Privacy Policy

Last updated 20 July 2026 · This is a template pending legal review.

This policy explains what personal data Deplyra processes, why, and the rights you have under the UK GDPR and EU GDPR. OpsCores is a multi-tenant platform; your organisation is the controller of the data it puts into OpsCores, and Deplyra is the processor.

Data we process

Account data (name, work email), organisation and site data you enter, attendance records (including optional selfies and location at check-in), form submissions, and special-category data you choose to store (e.g. induction health questionnaires) which is held in an encrypted, access-logged vault.

Lawful bases

We process personal data to perform our contract with your organisation, for our legitimate interests in operating and securing the service, and, for special-category data, on the basis your organisation establishes (typically employment and health-and-safety obligations).

Retention

Records are retained for as long as your organisation requires them for compliance (commonly 12 months to 6 years depending on record type), then deleted on request. We never delete your data automatically on downgrade, features simply lock.

Your rights

You may request access, rectification, erasure, restriction, portability and objection. Requests are handled through your organisation’s admin, with tooling for export and deletion built in.

Sub-processors & residency

We host on Supabase/Postgres with regional data-residency options for Enterprise. A current list of sub-processors is available on request.

Security

Row-level tenant isolation, encryption in transit and at rest, an append-only audit log, and role-restricted access to special-category data.

Contact

Data protection enquiries: help@deplyra.com.