Last updated: 7 September 2026
Controller: OPS DEFEND LIMITED (trading as Ops Defend) (“we”, “us”).
Contact for privacy requests: hello@opsdefend.co.uk
Registered address: 128 City Road, London, United Kingdom, EC1V 2NX · Companies House: 17154309
1. Who we are
We provide a UK Cyber Essentials preparation SaaS (CeGrc) and the marketing site at opsdefend.co.uk. We help organisations prepare for Cyber Essentials. We are not a Certification Body and we do not issue certificates.
2. Personal data we collect
| Context | Typical data | Why |
|---|---|---|
| Website (opsdefend.co.uk) | IP, device/browser, pages viewed; contact-form name, email, message; cookie/analytics data if enabled | Operate and secure the site; respond to enquiries; measure site use |
| Account / app | Work email, name, magic-link tokens; organisation name and profile; role (Customer / Admin) | Create and secure accounts; provide the service |
| Product use | Questionnaire answers, evidence metadata/uploads you choose to add, asset/inventory items you enter, progress status | Deliver prep workflows and reporting for your organisation |
| Billing | Name, email, billing address, payment method tokens via Stripe; plan/SKU, invoices | Take payment; manage subscriptions (Starter / Programme / Assist) |
| Support | Message content, related account/org identifiers | Help you use the product |
| Security / ops logs | IP, timestamps, auth events, error and access logs | Security, abuse prevention, reliability |
We do not intend to process special-category data or children’s data. Please do not upload special-category or children’s personal data into the product.
3. Lawful bases (UK GDPR)
- Contract — providing the SaaS, account, billing, and support you request.
- Legitimate interests — securing systems, preventing abuse, improving reliability, basic product analytics that are not intrusive, B2B marketing to business contacts where PECR allows. You can object: hello@opsdefend.co.uk.
- Consent — non-essential cookies / marketing emails where required (you can withdraw).
- Legal obligation — tax, accounting, and responding to lawful requests.
4. Who we share data with (processors / providers)
We use service providers under contracts with appropriate UK GDPR terms:
- Microsoft Azure (UK South) — hosting the application and related data.
- Stripe — payment processing (planned / when enabled).
- Microsoft 365 (Exchange Online / Microsoft Graph (Mail.Send)) — transactional email (e.g. magic links from noreply@opsdefend.co.uk); support/privacy mail to hello@opsdefend.co.uk.
- IONOS — WordPress hosting for the marketing site.
We do not sell personal data. We may disclose data if required by law or to protect rights, safety, or security.
Assist SKU: if you buy Assist, a UK-based Ops Defend team member assigned to your Assist session may access your organisation’s workspace and evidence to help you prepare. Access is limited to the assigned session and for 7 days after the session ends (then auto-revoked), logged where practicable, and covered by our confidentiality and security practices. We do not use Assist access for unrelated browsing of customer data.
5. International transfers
Primary hosting is Azure UK South (UK). If a provider processes data outside the UK, we use an appropriate safeguard (e.g. UK IDTA / Addendum, or adequacy). Details on request: hello@opsdefend.co.uk.
6. Retention (starter)
| Data | Starter retention |
|---|---|
| Account & org profile | While the account is active, then typically up to 12 months after closure unless you ask sooner and we can delete |
| Prep answers / evidence / assets | While the subscription/account is active; deleted or anonymised within 90 days after account closure (unless longer needed for disputes) |
| Billing / invoices | Usually 6–7 years (tax/accounting) |
| Support tickets | Typically 24 months after closed |
| Security logs | Typically 90 days (longer if investigating an incident) |
| Marketing site analytics | Per cookie/tool settings (often 14 months or less) |
Exact periods may be refined in our internal retention schedule.
7. Your rights
Under UK GDPR you can ask to access, rectify, erase, restrict, object, or request portability where applicable, and withdraw consent where processing is based on consent.
Email hello@opsdefend.co.uk. We aim to respond within one month. You can complain to the ICO (ico.org.uk).
8. Security
We use access controls (Customer vs Admin), encryption in transit, UK-region hosting where offered, and operational logging. No method of transmission or storage is 100% secure.
9. Children
The service is for businesses and organisations, not for children under 18. We do not knowingly collect children’s personal data.
10. Cookies
See our Cookie / PECR note on the website. Essential cookies keep the site and app working; non-essential cookies need consent where PECR requires it.
11. Changes
We may update this notice. Material changes will be posted on the site (and, where appropriate, notified in-app or by email).
12. Contact
Privacy: hello@opsdefend.co.uk · Support: hello@opsdefend.co.uk