Privacy Policy

What personal data we hold, why, and what you can ask us to do with it.

Who is responsible for your data

In this policy “we” means whoever operates this installation of Open Backlog — the organisation that put it online and holds the account you are signing in to. They are the people to go to for anything this policy says to raise with us, and if you reached the service through your employer, they are your employer.

The service is built to United Kingdom data protection standards, and this policy describes what it actually does with your data — which is the same wherever it is run from.

Which party is legally responsible for your data depends on how you signed in:

What we collect

Only what the service needs to work:

Some information is also kept on your own device to make signing in quicker — the username or work address you last used, and your colour-scheme choice. It stays on your device and clearing your browser data removes it.

What we do not do

Why we are allowed to use it

Under UK data protection law we must have a lawful basis for each use. Ours are:

Who else sees it

We do not add a new provider that handles personal data without updating the list at Data Processing Terms first.

Where it goes

The service runs on a global network, so your data may be handled outside the United Kingdom. Where it is, we rely on UK adequacy regulations for that country, or on the UK International Data Transfer Agreement (or the Addendum to the European Commission’s standard contractual clauses), together with an assessment of the protection actually available.

How long we keep it

Your rights

You have the right to a copy of your data, to have it corrected or deleted, to restrict or stop a particular use, and to have it handed to another provider. You can withdraw consent, and you can object to processing based on legitimate interests.

Most of it you can exercise yourself, without asking anyone, which is deliberate — a right you have to request is a right somebody can be slow about:

For anything you cannot do yourself, ask whoever operates this installation; a request must be answered within one month, free of charge, and you do not have to give a reason. If your account came from your employer, they are the controller and the request goes to them.

If it goes wrong you can complain to the Information Commissioner’s Office (ico.org.uk) or to the data protection authority where you live.

Security

We design the service so that a compromise of any one part gives up as little as possible: sign-in resists phishing by construction, data is encrypted in transit and at rest, each organisation’s data is separated from every other’s, and access to production is limited and recorded. There is more detail at Security. No service is immune, and if a breach affects your rights we will tell the regulator within 72 hours and you without undue delay.

Children

The service is not intended for children under 13, we do not knowingly create accounts for them, and an account found to belong to one is removed.

Changes

If this policy changes, the date at the foot of the page changes with it, and anything that materially affects you is announced in the app before it takes effect.

Last updated 29 July 2026.

All policies · Sign in