Privacy Policy
Last updated: September 6, 2026
1. Introduction and Data Controller
This Privacy Policy explains how OBRI ("we", "us", "our"), the operator of the www.obricrm.com platform, collects, uses, stores, and protects personal data.
We comply with Ukraine's Law on Personal Data Protection and, where applicable, the EU General Data Protection Regulation (GDPR) and UK GDPR.
Terms of use of the service are set out separately in the Terms of Service.
2. Roles Regarding Data
- Teacher account / subscription: OBRI is the controller of registration, profile, subscription, and technical log data.
- Student data entered by a teacher: the teacher is the controller of that data; OBRI processes it as a processor solely to provide the service on the customer's instructions.
- Student account: if a student signs into the portal themselves, OBRI is the controller of their access-account data; teaching content and teacher notes remain under the teacher's control.
3. Information We Collect
3.1. Information You Provide
- Name, email, phone (optional), profile photo (optional)
- Google account data when signing in with Google
- Student data, schedule, lessons, assignments, materials, notes, chat
- Lesson / invoice financial records (amounts, payment statuses between teacher and student — not the student's bank card details)
- Payout details for the referral program (if you provide them)
- Support requests
3.2. Automatically Collected Information
- IP address, device type, browser, OS
- Date/time of actions, pages viewed, product usage events
- UI theme and language preferences
- Technical errors and diagnostics (Sentry)
- Usage analytics via Google Analytics 4 (GA4)
3.3. Subscription Payment Data
Subscription payments are processed by Mono (Ukraine, UAH) or Paddle (international). We do not store full card numbers. For Mono auto-renewal we may store a card token / wallet ID issued by Mono. Paddle, as Merchant of Record, may process payment and tax data under its own policy.
3.4. Google Calendar
If you connect Google Calendar, we may access:
- Event list for lesson import / sync
- Event titles, dates, times, and descriptions
- OAuth access / refresh tokens (stored securely)
We do not permanently store calendar events "just in case" — we read them for import or sync. You can revoke access in OBRI settings or at myaccount.google.com/permissions. We do not use Google Calendar data for advertising and do not sell it.
4. How We Use Information
- Providing, maintaining, and improving the service
- Creating and managing accounts, authentication
- Organizing schedules, assignments, materials, and lesson finances
- Syncing with Google Calendar (if connected)
- Sending service emails (lessons, assignments, subscription, security)
- Processing subscription payments and preventing fraud
- Product analytics (GA4) to understand usage and conversions
- Error diagnostics (Sentry) and security
- Complying with legal obligations
- Marketing / product messages — only with an appropriate basis; you may opt out
We do not sell personal data.
5. Legal Bases (GDPR / UK GDPR)
For users in the EU / UK we rely on the following bases (GDPR Art. 6):
- Contract: account, CRM features, subscription, service emails
- Legitimate interests: security, abuse prevention, error diagnostics, product improvement, basic analytics
- Consent: optional integrations (e.g. Google Calendar), marketing emails (where consent is required)
- Legal obligation: accounting / tax requirements for payments, responses to regulators
6. Storage and Security
Data is stored in secure cloud services (primarily Supabase / PostgreSQL). Security measures include:
- Encryption in transit (TLS)
- Protection of sensitive secrets and OAuth tokens
- Row Level Security (RLS) in the database
- Regular infrastructure backups by the provider
- Limited administrative access
No system is perfectly secure. If a high-risk incident occurs, we will notify you and, where required, the regulator — in line with GDPR (including within 72 hours for supervisory authority notification, where applicable).
6.1. Retention
- Account data — while the account is active + up to 30 days after deletion (unless law requires longer)
- Lesson and subscription finance records — up to 3 years (accounting / disputes)
- Google Calendar tokens — until Calendar is disconnected or the account is deleted
- Mono auto-renewal tokens — until subscription cancellation / payment method removal
- Error logs (Sentry) — about 90 days
- GA4 analytics — per retention settings in Google Analytics
- Chat — while relevant participant accounts exist or until deletion on request
7. Sub-processors
We share limited data with services needed to operate the platform:
| Service | Purpose | Data |
|---|---|---|
| Supabase | Database, auth, storage | Account data and CRM content |
| Vercel | Hosting / edge | IP, request logs |
| OAuth, Calendar, GA4 | Email/name; Calendar (optional); analytics | |
| Resend | Email delivery | Email, name, email content |
| Sentry | Error monitoring | Technical data, sometimes session context |
| Mono | Subscription payments (UA) | Amount, status, card token |
| Paddle | Subscription payments (global) | Customer payment / tax data |
Sub-processors are required to maintain GDPR-compatible protection (via DPAs / SCCs / equivalent frameworks).
8. Cookies and Analytics
We use:
- Essential: authentication session, CSRF / OAuth state protection
- Preferences: theme, interface language
- Analytics: Google Analytics 4 for visit and product-event statistics (without intentionally sending email / phone in events)
Browsers allow blocking or deleting cookies. Blocking essential cookies may break sign-in. EEA users may also use Google consent settings / browser tracking controls.
9. Your Rights
Depending on applicable law (including GDPR) you may have the right to:
- Access — a copy of your data
- Rectification — correct inaccuracies
- Erasure — "right to be forgotten" (with legal exceptions)
- Restriction — restrict processing
- Portability — receive data in a machine-readable format
- Objection — to processing based on legitimate interests / direct marketing
- Withdraw consent — at any time, without affecting prior lawful processing
Request: support@obricrm.com. We will respond within 30 calendar days (GDPR; extendable for complex requests with notice to you). We may ask you to verify your identity.
If you are a student and a teacher entered your data, some requests (e.g. correcting teaching records) may need to be addressed to the teacher as controller.
10. Children
OBRI may be used by students of various ages in tutoring contexts. Creating a teacher account requires age 18+. For students under 16, access to their own account requires parental or guardian consent. If a child provided data without the required consent, contact us and we will delete or restrict the data where possible.
11. International Transfers
Data may be processed outside Ukraine and the EU (including in the US) via Supabase, Vercel, Google, Resend, Sentry, and Paddle. Transfers rely on EU Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework (where applicable), or other lawful mechanisms.
12. Changes to This Policy
We may update this Policy. For material changes we will notify you by email or in-product at least 14 days in advance. The update date is always shown at the top. Continued use after the effective date means you have been informed of the updated Policy.
13. Contact and Complaints
For privacy questions or to exercise your rights:
You may also lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or with your local EU / UK data protection authority.
© 2026 OBRI. All rights reserved.
This document is prepared as an operational SaaS policy and does not replace individualized legal advice.