Privacy Policy

Your data, in plain language.

This policy covers what Operelio collects, why we collect it, and what control you have. Written in plain language, with legal detail where it counts.

Last updated April 2026

At a glance

What matters most

What we collect: Account details, the files you upload, usage data, and payment information handled by Stripe.

What we don't do: We don't sell your data, use it to train AI models, serve ads, or share it with marketing partners.

Where it lives: AWS infrastructure in US-East. EU storage options are available on request, and email verification is performed by EU-based providers.

How long we keep files: 24 hours on Free, 30 days on Pro and Team, 90 days on Agency. After that, files are permanently deleted.

Your rights: Access, correct, delete, or export your data at any time. GDPR and CPRA rights are supported.

Questions: Email hello@operelio.com. We respond to data requests within 30 days.

Data collection

What we collect and why

Account information. Your name, email address, and company name. We use these to create your account, send service updates, and respond when you contact support. Clerk manages authentication, session tokens, and multi-factor login on our behalf.

Files you upload. Spreadsheets containing business contact data: names, emails, phone numbers, company information. We process these to run the transformations you configure. Files are stored in isolated S3 buckets with server-side encryption and deleted after your plan's retention period. When you run the Email Verifier & Finder, the email addresses in your file are sent to our EU-based verification providers to be checked. We keep the verdict, the confidence score, and a one-way hash of the address for 7 days. That record lets us reuse a verdict for any address already checked on Operelio instead of paying a provider to check it twice, so it is not scoped to your account. It holds no name, no company, no file reference, and no account reference, and the hash cannot be turned back into an address. The raw address is deleted with the rest of your file at the end of your retention window.

CRM credentials. If you connect HubSpot, Salesforce, or Pipedrive, we store OAuth tokens to push data on your behalf. These are encrypted separately from your account data using AWS KMS, never logged, and revoked the moment you disconnect.

Usage data. Job history, file sizes, processing times, and feature usage. This tells us which tools people use most and where errors occur. We also collect standard device and access data: IP address, browser type, and page navigation.

Payment data. Billing runs through Stripe. Card details are entered directly into Stripe's secure forms and never touch our servers. The only payment information we receive is your billing email, subscription tier, card type, last four digits, and expiry date.

Communication data. Messages you send through our contact form or support channels. We keep these for three years so we have context if you write back.

Legal basis for processing (GDPR Article 6)

Contract performance (6(1)(b)): Processing your uploads, managing your account, handling billing, and pushing data to CRM platforms you connect.

Legitimate interests (6(1)(f)): Improving the service, usage analytics, security monitoring, and fraud prevention.

Consent (6(1)(a)): Marketing emails and non-essential cookies. You can withdraw consent at any time.

Legal obligations (6(1)(c)): Tax records, financial regulations, and law enforcement requests.

File handling

How we handle your files

When you upload a spreadsheet, you are the data controller and Operelio acts as a data processor. We process your files only to perform the transformations you request. Where a transformation relies on an outside service, such as the email verification providers used by the Email Verifier & Finder, that service acts as our sub-processor and handles your data under the same instructions, never as an independent controller of your file content.

Files are stored in isolated S3 buckets with AES-256 encryption at rest. Every connection uses TLS 1.2 or higher, and our servers reject any unencrypted request. Only authorized personnel can access customer files, on a need-to-know basis, and we log every access event.

Retention depends on your plan. Files on the Free plan are deleted 24 hours after processing. Pro and Team give you 30 days. Agency gives you 90 days. After the retention window closes, files are permanently removed from all primary storage. Encrypted backup copies are purged within 30 days of the retention deadline.

We never use the contents of your files for analytics or model training. Each file is scoped to the job you created and is not accessible to other jobs or accounts.

Retention at a glance

Uploaded files: 24 hours (Free), 30 days (Pro and Team), 90 days (Agency)

Account data: Kept while your account is active. Deleted within 30 days of account closure, unless required by law.

Usage logs: 90 days for standard logs, 180 days for security incidents, then aggregated and anonymised.

Payment records: Retained as required by tax and financial regulations, typically six to seven years.

CRM tokens: Deleted immediately when you disconnect or close your account.

If your organization requires a Data Processing Agreement, we have a standard DPA ready to sign. It incorporates Standard Contractual Clauses for international transfers and details our obligations as a processor. Email hello@operelio.com and we'll send it over.

Sub-processors

Who else touches your data

We use a small number of third-party services to run Operelio. Each one has a specific role, and we only share the minimum data that role requires.

Clerk (authentication). Handles login, session management, and multi-factor authentication. Clerk receives your email address and authentication tokens. Data is stored in the US. Clerk's privacy policy applies to their processing.

Stripe (payments). Processes all billing and subscription payments. Stripe is PCI Level 1 certified. Card details are entered directly into Stripe's secure forms and never touch our servers. Stripe's privacy policy applies.

