Skip to main content
Ooplah
  • Services ▼

    Consulting

    • Digital Strategy
    • Business Transformation
    • Change Management
    • Process Optimisation

    Technology

    • Cloud Migration
    • AI & ML Solutions
    • Cybersecurity
    • Data Analytics

    Featured

    Free Digital Assessment

    Discover your digital maturity score and identify priority improvements.

    Get your assessment →
  • Contact
  • Home
    • Consulting
      • Digital Strategy
      • Business Transformation
      • Change Management
      • Process Optimisation
    • Technology
      • Cloud Migration
      • AI & ML Solutions
      • Cybersecurity
      • Data Analytics
  • Contact

Privacy Policy

How Ooplah collects, uses, and protects personal data, under the Data Protection Act 2004 and Gibraltar GDPR.

Effective Date: 21 April 2026 · Version 2.1

Table of Contents

  • Controller & Contact
  • Scope of this Policy
  • Personal Data We Collect
  • Sources of Data
  • Purposes & Lawful Bases
  • Recipients & Processors
  • International Transfers
  • Retention
  • Security
  • Your Rights
  • Automated Decision-Making
  • Children
  • Cookies & Tracking
  • Complaints & GRA
  • Changes to this Policy
  • Contact

Our Commitment to Your Privacy

At Ooplah, transparency and trust are the foundations of our digital transformation partnerships. As a Gibraltar-based consultancy with global reach, we are committed to protecting your personal data with the highest standards of care and compliance.

We process all personal data in strict accordance with the Data Protection Act 2004 and the Gibraltar GDPR, ensuring your information is handled with the respect and security it deserves. This policy clearly explains what we collect, why we need it, how we protect it, and your rights under Gibraltar law. Our practices are supervised by the Gibraltar Regulatory Authority.

Your privacy is not just a legal requirement for us—it's a core business value.

1. Controller & Contact

The controller responsible for personal data processed under this policy is:

Ooplah Limited
Company Number: 125876 (registered in Gibraltar)
13 Irish Town
Gibraltar

Privacy enquiries and data-subject requests: privacy@ooplah.net.
General contact: hello@ooplah.net.

While Ooplah has not appointed a statutory Data Protection Officer, we maintain a dedicated privacy team to ensure rapid response to all data protection inquiries. Your privacy concerns are our priority.

2. Scope of this Policy

This policy applies to personal data we collect when you visit ooplah.net, contact us, subscribe to our communications, or engage Ooplah for Services. Where we act as a processor on behalf of a client (for example, when handling data in the course of a consulting engagement), the relevant Engagement Document or data processing addendum governs that processing; this policy applies to our role as controller.

3. Personal Data We Collect

3.1 Data you provide

  • Contact data: name, email address, business phone number, company name, job title, country.
  • Correspondence: messages, feedback, and enquiries you send us via email or web forms.
  • Engagement data: information exchanged during a consulting engagement, including meeting notes, documents, and access credentials limited to the engagement scope.
  • Marketing preferences: your consents and opt-outs for newsletters and event invitations.

3.2 Data collected automatically

  • Device & log data: IP address, user-agent, device type, operating system, browser, referring URL, and approximate location derived from the IP.
  • Usage data: pages viewed, time on page, clicks, and navigation path.
  • Cookies and similar technologies: see our Cookie Policy for detail. Non-essential cookies are only set after you give consent.

3.3 Special category data

We do not deliberately collect special category data (such as health, racial or ethnic origin, political opinions, religious beliefs, or biometric data). Please do not send us such data through web forms or email.

4. Sources of Data

We obtain personal data from: (a) you directly; (b) our clients, in the course of an engagement; (c) our service providers (analytics, email, hosting); and (d) publicly available sources such as business registries and professional networking sites, where this is relevant to our legitimate interest in business development.

5. Purposes & Lawful Bases

We process personal data for the purposes, and on the lawful bases, set out below (Article 6 Gibraltar GDPR).

PurposeData categoriesLawful basis
Responding to enquiries and providing information you request Contact, correspondence Steps taken at your request prior to entering into a contract (Art 6(1)(b)); legitimate interests in running our business (Art 6(1)(f))
Performing a consulting engagement Contact, engagement Performance of a contract (Art 6(1)(b))
Marketing communications (newsletters, events) Contact, marketing preferences Consent (Art 6(1)(a)); soft opt-in where permitted
Website operation, security, and fraud prevention Device & log data Legitimate interests in operating a secure site (Art 6(1)(f))
Analytics and improvement of the Website Usage data, cookies Consent (Art 6(1)(a))
Accounting, billing, record-keeping Contact, engagement, financial Legal obligation (Art 6(1)(c)); legitimate interests (Art 6(1)(f))
Legal claims, regulatory compliance As necessary Legal obligation (Art 6(1)(c)); legitimate interests (Art 6(1)(f))

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded those interests are not overridden by your rights. You may request a summary of that assessment via privacy@ooplah.net.

