Skip to content
Operelli Logo
Product Pricing Trust FAQ Help
Sign In Request Access
Product Pricing Trust FAQ Help
Sign In Request Access

Back to Legal index

Legal · Controlled draft

Privacy Policy

Draft privacy practices for the OperelliOS website, application, support interactions, and related services.

Controlled Draft — Not Effective

This document is prepared for legal, product, and engineering review. It is not an effective agreement, policy, or public commitment.

Effective date placeholder
[LEGAL REVIEW REQUIRED: Set effective date after approval]
Last updated (draft)
July 17, 2026 — controlled draft
Review status
Controlled draft — not effective

Table of contents

  1. 1. Scope and Roles
  2. 2. Information We May Collect
  3. 3. Sources of Information
  4. 4. Why We Use Information
  5. 5. Tenant-Controlled End-Customer Information
  6. 6. How Information May Be Disclosed
  7. 7. AI-Related Processing
  8. 8. Aggregated and De-Identified Information
  9. 9. Cookies, Storage, and Online Tracking
  10. 10. Retention and Deletion
  11. 11. Security
  12. 12. Privacy Rights and Requests
  13. 13. United States State Privacy Notices
  14. 14. International Processing
  15. 15. Children
  16. 16. Changes to This Policy
  17. 17. Contact

1. Scope and Roles

This draft Privacy Policy is intended to describe personal-information practices for the OperelliOS public website, application, support interactions, and related services. It is not effective until approved by counsel, aligned with actual production data flows, dated, and published.

When OperelliOS processes account, website, sales, or support information for its own business purposes, it may act as a business, controller, or similar responsible party under applicable law.

When OperelliOS processes information that a Tenant enters about its customers, properties, workers, or business contacts to provide the Service, the Tenant generally determines why and how that information is used, and OperelliOS generally acts as a service provider or processor on the Tenant’s behalf.

End customers of a Tenant should ordinarily direct requests about Tenant-controlled records to that Tenant. OperelliOS will support the Tenant as required by applicable law and an approved agreement.

LEGAL REVIEW REQUIRED: Confirm jurisdiction-specific controller/processor and business/service-provider terminology.

2. Information We May Collect

The categories below are a controlled draft inventory. Each category must be confirmed against production telemetry, forms, vendors, logs, and database behavior before publication.

CategoryExamplesVerification status
Account and identity informationName, work email, organization, role, authentication identifiers[ENGINEERING VERIFICATION REQUIRED]
Business profile informationCompany name, service categories, contact and operating details[ENGINEERING VERIFICATION REQUIRED]
Tenant operational dataCustomer, property, price-book, estimate, proposal, work-order, invoice, and payment-status recordsSupported product-domain direction; verify exact fields
Support and communicationsSupport requests, feedback, correspondence, attachments[PRODUCT/ENGINEERING VERIFICATION REQUIRED]
Usage and device informationIP address, browser, device, timestamps, pages or features used, diagnostic events[ENGINEERING VERIFICATION REQUIRED]
Public-site request informationInformation entered into request-access or contact formsCurrent preview form states it does not submit or store information; verify deployed behavior
AI interaction dataPrompts, source content, outputs, confidence or feedback signals[ENGINEERING VERIFICATION REQUIRED]
Billing informationSubscription or payment detailsNot active for current public MVP; defer until Gate 1

3. Sources of Information

Information may come directly from the Customer or Authorized User, from the Customer’s end customers or workers through Customer-controlled workflows, from use of the Service, from authorized integrations, from service providers, and from publicly available business sources where permitted.

OperelliOS should not obtain information from data brokers or use purchased marketing lists unless separately approved, documented, and reflected in this Policy.

4. Why We Use Information

Subject to verification and applicable law, OperelliOS may use information to:

  • Provide, operate, secure, maintain, and support the Service.
  • Authenticate users, apply roles and permissions, and protect tenant boundaries.
  • Process Customer instructions and maintain workflow records.
  • Communicate about access, support, security, service changes, and accepted commercial relationships.
  • Detect, investigate, and prevent fraud, abuse, unauthorized access, and service disruption.
  • Monitor reliability, troubleshoot defects, and improve the Service using appropriately governed information.
  • Comply with legal obligations and establish, exercise, or defend legal claims.
  • Generate aggregated or de-identified insights only after the approved policy and technical controls are in place.

5. Tenant-Controlled End-Customer Information

Tenants may enter information about their own customers, properties, employees, contractors, and business contacts. The Tenant is responsible for providing appropriate notices, obtaining required permissions, and using that information lawfully.

OperelliOS should process Tenant-controlled information only to provide the Service, follow documented instructions, maintain security, comply with law, and perform other narrowly approved purposes stated in the agreement.

OperelliOS does not become the owner of a Tenant’s customer relationships or operational records.

6. How Information May Be Disclosed

OperelliOS may disclose information to verified service providers and subprocessors that perform services on its behalf, subject to appropriate contractual and security requirements.

Information may also be disclosed when directed by the Customer, required by law, necessary to protect rights or safety, or involved in an approved corporate transaction subject to appropriate safeguards and notice obligations.

OperelliOS should not characterize a disclosure as a sale, sharing, or targeted-advertising activity until the website and vendor stack have been audited under applicable state privacy definitions.

A current subprocessor structure is maintained at /legal/subprocessors. The draft list must not be treated as final until vendors, purposes, data categories, and locations are verified.

7. AI-Related Processing

AI-Assisted Features may process Customer Data to draft, extract, summarize, classify, or recommend information. Outputs require human review and do not control financial truth, permissions, payments, or irreversible actions.

