Ops Intel
Log In Get Started

Privacy Policy

Last updated: 5 October 2026

1. Who We Are

Ops Intel writes AI compliance frameworks for small and medium businesses worldwide. Ops Intel ("we", "us", "our") is operated by Scott Neve trading as Ops Intel. Our registered place of business is in England, United Kingdom.

We are registered with the Information Commissioner's Office (ICO) as a data controller. ICO Registration Number: ZC146281.

For any privacy-related enquiries, contact us at: scott@opsintel.io

2. What Data We Collect

We collect the following categories of personal data:

  • Account data: Email address, name, and password (hashed) when you register.
  • Billing data: Billing name and address, and payment card metadata (last 4 digits, expiry) — full card details are processed and stored by Stripe and never held by us.
  • Usage data: Log data, IP addresses, browser type, and pages visited for security and performance monitoring.
  • Content you create: Leads, campaigns, content items, workflows, and social posts you add to the platform.
  • Communications: Emails you send or receive via the platform's outreach features.
  • Free tool use: What you asked our free checkers to assess and the result you were shown, kept without any identifier. If you arrived from a marketing email we sent you, we also record the code in that link, which identifies the business we wrote to — so we can see whether the firms we contacted found the tool useful. That code is set only for people we emailed, it is stored on our own servers, and nothing is written to your device: no cookie, no tracking pixel, and we do not record whether you opened the email.
  • Sample pack requests: When you ask us to email you a full sample pack, your email address, your business name if you give it, which sample you asked for and the page you asked from. We use it to send the pack and to follow up with you about it. It is not added to any mailing list, and it is kept for 12 months unless you become a client.
  • Your compliance dashboard: If your framework comes with a compliance dashboard, what you enter on it: the AI tools you use, who looks after each one and when it was last reviewed; the names and job titles of the people you add, their work email address if you give it (used only to send them your policy to read and sign), and when each signed your AI policy and was trained; the incident notes you log; and where you keep each record your policy requires. We hold this on your behalf, as your processor (see section 6A of our Terms of Service), only to run your dashboard and keep your documents current. Staff names, training dates and incident notes are never sent to an AI model or to any company other than our hosting provider, Railway, and Resend, which delivers the emails asking your staff to sign your policy. The names and uses of AI tools you add are used, with the rest of your answers, to update your documents. The dashboard opens only with a one-time code we email to the address you bought with; we keep a scrambled copy of that code for 15 minutes. When your cover ends and is not renewed, everything you entered is deleted 30 days later, with the rest of your answers.
  • Law-change alerts: When you ask us, on our deadlines page, to tell you when a date on that page changes, your email address and the page you asked from. We use it to send you those alerts and for nothing else: it is not used for sales emails and it raises no enquiry with us. Every alert carries a link to stop them. We keep the address until you stop the alerts; after that we hold it only on our do-not-email list, so that we do not write to you again.

3. Legal Basis for Processing

We process your personal data on the following legal bases under UK GDPR:

  • Contract performance: To provide the service you have signed up for.
  • Legitimate interests: To improve the platform, prevent fraud, and ensure security.
  • Legal obligation: Where required by applicable law.
  • Consent: For optional marketing communications, where we have obtained your consent.

4. How We Use Your Data

We use your personal data to:

  • Provide, maintain, and improve the Ops Intel platform
  • Process payments and manage your subscription
  • Send transactional emails (account confirmations, invoices, password resets)
  • Respond to support requests
  • Comply with legal obligations
  • Detect and prevent fraudulent or abusive activity

5. Artificial Intelligence & Automated Processing

We use artificial intelligence tools and automated systems in the operation of our platform. We are committed to transparency about this use in compliance with UK GDPR, the Data (Use and Access) Act 2025, and ICO guidance on AI and automated decision-making.

AI Tools We Use

ToolProviderPurpose
Claude APIAnthropic PBCAI assistant features; drafting assistance using large language model (LLM) technology
Make.comCelonis SEBusiness process automation workflows using automated tools
HuggingFace Inference APIHugging Face Inc.Turning text into a numeric form so our AI receptionist can find the right answer in our knowledge base
Gemini APIGoogle LLCAI research, and company lookup during prospect enrichment (public business information only)
PageSpeed Insights APIGoogle LLCWebsite performance scoring for Business Intelligence Reports
Preferred Sources buttonGoogle LLCAn optional button on our blog pages letting you mark Ops Intel as a preferred source in your own Google results
StripeStripe Inc.Payment processing (card details held by Stripe, not us)
ResendResend, Inc.Transactional email delivery
RailwayRailway Corp.Cloud infrastructure hosting all platform data

Automated Decision-Making

Our Business Intelligence Report feature involves automated processing of website URLs to generate performance scores (page speed, SEO health, GEO readiness, AI compliance risk). This is automated analysis produced by an AI system — it is not a decision that produces legal effects concerning you, and you are free to disregard any automated findings or request a human review.

We do not use fully automated decision-making that produces legal or similarly significant effects concerning individuals, as defined under UK GDPR Articles 22A to 22D.

AI-Generated Content

Some platform features (AI assistant, caption generation) use generative AI to produce draft content. All AI-generated outputs are provided as drafts for human review — we do not represent AI-generated content as independently verified professional advice.

Third-Party AI Providers

Where we use third-party AI tools to process data you have provided, we ensure appropriate Data Processing Agreements are in place. We do not permit AI providers to train their models on your confidential data without your explicit consent.

