Last updated 25 August 2026
This is a comprehensive draft written to reflect what Oskli actually does. It has not been reviewed by a qualified solicitor or data protection professional, and shouldn't be relied on as a substitute for professional advice — particularly before using it as your organisation's sole record of GDPR compliance.
This policy explains how Oskli ("we", "us", "our") collects, uses and protects personal data. It applies to two different groups of people, treated differently under data protection law:
If you're an End Customer of a company that uses Oskli, we are not the organisation you have a direct relationship with — that's the company using Oskli, and you should look to them (as the data controller) for how your information is used. See clause 2.
Under UK GDPR and the Data Protection Act 2018, this differs by data type:
Oskli is operated by the company shown in your account's company settings, trading as Oskli. Contact details for data protection queries are in clause 13.
From Account Users, when your company signs up and as you use the Service:
On behalf of our customers, as End Customer data entered into the Service:
For Account User data, we rely on:
For End Customer data, the lawful basis is a matter for our customer, as the data controller for that data — we process it under Article 28 UK GDPR as their processor, on their documented instructions.
We use Account User data to:
We don't sell personal data, and we don't use it to build advertising profiles or share it with unrelated third parties for their own marketing purposes.
Some of our sub-processors (including Stripe) may process data outside the UK, including in the United States. Where that happens, we rely on the safeguards recognised under UK GDPR — such as the UK's international data transfer addendum to the EU Standard Contractual Clauses, or transfers to countries covered by a UK adequacy decision — to ensure your data continues to receive an equivalent standard of protection.
We keep Account User and Customer Data for as long as your account is active, so the Service can function. If you cancel your subscription, we retain your data for 30 days afterwards in case you'd like to reactivate, after which it is permanently deleted from our active systems, other than information we're legally required to retain for longer (for example, billing records for tax purposes, which we keep for the period required by law).
Backups may persist for a limited additional period after deletion from live systems, purely as a byproduct of standard backup rotation, and are not separately accessed.
We use technical and organisational measures appropriate to the risk, including:
No system is perfectly secure, and we can't guarantee absolute security — but we take reasonable, industry-standard steps to protect the data we hold, and we'll notify affected customers and, where legally required, the ICO, without undue delay in the event of a personal data breach likely to result in a risk to individuals' rights and freedoms.
If we're the data controller for your personal data (i.e. you're an Account User), you have the right to:
We don't use automated decision-making or profiling that produces legal or similarly significant effects on Account Users.
To exercise any of these rights, contact us using the details in clause 13. We'll respond within one month, as required by law (extendable by a further two months for complex requests, in which case we'll tell you why).
If you're an End Customer of a company that uses Oskli, these rights are exercised against that company directly, as the data controller for your data — not against Oskli. We'll assist our customers in responding to such requests where they ask us to.
Questions about this policy, or to exercise your rights — reach out via the contact details on your account, or the contact information shown on our website.
If you're unhappy with how we've handled your personal data, you have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to address your concern directly first, but you're not required to contact us before contacting the ICO.
Oskli is a business tool and isn't directed at, or knowingly used to collect data from, children. If you believe a child's personal data has been provided to us without appropriate authority, contact us and we'll delete it.
This policy is written primarily around UK GDPR, since Oskli is a UK-based service. If you're located elsewhere, your local law may give you additional or different rights — for example, the EU GDPR gives broadly equivalent rights to UK GDPR for individuals in the EEA; California's privacy law (CCPA/CPRA) gives California residents rights to know, delete, and opt out of the sale of personal information (we don't sell personal information, so there's nothing to opt out of); and other jurisdictions have their own frameworks. We aim to honour the spirit of those rights on request even where not strictly legally required to, but we don't claim specific certified compliance with every jurisdiction's framework — if you have a jurisdiction-specific request, contact us and we'll do our best to help.
We may update this policy from time to time, most often to reflect changes to the Service or legal requirements. We'll update the "last updated" date below when we do, and flag material changes more prominently where reasonably practical.
See also our Terms of Service.