Legal
Privacy Policy
ONbackup, operated by Onnen Solutions Ltd (trading as "Onnen")
Last updated: 3 July 2026 · Effective date: 3 July 2026
1. Introduction
This Privacy Policy explains how Onnen Solutions Ltd ("Onnen", "we", "us" or "our") collects, uses, shares and protects personal data in connection with ONbackup, our Meraki network-configuration backup platform (the "Platform" or the "Service").
We are committed to protecting personal data and respecting privacy rights. This Policy is written to comply with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 ("DPA 2018"), the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR") and other applicable data protection laws (together, "Data Protection Law").
This Policy applies to:
- visitors to our website and marketing pages;
- representatives of our business customers who register for, administer or use the Platform ("Authorised Users"); and
- individuals whose personal data may be incidentally contained within Meraki network configuration data backed up through the Platform (for example, in device or network labels).
Please read this Policy alongside our Terms and Conditions and, where applicable, the Data Processing Agreement entered into with our business customers.
2. Who we are and how to contact us
Onnen Solutions Ltd is a company registered in England and Wales.
- Company number: 17275906
- Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
- ICO registration number: ZC183731
- Email: support@onbackup.co.uk
For any privacy-related questions, requests or complaints, please contact us at support@onbackup.co.uk or write to us at the registered office address above, marking your correspondence "Data Protection".
3. Our roles under Data Protection Law
The Platform involves two distinct processing relationships:
(a) Onnen as controller. We act as a data controller for personal data we collect to operate our business and provide the Service, for example account registration data for Authorised Users, billing contacts, website analytics, and marketing communications. Sections 5 to 13 of this Policy describe this processing.
(b) Onnen as processor. When our business customers use the Platform to back up their Meraki network configuration data, our customer is the data controller of any personal data incidentally contained within that configuration data, and we act as a data processor acting on their instructions. Our processing in this capacity is governed by the Data Processing Agreement ("DPA") between us and the customer, summarised in Section 14.
If you are an individual whose data is incidentally contained within a customer's backed-up Meraki network configuration data, that customer is responsible for how your data is used. Please direct privacy requests to the relevant customer; we will assist them as required.
4. Data we do not access
Your Meraki network configuration and backup data remain under your control at all times. Onnen personnel do not routinely access, view or inspect the contents of your backups. Access is only granted to authorised support staff when necessary to diagnose an issue you have raised, or otherwise on your instruction, and is governed by the following principles:
- Least privilege: access is limited to the minimum data and duration needed to resolve the specific issue.
- Authorised and logged: all access to customer backup data is authorised in advance and logged, including who accessed it, when, and why.
- No routine or automated inspection: we do not review, analyse or otherwise use the contents of your Meraki configuration data for any purpose beyond providing and supporting the Service.
These safeguards form part of the technical and organisational measures described in Section 15 (Data security) and the Data Processing Agreement referenced in Section 14.
5. Personal data we collect (as controller)
We collect and process the following categories of personal data:
Account and identity data: name, job title, business email address, business telephone number, username, and password (stored in hashed form) of Authorised Users.
Customer and billing data: company name, billing contact details, billing address, VAT number, purchase order references and records of subscriptions and payments. Card payments are processed by our third-party payment provider; we do not store full card numbers.
Usage and technical data: IP address, device and browser type, operating system, login timestamps, pages and features accessed, and actions taken within the Platform, collected through logs and cookies.
Communications data: the content of emails, support tickets, chat messages and other correspondence you send to us.
Marketing data: your preferences in receiving marketing from us and your communication preferences.
We do not intentionally collect special category personal data through the Platform.
6. How we collect personal data
We collect personal data when you:
- register for an account, request a demo or free trial, or purchase a subscription;
- use, configure or administer the Platform;
- contact us for support or by email, telephone or web form;
- subscribe to our communications or interact with our website; or
- are referenced within a customer's backed-up Meraki network configuration data.
We also collect technical and usage data automatically through cookies and similar technologies (see Section 12).
7. Purposes and lawful bases for processing (as controller)
We rely on the following lawful bases under Article 6 of the UK GDPR and EU GDPR:
| Purpose | Lawful basis |
|---|---|
| Creating and administering accounts; providing the Service to Authorised Users | Performance of a contract; legitimate interests |
| Processing payments and managing subscriptions | Performance of a contract; legal obligation |
| Providing customer support and responding to enquiries | Performance of a contract; legitimate interests |
| Securing, monitoring and improving the Platform; preventing fraud and abuse | Legitimate interests |
| Sending service and administrative communications | Performance of a contract; legitimate interests |
| Sending marketing communications about our products | Consent; or legitimate interests for existing business contacts |
| Complying with legal, regulatory and tax obligations | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may request details of this assessment by contacting us. Where we rely on consent, you may withdraw it at any time.
8. Marketing communications
We may send you marketing about products and services similar to those you have used or enquired about, where permitted by law. You can opt out at any time by using the unsubscribe link in our emails or by contacting support@onbackup.co.uk. We will always obtain consent where required before sending electronic marketing, in accordance with the Privacy and Electronic Communications Regulations (PECR).
