Privacy Policy
How OpsIQ collects, uses, stores and protects information for our customers, their end-users, and visitors to this website — written to be read, not just signed.
No model training
We never train AI on your data. Calls go to the provider you choose, with live context only.
Encrypted by default
AES-256 at rest, TLS 1.3 in transit, signed webhooks, per-tenant isolation on Cloud.
You stay in control
Export or delete anytime from Account → Privacy. You set retention on your workspace.
GDPR & CCPA aligned
Controller/processor split, SCCs for transfers, 30-day DSAR response.
Plain-language promise. OpsIQ exists to run support, sales and analytics for your business — not to harvest data. We don't train AI on your data, we don't sell personal data, and on customer workspaces you control retention. This page explains the details; the summaries below each heading give you the short version.
1Overview & our roles
This Privacy Policy describes how OpsIQ — a product of Nabtech Digitalnet Limited ("OpsIQ", "we", "us", "our") — handles personal data when you visit this website, sign up for an account, install the OpsIQ product (Cloud or Self-Hosted), or interact with the AI operating layer we provide as a service to our customers.
Privacy law distinguishes two roles, and OpsIQ wears both depending on whose data is involved:
| Role | When it applies | Whose data |
|---|---|---|
| Controller | The marketing site, your account, and your billing relationship with us | You — our customer, prospect, or site visitor |
| Processor | When your visitors and end-users interact with OpsIQ-powered chat, tickets, analytics or actions on your website | Your end-users — processed only on your documented instructions |
For data we process on your behalf, the relevant terms are governed by our Data Processing Addendum, which forms part of your contract with us.
2What we collect
2.1 Account & billing data (we are controller)
- Name, email, company name, country, and phone (optional)
- Billing address and payment-method tokens — we never store full card numbers; those live only with our payment processor
- Plan choice, subscription status, invoice history, and transaction logs
- Support correspondence you send us directly
2.2 Product-usage data (we are controller)
- Login activity, IP address, browser/OS, and session timestamps
- Connected sites & configured connectors (slug, settings, API endpoints)
- AI prompts, responses, and per-turn metadata you generate inside your workspace (visible to you in the owner-only AI History)
- Diagnostic and error telemetry needed to keep the service reliable
2.3 End-user data (we are processor for our customers)
- Chat conversations between your visitors and the AI or your team
- Visitor analytics: IP, user-agent, session ID, pages visited, country/city (derived from IP), device, traffic source, scroll depth, and time on page
- Ticket data: subject, body, attachments, replies, internal notes, status, and department
- Identity hints your site chooses to expose (e.g. a logged-in customer's email, ID, or name)
- CRM, promotion-lead, and consent records captured through OpsIQ features you enable
2.4 Cookies & similar technologies
OpsIQ uses essential cookies for authentication and for the cookie-consent banner on this site. The customer-side widget uses localStorage for a visitor identifier so conversations persist across page loads. Non-essential cookies are set only with consent. See our Cookie Policy for the full inventory.
3How we use it
- To provide the OpsIQ service to you and your end-users
- To process payments, issue licenses, provision cloud tenants, and prevent fraud
- To improve reliability, quality and security of the platform
- To send transactional notices (incident alerts, password resets, billing receipts)
- To send product announcements you have opted in to receive
- To meet legal, regulatory and tax obligations
We process end-user data only on your documented instructions as the controller. We do not use it for our own purposes, and we do not sell personal data.
4Legal bases
Where GDPR, UK GDPR or equivalent laws apply, we rely on the following legal bases:
| Activity | Legal basis |
|---|---|
| Provide and operate the service | Performance of a contract |
| Billing & tax records | Legal obligation |
| Security, fraud prevention & abuse detection | Legitimate interest |
| Product analytics & reliability telemetry | Legitimate interest (opt-out available) |
| Marketing & product-announcement emails | Consent |
| Non-essential cookies | Consent |
| End-user data on customer workspaces | Processed on the customer's instructions; the customer determines the basis |
5AI & your data
AI is the core of OpsIQ, so we want to be precise about how your data flows through it.
- No model training on your data. We do not use customer content, conversations, or end-user data to train, fine-tune, or improve any AI model — ours or a third party's.
- You choose the provider. Each AI request is forwarded to the model provider you configure: Anthropic, OpenAI, Gemini, Grok, or a self-hosted model on your own infrastructure.
- Live context only. We send the model the conversation context needed to answer the current turn — not your entire history, and not other customers' data.
- Provider terms apply downstream. Once a request reaches your chosen provider, that provider's data-handling terms govern it. We recommend reviewing them and, where offered, enabling zero-retention or enterprise privacy modes.
- Self-hosted models never leave your network. If you point OpsIQ at a self-hosted model, inference happens entirely within your environment.
AI prompts and responses generated in your workspace are visible to you in the owner-only AI History and are subject to your retention settings.
