Data Processing Agreement
What we process for your organisation when it pays for Business, why, where, and for how long. These are our standard terms, in plain words.
Last updated: September 28, 2026
Who this is between
This agreement is between OBSCURA OS (“we”) and the organisation that pays for an OBSCURA Business subscription (“you”). It forms part of the terms for that subscription and applies for as long as it runs. A Team subscription can ask for it too. If your organisation needs a countersigned copy, write to [email protected] from the address the subscription was paid with.
For the personal data described under “What we process for you”, you are the controller and we are your processor. Where a data protection law uses other words for those two roles, they mean the same here.
What never reaches us
The tools run in each person’s browser, on files opened from their own device. Files, documents, what is typed into the tools, and what anybody opens, makes or saves with them are never sent to us, so we cannot process them, hand them to anyone, or lose them. You can check this yourself.
What we process for you
Only what the seats on your plan need:
- Seat records. For each person your admin adds: their name and email address, as your admin types them, the dates they were added, took their seat and were removed, and a hash of their one-time invitation. Nothing else about them.
- The record of seat changes. One line for each change: what it was, when, the person’s name and address, and the fingerprint of the key that made it. It exists so that you can show an auditor who had access and when.
- Invitation emails. Where this site sends email, the invitation to a seat goes to the person’s address, with their name and their link. Where it does not, your admin passes the link on and we send nothing.
- Keys. A person’s key says your plan, your organisation’s name as given at checkout, the subscription and seat it belongs to, and its dates. It carries no name and no email address. It is sent to this site when Pro code is fetched, checked, and not stored.
We process this only to provide the seats: to make, check and renew keys, to send invitations, and to show your admin the list and the record. We do not use it for anything else, do not sell it, and do not use it to market to anybody.
Billing
Payment is taken by Stripe on its own checkout page. Stripe holds the name, email and billing address of whoever pays, and the card, under its own privacy policy. Our server asks Stripe whether the subscription is paid, and which plan it is on; it never sees the card.
Who else processes it
- Cloudflare hosts the site and stores the seat records and the record of changes, in Workers KV, in our own Cloudflare account. It also keeps the standard logs a web host keeps.
- Resend sends the emails with keys and invitations, where this site sends email.
- Stripe takes payment and holds the billing records, as above.
Each works under its own data processing terms, which include the safeguards for moving data between countries, such as the EU Standard Contractual Clauses, where those apply. Data may be held in any country in which they operate. If we add or replace one, we will change this page and email the address the subscription was paid with at least thirty days before, and you may object, or end the subscription with a refund of the unused part.
How it is kept safe
- Only the key your subscription came with opens the list of seats and the record. The key is signed, and it is checked with Stripe on every request.
- Invitations are random and single use, run out after fourteen days, and are stored only as a hash.
- Everything travels over HTTPS. Cloudflare encrypts what Workers KV holds when it is stored.
- Access to the Cloudflare account that holds it is limited to the people who run OBSCURA OS.
The security page says plainly what is and is not in place, including that nobody independent has audited this service.
How long it is kept
- A seat is kept while it is in use. Once removed, its record is deleted automatically after 400 days, well after any key it had has run out.
- An invitation is deleted automatically fourteen days after it is made.
- The record of seat changes is kept for as long as the subscription’s records are, so that it can be shown to an auditor. When the subscription has ended, we delete it, and the seat records, within thirty days of being asked; download it first if you want to keep it.
People asking about their data
Your admin can see everything we hold about a person, and can remove them. If somebody asks us directly, we will tell you, and help you answer. Removing a line from the record of seat changes, or deleting a person from it, is done on your written request.
If something goes wrong
If we become aware that any of this data has been lost, changed, or seen by somebody who should not have seen it, we will tell the address the subscription was paid with without undue delay: what happened, what it affects, and what we are doing about it.
Checking we do this
We will answer your written questions about how we meet this agreement, within thirty days, and tell you if we believe an instruction from you would break a data protection law.