Privacy Notice
Notice version: privacy-notice-2026-07-13
Effective date: 13 July 2026
Summary
This notice explains how Obliga collects and uses personal data relating to visitors of obliga.co.uk, recipients of our business-to-business outreach, and invited practices using the hosted pilot at app.obliga.co.uk. It is written in plain British English and applies from the effective date above. Earlier notices are replaced by this version.
This notice describes what the current pilot actually does. It distinguishes data for which Obliga is the controller from client and case data that an invited practice controls and Obliga processes on that practice's behalf.
1. Data controller and contact
The controller responsible for the processing described in this notice is Ivo Stoykov trading as Obliga.
Privacy contact: hello@obliga.co.uk
Where this notice refers to an invited practice acting as its own controller, that practice is responsible for its own client and case data and for its own privacy obligations to its clients. Obliga acts as a processor on behalf of that practice only to the extent described in section 5.
2. What this notice covers
This notice covers personal data processed in two roles:
- Obliga as controller — public access requests; reviewed B2B outreach and prospect records; invited firm users, firm-bound invitations, authentication and account administration; service communications; feedback; product usage and audit events; support and security logs; and Cloudflare Web Analytics and Turnstile on the public site.
- Obliga as processor for an invited practice — practice-controlled company, case, contact, missing-item, secure upload, and file records, with the practice as controller for that data.
3. Public access requests (Obliga as controller)
When a visitor submits the public request-access form on obliga.co.uk, Obliga processes:
- full name;
- work email (stored in lower case);
- practice name;
- professional role (owner/manager/accountant/other);
- the selected primary workflow blocker;
- practice website (optional);
- additional message (optional);
- the consent value recorded from the on-page checkbox;
- submission timestamp;
- a salted SHA-256 hash of the visitor's IP address (the raw IP is not stored);
- the request's user agent;
- review workflow status and timestamps, operator review note, and an export timestamp used when an approved request is handed off for invitation.
Purpose: to evaluate whether the practice is a fit for the hosted pilot, to respond to the request, to operate the request-access review workflow, and to prevent fraud and automated abuse.
Lawful basis: the on-page consent checkbox records the visitor's specific consent to be contacted about that pilot request. Obliga processes the submitted contact details under that consent for the contact purpose, and under legitimate interests for fit assessment, request and review records, and fraud/abuse prevention and service security. The checkbox consent is specific to contact about the pilot request; it is not consent for unrelated marketing or for unrelated processing.
Withdrawing consent: a visitor can withdraw consent for further contact about their request at any time by emailing hello@obliga.co.uk. Withdrawal does not affect the lawfulness of processing before the withdrawal. Obliga may still need to keep minimal records under legitimate interests for fraud prevention, audit, and legal-defence purposes.
Submitted requests are stored in a Cloudflare D1 database used only for this intake and review workflow. They are not published or shared with third parties for marketing.
Turnstile verification flow: the request-access form includes a Cloudflare Turnstile token. The Pages Function sends the Turnstile token together with the visitor's raw IP address to Cloudflare's siteverify service for verification. Neither the Turnstile token nor the raw IP address is stored. After verification, Obliga stores only the salted SHA-256 hash of the IP address and the user agent described above.
4. B2B outreach and prospect records (Obliga as controller)
Obliga conducts limited, targeted business-to-business outreach to UK accountancy practices that appear to fit the pilot's target profile. Outreach records may include practice name, professional role, professional or business contact details, source reference, review status, and notes from prior interactions.
Purpose: to identify practices that may benefit from the pilot and to invite them in a targeted, low-volume way.
UK GDPR lawful basis: Obliga relies on legitimate interests for processing B2B outreach records. The interest is narrowly scoped: identifying and inviting practices that plausibly benefit from a UK accountancy workflow tool, and recording the source and status of each contact for review and suppression.
PECR and electronic marketing: the Privacy and Electronic Communications Regulations (PECR) govern the sending of electronic mail for marketing, separately from the UK GDPR lawful basis. Under PECR, electronic marketing may be sent to corporate subscribers (limited companies, LLPs, and similar bodies) without prior consent, provided the recipient is given a clear opt-out on every message and the address was obtained in the course of a commercial relationship or public professional listing. Sole traders and most ordinary partnerships are individual subscribers under PECR; electronic marketing to them requires PECR consent or a valid soft opt-in. Obliga's outreach policy treats sole traders and personal email addresses more cautiously than corporate business addresses and suppresses any recipient who opts out.
5. Data processed for an invited practice as controller
When an invited practice uses the hosted pilot, the practice typically creates or imports records about its own clients, companies, contacts, blocked cases, missing items, and case activity. That client and case data is controlled by the practice, not by Obliga. Obliga processes it on the practice's behalf as a processor for the agreed pilot purpose and follows the practice's reasonable instructions within the pilot.
This notice does not assign Obliga a controller lawful basis for the practice's client data. Practices remain responsible for telling their own clients how their data is handled, for their own lawful bases, and for their own client-facing privacy notices. Pilot terms are set out on the Pilot Terms page.
The hosted pilot records, used under the practice's control, typically include:
- tracked companies, blocked cases, case labels, client/contact context, missing-item notes, and case timeline/audit entries;
- generated draft outputs (chase messages, checklists, status summaries) that the practitioner reviews before use;
- secure upload requests created by the practitioner and the uploaded files and file metadata received through those requests;
- audit evidence for those records, such as file download and delete events.
Draft outputs are prepared for practitioner review and copy/paste into the practitioner's own workflow. The pilot does not send chase messages to clients automatically, and it does not automatically deliver generated drafts to clients. The practitioner decides whether, when, and how to use any draft.