9. How we share personal data
We may share personal data with:
Service providers (sub-processors): cloud hosting, infrastructure, payment processing, email delivery, customer support, analytics and security providers who process data on our behalf under appropriate contractual safeguards. Our current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting for backup storage (Blob Storage) and secrets management (Key Vault) | UK (UK South region) |
| Microsoft Azure Communication Services | Transactional email for service and security notifications | UK (UK South region) |
| Clerk | Authentication and sign-in for Authorised Users | Global |
| Stripe Payments UK Ltd | Payment processing and billing | UK / EU / US |
| Google (Google Analytics 4) | Website usage analytics — only where the visitor has consented | Global |
Professional advisers: lawyers, accountants, auditors and insurers, where necessary.
Authorities and regulators: where required to comply with a legal obligation, court order or lawful request.
Business transfers: in connection with a merger, acquisition, financing or sale of business assets, in which case personal data may be transferred subject to this Policy.
We do not sell personal data. We review the sub-processor list above periodically and will update it when our sub-processors change; contact support@onbackup.co.uk if you would like to be notified of material changes.
10. International data transfers
Our primary data hosting is within the UK and/or European Economic Area ("EEA"). Where personal data is transferred outside the UK or EEA (for example to a sub-processor), we ensure an appropriate safeguard is in place, such as:
- a UK or EU adequacy decision for the destination country;
- the UK International Data Transfer Agreement ("IDTA") or the UK Addendum to the EU Standard Contractual Clauses; or
- the EU Standard Contractual Clauses ("SCCs").
You may request a copy of the relevant safeguard by contacting us.
11. Data retention
We retain personal data only for as long as necessary for the purposes set out in this Policy, including to satisfy legal, accounting, tax or reporting requirements.
- Account data is retained for the duration of the customer relationship and deleted or anonymised within 14 days of account closure, unless required for legal or contractual reasons.
- Billing records are retained for at least six (6) years to meet UK tax and accounting requirements.
- Customer content (including Meraki backup data) is retained in accordance with the customer's instructions and the DPA. Upon termination, customer backup data is deleted in accordance with the DPA and our documented retention schedule, unless a longer retention period is requested by the customer or required by law.
- Marketing data is retained until you opt out or after a reasonable period of inactivity.
When data is no longer required, we securely delete or anonymise it.
12. Cookies and similar technologies
Our website and Platform use cookies and similar technologies to operate the Service and maintain security. We use strictly necessary cookies, which are required for the Service to function and, under the Privacy and Electronic Communications Regulations (PECR), do not require your consent.
On our public website we also use Google Analytics to understand how the site is used — but only with your consent. Analytics is off by default; Google Analytics is loaded, and its cookies set, only after you choose "Accept" in our consent banner, and you can change or withdraw that choice at any time. If you reject or ignore the banner, no analytics cookies are set. We do not use advertising, profiling or cross-site tracking cookies. Your consent choice is stored in your browser's local storage, not in a cookie, and is never sent to our servers. Our pricing page's Buy buttons redirect to a checkout hosted by Stripe, our payment processor, which may set its own strictly necessary cookies on Stripe's domain during checkout.
The ONbackup application uses strictly necessary cookies to keep Authorised Users signed in. You can control or delete cookies through your browser settings; blocking strictly necessary cookies may stop parts of the Service working. Full detail, including the specific analytics cookies and how to manage your consent, is available in our Cookie Notice.
13. Your data protection rights
Subject to conditions under Data Protection Law, you have the right to:
- Access: request a copy of the personal data we hold about you;
- Rectification: request correction of inaccurate or incomplete data;
- Erasure: request deletion of your data in certain circumstances;
- Restriction: request that we limit processing in certain circumstances;
- Portability: request transfer of your data in a structured, machine-readable format;
- Object: object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent: where processing is based on consent; and
- Rights relating to automated decision-making: we do not make solely automated decisions producing legal or similarly significant effects about you.
To exercise your rights, contact support@onbackup.co.uk. We will respond within one month, which may be extended for complex requests. We may need to verify your identity.
If you are an individual whose data is incidentally contained within a customer's backed-up network configuration data, please direct your request to that customer (the controller); we will support them in responding.
You also have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO), at ico.org.uk. In the EU you may complain to your local data protection authority. We would, however, appreciate the chance to address your concerns first.
14. Processing on behalf of customers (Onnen as processor)
When we process personal data incidentally contained within customer Meraki backup data, we do so as a processor under a DPA that includes the requirements of Article 28 of the UK GDPR and EU GDPR. In summary, we:
- process personal data only on the documented instructions of the customer;
- ensure persons authorised to process data are bound by confidentiality;
- implement appropriate technical and organisational security measures;
- engage sub-processors only under equivalent obligations and with the customer's authorisation;
- assist the customer with data subject requests, security, breach notification and impact assessments;
- delete or return personal data at the end of the services; and
- make available information necessary to demonstrate compliance and allow for audits.
15. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing, accidental loss, destruction or damage. These include encryption in transit and at rest, access controls, role-based permissions, network security, logging and monitoring, and regular review of our security practices. While we work hard to protect your data, no method of transmission or storage is completely secure.
In the event of a personal data breach affecting customer data, we will notify affected customers without undue delay where required by applicable Data Protection Law.
16. Children's data
The Platform is intended solely for business users and is not designed for use by children. If you believe we have inadvertently collected personal data from a child, please contact us and we will delete it.
17. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top indicates when it was last revised. Where changes are material, we will provide notice through the Platform or by email. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
18. Contact us
If you have any questions about this Policy or our data practices, please contact:
Onnen Solutions Ltd
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Email: support@onbackup.co.uk