Back to Home

PrivacyOps — Legal

Privacy Policy

Scope of this Policy

This Privacy Policy applies to personal data collected by PrivacyOps through our website (privacy-ops.io), partner application process, and marketing activities. It does not govern data processed by PrivacyOps on behalf of its customers under a separate Data Processing Agreement — that processing is governed by the applicable customer agreement.

PrivacyOps is a privacy operations platform that helps organisations manage data subject rights, consent, and compliance obligations. We take the privacy of individuals seriously — it is central to what we do and how we operate.

This policy explains what personal data we collect when you visit our website, enquire about our services, or apply to our partner programme; why we collect it; how we use and protect it; and what rights you have over it.

1

Who We Are

1.1
PrivacyOps is a technology company providing privacy operations software and services to businesses globally. We operate through regional entities across multiple jurisdictions. The specific PrivacyOps entity acting as data controller for your personal data depends on your region and how you interact with us.
1.2
For general website enquiries, marketing, and partner programme applications, the data controller is the PrivacyOps group entity responsible for your region. The identity of the applicable controller will be confirmed in any formal agreement or upon request.
1.3
For privacy enquiries, you can contact us at [email protected].
2

Definitions

TermMeaning
"Personal Data"Any information relating to an identified or identifiable natural person.
"Data Controller"The entity that determines the purposes and means of processing personal data. PrivacyOps acts as controller for data collected through this website and partner programme.
"Data Processor"An entity that processes personal data on behalf of a controller. PrivacyOps acts as processor for customer data under separate agreements.
"Processing"Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
"Data Subject"The individual whose personal data is being processed — in this context, you.
"Applicable Law"The data protection legislation applicable in your jurisdiction, including the EU GDPR, UK GDPR, Saudi PDPL, UAE Federal Decree-Law No. 45 of 2021, and equivalent laws.
3

Personal Data We Collect

We collect personal data in the following contexts. The table below summarises the categories, examples, legal basis, and how long we keep each type.

CategoryExamplesLegal BasisRetention
Contact & IdentityName, email address, job title, company name, phone numberLegitimate interests / contract performance3 years from last interaction
Partner ApplicationBusiness details, region, partnership type, consent recordsPre-contractual steps / consent5 years from application date
Demo & EnquiryMessage content, product interest, company sizeLegitimate interests2 years from submission
Usage & TechnicalIP address, browser type, pages visited, session durationLegitimate interests / consent (cookies)13 months
CommunicationsEmail open/click data, marketing preferences, opt-out recordsConsent / legitimate interests3 years or until opt-out

We do not knowingly collect special category data (health, biometric, political, religious) through this website. If you believe you have inadvertently provided such data, please contact us at [email protected].

4

How We Use Your Data

We use personal data for the following purposes:

4.1
To respond to enquiries, demo requests, and contact form submissions.
4.2
To process and evaluate partner programme applications and manage ongoing partner relationships.
4.3
To send relevant product updates, news, and marketing communications where you have consented or where we have a legitimate interest in doing so.
4.4
To improve our website, products, and services through analytics and user behaviour insights.
4.5
To comply with legal obligations, including record-keeping, regulatory reporting, and responding to lawful requests from authorities.
4.6
To protect the security and integrity of our platform and prevent fraud or misuse.
4.7
To enforce our terms and agreements where necessary.

We do not sell your personal data to third parties. We do not use your data for automated decision-making that produces legal or similarly significant effects without human review.

5

Legal Bases for Processing

Where applicable law requires a legal basis for processing personal data, we rely on the following:

5.1

Consent

Where you have given clear consent — for example, subscribing to marketing communications or accepting non-essential cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.

5.2

Contract Performance

Where processing is necessary to take steps at your request prior to entering a contract, or to perform a contract with you — for example, processing a partner application.

5.3

Legitimate Interests

Where we have a legitimate business interest that is not overridden by your rights — for example, responding to enquiries, improving our website, and preventing fraud. We conduct a balancing assessment before relying on this basis.

