Legal

Data Processing Agreement

This agreement applies automatically the moment you accept our Terms of Service. It is already in force for every Operelio customer, including those on the Free plan. You do not need to email us for a copy, and there is no signature step.

Last updated 6 August 2026

The short version

When you upload a file, you decide what happens to the personal data in it. We only do what you ask. That makes you the controller and us the processor.

Your files are stored in the EU and processed in the Netherlands. They do not leave the UK and the EU.

We use a small number of sub-processors, all listed publicly. We give you 14 days notice before adding or replacing one.

If there is a breach affecting your data, we tell you without undue delay and give you what you need for your own reporting.

The sections below are the binding terms. This summary is not.

1. How this agreement applies

This Data Processing Agreement (the "DPA") forms part of the agreement between Operelio Ltd, a company registered in England and Wales under number 17343466 with registered office at 66 Paul Street, London EC2A 4NA ("Operelio", "we", "us"), and the person or organization that accepts the Operelio Terms of Service (the "Customer", "you").

It becomes legally binding when you accept the Terms of Service, which happens when you create an account. No signature is required and nothing needs to be countersigned. If your procurement process requires a countersigned copy, email hello@operelio.com and we will provide one.

Terms defined in the Terms of Service have the same meaning here. "Data Protection Law" means the UK GDPR and the Data Protection Act 2018, the EU GDPR where it applies, and the Privacy and Electronic Communications Regulations 2003, each as amended.

2. Roles of the parties

Your files. For personal data contained in files you upload, you are the controller and Operelio is your processor. You decide what to upload, why, and what to do with the result.

Your account. For personal data about you and your team, such as names, email addresses, billing details and how you use the product, Operelio is an independent controller. That processing is described in our Privacy Policy and is not governed by this DPA.

If you are yourself a processor. Where you process personal data on behalf of your own clients, for example as an agency, you act as processor and Operelio acts as your sub-processor. This DPA applies on that basis, and you are responsible for having the necessary authority from your client.

You confirm that you have a lawful basis for the personal data you upload, that you have given any notices and obtained any consents required, and that your instructions to us will not put us in breach of Data Protection Law.

3. Our instructions

We process personal data in your files only on your documented instructions. Your use of the platform, including the tools you run and the integrations you connect, constitutes those instructions. This DPA and the Terms of Service are the complete set.

We will not process your data for our own purposes, with one narrow exception stated openly in clause 6.4: the verification result cache. We will never sell or license your data, and we will never use it to train machine learning models.

If we are required by law to process your data beyond your instructions, we will tell you before doing so unless the law prohibits it. If we believe an instruction from you would breach Data Protection Law, we will tell you promptly.

4. Confidentiality

We treat your data as confidential. Anyone we authorize to process it is subject to a duty of confidentiality and is given access only to the extent their role requires.

5. Security

We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Those measures are summarized in Annex C and described in more detail on our security page.

We may update our security measures over time. We will not make a change that materially reduces the overall level of protection.

6. Sub-processors

6.1 You give us general written authorization to engage sub-processors. The complete, current list is published at operelio.com/subprocessors, which forms Annex B to this DPA.

6.2 We will notify you by email at least 14 days before a new sub-processor starts processing your data, or before we replace an existing one. You may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected part of the service without penalty, and we will refund any prepaid fees for the unused period.

6.3 We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance.

6.4 Email verification result cache. We keep a short-lived operational cache of email verification results, so that an address checked anywhere on Operelio in the last 7 days is not paid for and checked again. The detail matters, because this is the one place where processing is not scoped to a single customer. Each entry is keyed by a one-way hash of the address, so the cache holds no plain-text addresses, and contains only the verification outcome: the status, the confidence score, the reason, and which provider produced it. It contains no name, no company, no file reference, no workspace reference and no account reference. Entries expire automatically within 7 days. Because entries are not linked to any customer, a result produced while processing one customer's file may be reused when processing another's. The underlying address is deleted with the rest of your file at the end of your retention window.

