IQOpsIQ
Home
Features
OpsIQ platformChoose the surface you want to improve.Every feature shares one customer timeline, one AI memory, and one operations layer.
View all
AI-First CRMPipeline, four AI agents, deal coaching, forecasting and a Trust Dial.Client Chat AICustomer-facing AI chat, handoff, identity, knowledge, and support flows.Promotion StudioPop-ups, bars and campaigns, visual builder, targeting, A/B, lead capture.Site IntelligenceCrawls, rank tracking, backlinks, competitors and an AI SEO analyst.Admin AI ChatAI command center for teams, decisions, and safe admin actions.Surveys & CSATCSAT, NPS and feedback intelligence, post-resolution prompts, AI analysis and detractor recovery.Team PerformanceReal-time workload, SLA, CSAT, coaching evidence, recognition and governed rewards.Ticket SystemTickets, SLA, routing, the Inbox Copilot, and the customer portal your customers submit from.Knowledge BaseGoverned articles, a multilingual Help Center, search, AI grounding and content-gap insight.AI AnalyticsVisitor intelligence, live sessions, geography, leads, and conversion insight.Consent & GDPRCookie-consent studio that enforces, plus a consent ledger and DSAR.OpsIQ WritingAI replies, ticket drafts, article writing, announcements, and support content.Webhooks & ActionsTriggers, action endpoints, HMAC signing, and developer automation.Email ChannelInbox-to-ticket, AI email replies, transactional + broadcast, SPF/DKIM.Security2FA, OIDC SSO, SCIM, blocking, audit and safe access.Remote SitesConnect websites and platforms into one OpsIQ intelligence workspace.IntegrationsWHMCS, Stripe, Shopify, WordPress, Slack, Zendesk, webhooks and custom connectors.
SolutionsPricingDevelopersContact
EnglishEnglish · ENالعربيةArabic · ARБългарскиBulgarian · BGবাংলাBengali · BNČeštinaCzech · CSDanskDanish · DADeutschGerman · DEΕλληνικάGreek · ELEspañolSpanish · ESEspañol (Latinoamérica)Latin American Spanish · ES-419فارسیPersian · FASuomiFinnish · FIFilipinoFilipino · FILFrançaisFrench · FRFrançais (Canada)Canadian French · FR-CAעבריתHebrew · HEहिन्दीHindi · HIMagyarHungarian · HUBahasa IndonesiaIndonesian · IDItalianoItalian · IT日本語Japanese · JA한국어Korean · KOBahasa MelayuMalay · MSNederlandsDutch · NLNorskNorwegian · NOPolskiPolish · PLPortuguêsPortuguese · PTPortuguês (Brasil)Brazilian Portuguese · PT-BRRomânăRomanian · ROРусскийRussian · RUSlovenčinaSlovak · SKSvenskaSwedish · SVKiswahiliSwahili · SWไทยThai · THTürkçeTurkish · TRУкраїнськаUkrainian · UKاردوUrdu · URTiếng ViệtVietnamese · VI简体中文Simplified Chinese · ZH繁體中文Traditional Chinese · ZH-TW
Log inStart free
HomePublic overviewPricingPlans and value
Product surfaces
All features AI-First CRM Client Chat AI Promotion Studio Site Intelligence Admin AI Chat Surveys & CSAT Team Performance Ticket System Knowledge Base AI Analytics Consent & GDPR OpsIQ Writing Webhooks & Actions Email Channel Security Remote Sites
Use casesSolutionsRole and workflow pathsCustomer storiesProof from teamsIntegrationsConnect your stack
ResourcesDevelopersAPI and webhook toolsDocsGuides and referencesFAQsCommon answersContactTalk to the team
Company and trustAboutCompany profileTrust centerSecurity postureSecurityControls and accessCompliancePolicies and auditsStatusSystem health
Log in Start free
Legal

Privacy Policy

How OpsIQ collects, uses, stores and protects information for our customers, their end-users, and visitors to this website. Written to be read, not just signed.

Effective August 7, 2026Version 2026.08Reviewed by OpsIQ SecurityReading time ~9 min
RelatedData Processing AddendumCookie PolicyTerms of ServiceTrust CenterSecurity
Policy controls
Plain-English terms

No model training

We never train AI on your data. Calls go to the provider you choose, with live context only.

Encrypted by default

AES-256 at rest, TLS 1.3 in transit, signed webhooks, per-tenant isolation on Cloud.

