Privacy Policy
LAST UPDATED: 2026-07-12
This policy explains what data Obsivara collects, how we use it, and the choices you have. It applies to obsivara.com and the Obsivara platform.
§ 01Information We Collect
We collect information you provide directly, such as your name, work email, company, and billing details when you create an account or contact us. We also collect the telemetry you choose to send to the platform: workflow execution traces, run metadata, error events, model usage records, and cost signals from connected integrations such as n8n.
We automatically collect limited technical information when you use the service, including IP address, browser type, device identifiers, and usage analytics that help us understand how features are used. We do not require, and ask that you avoid sending, sensitive personal data inside workflow payloads; payload capture can be disabled or redacted per integration.
§ 02How We Use Information
We use collected information to operate and improve the service: rendering dashboards and traces, computing health scores and predictions, generating cost attribution, detecting anomalies, and providing customer support. Aggregated, de-identified telemetry may be used to improve our detection models and benchmarks.
We use contact information to send transactional messages (alerts, billing, security notices) and, with your consent, product updates. We never sell your personal information, and we never use your customer data to train models made available to other customers in a way that could expose your data.
§ 03Data Retention
Telemetry data (execution traces, events, and metrics) is retained for 90 days by default. Enterprise plans can configure shorter or longer retention windows per workspace. After the retention window elapses, raw telemetry is permanently deleted from our primary stores and expires from backups on their rolling schedule.
Account and billing records are retained for as long as your account is active and thereafter as required for legal, tax, and audit purposes. When you delete your workspace, associated telemetry is deleted within 30 days.
§ 04Data Security
All customer data is encrypted at rest using AES-256-GCM and in transit using TLS 1.2 or higher. Integration credentials, such as n8n API keys, are stored in an isolated secrets vault with envelope encryption and are never exposed in logs or client responses.
Access to production systems follows least-privilege principles with role-based access controls, multi-factor authentication, and audited access trails. Our security roadmap includes continuous vulnerability scanning and periodic third-party penetration testing.
§ 05Subprocessors
We rely on a small set of vetted subprocessors to deliver the service, including cloud infrastructure providers for hosting and storage, a payment processor for billing, and an email delivery provider for transactional messages. Each subprocessor is bound by a data processing agreement with obligations at least as protective as this policy.
A current list of subprocessors is available on request at privacy@obsivara.com. We will provide notice before adding a new subprocessor that processes customer data, giving you an opportunity to object.
§ 06Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the right to access, correct, export, restrict processing of, or delete your personal data. Where we process data on the basis of consent, you may withdraw that consent at any time without affecting prior processing.
If you are in the European Economic Area or the United Kingdom, you may lodge a complaint with your supervisory authority. California residents may exercise rights under the CCPA/CPRA, including the right to know and the right to deletion; we do not sell or share personal information as defined by those laws. To exercise any right, email privacy@obsivara.com and we will respond within 30 days.
§ 07Cookies
We use strictly necessary cookies for authentication and session management, and a small number of first-party analytics cookies to understand product usage. We do not use third-party advertising cookies or cross-site tracking.
You can control cookies through your browser settings. Disabling strictly necessary cookies will prevent you from signing in to the service.
§ 08Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or applicable law. Material changes will be announced by email and in-product notice at least 14 days before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.
§ 09Contact
For privacy questions, data requests, or concerns about this policy, contact our privacy team at privacy@obsivara.com. For security disclosures, contact security@obsivara.com. Obsivara operates remote-first; our registered mailing address is available upon request for formal notices.