Legal

Privacy Policy

Last updated: 20 August 2026

Obsidian Metra ("Metra", "we", "us" or "our") is a product developed, operated and owned by Obsidian Reach Ltd, a company registered in England and Wales.

This Privacy Policy explains how we collect, use, store and protect personal information when you visit the Obsidian Metra website, create or use an Obsidian Metra account, interact with our services, or contact us.

It also explains your rights under applicable data protection law, including the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.

1. Who We Are

The operator of Obsidian Metra is:

Obsidian Reach Ltd
UK Registered Company No. 16394927
3rd Floor, 86-90 Paul Street
London
United Kingdom
EC2A 4NE

Telephone: 020 3051 5216
Email: support@obsidianreach.tech

Obsidian Metra is a product developed and owned by Obsidian Reach Ltd.

For personal information that we determine the purposes and means of processing, Obsidian Reach Ltd is the data controller.

For certain information entered into Obsidian Metra by organisations using the service, Obsidian Reach Ltd may instead act as a data processor on behalf of that organisation. See Section 4: Customer Data for further information.

2. Information We Collect

The information we collect depends on how you interact with Obsidian Metra.

Account Information

When an account is created or you are invited to an organisation, we may collect:

  • Your name.
  • Email address.
  • Organisation or employer.
  • Job title or role, where provided.
  • Account identifier.
  • Organisation memberships.
  • Application roles and permissions.
  • Account status.
  • Authentication and login information.

Organisation Information

When an organisation uses Obsidian Metra, we may collect information including:

  • Organisation name.
  • Business contact information.
  • Sites and locations.
  • User and membership information.
  • Subscription information.
  • Billing contact details.

Calibration and Equipment Data

Users may enter information relating to equipment and calibration activities, including:

  • Equipment identifiers.
  • Serial numbers.
  • Manufacturers and models.
  • Equipment locations.
  • Responsible personnel.
  • Calibration requirements.
  • Calibration schedules.
  • Calibration results.
  • Measurement results.
  • Calibration certificates.
  • Calibration procedures.
  • Calibration providers.
  • Environmental conditions.
  • Out-of-tolerance investigations.
  • Corrective actions.
  • Approval and review records.
  • Technical authorisations.
  • Controlled documents.
  • Audit evidence.

Some of this information may contain personal information where individuals are identified as responsible personnel, technicians, reviewers, approvers or other participants in a controlled process.

Audit and Activity Information

Obsidian Metra maintains audit records to support security, traceability and regulated workflows.

These records may include:

  • User identity.
  • Organisation membership.
  • Actions performed.
  • Date and time of actions.
  • Records accessed or changed.
  • Previous and updated values where appropriate.
  • Approval and review activity.
  • Request or transaction identifiers.
  • Technical information associated with an action.

Audit information may be retained where necessary to maintain the integrity and traceability of regulated records.

Technical Information

When you access Obsidian Metra, we may automatically collect technical information including:

  • IP address.
  • Browser type and version.
  • Device type.
  • Operating system.
  • Date and time of access.
  • Requested pages or API endpoints.
  • Application errors.
  • Security events.
  • Request identifiers.
  • Performance and diagnostic information.

Communications

If you contact us, we may retain:

  • Your name.
  • Email address.
  • Telephone number.
  • Organisation.
  • The contents of your communication.
  • Support correspondence.
  • Information necessary to investigate and resolve your request.

Billing Information

Where an organisation purchases a subscription, we may process information relating to:

  • Subscription plan.
  • Subscription status.
  • Billing contact.
  • Billing history.
  • Payment status.
  • Transaction identifiers.

Payment processing is provided by a third-party payment processor.

We do not intend to store complete payment card numbers or card security codes within Obsidian Metra.