6Sub-processors
OpsIQ relies on a small set of trusted sub-processors. We maintain a Data Processing Agreement with each and notify customers of material changes before they take effect.
| Sub-processor | Purpose | Region |
|---|---|---|
| Cloud infrastructure provider | Hosting, storage, backups | EU / West Africa |
| Stripe / Paystack / PayPal | Payment processing | Global |
| Anthropic / OpenAI / Gemini / Grok | AI model inference (the provider you choose) | US / EU |
| Mailgun / SendGrid / SMTP relay | Transactional email delivery | EU / US |
| Cloudflare | CDN and DDoS protection | Global |
Self-Hosted note: if you run OpsIQ on your own infrastructure, the only sub-processor in the path is the AI provider you configure — everything else stays within your environment. See section 14.
7Sharing & disclosure
We disclose personal data only in these limited circumstances:
- Sub-processors who help us operate the service, under contract (see section 6)
- At your direction — for example, when you connect a third-party integration or export your data
- Legal requirements — to comply with a valid court order, subpoena, or applicable law, after review and, where permitted, notice to you
- Corporate transactions — in a merger, acquisition, or asset sale, where the recipient is bound by this policy
- To protect rights and safety — to prevent fraud, abuse, or imminent harm
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
8International transfers
OpsIQ operates globally, so personal data may be processed in countries other than your own. When data leaves its region of origin, we protect it with appropriate safeguards:
- Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum for transfers out of the EEA/UK
- EU data residency by default — EU customer data is hosted in EU regions unless you choose otherwise
- Equivalent safeguards for transfers to other jurisdictions, including transfer-impact assessments where required
If you run OpsIQ Self-Hosted, no transfer occurs on our side — your data stays wherever you deploy it.
9Retention
We retain personal data only for as long as necessary for the purpose it was collected, or as required by law.
| Data type | Retention period |
|---|---|
| Account data | While your account is active, plus 90 days after deletion |
| Billing & tax records | 7 years (legal / accounting obligation) |
| Audit logs | 12 months by default; longer if your plan requires |
| End-user data on customer workspaces | Per your workspace retention settings — you control it (0 = keep forever) |
| Backups | Rotated on a 30-day cycle; deletions propagate within that window |
As a controller for your own end-users' data, you set the retention windows in your workspace, and OpsIQ enforces them automatically.
10Security
Security is built into the platform, not bolted on:
| Control | How we apply it |
|---|---|
| Encryption at rest | AES-256 |
| Encryption in transit | TLS 1.3 |
| Webhook integrity | HMAC-SHA256 signature on every delivery |
| Tenant isolation | Per-tenant separation and keys on Cloud |
| Secret storage | Credentials and keys stored outside the web root |
| Auditability | Per-action audit logs |
We align our practices with the GDPR and CCPA security principles. SOC 2 Type II and ISO 27001 are on our roadmap and are not yet held as certifications. See the Trust Center for our current posture, and report any concern to [email protected].
11Your rights
Depending on where you live, you have rights over your personal data under the GDPR, UK GDPR, the CCPA/CPRA, and similar laws — including the right to access, correct, export (portability), restrict, object to, and delete your data, and to withdraw consent at any time.
How to exercise them
- Self-serve: export and delete your data directly from Account → Privacy in your workspace.
- By email: send a Data Subject Access Request to
[email protected]. We verify your identity and respond within 30 days. - End-users of our customers: if you are an end-user whose data we process on a customer's behalf, please contact that customer (the controller); we will assist them in responding.
- No retaliation: exercising CCPA rights will never result in discriminatory treatment or pricing.
You may also lodge a complaint with your local data protection authority — though we hope you'll reach out to us first so we can help.
12Cookies
OpsIQ uses cookies and similar technologies sparingly. Essential cookies are required for authentication and to remember your consent choices. Non-essential cookies (e.g. analytics) are set only after you consent through the banner, and you can change your choice at any time.
The full inventory of cookies, their purposes, and lifetimes is documented in our Cookie Policy.
13Children
OpsIQ is a business tool and is not directed to children under 13 (or under 16 in parts of the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it promptly.
14Self-Hosted deployments
If you run OpsIQ Self-Hosted, the privacy picture is simpler:
- Your data — account, product, and end-user data — stays entirely on your infrastructure.
- We do not host, access, or process that data; you are the controller and the host.
- The only external dependency is the AI provider you choose to configure — and if that is a self-hosted model, even AI inference stays in your environment.
- This Privacy Policy then applies to us only in respect of your licence and billing relationship with Nabtech, and to your visits to this website.
15Changes to this policy
We update this policy as our services and the law evolve. The Effective date and Version at the top always reflect the current revision. For material changes, we email account admins and post a notice on this page at least 14 days before the changes take effect. Continued use of OpsIQ after the effective date constitutes acceptance of the revised policy.
16Contact us
We are Nabtech Digitalnet Limited, the company behind OpsIQ (www.nabtech.co). You can reach the right team directly:
| Topic | Contact |
|---|---|
| Privacy & data subject requests | [email protected] |
| Security & vulnerability reports | [email protected] |
| Data Protection Officer | [email protected] |
| Legal & contracts | [email protected] |
For our company details and mailing address, see About. Customers in regulated industries should review this policy with their own counsel before deployment.