Skip to content

Legal

Privacy Policy

How we handle personal data. Plain-English summary up top, full policy below. Last updated 2026-08-20.

The short version

  • We're a data controller for the personal data you provide directly (account, contact, contractual data).
  • We're a data processor for the personal data you load into the platform (your clients' contacts, ticket content, etc.).
  • OpsMerge is built and run from the United Kingdom. All customer data is hosted in the European Economic Area: the application and database in Helsinki, Finland, file storage in Amsterdam, Netherlands, and encrypted backups in Finland. The exact locations and safeguards are set out below.
  • Sub-processors: Stripe (subscription billing, US, Data Privacy Framework + SCCs), Cloudflare (edge network, certified under the EU-US Data Privacy Framework including the UK Extension; it does not store application data at rest), Backblaze (file storage, Amsterdam, Netherlands), Postmark by ActiveCampaign (platform transactional email, US, Standard Contractual Clauses), Google (Android device management via the Android Management API, only for devices you enrol into MDM), and Microsoft (only where you attach your own Microsoft 365 mailbox for ticket email). Updated as the platform evolves.
  • We do not run Google Analytics, Segment, Mixpanel or any other third-party tracking on the marketing site or in the app. Self-hosted, first-party analytics handles product analytics, and the data stays on our own infrastructure.
  • You have the right to access, correct, delete, and export your personal data. Email [email protected].
  • We respond to data subject requests within UK GDPR statutory timelines.

Data controller: Brindleford Technologies Ltd, company number 16871436, registered in England and Wales. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.

What we collect

  • Account data: name, email address, company name, billing information (processed and stored by Stripe — we do not store raw card data).
  • Service data: telemetry from agents you deploy (hostname, OS version, patch state, performance counters, installed software inventory). This data is collected solely to deliver the monitoring and management features of the Service.
  • Mobile device management data: where you enrol Android devices into the Service's MDM features, we process device data supplied by Google's Android Management API: device identifiers, hardware and OS details, installed application inventory, network information, security and compliance state, and, where a policy you configure enables it, device location. This data is used solely to deliver the device management features you configure. Google LLC processes this data as the provider of Android Enterprise device management, and enrolled devices display Android's standard managed-device notice to their users. You are responsible for informing the users of enrolled devices that the devices are managed and what is collected.
  • Usage analytics: pageviews, feature usage, error events — collected via our own self-hosted analytics instance. No third-party analytics vendors are used; no data is shared with Google Analytics, Meta, or any other external analytics service.

Lawful basis

We process personal data under the following lawful bases (UK GDPR):

  • Contract performance — for account data and service data required to deliver the features you have subscribed to.
  • Legitimate interest — for usage analytics used to improve the product. We have conducted a balancing test and concluded that this interest is not overridden by your rights given the privacy-preserving nature of our self-hosted analytics infrastructure.

Where your data is held

All customer data is hosted inside the European Economic Area:

  • Application and database: our application servers and primary database run in a Hetzner datacentre in Helsinki, Finland.
  • Files and attachments: documents, ticket attachments and other uploaded files are stored with Backblaze in Amsterdam, Netherlands.
  • Backups: nightly backups are encrypted with AES-256 before they leave the application server and are stored in a Hetzner facility in Finland.
  • Edge network: web traffic to the platform passes through Cloudflare's network, which provides TLS termination, content delivery and DDoS protection. Cloudflare does not store application data at rest.
  • Platform email: transactional email we send you (signup verification, alerts, billing notices) is delivered via Postmark, operated by ActiveCampaign LLC in the United States, under Standard Contractual Clauses in its data processing agreement.
  • Ticket email: where you attach your own Microsoft 365 mailbox, ticket email is sent and received inside your own Microsoft 365 tenancy. We access it via the Microsoft Graph API with the authorisation you grant, and that data remains subject to your own agreement with Microsoft.

How your data is protected

Statutes. Brindleford Technologies Ltd is established in the United Kingdom, so our processing of personal data is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Because customer data is hosted in the European Economic Area, that processing also takes place under the protection of the EU General Data Protection Regulation (Regulation (EU) 2016/679). Cookies and similar technologies are governed by the Privacy and Electronic Communications Regulations 2003 (PECR); see our Cookie Policy.

International transfers. Transfers from the UK to our EEA hosting are lawful because the UK recognises all EEA countries as providing adequate protection. Transfers from the EEA to the UK are covered by the European Commission's adequacy decision for the United Kingdom. Where a sub-processor is in the United States, we rely on the EU-US Data Privacy Framework including its UK Extension (Stripe, Cloudflare) or on Standard Contractual Clauses with the UK addendum (Postmark).

In transit. All web and API traffic is encrypted with TLS 1.2 or higher. Agent-to-server traffic flows over a TLS-encrypted message bus. Backups are encrypted before they are transferred off the application server.

At rest. Stored credentials and integration secrets are encrypted with AES-256-GCM using a key held outside the application database. See the Security page for the full picture.

Your rights

Under UK GDPR you have the right to:

  • Access a copy of the personal data we hold about you.
  • Rectification of inaccurate personal data.
  • Erasure ("right to be forgotten") — subject to our retention obligations.
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction of processing in certain circumstances.
  • Object to processing based on legitimate interest.

To exercise any of these rights, contact [email protected]. We will respond within one calendar month.

You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ico.org.uk).

Retention

  • Account data is retained for the lifetime of your subscription plus 6 years for tax and accounting records.
  • Agent telemetry data is retained for 13 months by default; you may request earlier deletion.
  • Mobile device management data is retained while the device remains enrolled; releasing or wiping a device stops collection.
  • Usage analytics data is retained for 24 months.

Cookies

See our Cookie Policy.

Changes

We may update this Privacy Policy. Material changes will be communicated via email before taking effect.

Contact

Brindleford Technologies Ltd, company number 16871436 (England and Wales).

Email: [email protected]

OpsMerge is a product of Brindleford Technologies Ltd, company number 16871436, registered in England and Wales.