Last updated: 6 August 2026
1. Purpose and scope
This Privacy Policy explains how AdyOps collects, uses, stores, discloses and protects personal data when people visit adyops.com, request a demo, communicate with support or use the AdyOps SaaS application. It also explains the difference between data processed for AdyOps's own business purposes and data processed on behalf of a customer.
2. Roles in the processing relationship
2.1 AdyOps as an independent data fiduciary or controller
AdyOps generally determines the purpose of processing for website enquiries, account administration, billing, product security, service communications and direct customer support.
2.2 AdyOps as a processor or service provider
For lead records, customer lists, call notes, campaign attribution, sales status and similar data entered into a customer's workspace, the customer normally determines why the data is processed. AdyOps processes that information to provide the configured service and follows the customer's documented instructions, subject to law and the applicable agreement.
3. Information we collect
- Contact information: name, business name, designation, phone number, email address and communication history.
- Account information: login ID, role, workspace, plan, subscription dates, settings, support requests and administrative actions.
- Customer-provided CRM data: lead details, form responses, addresses, remarks, follow-up dates, call outcomes, statuses, assignments, order information and logistics updates.
- Marketing attribution: UTM values, campaign, ad set, ad and placement identifiers, click IDs and connected advertising metrics.
- Technical and security information: IP address, browser, device, timestamps, session identifiers, login attempts, activity events, error logs and security signals.
- Billing information: invoices, tax details, payment status and payment references. Full card or banking credentials are normally handled by the selected payment provider rather than stored directly by AdyOps.
- Integration information: provider identifiers, connection status, webhook information and credentials strictly required to operate a configured integration.
4. How information is collected
Information may be provided directly through forms, account setup, support conversations or uploaded files. It may also be generated through use of the service, received from a customer's authorised user, or obtained from integrations that the customer chooses to connect.
5. Purposes of processing
- Provide, configure and maintain the AdyOps service.
- Create accounts, control permissions and administer subscriptions.
- Capture, route and manage leads according to customer instructions.
- Display dashboards, team activity, attribution and operational reports.
- Provide support, onboarding, data migration and requested customisation.
- Protect accounts, investigate misuse and maintain security logs.
- Send service notices, billing information and requested product communications.
- Meet contractual, accounting, tax, legal and regulatory obligations.
- Improve reliability, usability and performance using aggregated or appropriately limited information.
6. Legal grounds and consent
Depending on the context and applicable law, processing may be based on consent, steps requested before entering a contract, performance of a contract, compliance with law, or another permitted use. Where consent is relied upon, the request should be specific, informed and limited to the stated purpose. Withdrawal does not invalidate processing already carried out and may affect the ability to provide a requested function.
7. Customer responsibilities
Customers must provide appropriate notices, collect valid permissions, avoid unnecessary or prohibited data, configure user permissions, respond to data-subject requests and ensure their use of AdyOps is lawful. A customer should not upload sensitive or high-risk information unless the relevant module, contractual safeguards and lawful basis have been confirmed.
8. Sharing and subprocessors
AdyOps may use hosting, cloud infrastructure, email, payment, support, monitoring, backup and integration providers. Access is limited to what is reasonably required for the service. Information may also be disclosed to professional advisers, during a properly structured business transaction, to protect users and systems, or where required by a lawful authority.
9. International and cross-border processing
Providers or support personnel may process data from different locations. AdyOps and the customer should review applicable transfer restrictions, contractual safeguards, provider locations and any sector-specific localisation requirements before enabling an integration or deployment.
10. Retention and deletion
Retention depends on the subscription, customer instructions, backup cycle, dispute requirements, security needs and law. Active workspace data is generally retained while the account is in service. After termination, customers should export required data within the agreed period. Deleted information may remain temporarily in protected backups until the normal recovery cycle expires.
11. Security
AdyOps uses layered safeguards such as HTTPS, role permissions, login controls, session protections, input validation, protected storage, backups, activity records and restricted integration handling. Security is shared: customers must maintain strong credentials, control user access, secure connected providers and promptly report suspected compromise. No system can guarantee absolute security.
12. Individual rights and requests
Subject to applicable law, individuals may request information about processing, access, correction, completion, updating, erasure, withdrawal of consent or grievance review. When the request concerns data in a customer's CRM workspace, AdyOps may direct the requester to that customer because the customer controls the processing purpose.
13. Children and restricted data
AdyOps is designed for business users and is not directed to children. Customers must not knowingly process children's data without the required verifiable authorisation and safeguards. Customers must also avoid uploading passwords, payment authentication data, government credentials, medical records or other highly sensitive information unless a suitable lawful and contractual framework has been agreed.
14. Communications
Operational and security notices may be required for the service. Marketing communication, where used, should provide a practical opt-out. Opting out of marketing does not prevent essential account, billing or security messages.
15. Changes to this policy
AdyOps may update this policy when the service, providers or legal requirements change. Material changes will be reflected by a revised update date and may be communicated through the website, application or account contact.
16. Contact and grievance requests
Email Support@adyops.com with the subject “Privacy Request”. Include enough information to identify the relevant account and request, but do not send passwords or unnecessary personal data by email.