Help · Guide
GDPR and your data at BrandOps9
How BrandOps9 handles your personal data under the GDPR: what we process and why, who we share it with, how long we keep it, and how to exercise your rights.
Where you stand
BrandOps9 is operated and hosted inside the EU, and the GDPR applies to how we handle your personal data. This guide explains, in plain language, what we process, who we share it with, how long we keep it, and the rights you have. It describes how the product is built to support compliance; it isn't legal advice.
What we process and why
To run your workspace we process account details (your name and email), workspace membership, the brand details and website text you bring in, campaign briefs and generated assets, schedules, credit balances, and audit events. When you connect a social account we store its access tokens encrypted at rest.
We rely on two legal bases: performing our contract with you (running the service you signed up for) and our legitimate interest in operating, securing and improving the platform. We do not sell your personal data.
No tracking cookies
BrandOps9 sets no advertising or analytics cookies and runs no third-party tracking pixels. The only browser storage we use is the essential local storage that keeps you logged in and remembers basic preferences. Because there is no non-essential tracking, there is no cookie-consent banner to click through.
Who we share it with (sub-processors)
To deliver the service we use a small set of vetted sub-processors: OpenAI and (if you enable video) RunwayML for content generation; Google, Meta, LinkedIn and X when you connect those accounts; Stripe for payments; and SendPulse for transactional email. Content sent to the AI providers is used only to produce your requested output and is not used to train their models.
Several of these providers are in the United States, so some processing takes place outside the EEA under appropriate safeguards such as Standard Contractual Clauses. The full list, with purpose, data categories and region, is on the Sub-processors page, and a Data Processing Agreement is available on request.
Your rights and how to use them
Under the GDPR you can ask us to give you a copy of your data (access), correct it, export it in a portable format, delete it, restrict how we use it, or object to certain processing. To exercise any of these, email contact@brandops9.com and we will respond within 30 days.
Self-service tools to export and delete your data from inside the app are rolling out; until then we handle these requests for you on request. You can already update your name and profile photo from the account menu, and workspace owners can manage and revoke who has access to a brand.
How long we keep your data
We keep workspace data while your account and brands exist. Beyond that we apply retention limits so personal data isn't kept longer than needed:
- Audit and security logs: up to 12 months.
- Public content-view analytics (visitor IP/agent): up to 90 days.
- Support-chat logs: up to 6 months (visitor IPs are stored hashed, not raw).
- Billing and credit records: retained for as long as accounting and tax law require, in pseudonymized form after account deletion.
Deletion and your billing records
When you delete your account we remove your identifying data (name, email, profile photo and login identifiers) and delete your brands and their content. We keep the financial and credit records tied to past purchases, but pseudonymized so they can no longer identify you, because we are legally required to retain accounting records. This is expressly allowed under the GDPR's erasure rules.
Good to know
This guide explains how BrandOps9 is designed to support your compliance; it is not legal advice, and your own obligations depend on how you use the service. If GDPR compliance is critical for your organisation, have your own counsel review your usage and ask us for a Data Processing Agreement.