You stay in control

Export or delete anytime from Account → Privacy. You set retention on your workspace.

GDPR & CCPA aligned

Controller/processor split, SCCs for transfers, 30-day DSAR response.

Plain-language promise. OpsIQ exists to run support, sales and analytics for your business, not to harvest data. We don't train AI on your data, we don't sell personal data, and on customer workspaces you control retention. This page explains the details; the summaries below each heading give you the short version.

On this page
1Overview & our roles2What we collect3How we use it4Legal bases54b. Session replay6AI & your data7Sub-processors8Sharing & disclosure97b. Government & public authority requests10International transfers11Retention12Security13Your rights14Cookies15Children16Self-Hosted deployments17Changes to this policy18Contact us↑ Back to top

1Overview & our roles

In short: We are the controller for your account and our website; we are a processor handling your end-users' data on your behalf.

This Privacy Policy describes how OpsIQ, a product of Nabtech Digitalnet Limited ("OpsIQ", "we", "us", "our"), handles personal data when you visit this website, sign up for an account, install the OpsIQ product (Cloud or Self-Hosted), or interact with the AI operating layer we provide as a service to our customers.

Privacy law distinguishes two roles, and OpsIQ wears both depending on whose data is involved:

RoleWhen it appliesWhose data
ControllerThe marketing site, your account, and your billing relationship with usYou, our customer, prospect, or site visitor
ProcessorWhen your visitors and end-users interact with OpsIQ-powered chat, tickets, analytics or actions on your websiteYour end-users, processed only on your documented instructions

For data we process on your behalf, the relevant terms are governed by our Data Processing Addendum, which forms part of your contract with us.

2What we collect

In short: Account & billing details, product-usage logs, the end-user data your workspace processes, and a minimal set of cookies.

2.1 Account & billing data (we are controller)

  • Name, email, company name, country, and phone (optional)
  • Billing address and payment-method tokens, we never store full card numbers; those live only with our payment processor
  • Plan choice, subscription status, invoice history, and transaction logs
  • Support correspondence you send us directly

2.2 Product-usage data (we are controller)

  • Login activity, IP address, browser/OS, and session timestamps
  • Connected sites & configured connectors (slug, settings, API endpoints)
  • AI prompts, responses, and per-turn metadata you generate inside your workspace (visible to you in the owner-only AI History)
  • Diagnostic and error telemetry needed to keep the service reliable

2.3 End-user data (we are processor for our customers)

  • Chat conversations between your visitors and the AI or your team
  • Visitor analytics: IP, user-agent, session ID, pages visited, country/city (derived from IP), device, traffic source, scroll depth, and time on page
  • Ticket data: subject, body, attachments, replies, internal notes, status, and department
  • Identity hints your site chooses to expose (e.g. a logged-in customer's email, ID, or name)
  • CRM, promotion-lead, and consent records captured through OpsIQ features you enable

2.4 Cookies & similar technologies

OpsIQ uses essential cookies for authentication and for the cookie-consent banner on this site. The customer-side widget uses localStorage for a visitor identifier so conversations persist across page loads. Non-essential cookies are set only with consent. See our Cookie Policy for the full inventory.

3How we use it

In short: To run the service, bill you, keep things secure and reliable, and send notices you need or opted into, nothing more.
  • To provide the OpsIQ service to you and your end-users
  • To process payments, issue licenses, provision cloud tenants, and prevent fraud
  • To improve reliability, quality and security of the platform
  • To send transactional notices (incident alerts, password resets, billing receipts)
  • To send product announcements you have opted in to receive
  • To meet legal, regulatory and tax obligations

We process end-user data only on your documented instructions as the controller. We do not use it for our own purposes, and we do not sell personal data.

4Legal bases

In short: Each activity maps to a specific GDPR legal basis, contract, legal obligation, legitimate interest, or consent.

Where GDPR, UK GDPR or equivalent laws apply, we rely on the following legal bases:

ActivityLegal basis
Provide and operate the servicePerformance of a contract
Billing & tax recordsLegal obligation
Security, fraud prevention & abuse detectionLegitimate interest
Product analytics & reliability telemetryLegitimate interest (opt-out available)
Marketing & product-announcement emailsConsent
Non-essential cookiesConsent
End-user data on customer workspacesProcessed on the customer's instructions; the customer determines the basis

54b. Session replay

In short: Off unless your operator turns it on. When it is on, what you type is masked before it ever leaves your browser.

