OOskli

Privacy Policy

Last updated 25 August 2026

This is a comprehensive draft written to reflect what Oskli actually does. It has not been reviewed by a qualified solicitor or data protection professional, and shouldn't be relied on as a substitute for professional advice.

1. Scope of this policy

This policy explains how Oskli ("we", "us", "our") collects, uses and protects personal data. It applies to two different groups of people, treated differently under data protection law:

  • People who sign up for or use an Oskli account on behalf of a company — you, your team ('Account Users').
  • The people your company stores information about inside Oskli — your own customers, leads and staff ('End Customers'), whose data you enter as part of running your business.

If you're an End Customer of a company that uses Oskli, we are not the organisation you have a direct relationship with — that's the company using Oskli, and you should look to them (as the data controller) for how your information is used. See clause 2.

2. Are we a controller or a processor?

Under UK GDPR and the Data Protection Act 2018, this differs by data type:

  • For Account User data (your company details, team members' names and login emails, billing information, and how you use the Service) — Oskli is the data controller. We decide why and how this data is processed, as described in this policy.
  • For End Customer data (the names, addresses, phone numbers, job history and similar that an Oskli customer stores about their own customers) — Oskli is a data processor, acting solely on that customer's instructions, as given through their ordinary use of the Service. The Oskli customer is the data controller for that data and is responsible for having a lawful basis to collect and store it, and for responding to their own customers' rights requests. Our contractual data-processing obligations to our customers are set out in our Terms of Service.

3. Who we are

Oskli is operated by the company shown in your account's company settings, trading as Oskli. Contact details for data protection queries are below.

4. What personal data we collect

From Account Users, when your company signs up and as you use the Service:

  • Identity and contact data — name, work email address, phone number, company name and business address.
  • Account data — password (stored only as a salted cryptographic hash, never in plain text), role (owner/staff), login history and session activity.
  • Billing data — if you subscribe, Stripe processes and stores your payment details; we store a reference ID linking your account to your Stripe customer record, your billing address, VAT status, and the amount and history of what you've been charged. We never see or store full card numbers.
  • Usage data — pages visited, actions taken, and similar technical logs, used to operate and secure the Service.
  • Technical data — IP address, browser type, and device information, collected automatically as part of normal web request handling.

On behalf of our customers, as End Customer data entered into the Service:

  • Customer and site records — names, addresses, phone numbers, email addresses, and access notes for the properties they service.
  • Job, quote and invoice records — service history, pricing, and payment status connected to those customers.
  • If a customer connects their own Stripe account (Stripe Connect) to take card payments from their End Customers, saved card details are held by Stripe directly, not by us — we store only a reference token.

5. Our lawful basis for processing

For Account User data, we rely on:

  • Performance of a contract (Article 6(1)(b) UK GDPR) — to create and operate your account, and provide the Service you've signed up for.
  • Legitimate interests (Article 6(1)(f)) — to keep the Service secure, prevent fraud and abuse, and improve it, balanced against your rights and freedoms.
  • Legal obligation (Article 6(1)(c)) — for example, keeping billing records for tax purposes.
  • Consent (Article 6(1)(a)) — only where we ask for it separately, such as optional marketing communications you can opt out of at any time.

For End Customer data, the lawful basis is a matter for our customer, as the data controller for that data — we process it under Article 28 UK GDPR as their processor, on their documented instructions.

6. How we use personal data

We use Account User data to:

  • provide, maintain and secure the Service, including authenticating logins and enforcing account permissions;
  • process payments and manage your subscription, via Stripe;
  • respond to support requests;
  • send service-related communications — for example, password reset links, security notices, or billing confirmations;
  • understand how the Service is used, to fix problems and improve it;
  • meet legal and regulatory obligations.

We don't sell personal data, and we don't use it to build advertising profiles or share it with unrelated third parties for their own marketing purposes.

7. Cookies

We use a single strictly-necessary cookie to keep you logged in between requests. It doesn't track you across other websites, and we don't use advertising, analytics, or third-party tracking cookies. Because it's strictly necessary for the Service to function, no cookie-consent banner is shown for it — this is standard practice under UK PECR (Privacy and Electronic Communications Regulations), which only requires consent for non-essential cookies.

