Privacy Notice

Last Updated: September 7, 2026

1. Scope and our role

Obligata, LLC ("Obligata," "we," "us," or "our") provides the commercial website at obligata.com and the Obligata product at app.obligata.com, including associated account, support, and business communications. This notice explains how personal information is handled across those services.

For website inquiries, marketing subscriptions, and account and business administration for which we determine the purposes of processing, Obligata acts as a controller or business under applicable privacy law.

Organizations also use Obligata to manage their own matters, obligations, documents, assessments and communications. When we process personal information within that customer content on an organization's instructions, we act as its processor or service provider, or as a subprocessor where that organization acts for another controller. The relevant customer agreement and data processing terms govern that processing. This notice does not expand our rights to use customer content or replace those terms.

An organization's own privacy notices govern the purposes for which it collects and uses information in its workspace. Its administrators control access and relevant settings. For customer-hosted deployments, this notice applies to information Obligata actually receives or processes; running our software does not itself mean all deployment data is sent to Obligata.

2. Information we handle and its sources

Website and business contacts. When you send an inquiry, we collect your name, email address, reason for contacting us, and any organization or message you provide. We also handle earlier waitlist registrations and inquiry details, correspondence, support requests, subscription preferences and opt-out records. If you choose product updates, we record that choice and its time. We also record the Website Terms version accepted with an inquiry and the submission time.

Product accounts and access. We handle account identifiers, names, email addresses, organization memberships, roles, permissions, invitations, and authentication and session records. Depending on the sign-in method and enabled features, this includes identity-provider identifiers, password verification records, and multifactor authentication information. We receive information from you, your organization, authorized administrators, and the identity provider you use.

Customer content. Depending on enabled features and what customers submit or connect, the product processes contracts and other documents, uploaded files, excerpts, matter and incident records, evidence, assessment responses, notes, decisions, contact and recipient details, and related metadata. This information may concern users, customer personnel, clients, vendors or other individuals mentioned in the records. It can include sensitive information where customers choose to provide it. Data may come directly from users, invited participants, customer administrators, or connected systems.

Integrations and AI features. We process connection settings, authorization information and credentials supplied through designated configuration features, content retrieved through authorized integrations, and requests and outputs associated with enabled AI features. The information involved depends on the feature, provider and customer configuration.

Service and security records. We process information needed to operate and secure the services, such as IP addresses, browser and device information, session and authentication events, activity timestamps, permissions, audit records, and service-usage records. Website application logs also record email addresses associated with registrations and opt-outs, and email, company and role associated with conversation requests.

Optional website analytics. If you accept analytics on the commercial website, Google Analytics collects usage and device information, including identifiers and information about visited pages and interactions. The underlying collection is not limited to anonymous aggregate reports.

3. How we use information

For the purposes we determine, we use relevant information to respond to inquiries; administer accounts and business relationships; provide support; send requested updates; maintain and troubleshoot the services; prevent abuse and unauthorized access; maintain appropriate business records; meet legal obligations; and establish or defend legal claims. With your consent, we use optional website analytics to understand website usage.

We process customer content to provide the features requested by the customer, such as organizing matters and obligations, retrieving or analyzing documents, supporting assessments and decisions, maintaining records, and facilitating configured communications. The customer's instructions and agreement govern these uses. Registering an account or submitting an inquiry does not by itself subscribe you to unrelated marketing.

Where EU or UK data protection law applies to processing for which we are controller, we rely on legitimate interests in operating a business, providing support, administering organizational accounts and protecting the services; performance of a contract with you or steps you request before entering one, where applicable; consent for optional analytics and consent-based email subscriptions; and compliance with legal obligations. You may withdraw consent without affecting the lawfulness of processing before withdrawal. For processing on customer instructions, the relevant controller determines the applicable legal basis.