OpsIQ offers session replay: an optional feature an operator can enable to reconstruct how a visitor moved through their site, in order to diagnose faults and improve the experience. It records page structure, navigation, clicks, scrolling and pointer movement.

It is off unless the operator enables it, and it is scoped to that workspace.

Form inputs are masked at the point of capture. The characters typed into a field are replaced in the browser, before anything is transmitted, so the values never reach OpsIQ and are never stored. This is a stronger guarantee than redacting a recording after it arrives: there is no moment at which the original keystrokes exist on our systems. Passwords, payment fields and anything else entered into a form are covered.

Where an operator enables replay, that operator is the controller for it and is responsible for telling their own visitors, and for obtaining consent where their law requires it. Recordings follow the retention period configured for the workspace and are deleted with it.

6AI & your data

In short: We never train models on your data. AI calls go to the provider you choose, with live context only, and stop there.

AI is the core of OpsIQ, so we want to be precise about how your data flows through it.

  • No model training on your data. We do not use customer content, conversations, or end-user data to train, fine-tune, or improve any AI model, ours or a third party's.
  • You choose the provider. Each AI request is forwarded to the model provider you configure: Anthropic, OpenAI, Gemini, Grok, or a self-hosted model on your own infrastructure.
  • Live context only. We send the model the conversation context needed to answer the current turn, not your entire history, and not other customers' data.
  • Provider terms apply downstream. Once a request reaches your chosen provider, that provider's data-handling terms govern it. We recommend reviewing them and, where offered, enabling zero-retention or enterprise privacy modes.
  • Self-hosted models never leave your network. If you point OpsIQ at a self-hosted model, inference happens entirely within your environment.

AI prompts and responses generated in your workspace are visible to you in the owner-only AI History and are subject to your retention settings.

7Sub-processors

In short: A small, vetted set of providers help us run OpsIQ; we keep DPAs with each and notify you of material changes.

OpsIQ relies on a small set of trusted sub-processors. We maintain a Data Processing Agreement with each and notify customers of material changes before they take effect.

Sub-processorPurposeRegion
Cloud infrastructure providerHosting, storage, backupsEU / West Africa
Stripe / Paystack / PayPalPayment processingGlobal
Anthropic / OpenAI / Gemini / GrokAI model inference (the provider you choose)US / EU
Mailgun / SendGrid / SMTP relayTransactional email deliveryEU / US
CloudflareCDN and DDoS protectionGlobal

Self-Hosted note: if you run OpsIQ on your own infrastructure, the only sub-processor in the path is the AI provider you configure. Everything else stays within your environment. See section 14.

8Sharing & disclosure

In short: We share data only with sub-processors, when you direct us to, or when the law requires it, and we never sell it.

We disclose personal data only in these limited circumstances:

  • Sub-processors who help us operate the service, under contract (see section 6)
  • At your direction: for example, when you connect a third-party integration or export your data
  • Legal requirements: to comply with a valid court order, subpoena, or applicable law, after review and, where permitted, notice to you. How we handle these requests is set out in section 7b
  • Corporate transactions: in a merger, acquisition, or asset sale, where the recipient is bound by this policy
  • To protect rights and safety: to prevent fraud, abuse, or imminent harm

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

97b. Government & public authority requests

In short: Every request from a public authority is reviewed for legal validity, challenged where unlawful, answered with the minimum data necessary, and recorded.

Public authorities — law enforcement, regulators, courts or government bodies — occasionally request personal data. We treat every such request as an exception to be justified, never a routine disclosure. The following applies to all of them, in Nigeria and anywhere else we operate:

  • Legality review is mandatory. No request is actioned before it is reviewed for legal validity: whether the requesting body has authority over us, whether the instrument is valid and properly served, and whether it actually compels the data sought. A request that fails this review is refused.
  • We challenge unlawful or overbroad requests. Where a request appears unlawful, exceeds the requesting authority's powers, or is broader than its stated purpose, we push back and, where necessary and lawful to do so, contest it — including seeking to narrow it before any disclosure.
  • Data minimisation. We disclose the minimum information necessary to satisfy a valid request, never a whole account or dataset when specific records will do. Where the request can be met with less identifying data, we provide less.
  • We document every request. We record what was requested, by whom and under what legal authority, the legal reasoning applied, who inside Nabtech decided, what was disclosed, and when. These records support accountability and any later review.
  • Notice where we are permitted to give it. If a request concerns a customer's data and we are not legally barred from saying so, we notify that customer so they can seek their own remedy. Where a gag provision applies, we give notice as soon as it lapses.
  • Customer data belongs to the customer. Where an authority seeks data our customer controls and we merely process, we direct the request to that customer wherever the law allows, rather than disclosing on their behalf.

