Privacy policy.
What we hold
Who this covers
This policy covers the customer portal and every product reached through it. If you only visited our public website or wrote to us through the contact form, the shorter website policy covers you instead. For most of what the products hold, meaning bids, quotes, documents, and the content of a mailbox a company connects, the customer company decides what goes in and we process it only on their instruction; requests about that data go to them, and this policy explains how we handle it on their behalf. For account details, support conversations and this website, we decide how data is used and this policy is the full story.
What we collect
When an account is set up: name, work email, an optional phone number, a password (stored only as a hash), and any two-factor or passkey enrolment. For passkeys we hold only the public half, which cannot be used to sign in. For the company: its name, address, tax ID, billing contact and phone. As you use the products: the content you put in, support messages with any screenshots, and an activity log of account actions. Where a company chooses to connect a mailbox or calendar, we receive its content through Microsoft or Google after that account holder consents at the provider, and the access tokens are stored encrypted. Which accounts a company connects, and what it authorises the product to send, are set in that company’s own agreement with us. Automatically, for security: sign-in records with IP address and browser, and the same on requests sent from this site. We do not buy data about you and we do not track you across other websites.
Why we hold it
To run the service, keep accounts secure, answer support, bill correctly under a signed order, and improve the products. Where the products use AI to summarise mail, extract bid details, or draft follow-ups, your content is processed solely to produce that output for you. Our AI providers are contractually barred from training their models on it, and neither do we.
How long we keep it
Account and company data: for the life of the account, then deleted from live systems within 90 days of closure, with export available for the first 30 of those. Support conversations: for the life of the account. Security and audit logs: up to 12 months. Backups: continuous, aging out on a rolling window of at most 30 days. Billing records: as long as tax law requires, which in the United States is up to 7 years.
Your rights
You can ask for access to what we hold about you, correction, export in an open format, deletion, or an end to optional emails. We honour these regardless of which state’s law applies to you, and most don’t reach a business of our size or data in a work context. Write to privacy@operanttechnologies.com; we verify the request against the account’s email and answer within 30 days. Where the request concerns data we hold on a customer company’s behalf, we pass it to that company and help them answer.
How it is protected
Encryption in transit and at rest, per-company isolation on every record, access limited to the two founders and logged, including when we access an account to help with support. The full list of controls, including what is not in place yet, is on the security page. If we confirm a breach affecting your data, the account owner is notified by email within 72 hours of confirmation.
Where it lives
In the United States, on the processors named above. We do not transfer personal data outside the US today; if that changes, this section will name the destination and the safeguard relied on before it does.
Changes to this policy
Material changes are emailed to account owners at least 14 days before they take effect, and the updated date above always reflects the current version. The history of this page lives in our version control and is available on request.
To see, correct, export or delete what we hold, write to privacy@operanttechnologies.com. We answer within 30 days, usually much sooner. Account holders can also request an export from Settings.