top

8Security

8.1Our security measures are described at oboloo.com/data-and-security. They include hosting in ISO 27001 certified data centres, a separate database for every customer, encryption in transit and at rest, two-factor authentication and Microsoft single sign-on, role-based and record-level access controls, backups every 24 hours and continuous penetration testing with a published certificate.

8.2Our support staff may access a customer's environment to provide support, investigate problems and maintain the Services. Access is limited to what is needed and is subject to confidentiality obligations.

8.3You are responsible for keeping your login details secure and for telling us immediately at support@oboloo.app if you think your account has been compromised.

8.4If a personal data breach affects you, we will tell you and the relevant regulator where the law requires it, and we will tell affected customers as set out in the Data Processing Agreement.

Back to top

9Your rights

9.1Under UK and EU data protection law you have the right to: (a) access the personal data we hold about you; (b) have inaccurate data corrected; (c) have your data erased in certain circumstances; (d) restrict how we use it in certain circumstances; (e) receive the data you gave us in a portable format; (f) object to processing based on legitimate interests, and to direct marketing at any time; (g) withdraw consent where we rely on it; and (h) not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you.

9.2To exercise a right, email support@oboloo.app with the subject line “Privacy”. We may need to verify your identity. We will respond within one month, or tell you if we need up to two further months for a complex request. There is no charge unless a request is clearly unfounded or excessive.

9.3If your request concerns data we hold as a processor for a customer, we will pass it to that customer and help them respond.

9.4If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. If you are in the EEA you can complain to your local supervisory authority. We would welcome the chance to resolve your concern first.

Back to top

10Automated decision-making and AI

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The Services include AI features that produce summaries for a person to review. How they work, which provider we use and what data is involved is explained at oboloo.com/ai.

Back to top

11Cookies and similar technologies

11.1What they are. Cookies are small files placed on your device by a website. We also use similar technologies such as local storage, pixels in emails that tell us whether an email was opened, and session replay within the Services.

11.2Consent. When you first visit oboloo.com you are shown a cookie banner. Strictly necessary cookies are set without consent because the websites cannot work without them. Analytics and marketing cookies are set only if you accept them. You can change your choice at any time through the cookie settings link on the website or through your browser settings. Blocking cookies may stop parts of the websites or Services working.

11.3Categories.

CategoryPurposeExamples
Strictly necessaryLogging you in, keeping you logged in, protecting forms against forgery, security checks, remembering your cookie choiceoboloo session cookie and XSRF-TOKEN (session); Cloudflare __cf_bm (30 minutes); cookie consent preference (12 months)
FunctionalRemembering your language and display settingsLanguage and layout preferences (12 months)
Analytics and performanceUnderstanding how the websites and Services are used so we can improve themMixpanel mp_* cookies (12 months); HubSpot __hstc and hubspotutk (6 months), __hssc (30 minutes), __hssrc (session)

11.4Session replay. Within the Services we may record how pages are used, including mouse movement and clicks, to find and fix usability problems. Sensitive fields, including passwords and payment details, are masked and are never recorded.

11.5Third-party cookies. Some pages embed content from third parties, such as our status page, security certificate and video tutorials. Those providers may set their own cookies under their own policies.

11.6Managing cookies. Most browsers let you block or delete cookies. See aboutcookies.org for instructions. Email tracking can be disabled by turning off images in your email client.

Back to top

12Children

The websites and Services are for business use and are not directed at anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact support@oboloo.app and we will delete it.

Back to top

13Third-party websites

Our websites link to third-party sites, including social media, our status page and our security certificate. We do not control those sites and this policy does not apply to them. Read their privacy policies before giving them your data.

Back to top

14Changes to this policy

We may update this policy from time to time. The current version, with its version number and date, is always published at oboloo.com/privacy-cookies-policy. If a change materially affects how we use your data, we will tell you by email or by a notice on the websites or in the Services before it takes effect.

Back to top

15Contact and version history

Email: support@oboloo.app (subject line “Privacy”). Post: oboloo Limited, 7 Bell Yard, London, WC2A 2JR.

VersionDateSummary of changes
4.0October 2026Full rewrite. Controller and processor roles separated, with the DPA referenced. Lawful bases, sharing, retention, international transfers and data subject rights added. Cookie categories and named cookies listed. Updated to UK GDPR and the Data Protection Act 2018. Contact updated to support@oboloo.app.
3.0December 2025Previous version.

Approved by the Board of Directors of oboloo Limited in October 2026. This policy applies to oboloo.com, oboloo.app and all related subdomains operated by oboloo Limited.

Back to top