LEGAL — WRITTEN TO BE DIFFED AGAINST THE NETWORK TAB
Privacy policy
This policy covers two different relationships, kept structurally apart because they have almost nothing in common: Part A — this website, where some collection genuinely happens, and Part B — the product, a self-hosted deployment from which nothing reaches us. If you are a DPO, Part B is the paragraph you came for.
DRAFT — PENDING LEGAL REVIEW
PART A
This website — where collection happens
Applies to visitors of operativeops.com. This is the ordinary part: a website, an analytics script, a mailbox.
A.1 Analytics — Plausible, cookieless
This site loads one analytics script: Plausible (plausible.io), EU-hosted. It sets no cookie and assigns no identifier. What it receives per page view: the page URL, the referrer, and a coarse device class. What it cannot do: recognise you across sites, across days, or as a person. There is no Google Analytics and no advertising or tracking pixel of any kind — you can confirm this in your browser's network tab in under a minute, and the cookie policy tells you how.
A.2 Email you send us
Mail to contact@operativeops.com is stored in that mailbox and used to answer you. It is not entered into a CRM, not used for marketing, not shared, and not enriched with third-party data. Correspondence relating to a licence purchase is retained for the statutory commercial retention period; everything else is deleted when the conversation is closed and no longer needed.
A.3 Server logs
The web server keeps standard access logs (IP address, timestamp, requested path, user agent) for operational security, rotated and deleted on a short fixed schedule. They are not merged with analytics and not used to profile visitors.
A.4 Your rights
Under the GDPR you can request access, rectification, erasure, restriction, and portability of personal data we hold about you — which, per A.1–A.3, is at most your correspondence and short-lived server logs. Write to contact@operativeops.com; expect an answer within the statutory period, usually much faster. You also have the right to complain to a supervisory authority.
A.5 Impressum
OPEN ITEM
PART B
The product — where it doesn't
Applies to customers running a self-hosted OperativeOps deployment. This part is short because the data flow it describes does not exist.
B.1 Nothing reaches us
A customer's deployment sends us nothing under normal operation. No telemetry, no usage statistics, no documents, no prompts, no embeddings, no crash reports, no licence pings — the licence check runs offline. We are not a processor of your deployment's data for the simple reason that we never receive any of it. This is verifiable at your firewall, and the security page shows the boundary diagram.
B.2 Support engagements — the one exception
If you choose to share diagnostic material with us during a support engagement (log excerpts, configuration files), that is a separate, deliberate act by you — it happens over the channel you choose, is used only to resolve the issue, and is deleted afterwards. Redact before sending; we will never ask for documents or prompt contents.
B.3 Art. 28 — the customer's determination
Whether a processor agreement (Art. 28 GDPR / AVV) is required when no personal data reaches us under normal operation is a determination your DPO makes, not an assertion we sell you — the compliance pages frame it the same way. If your assessment concludes one is needed for support engagements under B.2, ask; that conversation is expected, not resisted.