BrandOps9
Back to BrandOps9

BrandOps9 document

Privacy Policy

Last updated September 24, 2026

This Privacy Policy explains the core data BrandOps9 uses to run authenticated brand workspaces and AI content workflows.

Data we process

BrandOps9 stores account information, workspace membership, extracted brand details, campaign briefs, generated assets, schedules, integrations, credit balances and audit events. Before public access opens, a waiting-list request contains your name, email, confirmation and consent timestamps, optional marketing choice, and limited first-touch campaign information (source, medium, campaign and landing page).

How data is used

Data is used to manage requested early access, authenticate users, separate tenant workspaces, generate content, operate scheduling and integrations, measure credit usage, troubleshoot issues and improve product reliability. Waiting-list confirmation and access messages are necessary to take steps at your request before providing the service. Optional product and marketing email is sent only with separate consent, which you can withdraw at any time. We process workspace data to perform our contract with you and on the basis of our legitimate interest in operating and securing the service.

Sub-processors

To deliver the service we use vetted sub-processors: OpenAI and (where you enable video) RunwayML for content generation; Google, Meta, LinkedIn and X when you connect those accounts; Stripe for payments; and SendPulse for transactional email. Content sent to the AI providers is used only to produce your requested output and is not used to train their models. The full list, with purpose, data categories and region, is on our Sub-processors page, and platform-specific data is exchanged according to the permissions you grant.

International transfers

Some sub-processors are located outside the EEA (for example the United States), so generation, authentication, payments and email may transfer data there under appropriate safeguards such as Standard Contractual Clauses. A Data Processing Agreement is available on request.

Retention and deletion

Unconfirmed waiting-list requests are removed after 7 days. Requests that are still waiting are removed 90 days after public registration opens; you can withdraw immediately from the link in a waiting-list email. Workspace data remains available while your account and brands exist. Audit/security logs are kept up to 12 months, public content-view analytics up to 90 days and support-chat logs up to 6 months (visitor IPs stored hashed). Deleting a brand removes its generated assets and schedules. When you delete your account we remove your identifying data and brands, while billing and credit records are retained in pseudonymized form where accounting and tax law require it.

Your controls and rights

You can request access, correction, export, deletion, restriction of, or objection to processing by emailing contact@brandops9.com; we respond within 30 days. Waiting-list emails include a signed link to change optional marketing consent or withdraw and remove the request. Active accounts provide self-service export and deletion. Administrators can support users, manage accounts and investigate security or operational issues through audited workflows.