THE DATA INFRASTRUCTURE FRAMEWORK
DataOpsIT provides infrastructure, not data exploitation.
Our platform operates on a strict Zero-Knowledge Model. We engineer and maintain secure data environments (“vessels”), but we do not inspect, index, analyse, profile, or monetise the content stored within them.
Any system-level access is strictly limited to technical necessity and never constitutes a commercial or analytical activity.
1. ROLE DEFINITIONS: CONTROL WITHOUT CONFUSION
To prevent liability ambiguity, DataOpsIT operates under two distinct roles as defined by the UK GDPR:
DataOpsIT as Data Controller
We act as the Controller solely for Account Metadata, including:
- User identity (name, email, organisation)
- Billing and transaction data
- Operational logs required to manage the service
DataOpsIT as Data Processor
We act as the Processor for all Hosted Content stored within customer-managed databases.
Legal Position
You are the Data Controller of all Hosted Content. You warrant that you possess a valid legal basis for processing such data and agree to indemnify DataOpsIT against any claims arising from its nature, use, or legality.
2. DATA MINIMALISM: COLLECTION BY NECESSITY ONLY
We do not deploy advertising trackers, behavioural analytics, or profiling systems.
We collect only the minimum data required to deliver and secure our services:
|
Data Category
|
Scope
|
Legal Basis
|
|
Account Identity
|
Name, email, organisation details
|
Contractual Necessity
|
|
Fiscal Data
|
Billing address, transaction records
|
Legal Obligation (HMRC)
|
|
Technical Telemetry
|
IP addresses, API logs, timestamps
|
Legitimate Interest (Security & Integrity)
|
|
Support Records
|
Helpdesk interactions, communication logs
|
Legitimate Interest (Service Delivery)
|
3. DATA SOVEREIGNTY & REGIONAL LOCKDOWN
Regional Integrity
Hosted Content remains strictly within the deployment region you select. DataOpsIT does not transfer or replicate your data across jurisdictions without explicit written instructions.
Sub-Processors
We engage Tier-1 infrastructure and payment providers (e.g. AWS, Stripe) under strict contractual safeguards.
By using our services, you grant general written authorisation for the use of such sub-processors. All partners are required to meet or exceed UK GDPR compliance standards.
4. THE “CLEAN SLATE” RETENTION MODEL
We operate a defined, non-accumulative data retention policy:
- Hosted Content: Permanently deleted within 30 days of account termination
- Security Logs: Deleted or irreversibly anonymised within 90 days
- Billing Records: Retained for 7 years in compliance with UK tax law (HMRC)
We do not retain data beyond its operational or legal necessity.
5. YOUR STATUTORY RIGHTS (SAR PROTOCOL)
Under UK GDPR, you retain full rights over your Account Data:
- Access – Obtain a copy of your data
- Rectification – Correct inaccurate information
- Erasure – Request deletion (subject to legal obligations)
- Objection – Object to processing based on Legitimate Interest
We respond to all valid Subject Access Requests (SARs) within 30 days.
We reserve the right to charge a reasonable fee for requests that are manifestly unfounded or excessive.
6. SECURITY: A SHARED RESPONSIBILITY MODEL
Security is enforced across infrastructure and account layers:
Our Responsibilities
- Encryption at rest (AES-256)
- Encryption in transit (TLS 1.2+)
- Network isolation and infrastructure hardening
Your Responsibilities
- Credential security and access control
- API key management
- Application-layer data protection
Breach Notification
In the event of a verified infrastructure-level breach, DataOpsIT will notify the Information Commissioner’s Office (ICO) and affected users within 72 hours, in accordance with regulatory requirements.
Notification does not constitute admission of liability.
7. THE 14-DAY UPDATE PROTOCOL (AFFIRMATIVE CONSENT MODEL)
We do not rely on passive acceptance mechanisms.
- Notice: Policy updates are communicated via registered administrative email
- Objection Window: You have 14 days to object formally
- Acceptance Mechanism: Continued use of the platform after this period constitutes affirmative and binding acceptance of the updated terms