6. Data Sharing

We do not sell your personal data. We may share data with the following categories of third parties:

  • Stripe: Payment processing (PCI DSS compliant)
  • Resend: Transactional email delivery
  • Railway: Cloud infrastructure hosting (EU/US data centres)
  • Anthropic: AI assistant features (message content processed; not stored by Anthropic)
  • Make.com: Automation workflow execution
  • Hugging Face: The message you type into our chat window, so the receptionist can look up the right answer
  • Google (Gemini and PageSpeed): AI research and company lookup for prospecting; website performance scoring for reports
  • Google (Preferred Sources button): On our blog pages only — your IP address and the address of the page you are reading, because the button is loaded from Google's servers
  • PostHog (EU): Website analytics, session replay and error reports — pages viewed, clicks, a playback of the visit with all typed input masked, and a report when a page hits a fault in our code. Also records product usage events if you hold an account (see below). Processed in the EU
  • Cal.com: Call booking — the name, email address and any details you enter when you book

All sub-processors operate under appropriate data processing agreements.

7. Data Retention

We retain your data for as long as your account is active, or as needed to provide services. Upon account deletion, we will delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes (typically 7 years for financial records).

8. Your Rights

Under UK GDPR, you have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate data.
  • Erasure: Request deletion of your data ("right to be forgotten").
  • Restriction: Restrict how we process your data in certain circumstances.
  • Portability: Receive your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interests.

To exercise any of these rights, contact us at hello@opsintel.io. We will respond within 30 days.

9. Cookies

We use strictly necessary cookies only. We do not use advertising or tracking cookies.

Most of the website sets no cookies at all. There are two exceptions, and both exist to make something work that you asked for:

  • Pages containing a form — our contact page and our guide request pages — set a security token when the page loads, which protects the form against misuse when you submit it. This happens whether or not you have an account.
  • Signing in sets a session cookie that keeps you logged in.

Both are strictly necessary cookies, which are exempt from the consent rules under PECR — there is nothing here for you to decline. Reading a page that has no form on it, without signing in, stores nothing on your device.

We measure how the website is used with PostHog, hosted in the EU and configured to store nothing on your device — no cookies, no browser storage. It records the pages viewed, the links and buttons clicked, the approximate location and device derived from your IP address, and the site you arrived from. We also record a playback of your visit, known as session replay. That playback shows what was on the screen, where you scrolled and moved, and what you clicked, so we can see where the site confuses people. Anything you type is hidden before the recording leaves your browser: every character you enter into any field — your name, business, email address, phone number and message — is replaced with an asterisk, so the recording never contains what you wrote and PostHog never receives it. If you go on to press send, the form itself of course delivers your message to us; it is the recording that never holds it. Payment card details are never on our pages at all — paying takes you to Stripe's own checkout on Stripe's domain, where we run no analytics. Because nothing is stored on your device, the analytics still cannot recognise you between visits or follow you to other websites — each visit is measured on its own, and this is why the site has no cookie banner.

We also record it when the site goes wrong for you. Since 7 September 2026, if a page hits a fault in our code, your browser sends us a report of that fault: the error message, the technical trace of which part of our code failed, and the address of the page you were on. It is how we find out that something is broken for real visitors instead of waiting for someone to tell us. It is sent only when a fault actually occurs, it contains nothing you typed, and it stores nothing on your device — the masking described above is unaffected.

Our fonts, stylesheets, images and scripts are all served from this domain. That matters because simply requesting a file from another company's server hands them your IP address and browser details before you have agreed to anything, so we keep it to the shortest list we can. There are two things on that list, and this is all of them:

  • Cal.com — the booking window, on the pages where you can book a call.
  • Google's "Preferred Sources" button — on our blog pages only. It is the button inviting you to see more of Ops Intel in your Google results. Because Google draws that button itself, Google is told your IP address and which article you are reading as soon as the page opens, whether or not you press it. Simply loading it stores nothing on your device — we have checked. Pressing it records a preference against your own Google account, which you can undo in Google at any time. It appears on our articles and nowhere else — not on the contact page, not at checkout, and not on these legal pages.

If you hold an account: how we measure the product

Everything above is about the public website. If you sign in and use the platform, we also record what you did — that a checkout was started or completed, a subscription began or ended, a payment failed, an AI conversation was started, a post was created or scheduled, a report was requested. These are recorded against your account rather than anonymously, because we need to know which customer hit a problem in order to fix it. We record the action and the plan or product involved. We do not send the contents of your work to PostHog — not the text of your AI conversations, not the documents you generate, not your posts. Where our platform uses AI, we record that a request happened along with the model, its speed and its cost, and deliberately not what was said in it.

PostHog used to be a third item on this list. Since 3 September 2026 the analytics described above is served through our own domain instead, so your browser never contacts PostHog and never hands them your IP address or browser details itself. That is not anonymity and we will not present it as such: we pass your IP address to PostHog ourselves, because it is what the approximate location described above is derived from. PostHog processes exactly what it processed before — what changed is that your browser now talks only to us. PostHog remains a processor of your data and is listed as one above.

10. Security

We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), hashed passwords, and restricted access controls. See our Security page for details.

11. International Transfers

Your data may be transferred to and processed in the United States (Stripe, Resend, Anthropic, Railway). These transfers are subject to standard contractual clauses or adequacy decisions as appropriate under UK GDPR.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on the platform. The "Last updated" date at the top of this page will reflect any changes.

13. Contact & Complaints

For privacy enquiries, contact us at hello@opsintel.io.

If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

© 2026 Ops Intel. All rights reserved.

Privacy Terms Security Service definition