GDPR
GDPR and data protection information
Last updated: 15 July 2026. This page explains how OpsFlow Management is intended to support UK GDPR compliance for business customers.
Customer role
For personal data a customer enters into their OpsFlow Management workspace, the customer is normally the controller. This includes their customer records, staff details, invoices, job sheets, delivery notes, calendar events, payroll records and notes.
OpsFlow Group LTD role
OpsFlow Group LTD normally acts as processor for workspace data. We process that data to provide the service, maintain security, host and back up records, send emails requested by users, provide support, and keep the system reliable.
OpsFlow Group LTD as controller
OpsFlow Group LTD is controller for data we use to run our own business, including account registration, subscription billing, website contacts, support messages, security logs and direct relationship records.
Data subject requests
If a person contacts OpsFlow Group LTD about data held inside a customer's workspace, we may refer the request to that customer. If the request relates to data controlled by OpsFlow Group LTD, contact [email protected].
Export and deletion
Customers should keep their own records and may request reasonable help exporting or deleting workspace data. Some data may need to be retained for tax, accounting, audit, fraud prevention, dispute, security or legal reasons.
Subprocessors
OpsFlow Group LTD may use trusted providers for hosting, database storage, backups, payment processing, email delivery, DNS/domain services, support and monitoring. Before going live, this page should list each live subprocessor by name, purpose and location.
Security measures
- Role-based access controls for administrators and employees.
- Password hashing rather than storing plain passwords.
- HTTPS in production.
- Audit logs for important workspace changes.
- Subscription access controls after trial expiry or failed billing.
- Operational backups and controlled access to production secrets.
Personal data breaches
If we become aware of a personal data breach affecting customer workspace data, we will investigate and notify affected customers without undue delay where required. Customers are responsible for assessing their own notification duties to individuals or regulators.
Data protection contact
Data protection questions can be sent to [email protected].
