Privacy Notice
You are handing STABO your company's documents and the details of the people behind it. This says what happens to them, who else sees them, and what you can ask us to do about it — in the order those questions actually occur to someone.
Draft, pending legal review. The description of what the portal does is accurate and generated from the running system. The statutory framing — which laws apply, which regulator you would complain to, the retention periods stated in years — is awaiting confirmation by counsel and the compliance team.
What we collect
About you, as a user
Your name, work email and a password credential; whether two-factor authentication is on; and a record of significant actions taken in the portal — who changed a profile answer, who uploaded a document, who proceeded to onboarding — which exists so that an account is accountable.
About your company
Legal name, jurisdiction, entity type, activity, expected volumes and the rest of the company profile; your ownership structure; and every document you upload.
About the people connected to it
Directors, shareholders, beneficial owners and authorised signatories: names, dates of birth, nationalities, residential addresses, identity document details, and the roles each person holds. Where you provide someone else's details, you should tell them that you have — this notice is written so you can send it to them.
From using the portal
Sign-in events and request metadata, including IP address and browser. Strictly necessary cookies keep you signed in. There is no advertising or analytics tracking in this portal.
Why we hold it
- To provide the portal — one profile that every STABO service reads from, so you are not asked the same question twice.
- To assess an application for a STABO service, and to tell you what a service still needs from you.
- To meet legal obligations — customer due diligence, sanctions and politically-exposed-person screening, record-keeping and reporting under anti-money-laundering law. This is the reason we cannot simply delete everything on request.
- To keep the account secure — authentication, the audit trail, and investigating misuse.
We do not sell your information, and we do not use it to train anyone's model.
Artificial intelligence: what it does, and what it does not
When you upload a document, its full contents are sent to OpenAI, STABO's AI partner, one document per request. The model answers two questions: what kind of document this is, and what it says. From that it proposes answers to your profile — a company number read off a certificate, a date of birth read off a passport page.
- Every proposal is a suggestion. Nothing reaches your profile until a person at your company accepts it.
- No decision about you is automated. Eligibility is decided by rules STABO publishes and by people; the model has no part in it.
- The document itself goes, not a summary. If a page contains a photograph, an identity number or a signature, that is what is sent — to each of the companies named above.
- You can avoid it by typing the profile answers yourself and uploading the document afterwards as evidence.
STABO sends these documents under business agreements that prohibit using them to train models. Each company's own handling is described in its privacy policy: OpenAI.
Who else processes it
This list is generated from the running system rather than written by hand, so it cannot quietly fall out of date. The standalone version lives at Who processes your data.
The database, sign-in and document storage behind the portal.
Your account and password credential, the company profile, the people you name, and every file you upload — held in a private bucket that is not readable without a signed link.
Reads an uploaded document, says what it is, and proposes profile answers.
The contents of the documents you upload — including any personal details printed on them, such as a passport page — sent as the file itself, one document per request.
When you upload a document.The alternative document reader, used in place of OpenAI where configured.
The same document contents as above. Only one of the two ever receives a given file.
Not in use on this deployment. Listed because it is the configured alternative and would be disclosed here before any document reached it.
Typesafe AI (JEV)
To be confirmed.
Suggests which CRS tax classification fits the company, from the answers already in its profile. The suggestion is a starting point — the company chooses.
Profile answers about the company: its name, addresses, what it does, where its money comes from and its tax details. Not documents, and not anything about named people.
When you ask for a CRS classification suggestion.Runs the identity and company verification when you proceed to onboarding.
The company profile, the people you have named with their roles and identity details, and the documents relevant to the check — sent once, when you confirm.
When you press Proceed to Onboarding.Hosts and serves the portal.
Request metadata — IP address, browser, the pages you open. Not the contents of your profile or your files, which pass through in transit and are not stored here.
Sends the mail the portal sends — verification, invitations, password resets.
Your name and email address, and the contents of those messages.
Beyond these, information is shared with regulators, law enforcement, auditors or our professional advisers where the law requires or permits it — and, if STABO is ever sold or reorganised, with the party taking on the business.
Where it goes
Your information is processed in the United States and, for verification, in the European Union and the United Kingdom — the locations are beside each company in the list above. Transfers out of your own jurisdiction are made under standard contractual clauses or an equivalent mechanism, depending on where your company is incorporated.
How it is protected
- Documents are held in a private store. They are not reachable by URL; opening one issues a short-lived signed link to that user for that file.
- Access is enforced in the database itself, per organisation. One company's rows are not visible to another company's users, regardless of what the application asks for.
- STABO staff access is limited to the people assigned to your account, and acting on a customer's behalf is recorded in the audit log.
- Traffic is encrypted in transit; stored data is encrypted at rest.
How long it is kept
Profile information and documents are kept while your company uses STABO. After a relationship ends, records connected to customer due diligence are retained for the period anti-money-laundering law requires — typically several years — and then deleted. A document you remove in the portal is withdrawn from use immediately; where it formed part of a completed verification, the record of that verification is retained.
The exact retention periods per record type are being confirmed with compliance and will be stated here as a table.
What you can ask for
Depending on where you and the people you have named are located, you may ask for a copy of the information held, for a correction, for deletion, for a restriction on how it is used, or for it in a portable form; and you may object to certain processing. Much of it you can do yourself: the profile is editable, documents can be replaced, and access for colleagues is managed in Settings.
Where a request conflicts with a record we are legally obliged to keep, we will say so and say which obligation, rather than refuse without explanation.
Write to info@omucloud.co. If you are not satisfied with the answer, you can complain to the data protection authority where you are — the specific authorities will be named here once the compliance review is complete.
Changes to this notice
When the list of companies above changes, this page changes with it. Where a change materially affects how your information is handled, account owners are told by email before it takes effect. See also the Terms of Service.