This Privacy Policy explains how XOps ("we", "us") processes personal data in connection with the XOps platform and this website. It is written to meet the transparency requirements of the EU/UK General Data Protection Regulation ("GDPR").
1. Roles
- We act as controller for: website visitors, contact-form messages, access applications, and account administration data.
- We act as processor for personal data our customers load into their workspace — crew records, duty rosters, qualifications, and similar ("Customer Data"). That processing is governed by the Data Processing Addendum; requests concerning Customer Data should be directed to the operator (our customer) that employs or engages you.
2. What we collect (as controller)
- Contact form: name, email, company, phone (optional), and your message.
- Access applications: company details (legal name, AOC number, codes, address) and representative details (name, job title, email, phone), plus the submitting IP address and browser user-agent for abuse prevention.
- Accounts: name, email, role, authentication events, and audit logs of actions taken in the platform.
- Technical logs: IP address, timestamps, and request metadata needed to run and secure the Service.
3. Why and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Answering contact-form enquiries | (b) steps prior to a contract / (f) legitimate interest |
| Reviewing access applications and provisioning workspaces | (b) contract |
| Operating, securing, and auditing the Service | (b) contract / (f) legitimate interest |
| Sending service and transactional email (via Brevo) | (b) contract / (f) legitimate interest |
| Compliance with legal obligations | (c) legal obligation |
We do not sell personal data and we do not use it for third-party advertising.
4. Processors and recipients
We share personal data only with service providers that help us run the platform, under data-processing agreements:
- Brevo (Sendinblue SAS, France) — transactional email delivery.
- Hosting / infrastructure provider(s) — compute, storage, and backups for the environments in which the Service runs.
- LLM provider(s) — only where AI features are used; inputs are limited to what the feature needs. Customers may connect their own provider key, in which case their agreement with that provider applies.
- Integrations you connect (e.g. LEON, XOps) — data flows to these systems only when a customer configures the connection.
The current subprocessor list is maintained in the DPA.
5. International transfers
Where personal data is transferred outside the EEA/UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (and the UK addendum), plus supplementary measures where appropriate.
6. Retention
- Contact messages: up to 24 months after the last exchange, then deleted or anonymised.
- Access applications: for the life of the resulting account, or 12 months if rejected/withdrawn.
- Account and audit records: for the subscription term plus the period needed for legal defence and bookkeeping obligations.
- Customer Data: retained per the customer's instructions and the DPA; exportable for 30 days after termination.
7. Your rights
Subject to law, you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. Where we act as processor, we will refer your request to the relevant operator and assist them in answering it. You may also lodge a complaint with your supervisory authority.
8. Security
Measures include role-based access control enforced in the application and service layers, company-scoped multi-tenant isolation, encrypted transport (TLS), audited approvals with frozen snapshots, and full outbound-email audit records. We notify affected customers without undue delay after becoming aware of a personal-data breach involving their data.
9. Contact
To exercise rights or ask questions, use the contact form. We may update this Policy; material changes are announced on this page with a new "last updated" date.