Legal Effective July 6, 2026

Data Privacy

DataBridge Ops collects only what is needed to do the work. This document explains what that is, how it is handled, and what your rights are. Short version: your data is yours, it is not sold, and it is deleted when the engagement ends.

Contents
  1. 01What We Collect and Why
  2. 02How Data Is Stored
  3. 03Third-Party Services
  4. 04Retention and Deletion
  5. 05Security
  6. 06Your Rights
  7. 07International Transfers
Section 01

What We Collect and Why

Inquiry and intake: When you submit a form on this site, we collect your name (if provided), work email, company name, and the information you share about your operation and the problem you are trying to solve. This is used to assess your request and respond to it. Nothing else.

Build engagement: Once an engagement begins, we collect and process only the data necessary to build and operate the agreed system. The specific data depends on what the build requires. We confirm what will be collected before work starts.

Builds that process employee or team data: Some builds require storing personal data about your employees or team members (for example, filing records, computed figures, or access credentials). In those cases, you remain the Data Controller. DataBridge Ops acts as a Data Processor under your instruction. You are responsible for informing the individuals whose data is processed, to the extent required by applicable law in your jurisdiction.

Site analytics: This site uses Cloudflare Web Analytics. It is cookieless and does not collect or transmit personally identifiable information.

What we do not collect: We do not collect special categories of personal data (health, union membership, disciplinary records) unless separately agreed in writing, or any data not required for the agreed build. Payment card details are handled entirely outside DataBridge Ops systems. See the Terms of Service for payment processing details.

Section 02

How Data Is Stored

Inquiry submissions are received via Tally and delivered by email to DataBridge Ops. They are not stored in a third-party CRM.

Build data is stored in the infrastructure appropriate to the system being built. The specific storage configuration is confirmed at intake. All DataBridge Ops-managed infrastructure uses HTTPS-only access, secrets stored as environment variables (never hardcoded), and role-based access controls. Credentials are revoked on engagement end.

Where a build stores employee or operational data in a shared database environment, that data is isolated at the database level so that no other client can access it. Where a dedicated environment is required, client data resides in a completely separate project with no shared infrastructure.

Section 03

Third-Party Services

DataBridge Ops uses a small set of third-party services. The relevant ones for data handling are:

Third-party processors
Tally
Form submissions. Intake data passes through Tally servers before delivery to DataBridge Ops.
Supabase
Database and authentication for applicable builds. Data stored in the United States (AWS us-east-1 by default).
Cloudflare
Application hosting and DNS. Global network. Cookieless analytics (no PII transmitted).
Anthropic
AI processing for applicable builds. Data processed in the United States. Only used in builds where AI processing is part of the agreed scope.

The specific processors used in your build are confirmed at intake. If a build requires a processor not listed here, it will be disclosed before work begins.

Section 04

Retention and Deletion

Inquiry data: Contact information and problem descriptions submitted via the inquiry form are retained while the inquiry is active and for 90 days after. If no engagement follows, data is deleted at the 90-day mark.

Build data: Data collected and processed as part of a build is retained for the duration of the engagement. On termination, DataBridge Ops provides a data export on request and deletes all client data within 30 days of confirmation.

Statutory retention (where applicable): If applicable law in your jurisdiction requires you to retain operational records for a minimum period (for example, employment or payroll records), that obligation rests with you as the employer or operator. DataBridge Ops recommends exporting records periodically and maintaining your own copies, rather than relying solely on the DataBridge Ops system for statutory compliance.

Deletion requests are actioned within 10 business days. Email build@databridgeops.com.

Section 05

Security

Standard measures applied to all DataBridge Ops-managed infrastructure: HTTPS-only access, API credentials stored as environment variables, role-based access controls, and credential revocation on engagement end.

In the event DataBridge Ops identifies or suspects a data breach affecting client data, we will notify you by email within 24 hours of identification, provide a written summary of what occurred and what was affected, and cooperate with any required notifications to supervisory authorities or affected individuals.

Security specifics for your build are documented and confirmed before go-live.

Section 06

Your Rights

You may request access to, correction of, or deletion of any data DataBridge Ops holds about you or your organisation at any time. Requests are actioned within 10 business days.

Clients in jurisdictions with additional data subject rights (including the Philippine Data Privacy Act, GDPR, UK GDPR, and the California Consumer Privacy Act) retain all rights afforded by applicable local law. Nothing in these documents limits those rights.

Where a build processes personal data about your employees, those individuals may also have rights under applicable law. You, as the Data Controller, are responsible for facilitating those rights. DataBridge Ops will cooperate with any verified request you relay on behalf of an affected individual.

To exercise any right: build@databridgeops.com. We work async by default.

Section 07

International Transfers

DataBridge Ops is based in the Philippines. Depending on the build, data may be processed by third-party services operating in the United States (Supabase, Anthropic, Cloudflare, Lemon Squeezy, Paddle).

By proceeding with a build, you acknowledge these transfers and confirm you have assessed any transfer mechanisms applicable to your situation. Clients subject to GDPR or UK GDPR who require Standard Contractual Clauses may request these before go-live.

This document is provided in good faith for a lean B2B services operation. It is not a substitute for legal advice. Clients in regulated jurisdictions, or those whose builds will process sensitive personal data, should have their legal counsel review this document before proceeding.

Data protection queries

build@databridgeops.com

Response within 2 business days.