Data protection

GDPR Commitment

Last updated: 28 July 2026

In summary: OperAxis designs and supports digital solutions with privacy and security in mind. Where we process personal data for a client, we aim to act only on documented instructions, restrict access, use appropriate safeguards and support the client in meeting its UK data-protection obligations.

Important: This page explains our approach and does not replace a project-specific contract, Data Processing Agreement, privacy notice, security schedule or legal advice.

1. Our role under UK data-protection law

OperAxis may act in different roles depending on the service:

The applicable roles and responsibilities should be confirmed in the project agreement before access to live personal data is provided.

2. Data protection by design and by default

We aim to consider privacy throughout discovery, design, development, testing, deployment and support. Depending on the project and assessed risk, measures may include:

The exact controls will depend on the sensitivity, volume, context and risk of the data involved and will be agreed as part of the project scope.

3. Access to client data

OperAxis will seek to avoid access to live personal data unless it is genuinely required to deliver the agreed service. Where access is necessary, we aim to:

Clients should not send special-category, criminal-offence or other highly sensitive data until the need, lawful basis, security controls and project responsibilities have been specifically agreed.

4. Data Processing Agreements

Where OperAxis acts as a processor, the parties should enter into a written Data Processing Agreement or equivalent clauses before processing begins. The agreement should cover the subject matter and duration of processing, the types of personal data and people involved, documented instructions, confidentiality, security, sub-processors, data-subject rights, breach support, audits, and deletion or return of data at the end of the service.

A public GDPR statement is not a substitute for that contractual agreement.

5. Client responsibilities

Where the client is the controller, the client remains responsible for decisions about:

OperAxis can help implement technical features that support these decisions, but cannot determine or guarantee a client's legal compliance.

6. Sub-processors and third-party services

Projects may use hosting, database, authentication, analytics, messaging, payment, app-store, cloud or support providers. Before introducing a sub-processor for client data, OperAxis will aim to identify the provider, assess its suitability, document the arrangement and obtain any authorisation required by the client agreement.

Where personal data is transferred outside the United Kingdom, appropriate safeguards and transfer arrangements should be considered and documented.

7. Data-subject rights

Where OperAxis acts as a processor, requests from individuals will normally be referred promptly to the client controller. Taking account of the nature of the processing and the agreed contract, we will provide reasonable assistance to help the client respond to requests for access, correction, deletion, restriction, objection or portability.

8. Data retention and project completion

Client personal data should be retained only for the agreed purpose and period. At the end of a project or support arrangement, OperAxis will follow the controller's documented instructions to return or securely delete personal data, subject to legal requirements and any agreed backup-deletion cycle.

9. Personal-data breaches

If OperAxis becomes aware of a suspected personal-data breach affecting data processed for a client, we will aim to contain and investigate it, preserve relevant records, and notify the client without undue delay in accordance with the contract. The controller is normally responsible for assessing whether notification to the ICO or affected individuals is legally required.

Clients should provide an emergency contact and agreed breach-reporting route before live processing begins.

10. Security is a shared responsibility

No system can be guaranteed completely secure. Effective protection depends on both parties, including secure user behaviour, device management, account administration, permissions, staff training, incident response and timely updates. Project contracts should state which party is responsible for each control.

11. Questions and data-protection enquiries

For questions about how OperAxis handles personal data, contact mark@operaxis.co.uk. For information about personal data collected directly by a client's application, users should normally contact the client identified in that application's privacy notice.