In summary: OperAxis designs and supports digital solutions with privacy and security in mind. Where we process personal data for a client, we aim to act only on documented instructions, restrict access, use appropriate safeguards and support the client in meeting its UK data-protection obligations.
1. Our role under UK data-protection law
OperAxis may act in different roles depending on the service:
- Data controller: where we decide why and how personal data is used for our own website, enquiries, contracts, invoicing and business administration.
- Data processor: where we handle personal data solely on a client's documented instructions while developing, hosting, integrating, testing, maintaining or supporting a system.
- Independent or joint controller: in less common situations where the parties independently or jointly determine the purposes and means of processing. Any such arrangement should be identified and documented before processing begins.
The applicable roles and responsibilities should be confirmed in the project agreement before access to live personal data is provided.
2. Data protection by design and by default
We aim to consider privacy throughout discovery, design, development, testing, deployment and support. Depending on the project and assessed risk, measures may include:
- collecting only the information necessary for the agreed purpose;
- role-based access and least-privilege permissions;
- secure authentication and appropriate password controls;
- encryption in transit and, where appropriate, at rest;
- segregated development, test and production environments;
- use of anonymised, pseudonymised or synthetic test data where practical;
- audit logs, monitoring, backups and recovery controls where proportionate;
- secure configuration, dependency management and software updates;
- retention and deletion controls aligned to client instructions.
The exact controls will depend on the sensitivity, volume, context and risk of the data involved and will be agreed as part of the project scope.
3. Access to client data
OperAxis will seek to avoid access to live personal data unless it is genuinely required to deliver the agreed service. Where access is necessary, we aim to:
- use named, authorised accounts rather than shared credentials;
- limit access to the minimum people, systems and period required;
- follow the client's written instructions and access procedures;
- keep credentials and secrets out of source code and unsecured communications;
- use secure transfer and storage methods;
- remove or disable access promptly when it is no longer needed.
Clients should not send special-category, criminal-offence or other highly sensitive data until the need, lawful basis, security controls and project responsibilities have been specifically agreed.
4. Data Processing Agreements
Where OperAxis acts as a processor, the parties should enter into a written Data Processing Agreement or equivalent clauses before processing begins. The agreement should cover the subject matter and duration of processing, the types of personal data and people involved, documented instructions, confidentiality, security, sub-processors, data-subject rights, breach support, audits, and deletion or return of data at the end of the service.
A public GDPR statement is not a substitute for that contractual agreement.
5. Client responsibilities
Where the client is the controller, the client remains responsible for decisions about:
- the purposes and lawful bases for processing;
- what information is collected and whether it is necessary;
- privacy notices, transparency and consent where required;
- retention periods and deletion rules;
- responding to individuals' rights requests;
- whether a Data Protection Impact Assessment is required;
- any sector-specific legal or regulatory obligations.
OperAxis can help implement technical features that support these decisions, but cannot determine or guarantee a client's legal compliance.
6. Sub-processors and third-party services
Projects may use hosting, database, authentication, analytics, messaging, payment, app-store, cloud or support providers. Before introducing a sub-processor for client data, OperAxis will aim to identify the provider, assess its suitability, document the arrangement and obtain any authorisation required by the client agreement.
Where personal data is transferred outside the United Kingdom, appropriate safeguards and transfer arrangements should be considered and documented.
7. Data-subject rights
Where OperAxis acts as a processor, requests from individuals will normally be referred promptly to the client controller. Taking account of the nature of the processing and the agreed contract, we will provide reasonable assistance to help the client respond to requests for access, correction, deletion, restriction, objection or portability.
8. Data retention and project completion
Client personal data should be retained only for the agreed purpose and period. At the end of a project or support arrangement, OperAxis will follow the controller's documented instructions to return or securely delete personal data, subject to legal requirements and any agreed backup-deletion cycle.
9. Personal-data breaches
If OperAxis becomes aware of a suspected personal-data breach affecting data processed for a client, we will aim to contain and investigate it, preserve relevant records, and notify the client without undue delay in accordance with the contract. The controller is normally responsible for assessing whether notification to the ICO or affected individuals is legally required.
Clients should provide an emergency contact and agreed breach-reporting route before live processing begins.
10. Security is a shared responsibility
No system can be guaranteed completely secure. Effective protection depends on both parties, including secure user behaviour, device management, account administration, permissions, staff training, incident response and timely updates. Project contracts should state which party is responsible for each control.
11. Questions and data-protection enquiries
For questions about how OperAxis handles personal data, contact mark@operaxis.co.uk. For information about personal data collected directly by a client's application, users should normally contact the client identified in that application's privacy notice.
