Privacy Notice

Notice version: privacy-notice-2026-07-13
Effective date: 13 July 2026

Summary

This notice explains how Obliga collects and uses personal data relating to visitors of obliga.co.uk, recipients of our business-to-business outreach, and invited practices using the hosted pilot at app.obliga.co.uk. It is written in plain British English and applies from the effective date above. Earlier notices are replaced by this version.

This notice describes what the current pilot actually does. It distinguishes data for which Obliga is the controller from client and case data that an invited practice controls and Obliga processes on that practice's behalf.

1. Data controller and contact

The controller responsible for the processing described in this notice is Ivo Stoykov trading as Obliga.

Privacy contact: hello@obliga.co.uk

Where this notice refers to an invited practice acting as its own controller, that practice is responsible for its own client and case data and for its own privacy obligations to its clients. Obliga acts as a processor on behalf of that practice only to the extent described in section 5.

2. What this notice covers

This notice covers personal data processed in two roles:

3. Public access requests (Obliga as controller)

When a visitor submits the public request-access form on obliga.co.uk, Obliga processes:

Purpose: to evaluate whether the practice is a fit for the hosted pilot, to respond to the request, to operate the request-access review workflow, and to prevent fraud and automated abuse.

Lawful basis: the on-page consent checkbox records the visitor's specific consent to be contacted about that pilot request. Obliga processes the submitted contact details under that consent for the contact purpose, and under legitimate interests for fit assessment, request and review records, and fraud/abuse prevention and service security. The checkbox consent is specific to contact about the pilot request; it is not consent for unrelated marketing or for unrelated processing.

Withdrawing consent: a visitor can withdraw consent for further contact about their request at any time by emailing hello@obliga.co.uk. Withdrawal does not affect the lawfulness of processing before the withdrawal. Obliga may still need to keep minimal records under legitimate interests for fraud prevention, audit, and legal-defence purposes.

Submitted requests are stored in a Cloudflare D1 database used only for this intake and review workflow. They are not published or shared with third parties for marketing.

Turnstile verification flow: the request-access form includes a Cloudflare Turnstile token. The Pages Function sends the Turnstile token together with the visitor's raw IP address to Cloudflare's siteverify service for verification. Neither the Turnstile token nor the raw IP address is stored. After verification, Obliga stores only the salted SHA-256 hash of the IP address and the user agent described above.

4. B2B outreach and prospect records (Obliga as controller)

Obliga conducts limited, targeted business-to-business outreach to UK accountancy practices that appear to fit the pilot's target profile. Outreach records may include practice name, professional role, professional or business contact details, source reference, review status, and notes from prior interactions.

Purpose: to identify practices that may benefit from the pilot and to invite them in a targeted, low-volume way.

UK GDPR lawful basis: Obliga relies on legitimate interests for processing B2B outreach records. The interest is narrowly scoped: identifying and inviting practices that plausibly benefit from a UK accountancy workflow tool, and recording the source and status of each contact for review and suppression.

PECR and electronic marketing: the Privacy and Electronic Communications Regulations (PECR) govern the sending of electronic mail for marketing, separately from the UK GDPR lawful basis. Under PECR, electronic marketing may be sent to corporate subscribers (limited companies, LLPs, and similar bodies) without prior consent, provided the recipient is given a clear opt-out on every message and the address was obtained in the course of a commercial relationship or public professional listing. Sole traders and most ordinary partnerships are individual subscribers under PECR; electronic marketing to them requires PECR consent or a valid soft opt-in. Obliga's outreach policy treats sole traders and personal email addresses more cautiously than corporate business addresses and suppresses any recipient who opts out.

5. Data processed for an invited practice as controller

When an invited practice uses the hosted pilot, the practice typically creates or imports records about its own clients, companies, contacts, blocked cases, missing items, and case activity. That client and case data is controlled by the practice, not by Obliga. Obliga processes it on the practice's behalf as a processor for the agreed pilot purpose and follows the practice's reasonable instructions within the pilot.

This notice does not assign Obliga a controller lawful basis for the practice's client data. Practices remain responsible for telling their own clients how their data is handled, for their own lawful bases, and for their own client-facing privacy notices. Pilot terms are set out on the Pilot Terms page.

The hosted pilot records, used under the practice's control, typically include:

Draft outputs are prepared for practitioner review and copy/paste into the practitioner's own workflow. The pilot does not send chase messages to clients automatically, and it does not automatically deliver generated drafts to clients. The practitioner decides whether, when, and how to use any draft.

6. Firm-user account, authentication, and usage data (Obliga as controller)

For an invited practice, Obliga — as controller — processes the following account and operational data, separate from the practice's controlled client/case/file data:

Purpose: to operate the hosted pilot, authenticate invited firm users, administer accounts, maintain service and security, improve the pilot, and respond to support and feedback.

Lawful basis: legitimate interests for operating the pilot, authenticating firm users, account administration, securing the service, improving the product, handling support, and processing feedback and product usage data. The invited practice's acceptance of the Pilot Terms governs the pilot access; Obliga relies on legitimate interests rather than Article 6(1)(b) for the firm user's account and authentication data because the user may be acting on behalf of the contracting practice rather than as the contracting party.

7. Sources of personal data

Obliga obtains personal data from the following sources:

8. Recipients and providers

Obliga does not sell personal data. Personal data is shared only with the recipients described here and with the providers that run the current pilot infrastructure.

Known deployed providers used by the current pilot, described by function:

The public site uses Cloudflare Turnstile for bot verification on the request-access form. Turnstile may process a visitor's browser and network information to assess whether the submission is from a real person; the verification flow is described in section 3.

9. Direct marketing objection and opt-out

You have the right to object to direct marketing at any time, including B2B outreach, and Obliga will honour that objection. To opt out, email hello@obliga.co.uk with "Marketing opt-out" in the subject line, or reply to any outreach message asking to stop.

When you opt out, Obliga normally retains a minimal do-not-contact record — your email address and the source of the opt-out — even when other marketing data are erased, because that record is needed to honour the objection and to ensure future outreach and follow-ups are not sent to you. That record is not used for marketing. Any erasure request relating to the do-not-contact record is assessed under the statutory conditions and exceptions that apply to retaining data necessary to uphold an absolute objection.

10. Retention

11. Your rights

Under UK GDPR you have the following rights, subject to the conditions and exceptions set out in the law. They are not absolute: some rights apply only in certain situations, some can be restricted, and some are balanced against Obliga's and others' legitimate grounds.

For practice-controlled client data processed on a practice's behalf, rights requests about that client data should normally be directed to the practice, which is the controller for that data. Obliga will assist practices where required by the processing relationship.

To exercise any of these rights, email hello@obliga.co.uk. Obliga may need to verify your identity before responding.

12. Right to complain to the ICO

If you are not satisfied with how Obliga handles a concern about your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO). The ICO's official complaint guidance is at https://ico.org.uk/make-a-complaint/. Contacting the ICO does not remove your right to use other remedies.

13. Website analytics and bot protection

The public site uses Cloudflare Web Analytics, which provides aggregate page-visit and performance measurement. Cloudflare Web Analytics does not use cookies for behavioural advertising. It is enabled through Cloudflare's automatic injection for the obliga.co.uk hostname; the repository does not contain a manual analytics beacon or token.

The request-access form uses Cloudflare Turnstile for bot verification. The verification flow is described in section 3.

14. Changes to this notice

When this notice changes, Obliga will update the version identifier and effective date at the top of the page and publish the new version at https://obliga.co.uk/privacy. Material changes will be reflected before, or at the same time as, the related change in processing.