5.4

Legal Obligation

Where processing is necessary to comply with a legal obligation applicable to PrivacyOps in the relevant jurisdiction.

6

Sharing Your Data

We do not sell personal data. We may share it in the following limited circumstances:

6.1
Service Providers. We engage trusted third-party providers to support our operations — including cloud hosting, email delivery, CRM, and analytics. These providers act as data processors under written agreements and may only process data on our instructions.
6.2
Regional Entities. Personal data may be shared within the PrivacyOps group of companies for internal administrative purposes, subject to appropriate safeguards.
6.3
Legal Requirements. We may disclose personal data where required by law, court order, or regulatory authority, or where necessary to protect the rights, property, or safety of PrivacyOps, our users, or the public.
6.4
Business Transfers. In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the relevant successor entity, subject to equivalent privacy protections.
7

International Data Transfers

7.1
PrivacyOps operates globally. Your personal data may be transferred to and processed in countries outside your own, including countries that may not have the same level of data protection as your jurisdiction.
7.2
Where we transfer personal data from the EEA, UK, or other jurisdictions with transfer restrictions, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent mechanisms recognised under applicable law.
7.3
You may request details of the specific safeguards applicable to your data by contacting [email protected].
8

Data Retention

8.1
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Indicative retention periods are set out in the table in Section 3.
8.2
When personal data is no longer required, we securely delete or anonymise it. Where immediate deletion is not technically feasible, data is isolated from further processing until deletion is possible.
8.3
Retention periods may be extended where required by legal proceedings, regulatory investigations, or other legitimate legal obligations.
9

Your Rights

Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data:

9.1

Access. Request a copy of the personal data we hold about you.

9.2

Rectification. Request correction of inaccurate or incomplete data.

9.3

Erasure. Request deletion of your personal data where there is no compelling reason for us to continue processing it.

9.4

Restriction. Request that we restrict processing of your data in certain circumstances.

9.5

Portability. Receive your personal data in a structured, machine-readable format and transmit it to another controller.

9.6

Objection. Object to processing based on legitimate interests or for direct marketing purposes.

9.7

Withdraw Consent. Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.

9.8

Complaint. Lodge a complaint with your local data protection authority if you believe your rights have been infringed.

To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (typically 30 days). We may need to verify your identity before processing your request.
10

Cookies & Tracking Technologies

10.1
Our website uses cookies and similar technologies to operate core functionality, analyse usage, and support marketing. Cookies are small text files stored on your device.
10.2
Strictly necessary cookies are required for the website to function and cannot be disabled. They do not require your consent.
10.3
Analytics cookies help us understand how visitors use our website. We use this data in aggregate to improve our content and user experience. These cookies are set only with your consent.
10.4
Marketing cookies may be used to deliver relevant advertising and track campaign performance. These are set only with your consent.
10.5
You can manage your cookie preferences at any time through your browser settings or by contacting us. Withdrawing consent for non-essential cookies will not affect your ability to use the website.
11

Children's Privacy

11.1
Our website and services are not directed at children under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children.
11.2
If you believe a child has provided us with personal data, please contact us at [email protected] and we will take steps to delete it promptly.
12

Changes to This Policy

12.1
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last updated" date at the top of this document will reflect the most recent revision.
12.2
Where changes are material, we will provide prominent notice — for example, via a banner on our website or by email to known contacts — prior to the changes taking effect.
12.3
Continued use of our website or services after the effective date of any update constitutes acceptance of the revised policy.
13

Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or the way we handle your personal data, please reach out:

Privacy & Data Rights

[email protected]

Data subject requests, rights exercises, general privacy questions

Legal

[email protected]

Legal notices, regulatory correspondence, DPA requests

We aim to respond to all privacy enquiries within 30 days. For complex requests, we may extend this period by a further two months and will notify you accordingly.

PrivacyOps Privacy Policy

Document ref. PO-PP-2026-001 · Version 1.0 · Effective June 13, 2026

© 2026 PrivacyOps. All rights reserved.