3. How We Use Personal Information

We may use personal information to:

  • Provide and operate Obsidian Metra.
  • Create and manage user accounts.
  • Manage organisation memberships and permissions.
  • Authenticate users.
  • Provide calibration and equipment management functionality.
  • Maintain calibration, approval and audit records.
  • Generate compliance and audit evidence.
  • Provide notifications and reminders.
  • Process subscriptions.
  • Provide customer support.
  • Respond to enquiries.
  • Monitor service availability and performance.
  • Diagnose technical problems.
  • Detect and prevent fraud, abuse and security incidents.
  • Protect the integrity of customer and regulatory records.
  • Improve the service.
  • Comply with legal and regulatory obligations.
  • Establish, exercise or defend legal claims.

We will not use personal information for purposes that are incompatible with the purposes for which it was collected unless permitted or required by law.

4. Customer Data

Organisations using Obsidian Metra may enter and manage information about their employees, contractors, customers, calibration personnel and other individuals.

For this information, the customer organisation will generally determine why the information is processed and how Obsidian Metra is used.

In these circumstances:

  • The customer organisation will generally act as the data controller.
  • Obsidian Reach Ltd will generally act as a data processor on behalf of the customer.

We process this information in accordance with the customer's instructions, our agreement with the customer and applicable law.

If you have questions about personal information entered into Obsidian Metra by your employer or another organisation, you should normally contact that organisation first.

Where required, we will assist our customers in responding to data protection requests relating to information we process on their behalf.

A Data Processing Agreement may be made available to customers where required.

6. Calibration, Quality and Audit Records

Obsidian Metra is designed to support controlled calibration and quality-management workflows.

Certain records may therefore be deliberately retained as immutable or append-only records.

These may include:

  • Calibration records.
  • Calibration approvals.
  • Calibration certificates.
  • Equipment status history.
  • Out-of-tolerance investigations.
  • Corrective actions.
  • Controlled-document revisions.
  • Technical authorisations.
  • Audit events.
  • Compliance evidence.

Where personal information forms part of these records, deleting or altering it may affect the integrity, traceability or regulatory value of the record.

Requests relating to this information will therefore be assessed in accordance with applicable data protection law and any applicable legal, regulatory, contractual or legitimate record-retention requirements.

A right to erasure does not necessarily require information to be deleted where a lawful exception applies.

7. How We Share Information

We do not sell personal information.

We may share information with third parties where necessary to operate Obsidian Metra.

These may include providers of:

  • Cloud hosting and infrastructure.
  • Database services.
  • Object and document storage.
  • Email delivery.
  • Authentication and identity services.
  • Payment processing.
  • Monitoring and error reporting.
  • Security services.
  • Customer support infrastructure.

These providers may process personal information only as necessary to provide their services to us and subject to appropriate contractual and data protection requirements.

We may also disclose information:

  • Where required by law.
  • In response to a valid legal process.
  • To protect our legal rights.
  • To investigate fraud, abuse or security incidents.
  • In connection with a merger, acquisition, restructuring or sale of all or part of our business.

Where appropriate, we will maintain information about the subprocessors used to provide Obsidian Metra.

8. International Data Transfers

Some service providers used by Obsidian Metra may process information outside the United Kingdom.

Where personal information is transferred internationally, we will take appropriate steps to ensure that the transfer complies with applicable data protection law.

Depending on the destination and circumstances, these safeguards may include:

  • UK adequacy regulations.
  • The UK International Data Transfer Agreement.
  • The UK Addendum to the EU Standard Contractual Clauses.
  • Other legally recognised transfer mechanisms.

Where appropriate, we will also assess the protections applicable to transferred information.

9. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including legal, regulatory, contractual, security and legitimate business requirements.

Retention periods may differ depending on the type of information.

Account information may be retained while an account remains active and for an appropriate period afterwards.

Billing and transaction records may be retained where required for accounting, taxation and legal purposes.

Support communications may be retained where necessary to maintain customer-service and business records.