Because the cache serves every customer rather than any one customer's instructions, Operelio operates it as a controller in its own right (Article 28(10) UK GDPR). Our lawful basis is legitimate interest (Article 6(1)(f)): keeping the cost of verification down for us and, through pricing, for customers, using the least data that makes that possible. The corresponding public notice is in our Privacy Policy.

6.5 The AI assistant. When you use Bridgeant, we send our AI provider a structural summary of your file: the column headers, how full each column is, the row and column counts, and the quality issues found. We also send the message you typed, and the names of your files, sheets and any saved workflows, mappings or schemas the conversation refers to. Names you choose can themselves contain personal data, so choose them accordingly. We do not send the values in your cells or any of your rows. This is enforced in code by a whitelist that assembles the summary and a second check that rejects the request if raw data is present. You can view the exact summary sent for any given reply inside the product.

7. International transfers

7.1 Files you upload are stored in the European Union and processed in the Netherlands. They are not transferred outside the UK and the EU. The structural summary described in clause 6.5 is the one payload derived from a file that is sent further, never the file itself.

7.2 Some sub-processors that support the service are established in the United States. Where personal data reaches one of them, the transfer is made on one of the following bases, identified per recipient on our sub-processor page:

  • the recipient's active certification under the EU-US Data Privacy Framework and the UK Extension to it; or
  • the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two or Module Three as applicable, amended by the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018 where the transfer is subject to the UK GDPR.

7.3 Where the Standard Contractual Clauses apply they are incorporated into this DPA by reference and are deemed entered into by both parties. Annex A supplies the information required by Annex I of those Clauses, Annex B identifies the sub-processors, and Annex C supplies the information required by Annex II. The optional docking clause does not apply. For Clause 9, Option 2 (general written authorization) applies, with the time period set out in clause 6.2 of this DPA.

Where the Clauses are amended by the UK Addendum, they are governed by the law of England and Wales and disputes are resolved in the courts of England and Wales. Where the EU Standard Contractual Clauses apply without the UK Addendum, Clause 17 Option 1 applies with the law of Ireland, and under Clause 18 disputes are resolved in the courts of Ireland.

7.4 If a transfer mechanism we rely on ceases to be valid, we will implement an alternative that satisfies Data Protection Law, or cease the affected transfer.

8. Personal data breaches

If we become aware of a personal data breach affecting personal data we process for you, we will notify you without undue delay and in any event within 72 hours of becoming aware of it.

The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of that at once, we will provide it in phases without undue further delay.

We will assist you with your own obligations to notify a supervisory authority or affected individuals. Notifying you is not an admission of fault or liability.

9. Assisting you

Taking into account the nature of the processing, we will assist you with requests from individuals exercising their rights of access, rectification, erasure, restriction, portability and objection. Most of what you need is available to you directly in the product. If we receive such a request relating to your data, we will direct the individual to you rather than responding ourselves.

We will also provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority, to the extent these relate to our processing and you cannot obtain the information yourself.

10. Audits

We will make available the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and allow for audits by you or an independent auditor you appoint.

In the first instance we will answer written questions in writing, and point you to the technical and organizational measures set out in Annex C and on our security page. Where that is genuinely insufficient, an on-site or remote audit may be conducted on reasonable written notice, no more than once in any 12 months unless required by a supervisory authority or following a personal data breach, during business hours, subject to confidentiality, and without compromising the security or confidentiality of other customers' data. You bear your own costs and our reasonable costs of supporting an audit that goes beyond answering written questions.

11. Deletion and return

Files are deleted automatically at the end of the retention window for your plan, as set out in Annex A. You can delete a file yourself at any time.

When your account closes, we delete the personal data we process for you. Your files are deleted, and so is everything taken from them: what you typed into a tool, the summaries a tool produced, and any content quoted back in a result or an error.

Two things are kept. Records the law requires us to hold, such as transaction records kept for tax purposes. And a stripped record of each job (the tool used, the date, how long it took and how many rows warned or errored) which we keep for 2 years as proof of the service provided, in case a payment is disputed. That record carries no personal data belonging to your data subjects, because everything drawn from your files is removed before it is kept. Anything retained remains subject to this DPA for as long as we hold it.