The final Policy must identify the approved model-training posture and describe relevant providers, logging, retention, and opt-out or consent mechanisms where required.

Target policy: identifiable Tenant and end-customer data will not be used to train shared or generally available models by default. Any future contribution program should require separate, informed opt-in and verified de-identification controls.

[PRODUCT DECISION REQUIRED: Approve no-training-by-default policy.] [ENGINEERING VERIFICATION REQUIRED: Confirm provider contracts and runtime controls.]

8. Aggregated and De-Identified Information

OperelliOS may wish to use aggregated or de-identified information for reliability, product improvement, analytics, and future benchmarking.

That use should be permitted only where the information cannot reasonably identify a Tenant, individual, property, or end customer; raw cross-tenant records are not exposed; re-identification is prohibited; access is controlled; and retention is approved.

[PRODUCT DECISION REQUIRED: Approve exact permitted uses.] [ENGINEERING VERIFICATION REQUIRED: Confirm transformation, minimum aggregation thresholds, access controls, and re-identification tests.]

9. Cookies, Storage, and Online Tracking

A source audit of the supplied public-site ZIP found no application code referencing analytics libraries, advertising pixels, cookies, localStorage, or sessionStorage. That finding does not establish the behavior of the deployed host, consent tooling, reverse proxy, or future integrations.

The final website inventory must verify essential storage, analytics, advertising, embedded content, and hosting-level tracking. See the conditional Cookie Policy.

[ENGINEERING VERIFICATION REQUIRED: Audit deployed website requests, response headers, browser storage, consent platform, and host-injected scripts.]

10. Retention and Deletion

OperelliOS should retain personal information only for approved business, contractual, security, and legal purposes. Exact periods must be defined by data category, system of record, and deletion capability.

Termination does not necessarily cause immediate deletion from backups, audit records, security records, or records subject to legal obligations. Those exceptions must be narrow and documented.

See the Data Retention Policy for the controlled decision matrix. No specific retention period is promised in this draft.

11. Security

OperelliOS uses a kernel-first architecture intended to enforce tenant boundaries, identity, policy, auditable mutations, and deterministic financial calculations. Public statements must remain limited to controls that engineering has verified in production.

No certification, encryption implementation, backup schedule, penetration-test frequency, incident-notification period, or uptime commitment is stated by this draft.

See the Data Security Overview for verification gates and customer responsibilities.

12. Privacy Rights and Requests

Depending on location and relationship, individuals may have rights to access, correct, delete, restrict, object to, or obtain a copy of certain personal information, and to appeal a decision or opt out of certain processing.

These rights are not absolute and may be subject to identity verification, legal exceptions, the Tenant’s role as controller, and technical limitations that must be addressed before publication.

Requests concerning Tenant-controlled records should generally be directed first to the applicable Tenant. OperelliOS should maintain an internal process for receiving, routing, verifying, recording, and responding to requests.

[LEGAL REVIEW REQUIRED: Determine applicable state and international privacy laws.] [ENGINEERING VERIFICATION REQUIRED: Confirm request, export, correction, deletion, and appeal workflows.]

13. United States State Privacy Notices

[LEGAL REVIEW REQUIRED: Determine whether and when CCPA/CPRA and other comprehensive U.S. state privacy laws apply to OperelliOS, including thresholds, exemptions, sale/share definitions, sensitive information, appeals, and authorized agents.]

Do not publish a categorical statement about selling or sharing information until advertising, analytics, and vendor data flows are audited under each applicable statutory definition.

14. International Processing

OperelliOS is currently positioned for U.S. service companies, but data may be processed by providers in other locations depending on the confirmed infrastructure and vendor stack.

[LEGAL REVIEW REQUIRED: Determine international-transfer obligations.] [ENGINEERING VERIFICATION REQUIRED: Confirm processing and support locations for each subprocessor.]

15. Children

OperelliOS is a business service and is not directed to children. Authorized Users must meet the minimum age and authority requirements approved in the final Terms.

Tenants should not intentionally enter children’s personal information unless required for a lawful business purpose and supported by the applicable Service configuration and notices.

[LEGAL REVIEW REQUIRED: Confirm age threshold and any handling obligations for incidental information about minors.]

16. Changes to This Policy

The final Policy should identify how material changes are communicated and when they become effective. Merely changing a date may be insufficient for material changes in certain circumstances.

[LEGAL REVIEW REQUIRED: Approve notice and consent requirements.]

17. Contact

Privacy questions and requests: [LEGAL REVIEW REQUIRED: Confirm legal and privacy contact email]

[LEGAL REVIEW REQUIRED: Confirm mailing address, privacy officer or contact role, verification method, and appeal channel.]

Related documents:

  • Terms of Service
  • AI Disclosure
  • Subprocessor List
  • Data Retention Policy
  • Cookie Policy

Related documents

  • Terms of Service — Controlled draft — not effective
  • AI Disclosure — Controlled draft — not effective
  • Subprocessor List — Controlled draft — not effective
  • Data Retention Policy — Controlled draft — not effective
  • Cookie and Browser Storage Policy — Controlled draft — not effective

Contact

Privacy questions and requests regarding this pending Privacy Policy draft.

[LEGAL REVIEW REQUIRED: Confirm legal and privacy contact email]

Operelli Logo © 2026 OperelliOS. All rights reserved.
  • Product
  • Pricing
  • Trust
  • FAQ
  • Help
  • Legal
Privacy Terms