REVIEW-READY DRAFT — GBOS-specific and factual, but NOT final and NOT legal advice. Must be confirmed by a qualified solicitor before GBOS relies on it (see the [SOLICITOR TO CONFIRM] items).
Privacy Policy
Version 2026-08-r1 · Effective 2026-08-02
How GBOS collects, uses, shares and protects personal data.
1. Who we are
GBOS (the “Company”, “we”, “us”) is the controller of personal data about our account holders, prospects and website visitors. For personal data contained in Customer Data that we process on your behalf, you are the controller and we are the processor (see the DPA).
Data-protection contact: privacy@[YOUR-DOMAIN]. [SOLICITOR TO CONFIRM] whether a statutory Data Protection Officer and/or a UK/EU representative must be appointed for the platform’s scale and processing, and insert their details.
2. What we collect
Account data: name, work email, workspace/organisation details, and authentication data (passwords are stored hashed by our auth provider; MFA secrets and backup codes are stored encrypted).
Customer Data: the business records you input (e.g. contacts, finance/ledger entries, documents). We process these under your instructions per the DPA and aim not to use them for our own purposes.
Usage, device and log data; billing metadata; support communications; consent records (including the document version, timestamp, and — where you provide them — IP address and user agent, retained as proof of consent).
Auth email delivery status is recorded using only an opaque token reference, never the verification/reset token itself.
We aim to minimise personal data and do not sell it.
3. Why we use it (lawful bases)
To provide, secure and support the Service (performance of a contract); to comply with legal obligations; and, where applicable, for legitimate interests such as product improvement, fraud prevention and platform security, balanced against your rights. Marketing communications are sent only with consent where required. [SOLICITOR TO CONFIRM] the lawful-basis mapping and any legitimate-interests assessments.
4. Sharing and sub-processors
We share personal data with vetted sub-processors that help us run the Service (for example hosting and database providers) under written data-processing terms. Our current sub-processors are listed on the Sub-processors page, which we keep up to date.
We may disclose data where legally required, and to professional advisers, in each case under appropriate safeguards.
5. Retention
We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymise it. Workspace deletion removes tenant-scoped data and anonymises the workspace record, leaving an immutable deletion record.
The append-only audit trail is retained as a tamper-evident record. [SOLICITOR TO CONFIRM] concrete retention periods, including any minimum statutory retention for financial and tax records and the retention applied to audit/consent records.
6. International transfers
GBOS is offered globally with the UK as its primary jurisdiction. Personal data may be processed in the regions where our hosting and database providers operate. Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards. [SOLICITOR TO CONFIRM] the transfer mechanism (UK IDTA / EU SCCs), and the owner must pin the hosting (Vercel) and database (Neon) regions to match the residency commitments made to customers.
7. Your rights
Subject to law, you may access, correct, export, restrict, object to, or delete your personal data. Use the in-product data export and account deletion tools, or contact us. If you are in the UK you may complain to the ICO; in the EEA, to your local supervisory authority.
8. Security
We implement technical and organisational measures described in the Security Schedule, including database-enforced tenant isolation, an HMAC-keyed append-only audit trail, MFA and server-verified step-up for sensitive actions, encryption in transit, rate limiting and strict security headers.
9. Cookies
We use essential cookies and, with consent, analytics cookies. See the Cookie Notice.
Clauses a solicitor must confirm
The following points in this document require qualified legal sign-off before GBOS relies on it.
- Controller identity and DPO / representative appointment (clause 1) — confirm whether a DPO and/or UK/EU representative is required and appoint.
- Lawful bases and any legitimate-interests assessments (clause 3).
- International transfer mechanism (clause 6) — UK IDTA / EU SCCs, and the pinned hosting/database regions.
- Retention periods (clause 5) — confirm against statutory retention (e.g. financial-records retention) and set concrete durations.
- The final sub-processor list and change-notification mechanism (see the Sub-processors page).
This document is a GBOS-specific, review-ready draft. It is not final and does not constitute legal advice; it must be confirmed by a qualified solicitor (see the clauses flagged above) before GBOS relies on it.