AWS (infrastructure). Hosts the platform, stores files, runs compute, and manages backups. Data centers are in the US. AWS operates under the AWS Data Processing Addendum and has executed the DPA required under GDPR.

Email verification providers (MillionVerifier and Bouncer). When you run the Email Verifier & Finder, the email addresses being checked are sent to our verification providers to confirm whether each inbox accepts mail. Both are EU-based and GDPR-compliant. MillionVerifier runs the first check; its servers are in the EU (Hungary and Sweden), it processes addresses only within the EU, and it deletes uploaded data within one month. Bouncer runs the deeper second check; it is hosted in EU data centers, hashes uploaded addresses across its system, and deletes uploaded data within 60 days. Neither provider sends mail to your contacts, and both operate under a signed Data Processing Agreement. MillionVerifier's privacy policy and Bouncer's privacy policy apply to their processing.

CRM platforms (data destination). When you authorize an integration, we send the data you select to HubSpot, Salesforce, or Pipedrive. From that point, the CRM platform is an independent data controller under its own privacy policy.

We notify customers by email at least 30 days before adding a new sub-processor. A complete and current list is available in our DPA and on request.

Your rights

What you can ask us to do

The GDPR gives UK and EU residents specific rights over their personal data. The California Privacy Rights Act provides similar protections for California residents. We honor both sets of rights for all users.

Access your data. Request a copy of everything we hold about you, in a portable machine-readable format.

Correct or delete your data. If something is wrong, tell us and we will fix it. You can also update most account information directly in your settings. If you want your data removed, we will delete it unless we have a legal obligation to keep it (such as tax records).

Restrict or object to processing. If you dispute the accuracy of your data, you can ask us to limit processing until we resolve it. You can also object to processing based on legitimate interests. For marketing emails, unsubscribe at any time using the link in every email.

Data portability. Receive your data in a structured format and transfer it to another provider.

We do not use automated processing to make decisions that have legal or similarly significant effects on you.

Additional rights for California residents (CPRA)

Right to opt out of sale or sharing: We do not sell personal information or share it for cross-context behavioral advertising.

Right to limit use of sensitive data: You can request we limit the use of sensitive personal information to providing the service.

Right to non-discrimination: Exercising your rights will never affect the quality or pricing of the service.

Right to appeal: If we deny a request, you can appeal our decision. You may also designate an authorized agent to submit requests on your behalf.

To exercise any of these rights, email hello@operelio.com. We respond to data subject requests within 30 days. Complex requests may take up to 45 days under GDPR, and we will let you know if that applies. You also have the right to lodge a complaint with your local data protection authority, such as the UK ICO or the relevant EU supervisory authority.

Cookies

Cookies and tracking

We use essential cookies for authentication and session management. Analytics and performance cookies help us understand usage patterns and monitor uptime.

We do not use advertising cookies or retargeting scripts. There are no social media tracking pixels on any Operelio page, and no third-party marketing tools running in the background.

If your browser sends a Do Not Track signal, we respect it and will not set optional cookies. You can manage all cookie preferences through our cookie banner, or disable cookies in your browser settings (though this may affect core functionality).

Data transfers

International transfers

Operelio infrastructure is hosted on AWS in the United States. If you are based in the UK or EU, your data is transferred to and stored in the US.

We rely on Standard Contractual Clauses approved by the UK ICO and EU Commission to ensure these transfers meet GDPR requirements. The clauses are incorporated into our Data Processing Agreement. The UK has also issued an adequacy decision for US transfers under the UK GDPR, which is reflected in our DPA.

For organizations that require EU-based storage, email hello@operelio.com and we can discuss options.

Other details

Compliance, incidents, and updates

Breach notification. If we discover a data breach affecting your personal data, we notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Article 33. Every notification describes the incident, the data involved, and the steps we are taking to resolve it.

Compliance certifications. Operelio complies with GDPR, UK GDPR, and CCPA/CPRA. Our security page covers encryption standards, infrastructure, and access controls in full.

Operelio is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe we have, email security@operelio.com and we will delete the data within 10 business days.

Under California's Shine the Light law (Cal. Civ. Code § 1798.83), we confirm that we do not share personal information with third parties for their direct marketing purposes. California residents can request written confirmation by emailing hello@operelio.com.

If we make material changes to this policy, we will notify you by email or through a notice in the product at least 30 days before they take effect. We maintain a version history on our website.

Contact

Privacy inquiries and data requests

For data subject requests or questions about this policy, email hello@operelio.com. For security issues or vulnerability reports, email security@operelio.com.

Operelio Limited, United Kingdom. This policy describes our data practices and is not legal advice. For guidance on your specific rights, consult a qualified legal professional in your jurisdiction.