About the firm

Two partners. Three disciplines. One table.

Omerbeyoglu Unlu Ltd is run by its two partners. Feyzullah Omerbeyoglu leads the technology, Bilge Unlu Omerbeyoglu leads the legal work, and the strategy decisions are made by both at the same table. Technology, legal, strategy is the firm's whole proposition, and the partners answer for every engagement personally.

Who we are

Most technology problems that reach a consultancy are not purely technical. A data platform stalls because nobody can say whether the transfer to the analytics vendor is lawful. A supplier contract gets signed with an uptime clause the architecture cannot meet. A public programme is designed before anyone has checked which authority actually allows it.

Those failures happen in the gap between the engineer and the lawyer. We closed the gap by putting both in the same firm, with a shared calendar and a shared incentive. When we review a system, the architecture review and the contract review happen in the same week and the two reviewers read each other's notes.

That is also where the strategy work comes from. Whether to build or buy, which supplier, which market first, whether a company is worth the price an acquirer is about to pay: those questions have a technical answer and a legal answer, and the honest recommendation is the one that survives both. Technology, legal, strategy is not a list of three services. It is the order in which a good decision gets checked.

We work across three kinds of client. Commercial operators in consumer goods, retail and e-commerce who need integration, data and reporting work with the legal side handled properly, which is the longest-running part of the practice. Organisations running mission-critical or regulated systems, where an incorrect output has a consequence. And public bodies that need programme and policy work they can defend.

What you can take at face value

Everything on this site is written to be checked. That is the standard we hold our client work to, so it is the standard we hold our own pages to.

  • Every claim here can be evidenced. The work is described by what it involved and what you keep at the end. Ask about any of it in a meeting and you will get the file, the method and the reasoning behind it.
  • Credentials are stated as exactly what they are. PMP, PSPO II and ISC2 on the technology side, a qualified lawyer on the legal side, and vendor training from IBM, Google, Meta and SAP. Each is listed on the partners page with the body that issued it.
  • Confidentiality is part of the service. Most of our engagements run under NDA and we treat that as a feature. A client is named only with written permission, and the same discretion covers you from the first call onwards.
  • You get a straight answer on fit. If your problem needs a different specialism, or representation by a regulated firm, you hear that in the first call, along with a pointer to where to go. Our reputation rests on the advice being right, not on the engagement being ours.

The firm in facts

Registered name
Omerbeyoglu Unlu Ltd
Company number
16504956, England & Wales. Listed on the public Companies House register.
Registered office
82A James Carter Road, Mildenhall, Suffolk IP28 7DE, United Kingdom
Partners
Feyzullah Omerbeyoglu, Technology Bilge Unlu Omerbeyoglu, Legal
Where we work
United Kingdom, Europe, Turkey and the Middle East. Remote first, on site where the work needs it.
Disciplines
Technology, legal, strategy. Two partners cover all three.
Engagement models
Fixed-scope assessment, retained advisory, or delivery in agreed increments
General enquiries
contact@omerbeyogluunlu.com

How we work

Four commitments you can hold us to

Every consultancy says it is practical, client focused and expert. None of that can be checked. These four can.

  1. You get the partners

    Feyzullah leads the technology, Bilge leads the legal work, and both sit in the strategy decisions. The partner who scopes your work is the partner who answers for it, from the first call to the handover.

  2. Decisions get written down

    Anything expensive to reverse gets a short record: the decision, the options we rejected, and the reason. On our own platform work that register runs to forty-one entries. You keep those records whether or not you keep us, so your next supplier does not have to re-derive our reasoning.

  3. We separate verified from assumed

    Our reports mark each finding as confirmed, inferred or unverified, and a closing section names what we could not reach and why. On larger files that verification register is a deliverable in its own right. A recommendation you cannot audit is not worth acting on.

  4. We tell you what is still open

    Handovers include the list of decisions nobody can close yet, with the input each one is waiting on. Pretending an open question is settled is how programmes fail eighteen months later.

How we write

Documents a busy reader can act on

Most of what we deliver is a document, and a document nobody reads is a failed deliverable. These are the rules every report, register and note we produce follows. They are the same rules we hold our own templates to.

  1. Every number carries its source

    A figure without a citation does not go in. If the source is our own measurement, the method is stated with it.

  2. Confirmed, inferred, unverified

    Findings are marked as one of the three. What we asked for and did not receive is listed, so nobody mistakes silence for a clean bill.

  3. Plain sentences

    Short, in the active voice, with no jargon a reader outside the team would have to look up. If a sentence needs a semicolon it needs to be two sentences.

  4. Readable without us

    The test for every handover is whether your next supplier can pick it up cold. If they would need us in the room, it is not finished.

What you leave with

The documents, not just the deliverable

Every engagement ends with a set of written artefacts. They are yours, they read without us in the room, and they are the reason a second supplier does not have to start from zero.

Decision records

One page per choice that would be expensive to reverse: what we chose, what we rejected, and why.

Verification register

Each finding marked confirmed, inferred or unverified, with its source, and a list of what we asked for and did not get.

Open items register

Every decision nobody can close yet, the options, and the input each one is waiting on. Pretending it is settled is how programmes fail later.

Threat model

The threats, the control that answers each one and where it lives in the code, and the rows that are honestly still open.

Integration map

What talks to what, over which protocol, and who owns each field. The document that stops the next migration from guessing.

Metric dictionary

A definition, an owner and a refresh schedule for every number on a dashboard, so two departments stop arguing about whose is right.

Runbooks

What to do when a dependency is down, a credential is compromised or a job fails silently. Written before the night it is needed.

Contract and data map

Which agreement governs which system, where the data goes, which country it reaches, and which transfer mechanism covers each hop.

Sectors

Where we work

Consumer goods, retail and e-commerce

The longest-running part of the practice. The integration and data work that keeps a commercial operation running, with the supplier contracts and data protection position handled at the same time rather than afterwards.

  • Supply chain and inventory visibility, and the systems behind it
  • Point of sale, marketplace and omnichannel integration
  • Payment and order flows, and the data protection position around them
  • Customer data management, reporting and retention
  • Supplier and processor contract review

Public sector

We produce policy and strategy for public bodies, and the programme plans and scheme designs that carry them through institutional review.

  • Programme management and work package definition
  • Comparative research and options analysis
  • Feasibility and institutional framework analysis
  • Public-facing application system design

Defence, public safety and critical systems

Software where an incorrect output has a physical consequence. Real-time data, geospatial accuracy, standards-based interoperability, and audit trails that survive an investigation.

  • Telemetry ingest and sensor fusion
  • Operational picture and mapping interfaces
  • Human approval gates on consequential decisions
  • Append-only audit chains and evidence retention

Regulated and data-heavy operations

Organisations whose data processing has to stand up to a regulator. We map what you hold, how it moves, who it reaches, and what has to change before the next audit.

  • Records of processing and data mapping
  • Data protection impact assessments
  • International transfer mechanisms
  • Incident readiness and breach response drafting

Two partners, one conversation

You will speak to both of us. Bring the problem in whatever state it is in, and we will tell you what we think it actually is.

Get in touch