Calibration, quality, compliance and audit information may be retained for longer periods where required by the customer, applicable standards, contractual obligations, regulatory requirements or the need to maintain complete historical evidence.

When information is no longer required, it will be deleted, anonymised or otherwise disposed of appropriately.

10. Security

We use technical and organisational measures designed to protect information against:

  • Unauthorised access.
  • Unauthorised alteration.
  • Accidental loss.
  • Destruction.
  • Disclosure.
  • Misuse.

Measures used by Obsidian Metra may include:

  • Authentication and access controls.
  • Organisation-level data isolation.
  • Role-based permissions.
  • Encryption in transit.
  • Restricted infrastructure access.
  • Private file storage.
  • Cryptographic file checksums.
  • Audit logging.
  • Controlled approval workflows.
  • Security monitoring.
  • Backup and recovery processes.

No internet-based service can guarantee absolute security.

Users are responsible for protecting their own credentials and for notifying us promptly if they believe their account or organisation has been compromised.

11. Cookies and Similar Technologies

The Obsidian Metra website and application may use cookies or similar technologies where necessary to:

  • Maintain sessions.
  • Provide authentication.
  • Remember user preferences.
  • Protect the service against security threats.
  • Understand service performance and usage.

Where non-essential cookies or similar technologies are used, we will obtain consent where required by law.

Further information may be provided in our Cookie Policy.

12. Marketing Communications

Where permitted by law, we may send information about Obsidian Metra, including product updates, relevant services and other business communications.

You may opt out of marketing communications at any time using the unsubscribe mechanism provided or by contacting us.

Service communications relating to security, subscriptions, account administration or essential functionality are not marketing communications and may still be sent where necessary to operate the service.

13. Your Data Protection Rights

Depending on the circumstances and applicable law, you may have rights including:

  • The right to be informed about how your personal information is used.
  • The right to access your personal information.
  • The right to correct inaccurate or incomplete information.
  • The right to request erasure of your personal information.
  • The right to restrict processing.
  • The right to data portability.
  • The right to object to certain processing.
  • Rights relating to automated decision-making and profiling.
  • The right to withdraw consent where processing is based on consent.

These rights are not absolute and may be subject to legal exceptions.

To exercise your rights where Obsidian Reach Ltd is the controller, contact:

support@obsidianreach.tech

We may need to verify your identity before completing a request.

Where the information is controlled by an organisation using Obsidian Metra, we may refer your request to that organisation or assist it in responding.

14. Automated Decision-Making

Obsidian Metra may calculate or display information such as:

  • Calibration status.
  • Due and overdue status.
  • Measurement results.
  • Audit-readiness indicators.
  • Compliance warnings.

These features are intended to support users in making decisions.

Unless expressly stated otherwise, Obsidian Metra does not make solely automated decisions about individuals that produce legal or similarly significant effects.

Future analytical or artificial-intelligence features will be assessed for applicable data protection requirements before deployment.

15. Children's Privacy

Obsidian Metra is a business service and is not intended for use by children.

We do not knowingly provide accounts directly to children or intentionally collect personal information from children through the service.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to Obsidian Metra.
  • Changes to our service providers.
  • Changes to applicable law or regulatory guidance.
  • Changes to how we process information.

The latest version will be published on the Obsidian Metra website with an updated revision date.

Where a change materially affects how we process personal information, we will provide additional notice where appropriate.

18. Complaints

If you have concerns about how we process your personal information, please contact us first so that we can investigate.

You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK's data protection regulator.

Information about making a complaint is available from the ICO.

19. Contact Us

For questions about this Privacy Policy or how Obsidian Metra processes personal information, contact:

Obsidian Reach Ltd
3rd Floor, 86-90 Paul Street
London
United Kingdom
EC2A 4NE

Telephone: 020 3051 5216
Email: support@obsidianreach.tech
Company No.: 16394927

Obsidian Metra is a product developed and owned by Obsidian Reach Ltd.