Privacy Policy

Last updated: September 6, 2026

1. Introduction and Data Controller

This Privacy Policy explains how OBRI ("we", "us", "our"), the operator of the www.obricrm.com platform, collects, uses, stores, and protects personal data.

We comply with Ukraine's Law on Personal Data Protection and, where applicable, the EU General Data Protection Regulation (GDPR) and UK GDPR.

Terms of use of the service are set out separately in the Terms of Service.

2. Roles Regarding Data

  • Teacher account / subscription: OBRI is the controller of registration, profile, subscription, and technical log data.
  • Student data entered by a teacher: the teacher is the controller of that data; OBRI processes it as a processor solely to provide the service on the customer's instructions.
  • Student account: if a student signs into the portal themselves, OBRI is the controller of their access-account data; teaching content and teacher notes remain under the teacher's control.

3. Information We Collect

3.1. Information You Provide

  • Name, email, phone (optional), profile photo (optional)
  • Google account data when signing in with Google
  • Student data, schedule, lessons, assignments, materials, notes, chat
  • Lesson / invoice financial records (amounts, payment statuses between teacher and student — not the student's bank card details)
  • Payout details for the referral program (if you provide them)
  • Support requests

3.2. Automatically Collected Information

  • IP address, device type, browser, OS
  • Date/time of actions, pages viewed, product usage events
  • UI theme and language preferences
  • Technical errors and diagnostics (Sentry)
  • Usage analytics via Google Analytics 4 (GA4)

3.3. Subscription Payment Data

Subscription payments are processed by Mono (Ukraine, UAH) or Paddle (international). We do not store full card numbers. For Mono auto-renewal we may store a card token / wallet ID issued by Mono. Paddle, as Merchant of Record, may process payment and tax data under its own policy.

3.4. Google Calendar

If you connect Google Calendar, we may access:

  • Event list for lesson import / sync
  • Event titles, dates, times, and descriptions
  • OAuth access / refresh tokens (stored securely)

We do not permanently store calendar events "just in case" — we read them for import or sync. You can revoke access in OBRI settings or at myaccount.google.com/permissions. We do not use Google Calendar data for advertising and do not sell it.

4. How We Use Information

  • Providing, maintaining, and improving the service
  • Creating and managing accounts, authentication
  • Organizing schedules, assignments, materials, and lesson finances
  • Syncing with Google Calendar (if connected)
  • Sending service emails (lessons, assignments, subscription, security)
  • Processing subscription payments and preventing fraud
  • Product analytics (GA4) to understand usage and conversions
  • Error diagnostics (Sentry) and security
  • Complying with legal obligations
  • Marketing / product messages — only with an appropriate basis; you may opt out

We do not sell personal data.

5. Legal Bases (GDPR / UK GDPR)

For users in the EU / UK we rely on the following bases (GDPR Art. 6):

  • Contract: account, CRM features, subscription, service emails
  • Legitimate interests: security, abuse prevention, error diagnostics, product improvement, basic analytics
  • Consent: optional integrations (e.g. Google Calendar), marketing emails (where consent is required)
  • Legal obligation: accounting / tax requirements for payments, responses to regulators

6. Storage and Security

Data is stored in secure cloud services (primarily Supabase / PostgreSQL). Security measures include:

  • Encryption in transit (TLS)
  • Protection of sensitive secrets and OAuth tokens
  • Row Level Security (RLS) in the database
  • Regular infrastructure backups by the provider
  • Limited administrative access

No system is perfectly secure. If a high-risk incident occurs, we will notify you and, where required, the regulator — in line with GDPR (including within 72 hours for supervisory authority notification, where applicable).

6.1. Retention

  • Account data — while the account is active + up to 30 days after deletion (unless law requires longer)
  • Lesson and subscription finance records — up to 3 years (accounting / disputes)
  • Google Calendar tokens — until Calendar is disconnected or the account is deleted
  • Mono auto-renewal tokens — until subscription cancellation / payment method removal
  • Error logs (Sentry) — about 90 days
  • GA4 analytics — per retention settings in Google Analytics
  • Chat — while relevant participant accounts exist or until deletion on request

7. Sub-processors

We share limited data with services needed to operate the platform:

ServicePurposeData
SupabaseDatabase, auth, storageAccount data and CRM content
VercelHosting / edgeIP, request logs
GoogleOAuth, Calendar, GA4Email/name; Calendar (optional); analytics
ResendEmail deliveryEmail, name, email content
SentryError monitoringTechnical data, sometimes session context
MonoSubscription payments (UA)Amount, status, card token
PaddleSubscription payments (global)Customer payment / tax data

Sub-processors are required to maintain GDPR-compatible protection (via DPAs / SCCs / equivalent frameworks).

8. Cookies and Analytics

We use:

  • Essential: authentication session, CSRF / OAuth state protection
  • Preferences: theme, interface language
  • Analytics: Google Analytics 4 for visit and product-event statistics (without intentionally sending email / phone in events)

Browsers allow blocking or deleting cookies. Blocking essential cookies may break sign-in. EEA users may also use Google consent settings / browser tracking controls.

9. Your Rights

Depending on applicable law (including GDPR) you may have the right to:

  • Accessa copy of your data
  • Rectificationcorrect inaccuracies
  • Erasure"right to be forgotten" (with legal exceptions)
  • Restrictionrestrict processing
  • Portabilityreceive data in a machine-readable format
  • Objectionto processing based on legitimate interests / direct marketing
  • Withdraw consentat any time, without affecting prior lawful processing

Request: support@obricrm.com. We will respond within 30 calendar days (GDPR; extendable for complex requests with notice to you). We may ask you to verify your identity.

If you are a student and a teacher entered your data, some requests (e.g. correcting teaching records) may need to be addressed to the teacher as controller.

10. Children

OBRI may be used by students of various ages in tutoring contexts. Creating a teacher account requires age 18+. For students under 16, access to their own account requires parental or guardian consent. If a child provided data without the required consent, contact us and we will delete or restrict the data where possible.

11. International Transfers

Data may be processed outside Ukraine and the EU (including in the US) via Supabase, Vercel, Google, Resend, Sentry, and Paddle. Transfers rely on EU Standard Contractual Clauses (SCCs), the EU-US Data Privacy Framework (where applicable), or other lawful mechanisms.

12. Changes to This Policy

We may update this Policy. For material changes we will notify you by email or in-product at least 14 days in advance. The update date is always shown at the top. Continued use after the effective date means you have been informed of the updated Policy.

13. Contact and Complaints

For privacy questions or to exercise your rights:

Email: support@obricrm.com

Website: www.obricrm.com

Response time: within 30 calendar days

You may also lodge a complaint with the Ukrainian Parliament Commissioner for Human Rights or with your local EU / UK data protection authority.

© 2026 OBRI. All rights reserved.

This document is prepared as an operational SaaS policy and does not replace individualized legal advice.