Skip to Content

Privacy Policy (Politique vie privée) — Onbora

In effect from 23 June 2026 


This Privacy Policy details the commitment of the company Onbora SRL (based at Avenue Horte Chêne 10, 4053 Embourg (Chaudfontaine), Belgium, under the company number BE 1038.898.803) regarding the collection, processing, securing and confidentiality of personal data on its SaaS platform (app.onbora.com, portal.onbora.com) and its showcase site (onbora.com). Designed according to the principles of "by design" compliance and data minimisation, this policy is rigorously aligned with the General Data Protection Regulation (GDPR) and the "Enterprise-Grade" security requirements demanded by our professional clients subject to AML/CFT obligations.

1. Duality of Onbora's Roles (Controller vs Processor)

To understand the processing of your data, it is important to distinguish the two frameworks of Onbora's intervention: 

● Onbora as Data Controller: This exclusively concerns the data collected from our professional Clients (Notaries, Lawyers, Trustees, Brokers, Estate Agents) for the management of their account, from billing to usage, their subscription and the optimisation of their SaaS tool. 

● Onbora as Processor: This concerns all onboarding data, identity documents, organisational charts and KYC information imported or submitted on the platform by the clients of our clients (the end users). In this context, Onbora's professional Client remains the sole and unique Data Controller. Onbora acts under their strict and exclusive instructions to provide them with a compliant decision support assistant.  

2. Categories of Data Collected & Purposes

Onbora applies a strict data minimization policy. We do not collect any unnecessary data.

Date Collected : First name, last name, professional email address, phone number, company name, bank details, full and immutable activity logs (IP address, timestamp of review actions).

Legitimate Purpose of Processing
:
 Execution of the SaaS contract, billing management per active file, multi-tenant cloud security, and establishment of the audit trail mandated by regulatory authorities (CTIF, Tracfin).

Data Collected : Identification details (First name, last name, date & place of birth, nationality, national ID number), proof of residency, encrypted ID documents, PEP declarations, source of funds and transaction details, ownership & control structure charts (UBO).


End User (KYC Onboarding Candidate) : Enabling the Client (Data Controller) to perform its due diligence obligations regarding Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT).

3.  Data Recipients & Global Screening

The collected KYC data is under no circumstances sold, rented, or shared for commercial purposes. It is exclusively accessible to:

1. Authorized users of the Business Client (the ordering notary's office or firm) through our Role-Based Access Control (RBAC) system.

2. To our third-party global screening providers (World-Check / Refinitiv) for instant and automated verification of matches on sanctions lists (EU, UN, OFAC, UK HMT), PPE and Adverse Media. These queries are conducted via highly secure and encrypted APIs.


4. "Enterprise-Grade" Security and Waterproof Hosting

Onbora's infrastructure is based on a multi-tenant cloud architecture with absolute logical data isolation between each study or client firm. Your data benefits from the most advanced protection measures in the RegTech market: 

● Total Encryption: All documentary pieces, passports, statuses and UBO registers are stored in an encrypted state at rest using the military-grade AES-256 algorithm. Transit flows are protected by the TLS 1.3 protocol. 

● European Sovereignty: The entirety of Onbora's Cloud infrastructure and storage servers is located within the European Union, excluding any unsecured transfer outside the EU.

● Immutable Audit Trail: Every consultation, modification, screening or lifting of doubt performed by a manager is recorded in an immutable and unmodifiable log register, guaranteeing an "Audit-Ready" record in the face of regulatory checks.


5. Data Retention Period

Data is retained only for as long as necessary for the purposes for which it was collected, in strict compliance with the law: 

● Client Account Management Data: Retained for the entire duration of the SaaS contractual relationship, then archived for 5 years for tax and evidential purposes. 

● KYC Data and Documents: In accordance with the mandatory obligations of the Law Prevention of Money Laundering and to anticipate the strict framework of the AMLR 2027, the data from onboarding, screening reports and decisions to lift doubts are kept for a regulatory period of 10 years after the end of the business relationship between the regulated professional and their client, under the responsibility of the Client giving the order. 


6. Your Rights under the GDPR

In accordance with European regulations, any concerned person has the following rights: right of access, rectification, limitation of processing, portability and objection. To exercise these rights or for any questions regarding the protection of your data, you can write directly to our team at the address: legal@onbora.com. Critical regulatory note: The right to immediate erasure of data (right to be forgotten) may be legally limited or denied regarding KYC data. Legal obligations of public order in terms of anti-money laundering (AML/CFT) take precedence over the right to erasure for the mandatory legal retention period of 10 years.

7. Policy Updates

Onbora reserves the right to modify this policy at any time to reflect the developments of its platform or legislative updates (notably through our ongoing legal monitoring partnership with the law firm Elegis). Any significant changes will be notified directly on the administration interface of our Clients.