4. AI features and connected services

When an AI feature is used, relevant prompts, document text, excerpts or other selected context may be sent to the provider configured for that feature, and the resulting output may be stored in the workspace or its records. Available configurations include third-party hosted providers and customer-selected endpoints. A reference-based integration can still involve reading, transmitting or retaining content and excerpts; it does not mean that only non-personal metadata is processed.

Provider access, processing location, retention and any use of information for model training depend on the applicable service arrangements and configuration. Customers should review those arrangements before enabling a provider or supplying sensitive content. Where we appoint a provider to process customer content on our behalf, our obligations remain governed by the customer agreement and applicable data processing terms. Customer-selected services may also be subject to the customer's own agreement with that provider.

5. When information is disclosed

We disclose information as needed to providers supporting hosting, storage, authentication, communications, support and other enabled service functions. Google Analytics receives information when optional website analytics is enabled. AI and other integrations receive information as described above and as configured for the relevant feature.

Within a customer workspace, information is available to administrators, authorized users, invited participants and configured recipients according to the relevant access settings and workflows. Customers should consider those settings when submitting information.

We may also disclose relevant information where required by law or reasonably necessary to protect rights and security or establish or defend legal claims, subject to our applicable contractual and legal obligations.

6. Cookies and browser storage

The commercial website and product use different storage features. The commercial website uses optional analytics cookies after acceptance and browser local storage to remember the analytics choice. The product uses a session cookie to provide authenticated access and browser storage for functions such as remembering the selected workspace and interface preferences.

Necessary authentication storage is used to provide requested product functionality and is separate from optional analytics consent. Blocking it may prevent login or other requested features. You can manage optional website analytics through the Cookie preferences link in the Website footer. The Cookie Policy describes these technologies and their durations in more detail.

7. Retention and security

We retain information for the purposes described in this notice, taking into account the duration of the relationship, operational and security needs, applicable legal obligations, and the establishment or defense of claims. Retention of customer content is governed by the customer agreement, applicable instructions and configured retention rules. Audit and decision records may need to outlast an individual user's account; closing an account does not necessarily erase the organization's records.

We retain limited suppression information to honor marketing opt-outs. Deleting active records may not immediately remove every backup copy; backup handling remains subject to the applicable retention arrangements and legal requirements.

We use technical and organizational safeguards designed to protect information. No system is completely secure. Public website forms should not be used to submit privileged matter information, sensitive personal information, credentials or production data. Within the product, use the designated features and the organization's approved access, storage and provider settings. A privilege label or use of Obligata does not itself create or guarantee legal privilege.

8. International processing

Processing locations depend on the service, deployment and enabled providers. Information may be processed outside your home country, where laws may differ. Where applicable law restricts an international transfer, the required safeguards or other lawful transfer basis must apply.

For information about processing locations and the transfer arrangements applicable to our services, contact privacy@obligata.com. For customer-configured integrations, also consult your organization and the relevant provider.

9. Your choices and rights

You can unsubscribe from marketing and early-access emails through our Email Opt-Out page or contact privacy@obligata.com. An opt-out does not prevent non-marketing messages needed to respond to your requests, administer the service or meet legal obligations.

Depending on applicable law, you may have rights to access, correct, delete or obtain a portable copy of personal information; restrict or object to processing, including direct marketing; withdraw consent; and complain to a competent data protection authority. Rights are subject to applicable conditions and exceptions. We may request information reasonably needed to verify and respond to a request.

For information controlled by your organization or another customer, direct your request to that organization first. If you contact us, we will assist or refer the request as appropriate to our role and obligations. An individual request does not automatically authorize us to delete a customer's matter, evidence or audit records.

10. Children, changes and contact

Our website and product are intended for adults in a business or professional capacity. Customer content may nevertheless include information about minors where relevant to the customer's work; the customer is responsible for the lawfulness of its instructions. Contact us if you believe information about a child has been provided improperly.

We may update this notice as our services or practices change. We will update the effective date and provide additional notice where required.

Contact Obligata, LLC at privacy@obligata.com.