Skip to main content

Data processing and security information

Roles, sub-processors, retention, security measures and how to request a data processing agreement for Observe IQ.

Last updated 1 July 2026

This page summarises how data is processed and protected when you use Observe IQ. It is written for compliance, legal, procurement and security teams carrying out a supplier review.

Roles

For the content you ask us to scan and the documents you upload, you are the controller and Observe IQ is the processor. We process that content only to provide the service and on your instructions.

For your account, billing and enquiry data, and for our own website analytics, Observe IQ is the controller. See our privacy policy.

Data processing agreement

Our standard data processing terms are available on request and are incorporated into subscriptions where required. They cover subject matter and duration, processing instructions, confidentiality, sub-processing, security measures, assistance with data subject requests, breach notification, audit and deletion. Email privacy@observeiq.com to request a copy or to discuss a specific arrangement.

Categories of data processed

  • Account data: names, work email addresses, roles, workspace membership.
  • Configuration data: website addresses, jurisdictions, selected rulesets, schedules, notification settings.
  • Scanned content: text and structure retrieved from the pages you specify, and text extracted from documents you upload.
  • Findings and reports: generated output, including suggested wording and review status.
  • Log data: authentication events, scan runs, administrative actions.

Scanned content may incidentally contain personal data. We do not ask for, and you should not deliberately submit, special category data beyond what is present in your published content and policy documents.

Sub-processors

Function Location of processing
Cloud hosting and database United Kingdom or European Economic Area
Object storage for uploaded documents United Kingdom or European Economic Area
Language model provider for suggested wording European Economic Area or United States, under transfer safeguards and no-training terms
Transactional email delivery European Economic Area
Error monitoring and logging European Economic Area
CRM and marketing email European Economic Area or United Kingdom
Payment processing European Economic Area or United Kingdom

A current, named list with links to each provider's terms is available on request, and we give notice of new sub-processors so that customers can object.

International transfers

Where processing takes place outside the UK or the EEA, transfers rely on an adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses, with a transfer risk assessment on file.

Retention and deletion

  • Scan results and reports: retained while the account is active, and for the retention period on your plan.
  • Uploaded documents: retained until you delete them or the workspace is closed. Deletion removes the stored file and its extracted text.
  • Account data: deleted or anonymised within 90 days of account closure, except where we must keep records for accounting or legal reasons.
  • Backups: encrypted, retained for up to 35 days, then overwritten.

Security measures

  • Encryption in transit using TLS 1.2 or above, and encryption at rest for databases, object storage and backups.
  • Role-based access control, with least-privilege administrative access and multi-factor authentication for our staff.
  • Environment separation between development, staging and production, with no production content used in testing.
  • Centralised audit logging of authentication and administrative events.
  • Dependency scanning, patching and periodic penetration testing, with findings tracked to resolution.
  • Documented incident response, with notification to affected customers without undue delay and within the periods required by applicable law.
  • Vetting of staff with access to production systems, and confidentiality obligations in employment and contractor terms.

Availability and continuity

Data is stored in managed services with automated backups and point-in-time recovery. Recovery objectives and continuity arrangements can be shared as part of a supplier review.

Your controls in the platform

  • Delete an individual document, a scan or an entire workspace.
  • Restrict which pages are scanned and how frequently.
  • Manage users and their permissions.
  • Export reports for your own records at any time while your subscription is active.

Security contact

Report a suspected vulnerability or security concern to security@observeiq.com. We aim to acknowledge reports within one working day and do not pursue researchers who act in good faith and avoid privacy violations or service disruption.

Observe IQ is a compliance-support tool. Results should be reviewed by an appropriately qualified person. Observe IQ does not provide legal advice or guarantee regulatory compliance.