Requests should be sent to [email protected]. Requests received through other channels are routed there for review; no individual employee may disclose personal data to an authority outside this process.

If you run OpsIQ Self-Hosted, we hold none of your data and cannot disclose it — any request must go to you directly.

10International transfers

In short: When data crosses borders we use Standard Contractual Clauses; EU customer data is hosted in EU regions by default.

OpsIQ operates globally, so personal data may be processed in countries other than your own. When data leaves its region of origin, we protect it with appropriate safeguards:

  • Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum for transfers out of the EEA/UK
  • EU data residency by default: EU customer data is hosted in EU regions unless you choose otherwise
  • Equivalent safeguards for transfers to other jurisdictions, including transfer-impact assessments where required

If you run OpsIQ Self-Hosted, no transfer occurs on our side. Your data stays wherever you deploy it.

11Retention

In short: We keep each data type only as long as needed; on customer workspaces, retention is fully under your control.

We retain personal data only for as long as necessary for the purpose it was collected, or as required by law.

Data typeRetention period
Account dataWhile your account is active, plus 90 days after deletion
Billing & tax records7 years (legal / accounting obligation)
Audit logs12 months by default; longer if your plan requires
End-user data on customer workspacesPer your workspace retention settings. You control it (0 = keep forever)
BackupsRotated on a 30-day cycle; deletions propagate within that window

As a controller for your own end-users' data, you set the retention windows in your workspace, and OpsIQ enforces them automatically.

12Security

In short: Encryption in transit and at rest, signed webhooks, per-tenant isolation, and secrets stored outside the web root.

Security is built into the platform, not bolted on:

ControlHow we apply it
Encryption at restAES-256
Encryption in transitTLS 1.3
Webhook integrityHMAC-SHA256 signature on every delivery
Tenant isolationPer-tenant separation and keys on Cloud
Secret storageCredentials and keys stored outside the web root
AuditabilityPer-action audit logs

We align our practices with the GDPR and CCPA security principles. SOC 2 Type II and ISO 27001 are on our roadmap and are not yet held as certifications. See the Trust Center for our current posture, and report any concern to [email protected].

13Your rights

In short: Access, correct, export, restrict, object, or delete, self-serve from Account → Privacy, or via [email protected].

Depending on where you live, you have rights over your personal data under the GDPR, UK GDPR, the CCPA/CPRA, and similar laws, including the right to access, correct, export (portability), restrict, object to, and delete your data, and to withdraw consent at any time.

How to exercise them

  • Self-serve: export and delete your data directly from Account → Privacy in your workspace.
  • By email: send a Data Subject Access Request to [email protected]. We verify your identity and respond within 30 days.
  • End-users of our customers: if you are an end-user whose data we process on a customer's behalf, please contact that customer (the controller); we will assist them in responding.
  • No retaliation: exercising CCPA rights will never result in discriminatory treatment or pricing.

You may also lodge a complaint with your local data protection authority, though we hope you'll reach out to us first so we can help.

OpsIQ is operated by Nabtech Digitalnet Limited, a company incorporated in the Federal Republic of Nigeria. Our lead supervisory authority is the Nigeria Data Protection Commission (NDPC), and we process personal data in accordance with the Nigeria Data Protection Act 2023 alongside the EU and UK GDPR and the CCPA where those apply. If you are in the EEA or the UK, you may instead complain to the supervisory authority where you live, where you work, or where the alleged infringement took place.

14Cookies

In short: Essential cookies keep you signed in; non-essential ones run only with consent, manage them anytime.

OpsIQ uses cookies and similar technologies sparingly. Essential cookies are required for authentication and to remember your consent choices. Non-essential cookies (e.g. analytics) are set only after you consent through the banner, and you can change your choice at any time.

The full inventory of cookies, their purposes, and lifetimes is documented in our Cookie Policy.

15Children

In short: OpsIQ is not for children under 13 (or 16 in the EU); we don't knowingly collect their data.

