Privacy Policy
Last updated: [DATE — TBD]
This Privacy Policy explains how O.G.B. Systems Ltd, a company [incorporated / to be incorporated — TBD] in England and Wales under company number [COMPANY NUMBER — TBD], whose registered office is at [REGISTERED OFFICE ADDRESS — TBD] (“O.G.B. Systems”, “we”, “us” or “our”), collects, uses, shares and protects personal data in connection with the O.G.B. Systems platform, including the websites at ogbsystems.com and ogbsystems.co.uk (together, the “Platform”). It should be read alongside our Terms of Use, which it forms part of.
This Policy applies to personal data of individuals who use the Platform on behalf of a Firm (Firm Admins, Primary Users, Invitees, Transfer Agents, Administrators and Fund Managers), individuals who submit a Request Access application, and individuals whose details appear within records, documents or messages that a Firm submits to the Platform.
1. Controller and processor roles
1.1 For Account registration, sign-in, team management and billing data, O.G.B. Systems is the controller and decides how and why that data is processed.
1.2 For personal data contained within a Firm’s own User Content, such as names in an uploaded document, a message, or an order or registrar account detail, the Firm that submitted it is the controller. O.G.B. Systems processes that data only as a service provider, on the Firm’s instructions, to host, store, transmit and display it as the Platform is designed to do. A Firm is responsible for having its own lawful basis and, where required, its own privacy notice to the individuals concerned before it submits their data to the Platform.
2. Personal data we collect
Depending on how you use the Platform, we collect:
- Registration and account data: name, job title, work email, work phone, country, your Firm’s name, and your role (Firm Admin, Primary User or Invitee).
- Request Access data: firm name, an optional Legal Entity Identifier, primary contact name, work email and work phone submitted on the Request Access form, together with the consent confirmations given at that point.
- Security data: your passphrase (stored hashed, never in plain text) and information confirming that two-factor authentication has been enrolled, together with one-time recovery codes (stored hashed).
- Billing data: your Firm’s billing contact details and subscription status. Card and bank details are collected and stored by our payment provider, Stripe, not by us directly.
- Content you or your Firm submit: fund and launch details, uploaded documents, messages between Firms, and order, Summary Report and Share Class Switch details, which may include personal data such as an authorised signatory’s name or a registrar account holder’s name.
- Technical and usage data: sign-in timestamps, IP address, device and browser information, and audit and activity logs of actions taken on the Platform.
- Correspondence: records of communications with our support, billing or legal contacts.
3. How we use personal data, and our legal basis
Under UK GDPR, we rely on the following legal bases:
- Performance of a contract, or steps taken at your request before entering one: creating and administering Accounts, operating the Platform’s core functionality, processing a Request Access application, and billing and invoicing.
- Legitimate interests: keeping the Platform secure, preventing fraud and misuse, enforcing our Terms of Use, maintaining and improving the Platform, and carrying out a GLEIF lookup against a submitted LEI as a due diligence aid (this returns publicly available legal-entity information, not personal data about you).
- Legal obligation: complying with applicable law, responding to a valid request from a regulator, court or other authority, and keeping records we are required to keep, such as for tax purposes.
- Consent: any optional communications we ask your permission for, which you may withdraw at any time.
4. Who we share personal data with
We share personal data with:
- Other Firms and Users on the Platform, but only to the extent the Platform’s own permissioning is designed to share it, for example an Issuer and an invited Purchaser seeing the shared record for their Fund Launch, or a Transfer Agent, Administrator or Fund Manager seeing what their invited, scoped role allows.
- Service providers who process data on our behalf under contract, currently including Supabase (database, authentication and file storage), Vercel (hosting), Stripe (billing and payment processing), and our transactional email provider.
- GLEIF’s public LEI register, where a Firm supplies an LEI, to check it against publicly available legal-entity data.
- Professional advisers such as lawyers, accountants and auditors, where reasonably necessary.
- Regulators, law enforcement, courts or other authorities, where required or permitted by law.
- A buyer or successor in connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality protection.
We do not sell personal data, and we do not share it with third parties for their own independent marketing purposes.
5. International data transfers
Our hosting and infrastructure providers may process data outside the country where you or your Firm are based, including outside the UK or European Economic Area. Where that happens, we use safeguards recognised under UK GDPR and EU GDPR, such as the UK International Data Transfer Addendum, EU Standard Contractual Clauses, or a provider’s own approved transfer mechanism. [Confirm the actual hosting/data regions and transfer safeguards in place with Supabase, Vercel and Stripe’s Data Processing Agreements before publishing this section.]
6. How long we keep personal data
6.1 Account and profile data is kept for as long as your Account is active, and indefinitely afterwards, unless you ask us to delete it, in which case we will action your request in line with Section 8. At our discretion, we may also delete or anonymise this data on our own initiative at any point from 10 years after your Account was cancelled or closed, but we are under no obligation to do so within that or any other timeframe.
6.2 Records created within a Fund Launch, Order, Summary Report, Share Class Switch, and their audit trail, are, by design, a permanent shared record between the Firms involved, similar to a transaction record either Firm would itself be expected to keep. These records, including the identity of the individual who created or confirmed an entry, are retained for as long as either Firm involved has an active relationship with the Platform, and afterwards for as long as necessary for the purpose the record was created for, including the possibility of a legal claim. Where an individual asks us to erase personal data that forms part of such a shared record, we will consider the request, but may not always be able to grant it in full without compromising another Firm’s own record; where we cannot, we will explain why and consider alternatives, such as restricting further visibility. [Specific retention period for the shared order archive (Section 6.2) to be confirmed, and this section to be reviewed against UK GDPR Article 17 before publishing.]
7. Security
We use technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access controls aligned with the Platform’s own permissioning, mandatory two-factor authentication, and audit logging of activity. As explained in our Terms of Use, references to the Platform being “secure” describe these measures, not a literal end-to-end encryption that would prevent us from ever accessing data. No system is completely secure and we cannot guarantee absolute security.
8. Your rights
Depending on where you are based, you may have the right to: access the personal data we hold about you; have inaccurate data corrected; request erasure, subject to Section 6; restrict or object to certain processing; receive a portable copy of data you provided to us; and withdraw consent where we rely on it. To exercise a right, contact support@ogbsystems.com. We may need to verify your identity before acting on a request. If you are not satisfied with our response, UK-based individuals can complain to the Information Commissioner’s Office at ico.org.uk, and individuals elsewhere can complain to their local data protection authority.
9. Cookies and similar technologies
The Platform uses only cookies that are strictly necessary for it to work: a session cookie set by our authentication provider, Supabase, to keep you signed in and to operate core functionality such as your workspace and permissions. We do not use analytics, performance, advertising or other non-essential cookies, and the Platform does not load any third-party tracking scripts. Because these cookies are strictly necessary, we do not ask for consent to set them, consistent with the UK Privacy and Electronic Communications Regulations. If that ever changes, for example if we add analytics to the public website, we will update this section and, where the law requires it, ask for your consent first.
10. Children
The Platform is not directed at, and must not be used by, anyone under 18. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify material changes in the same way as changes to our Terms of Use. The date at the top of this page shows when it was last revised.
12. Contact us
Questions about this Privacy Policy, how we handle personal data, or general product support: support@ogbsystems.com. This Privacy Policy should be read together with our Terms of Use.