Privacy Policy

Last updated: May 2026

Data we collect

We collect the information you provide when you create an account and onboard your company — company name, registered state, employee count, and contact details. We also collect compliance activity data (tasks completed, deadlines, evidence uploads) solely to operate the service.

How we store and protect it

Your data is stored on Neon (PostgreSQL), hosted on AWS infrastructure. All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). The application is deployed on Vercel with no cross-customer data sharing.

What we do not do

We do not sell your data. We do not share it with third parties except as required to operate the service (hosting, email delivery). We do not use your compliance data for any purpose outside your account.

Data residency

Data is stored on AWS US East region infrastructure via Neon. We are evaluating an AWS Mumbai region option and will notify customers if data residency changes.

Your rights

You may request a full export or deletion of your data at any time by writing to hello@obligo.in. We will action it within 7 business days.

Contact

Questions about this policy: hello@obligo.in