6. Firm-user account, authentication, and usage data (Obliga as controller)
For an invited practice, Obliga — as controller — processes the following account and operational data, separate from the practice's controlled client/case/file data:
- firm identity and firm-bound invitation state, including operator-managed firm access links;
- firm user login email and short-lived login-code state used for authentication;
- account administration, including trial start and trial expiry;
- product usage events and feedback submissions;
- support communications and security logs;
- service communications relating to the pilot.
Purpose: to operate the hosted pilot, authenticate invited firm users, administer accounts, maintain service and security, improve the pilot, and respond to support and feedback.
Lawful basis: legitimate interests for operating the pilot, authenticating firm users, account administration, securing the service, improving the product, handling support, and processing feedback and product usage data. The invited practice's acceptance of the Pilot Terms governs the pilot access; Obliga relies on legitimate interests rather than Article 6(1)(b) for the firm user's account and authentication data because the user may be acting on behalf of the contracting practice rather than as the contracting party.
7. Sources of personal data
Obliga obtains personal data from the following sources:
- Direct submissions: the public request-access form, email replies to hello@obliga.co.uk, feedback submitted in the app, and direct replies to outreach messages.
- Invited practices: firms accepted into the pilot enter their own firm, company, contact, and case data into the hosted pilot.
- Public professional and business sources: publicly available accountancy directories and professional listings used to identify and review outreach prospects.
- Companies House: public company information (name, number, status, accounts and confirmation statement dates) retrieved via the Companies House API for tracked companies.
- Prior interactions: notes and status records from previous outreach, replies, and pilot conversations.
8. Recipients and providers
Obliga does not sell personal data. Personal data is shared only with the recipients described here and with the providers that run the current pilot infrastructure.
Known deployed providers used by the current pilot, described by function:
- Cloudflare — public website hosting, request-access backend (Pages and D1), bot protection (Turnstile), web analytics, and object storage for secure uploads (Cloudflare R2).
- Neon — hosted PostgreSQL database for the pilot application.
- Northflank — application hosting platform for the pilot service.
- Purelymail — outbound email delivery for pilot login codes and service messages.
- Companies House API — source of public company information for tracked companies.
The public site uses Cloudflare Turnstile for bot verification on the request-access form. Turnstile may process a visitor's browser and network information to assess whether the submission is from a real person; the verification flow is described in section 3.
9. Direct marketing objection and opt-out
You have the right to object to direct marketing at any time, including B2B outreach, and Obliga will honour that objection. To opt out, email hello@obliga.co.uk with "Marketing opt-out" in the subject line, or reply to any outreach message asking to stop.
When you opt out, Obliga normally retains a minimal do-not-contact record — your email address and the source of the opt-out — even when other marketing data are erased, because that record is needed to honour the objection and to ensure future outreach and follow-ups are not sent to you. That record is not used for marketing. Any erasure request relating to the do-not-contact record is assessed under the statutory conditions and exceptions that apply to retaining data necessary to uphold an absolute objection.
10. Retention
- Public access requests are retained for the request-access review workflow and for evidence that the request was handled.
- Login codes are short-lived; a code expires shortly after issue and can be used only once.
- Upload requests have an expiry date set when the practitioner creates them; an expired or revoked request stops accepting new uploads but does not by itself delete files already received.
- Uploaded file bytes are removed when a practitioner deletes the file from the case workflow. Metadata and audit entries about the file (filename, checksum, upload, download, and delete evidence) are retained after the file bytes are deleted.
- B2B outreach records are retained while outreach and follow-up are active, plus the minimal do-not-contact record described in section 9.
- Product usage, audit, and security logs are retained for pilot operation and security investigation.
11. Your rights
Under UK GDPR you have the following rights, subject to the conditions and exceptions set out in the law. They are not absolute: some rights apply only in certain situations, some can be restricted, and some are balanced against Obliga's and others' legitimate grounds.
- Access — ask what personal data Obliga holds about you and receive a copy.
- Rectification — ask for inaccurate or incomplete personal data to be corrected.
- Erasure — ask for personal data to be deleted where there is no compelling reason to keep it.
- Restriction — ask for processing to be restricted in certain circumstances.
- Portability — receive some personal data you provided in a structured, machine-readable format, where applicable.
- Objection — object to processing based on legitimate interests, including a absolute right to object to direct marketing at any time.
- Withdrawal of consent — where consent is the genuine basis for a specific activity, withdraw consent at any time without affecting the lawfulness of processing before the withdrawal.
For practice-controlled client data processed on a practice's behalf, rights requests about that client data should normally be directed to the practice, which is the controller for that data. Obliga will assist practices where required by the processing relationship.
To exercise any of these rights, email hello@obliga.co.uk. Obliga may need to verify your identity before responding.
12. Right to complain to the ICO
If you are not satisfied with how Obliga handles a concern about your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO). The ICO's official complaint guidance is at https://ico.org.uk/make-a-complaint/. Contacting the ICO does not remove your right to use other remedies.
13. Website analytics and bot protection
The public site uses Cloudflare Web Analytics, which provides aggregate page-visit and performance measurement. Cloudflare Web Analytics does not use cookies for behavioural advertising. It is enabled through Cloudflare's automatic injection for the obliga.co.uk hostname; the repository does not contain a manual analytics beacon or token.
The request-access form uses Cloudflare Turnstile for bot verification. The verification flow is described in section 3.
14. Changes to this notice
When this notice changes, Obliga will update the version identifier and effective date at the top of the page and publish the new version at https://obliga.co.uk/privacy. Material changes will be reflected before, or at the same time as, the related change in processing.