OpsIQ is a business tool and is not directed to children under 13 (or under 16 in parts of the EU). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact [email protected] and we will delete it promptly.

16Self-Hosted deployments

In short: On Self-Hosted, your data stays on your infrastructure. We have no access to it.

If you run OpsIQ Self-Hosted, the privacy picture is simpler:

  • Your data (account, product, and end-user data) stays entirely on your infrastructure.
  • We do not host, access, or process that data; you are the controller and the host.
  • The only external dependency is the AI provider you choose to configure, and if that is a self-hosted model, even AI inference stays in your environment.
  • This Privacy Policy then applies to us only in respect of your licence and billing relationship with Nabtech, and to your visits to this website.

17Changes to this policy

In short: We post material changes here and email account admins at least 14 days before they take effect.

We update this policy as our services and the law evolve. The Effective date and Version at the top always reflect the current revision. For material changes, we email account admins and post a notice on this page at least 14 days before the changes take effect. Continued use of OpsIQ after the effective date constitutes acceptance of the revised policy.

18Contact us

In short: Reach our privacy, security, DPO, and legal teams directly. We read every message.

We are Nabtech Digitalnet Limited, the company behind OpsIQ (www.nabtechonlineng.net). You can reach the right team directly:

TopicContact
Privacy & data subject requests[email protected]
Security & vulnerability reports[email protected]
Data Protection Officer[email protected]
Legal & contracts[email protected]

For our company details and mailing address, see About. Customers in regulated industries should review this policy with their own counsel before deployment.

Need a hand?

Questions about this policy?

Our team is happy to clarify anything on this page. Reach out any time.

Contact us Trust Center
IQOpsIQ

AI-first operations, customer support, licensing, and analytics for modern software teams.

TrackingAI SupportAutomationAnalyticsWebhooksTickets
Stay in the loop

A short, founder-written email, every couple of weeks. No fluff, unsubscribe anytime.

Product
All Features→AI CRM→Client Chat AI→Admin Chat AI→OpsIQ Writing→AI Analytics→Visitor Intelligence→AI Actions→
Operations
Tickets→Team Performance→Knowledge Base→Email Channel→Promotion Studio→Site Intelligence→Consent & GDPR→Sales Bridge→Webhooks→Surveys→Remote Sites→
Use cases
Solutions→Customer stories→Integrations→Compare→Pricing→
Resources
Developers→Docs→Help Center→FAQs→Contact→Roadmap→Status→
Company
About→Partners→Brand kit→Trust center→Security→Compliance→
Legal
Privacy→Terms→Acceptable use→DPA→Refunds→Cookies→
OpsIQ © 2026 Nabtech Digitalnet Limited. All rights reserved. Nabtech Digitalnet Limited · RC 1941738 · Osayande Ize-Iyamu Drive, Ugbor GRA Benin, Oredo, Edo State, Nigeria · +234 907 555 4548 All systems operational
Display currency
$USDUS Dollar₦NGNNigerian Naira€EUREuro£GBPBritish Pounds
EnglishEnglish · ENالعربيةArabic · ARБългарскиBulgarian · BGবাংলাBengali · BNČeštinaCzech · CSDanskDanish · DADeutschGerman · DEΕλληνικάGreek · ELEspañolSpanish · ESEspañol (Latinoamérica)Latin American Spanish · ES-419فارسیPersian · FASuomiFinnish · FIFilipinoFilipino · FILFrançaisFrench · FRFrançais (Canada)Canadian French · FR-CAעבריתHebrew · HEहिन्दीHindi · HIMagyarHungarian · HUBahasa IndonesiaIndonesian · IDItalianoItalian · IT日本語Japanese · JA한국어Korean · KOBahasa MelayuMalay · MSNederlandsDutch · NLNorskNorwegian · NOPolskiPolish · PLPortuguêsPortuguese · PTPortuguês (Brasil)Brazilian Portuguese · PT-BRRomânăRomanian · ROРусскийRussian · RUSlovenčinaSlovak · SKSvenskaSwedish · SVKiswahiliSwahili · SWไทยThai · THTürkçeTurkish · TRУкраїнськаUkrainian · UKاردوUrdu · URTiếng ViệtVietnamese · VI简体中文Simplified Chinese · ZH繁體中文Traditional Chinese · ZH-TW
Verify License Privacy Terms