Legal
Privacy Policy
Last updated 31 July 2026
This describes what Obsevo Cloud does with personal data — what we collect, why, how long we keep it, and what you can ask us to do with it.
1. Who is responsible
{{LEGAL_ENTITY}} operates Obsevo Cloud and is the controller for the account data described below. For the workflow data you send us, you are the controller and we are a processor acting on your instructions.
Privacy questions and data-subject requests: see the contact page.
2. Account data we collect
- Account— email address, name if you provide one, hashed password or identity-provider subject, workspace name and role.
- Billing— a customer reference and subscription state. Card details go to our payment processor and are never seen or stored by us.
- Operational logs— server logs including IP address and user agent, kept for security and debugging.
There is no analytics, no session replay and no advertising technology anywhere in the product or on this website. No third-party scripts are loaded at all, which you can verify in your browser’s network tab.
3. Workflow data you send us
This is the part that matters, and what reaches us depends on how you connect:
- Agent mode. The agent runs on your infrastructure, reduces executions locally and sends only metadata: workflow and node names, run status, timings, item counts, error text, and for AI nodes the model, provider and token counts. Execution payloads, prompt and completion content, and credentials are never transmitted.
- API-key mode. We poll your n8n directly. Execution data transits our systems, where payloads are stripped before anything is written. The payloads are not persisted, but they do reach us.
Two things carry free-form content and can therefore contain personal data if your workflows put it there: error messages and log lines or business events you send us deliberately. Values under credential-shaped keys are redacted on arrival, but we cannot detect personal data in an arbitrary field.
Full technical detail is on the security page.
4. Why we process it
- To provide the service you asked for — performance of a contract.
- To bill you, and to meet accounting obligations — contract and legal obligation.
- To keep the service secure and to debug failures — legitimate interests, balanced against your rights.
- To send service messages such as alerts, invites and incident notices. These are not marketing and cannot be unsubscribed from without closing the account.
We do not sell personal data, do not share it for advertising, and do not use your workflow data to train machine-learning models.
5. How long we keep it
- Run history and logs— pruned on the retention window that applies to your deployment. See the note on the pricing page for what is enforced today.
- Business events— kept longer than run history, so year-on-year comparison is possible. The default is 400 days.
- Account and billing records— for the life of the account, then as long as tax and accounting law requires.
We keep no off-site backups, so deletion from live systems is not shadowed by a copy elsewhere. A snapshot is taken on the server immediately before a schema migration and the newest few are kept, which means deleted data may persist there for a short window.
6. Who else processes it
A short list of subprocessors, each named with what it does and where, is on the subprocessors page. We will publish changes there before they take effect.
7. Security
Credentials for connected instances are encrypted at rest using envelope encryption. Traffic is TLS-encrypted in transit. Agent pushes are signed and replay-protected.
We hold no security certifications. That is stated plainly on the security page rather than implied away.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, export or restrict processing of your personal data, and to object to processing based on legitimate interests. You may also complain to your local supervisory authority.
To exercise any of these, use the address on the contact page. We will respond within the period the applicable law requires.
Where you are the controller and we are your processor, requests from your own users should come to you, and we will assist you in answering them.
9. International transfers
Obsevo Cloud runs in a single region, and our subprocessors are listed with their locations. Where personal data moves outside your jurisdiction, we rely on the transfer mechanisms the relevant law provides, such as standard contractual clauses.
10. Cookies
The dashboard sets one cookie, for your session. It is strictly necessary for signing in, and there is no consent banner because there is nothing optional to consent to.
This marketing site sets no cookies and loads no third-party resources. Your theme preference is kept in local storage on your own device and is never sent to us.
11. Changes
Material changes will be notified by email or in the dashboard before they take effect, and the date at the top of this page always reflects the current version.