8. Who we share data with

We share personal data only with the sub-processors necessary to run the Service, each bound by a data processing agreement or equivalent contractual protections, and only to the extent needed for the purpose stated:

  • Stripe, Inc. — payment processing, subscription billing, and (where a customer connects their own account) their End Customers' card payments. Stripe is an independent controller for its own compliance and fraud-prevention purposes; see Stripe's own privacy policy.
  • Railway — our infrastructure/hosting provider, which stores the application database and runs the Service. Railway does not access data for its own purposes beyond providing hosting.

We may also disclose personal data where required by law, to protect our legal rights, or in connection with a merger, acquisition or sale of assets (in which case we'd expect the same protections to continue to apply). We do not sell personal data to third parties.

9. International data transfers

Some of our sub-processors (including Stripe) may process data outside the UK, including in the United States. Where that happens, we rely on the safeguards recognised under UK GDPR — such as the UK's international data transfer addendum to the EU Standard Contractual Clauses, or transfers to countries covered by a UK adequacy decision — to ensure your data continues to receive an equivalent standard of protection.

10. How long we keep data

We keep Account User and Customer Data for as long as your account is active, so the Service can function. If you cancel your subscription, we retain your data for 30 days afterwards in case you'd like to reactivate, after which it is permanently deleted from our active systems, other than information we're legally required to retain for longer (for example, billing records for tax purposes, which we keep for the period required by law).

Backups may persist for a limited additional period after deletion from live systems, purely as a byproduct of standard backup rotation, and are not separately accessed.

11. How we protect data

We use technical and organisational measures appropriate to the risk, including:

  • encrypting data in transit;
  • storing passwords only as salted cryptographic hashes, never in plain text;
  • restricting access to production data to what's necessary to operate and support the Service;
  • session security controls, including automatic session expiry after a period of inactivity, and single-session enforcement per login;
  • never storing full payment card numbers — card data is handled directly by Stripe, a PCI-DSS compliant payment processor.

No system is perfectly secure, and we can't guarantee absolute security — but we take reasonable, industry-standard steps to protect the data we hold, and we'll notify affected customers and, where legally required, the ICO, without undue delay in the event of a personal data breach likely to result in a risk to individuals' rights and freedoms.

12. Your rights under UK GDPR

If we're the data controller for your personal data (i.e. you're an Account User), you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected (rectification);
  • have your data deleted in certain circumstances (erasure);
  • restrict how we use your data in certain circumstances;
  • receive your data in a portable format, or have it transferred directly to another provider (data portability);
  • object to processing based on legitimate interests;
  • withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

We don't use automated decision-making or profiling that produces legal or similarly significant effects on Account Users.

To exercise any of these rights, contact us using the details below. We'll respond within one month, as required by law (extendable by a further two months for complex requests, in which case we'll tell you why).

If you're an End Customer of a company that uses Oskli, these rights are exercised against that company directly, as the data controller for your data — not against Oskli. We'll assist our customers in responding to such requests where they ask us to.

13. Complaints, and how to contact us

Questions about this policy, or to exercise your rights — reach out via the contact details on your account, or the contact information shown on our website.

If you're unhappy with how we've handled your personal data, you have the right to complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk or on 0303 123 1113. We'd appreciate the chance to address your concern directly first, but you're not required to contact us before contacting the ICO.

14. Children's privacy

Oskli is a business tool and isn't directed at, or knowingly used to collect data from, children. If you believe a child's personal data has been provided to us without appropriate authority, contact us and we'll delete it.

15. Users outside the UK

This policy is written primarily around UK GDPR, since Oskli is a UK-based service. If you're located elsewhere, your local law may give you additional or different rights — for example, the EU GDPR gives broadly equivalent rights to UK GDPR for individuals in the EEA; California's privacy law (CCPA/CPRA) gives California residents rights to know, delete, and opt out of the sale of personal information (we don't sell personal information, so there's nothing to opt out of); and other jurisdictions have their own frameworks. We aim to honour the spirit of those rights on request even where not strictly legally required to, but we don't claim specific certified compliance with every jurisdiction's framework — if you have a jurisdiction-specific request, contact us and we'll do our best to help.

16. Changes to this policy

We may update this policy from time to time, most often to reflect changes to the Service or legal requirements. We'll update the "last updated" date when we do, and flag material changes more prominently where reasonably practical.