6. Recipients & Processors

We share personal data only with parties that have a need to receive it. Recipients fall into these categories:

  • Processors acting on our instructions — hosting, email, analytics, CRM, and support providers, each under a written data processing agreement. Current processors include, without limitation:
    • Cloudflare, Inc. — content delivery, DDoS protection, and Workers asset hosting
    • Google LLC — Google Analytics 4 (activated only after analytics consent)
    • Microsoft Corporation — Microsoft Clarity (activated only after analytics consent)
    • Formspree, Inc. — form submission handling
  • Professional advisers — lawyers, accountants, and auditors bound by confidentiality obligations.
  • Regulators, law enforcement, and courts — where we are required to disclose by Gibraltar law or a binding legal request.
  • Successors — in connection with a merger, acquisition, or sale of business or assets, subject to equivalent privacy protection.

We do not sell personal data.

7. International Transfers

Gibraltar, the United Kingdom, and the European Economic Area currently benefit from mutual recognition of data protection standards. Where personal data is transferred outside those jurisdictions (for example, to processors based in the United States), we rely on an appropriate transfer mechanism under the Gibraltar GDPR:

  • an adequacy decision, where one applies;
  • the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as recognised in Gibraltar; or
  • other safeguards under Chapter V of the Gibraltar GDPR, supplemented by technical measures such as encryption.

You may obtain a copy of the relevant safeguards by contacting privacy@ooplah.net.

8. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, and reporting requirements. Indicative retention periods:

  • Enquiry correspondence: up to 2 years after last contact, unless an engagement arises.
  • Client engagement records: 7 years after the end of the engagement, aligned with our statutory accounting retention obligation.
  • Marketing contacts: until you unsubscribe, and then in a suppression list only, to honour your opt-out.
  • Website analytics: retention period set in the relevant analytics platform; see Cookie Policy.
  • Security and access logs: up to 12 months.

Where retention is not prescribed by law, we delete, anonymise, or securely archive data once it is no longer needed.

9. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure, including:

  • TLS encryption of data in transit and encrypted storage at rest where supported
  • Access controls based on least-privilege and multi-factor authentication for staff
  • Separation of production and non-production environments
  • Vendor due diligence and contractual data-processing safeguards
  • Security logging and monitoring
  • A documented incident response procedure, including notification to the Gibraltar Regulatory Authority within 72 hours of becoming aware of a reportable personal data breach, where required by law

No system is perfectly secure. We continue to review and improve our safeguards.

10. Your Rights

Subject to conditions set out in the Gibraltar GDPR, you have the following rights:

  • Access — to obtain confirmation of whether we process your data and a copy of it.
  • Rectification — to have inaccurate data corrected and incomplete data completed.
  • Erasure — to have data deleted where one of the statutory grounds applies.
  • Restriction — to limit our processing in specified circumstances.
  • Portability — to receive data you provided in a structured, commonly used, machine-readable format where processing is based on consent or contract and is automated.
  • Objection — to object to processing based on legitimate interests, and to object at any time to direct marketing.
  • Withdrawal of consent — at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Automated decision-making — rights in relation to decisions producing legal or similarly significant effects based solely on automated processing (see clause 11).

To exercise any right, email privacy@ooplah.net. We may need to verify your identity. We aim to respond within one calendar month and may extend by a further two months for complex requests, notifying you of any extension.

11. Automated Decision-Making

Ooplah does not make decisions producing legal or similarly significant effects about you based solely on automated processing or profiling. Where this changes for a specific Service, we will provide meaningful information about the logic involved and your rights at that point.

12. Children

Our Services are directed to businesses and professional users. We do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, please contact privacy@ooplah.net and we will delete it.

13. Cookies & Tracking

We use cookies and similar technologies as described in our Cookie Policy. Strictly necessary cookies do not require consent. Analytics and marketing cookies are set only after you grant consent, which you can withdraw at any time from the cookie banner or the preferences link in our footer.

14. Complaints & Supervisory Authority

If you are concerned about how we handle personal data, please contact us first at privacy@ooplah.net so we can try to resolve the matter.

You also have the right to lodge a complaint with the Gibraltar data protection supervisory authority:

Gibraltar Regulatory Authority (GRA)
2nd Floor, Eurotowers 4
1 Europort Road
Gibraltar
Email: info@gra.gi
Web: www.gra.gi

If you are located in the EEA or the UK you may also contact your local supervisory authority.

15. Changes to this Policy

We may update this policy from time to time. The current version will always be posted on this page with an updated effective date. Material changes will be notified by a prominent notice on the Website or, where we hold your email address, by email. Continued use of the Website after the effective date of a change indicates acceptance of the updated policy.

16. Contact

Email

privacy@ooplah.net

Post

Ooplah
13 Irish Town
Gibraltar

This Privacy Policy was last updated on 21 April 2026 (version 2.1).