DataBridge Ops collects only what is needed to do the work. This document explains what that is, how it is handled, and what your rights are. Short version: your data is yours, it is not sold, and it is deleted when the engagement ends.
Inquiry and intake: When you submit a form on this site, we collect your name (if provided), work email, company name, and the information you share about your operation and the problem you are trying to solve. This is used to assess your request and respond to it. Nothing else.
Build engagement: Once an engagement begins, we collect and process only the data necessary to build and operate the agreed system. The specific data depends on what the build requires. We confirm what will be collected before work starts.
Builds that process employee or team data: Some builds require storing personal data about your employees or team members (for example, filing records, computed figures, or access credentials). In those cases, you remain the Data Controller. DataBridge Ops acts as a Data Processor under your instruction. You are responsible for informing the individuals whose data is processed, to the extent required by applicable law in your jurisdiction.
Site analytics: This site uses Cloudflare Web Analytics. It is cookieless and does not collect or transmit personally identifiable information.
What we do not collect: We do not collect special categories of personal data (health, union membership, disciplinary records) unless separately agreed in writing, or any data not required for the agreed build. Payment card details are handled entirely outside DataBridge Ops systems. See the Terms of Service for payment processing details.
Inquiry submissions are received via Tally and delivered by email to DataBridge Ops. They are not stored in a third-party CRM.
Build data is stored in the infrastructure appropriate to the system being built. The specific storage configuration is confirmed at intake. All DataBridge Ops-managed infrastructure uses HTTPS-only access, secrets stored as environment variables (never hardcoded), and role-based access controls. Credentials are revoked on engagement end.
Where a build stores employee or operational data in a shared database environment, that data is isolated at the database level so that no other client can access it. Where a dedicated environment is required, client data resides in a completely separate project with no shared infrastructure.
DataBridge Ops uses a small set of third-party services. The relevant ones for data handling are:
The specific processors used in your build are confirmed at intake. If a build requires a processor not listed here, it will be disclosed before work begins.
Inquiry data: Contact information and problem descriptions submitted via the inquiry form are retained while the inquiry is active and for 90 days after. If no engagement follows, data is deleted at the 90-day mark.
Build data: Data collected and processed as part of a build is retained for the duration of the engagement. On termination, DataBridge Ops provides a data export on request and deletes all client data within 30 days of confirmation.
Statutory retention (where applicable): If applicable law in your jurisdiction requires you to retain operational records for a minimum period (for example, employment or payroll records), that obligation rests with you as the employer or operator. DataBridge Ops recommends exporting records periodically and maintaining your own copies, rather than relying solely on the DataBridge Ops system for statutory compliance.
Deletion requests are actioned within 10 business days. Email build@databridgeops.com.
Standard measures applied to all DataBridge Ops-managed infrastructure: HTTPS-only access, API credentials stored as environment variables, role-based access controls, and credential revocation on engagement end.
In the event DataBridge Ops identifies or suspects a data breach affecting client data, we will notify you by email within 24 hours of identification, provide a written summary of what occurred and what was affected, and cooperate with any required notifications to supervisory authorities or affected individuals.
Security specifics for your build are documented and confirmed before go-live.
You may request access to, correction of, or deletion of any data DataBridge Ops holds about you or your organisation at any time. Requests are actioned within 10 business days.
Clients in jurisdictions with additional data subject rights (including the Philippine Data Privacy Act, GDPR, UK GDPR, and the California Consumer Privacy Act) retain all rights afforded by applicable local law. Nothing in these documents limits those rights.
Where a build processes personal data about your employees, those individuals may also have rights under applicable law. You, as the Data Controller, are responsible for facilitating those rights. DataBridge Ops will cooperate with any verified request you relay on behalf of an affected individual.
To exercise any right: build@databridgeops.com. We work async by default.
DataBridge Ops is based in the Philippines. Depending on the build, data may be processed by third-party services operating in the United States (Supabase, Anthropic, Cloudflare, Lemon Squeezy, Paddle).
By proceeding with a build, you acknowledge these transfers and confirm you have assessed any transfer mechanisms applicable to your situation. Clients subject to GDPR or UK GDPR who require Standard Contractual Clauses may request these before go-live.