Legal

GDPR Compliance

Last updated: December 18, 2025

Ops Atlas is committed to protecting the privacy of individuals in the European Union and European Economic Area in accordance with the General Data Protection Regulation (GDPR).

Our Commitment

We process personal data lawfully, fairly, and transparently. We collect only what's necessary, keep it accurate, store it securely, and delete it when no longer needed.

Your Rights Under GDPR

As an EU/EEA resident, you have the following rights regarding your personal data:

πŸ“‹

Right to Access

Request a copy of all personal data we hold about you

✏️

Right to Rectification

Request correction of inaccurate or incomplete data

πŸ—‘οΈ

Right to Erasure

Request deletion of your personal data ("right to be forgotten")

⏸️

Right to Restriction

Request restriction of processing of your data

πŸ“¦

Right to Portability

Receive your data in a structured, machine-readable format

βœ‹

Right to Object

Object to processing based on legitimate interests or marketing

↩️

Right to Withdraw Consent

Withdraw consent at any time for consent-based processing

πŸ€–

Rights Related to Automated Decisions

Not be subject to decisions based solely on automated processing

How to Exercise Your Rights

To exercise any of these rights, you can:

We will respond to your request within 30 days. In complex cases, we may extend this by an additional 60 days, but we will inform you of any extension within the initial 30-day period.

Legal Basis for Processing

We process your personal data under the following legal bases:

Processing Activity Legal Basis
Providing the Service Contract performance
Account management Contract performance
Customer support Legitimate interest
Marketing emails Consent
Analytics Consent (via cookie banner)
Security & fraud prevention Legitimate interest
Legal compliance Legal obligation

Data Transfers

Some of our service providers are located outside the EU/EEA (primarily in the United States). When we transfer your data outside the EU/EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable
  • Data Processing Agreements with all processors

Data Processing Agreements

We have Data Processing Agreements (DPAs) in place with all our sub-processors that handle personal data on our behalf. These agreements ensure:

  • Data is processed only according to our instructions
  • Appropriate security measures are implemented
  • Sub-processors meet GDPR requirements
  • Data subjects' rights are protected

Data Retention

We retain personal data only for as long as necessary:

  • Account data: Until account deletion + 30 days backup period
  • Transaction records: 7 years (legal requirement)
  • Support tickets: 2 years after resolution
  • Analytics data: 14 months
  • Marketing consent records: Until consent withdrawal + 3 years

Security Measures

We implement technical and organizational measures to protect your data:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures
  • Regular backups with encryption

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it. If the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.

Children's Data

Ops Atlas is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware of such collection, we will delete the data promptly.

Supervisory Authority

If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

Find your local supervisory authority β†’

Data Controller

The data controller responsible for processing your personal data is:

David Ayman

Ops Atlas

Email: privacy@opsatlas.io

As a small operation, we have not appointed a Data Protection Officer (DPO). All data protection inquiries should be directed to the email above.

Sub-Processors

We use the following third-party services that may process your data:

Service Purpose Location
Vercel Inc. Website hosting USA (SCCs)
Google LLC Analytics USA (SCCs)
Kit (ConvertKit) Email newsletter USA (SCCs)
Formspree Inc. Contact forms USA (SCCs)
GitHub Inc. Code hosting USA (SCCs)

SCCs = Standard Contractual Clauses approved by the European Commission for data transfers outside EU/EEA.

Contact Our Data Protection Team

For any GDPR-related inquiries:

Email: privacy@opsatlas.io

Subject Line: "GDPR Request - [Your Request Type]"

Response Time: Within 30 days

For Self-Hosted Users

If you self-host Ops Atlas, you are the data controller for any data processed by your instance. We (Ops Atlas) do not have access to your self-hosted data. You are responsible for GDPR compliance for data processed on your own infrastructure.