Download anything you want to keep before closing your account; once deletion has run we cannot recover it. If you would rather have your data returned, ask us before you close and we will provide a copy of the personal data we process for you before it is deleted.

12. Liability, conflicts and law

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

If there is a conflict, the order of precedence is: the Standard Contractual Clauses where they apply, then this DPA, then the Terms of Service, then the Privacy Policy.

This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except where the Standard Contractual Clauses require otherwise.

We may update this DPA where necessary to reflect a change in law, a change in our sub-processors, or a change to the service. We will give at least 30 days notice of any material change, and we will not make a change that materially reduces your protection.

Annex A

Details of processing

This annex supplies the information required by Annex I of the Standard Contractual Clauses where they apply.

Subject matter

Providing the Operelio platform: cleaning, transforming, validating and formatting spreadsheet data, and pushing it to a CRM the Customer connects.

Duration

For as long as the Customer has an account, plus the retention window applicable to their plan. Processing of any individual file ends when that file is deleted.

Nature and purpose

Automated processing of files the Customer uploads, in accordance with the tools and settings the Customer chooses. Operelio does not determine the purposes of that processing.

Categories of data subjects

The individuals whose records appear in files the Customer uploads. Typically business contacts: the Customer's own customers, prospects and suppliers.

Categories of personal data

Whatever the Customer chooses to upload. Typically names, business email addresses, telephone numbers, job titles, employer names and company details. Operelio does not require any particular field.

Special category data

None. The Terms of Service prohibit uploading special category data, and Operelio's tools are not designed to process it.

Frequency of transfer

Continuous, for the duration of the agreement.

Retention

Files are deleted 24 hours after processing on the Free plan, after 30 days on Pro and Team, and after 90 days on Agency. Files the Customer stars are kept until the Customer deletes them.

Competent supervisory authority

The Information Commissioner's Office (United Kingdom). For transfers subject to the EU GDPR, the supervisory authority determined in accordance with Clause 13 of the Standard Contractual Clauses.

Annex B

Parties and sub-processors

How the Clauses attach. The transfer from you to Operelio is not a restricted transfer: your files are stored and processed in the UK and the EU. The Standard Contractual Clauses attach to onward transfers. For those, the data exporter is Operelio Ltd, 66 Paul Street, London EC2A 4NA, United Kingdom (contact: hello@operelio.com), acting as processor on your behalf, and the data importer is the sub-processor receiving the data.

Sub-processors. The complete and current list, including what each one receives, where it is established, and the transfer basis for any recipient outside the UK and EEA, is published at operelio.com/subprocessors. That page forms part of this annex. It is kept there rather than reproduced here so that there is one authoritative list, and so that the 14 days notice in clause 6.2 attaches to a page you can check at any time.

Signature is not required. Execution of the Terms of Service by both parties constitutes execution of this DPA and, where they apply, of the Standard Contractual Clauses including their annexes.

Annex C

Technical and organizational measures

This annex supplies the information required by Annex II of the Standard Contractual Clauses where they apply.

Location of processing

Customer files are stored in the European Union and processed in the Netherlands. The application and database run in the United Kingdom. Files are not processed or stored outside the UK and the EU.

Encryption in transit

TLS 1.2 or higher on every connection. Plain HTTP is redirected to HTTPS before anything is processed.

Encryption at rest

Files and database records are encrypted at rest by the providers that store them. CRM access tokens are additionally encrypted with AES-256-GCM using a key held separately from the database.

Access control

Every file, job and setting is scoped to a workspace, and ownership is checked on every request. Within a workspace, roles are admin or member. Operelio operates no internal tool for browsing Customer files.

Authentication

Sign-in is provided by Clerk, supporting social sign-in and multi-factor authentication. API keys are hashed before storage, displayed once, and rate limited.

Network protection

A managed firewall sits in front of the application with always-on DDoS mitigation, and automated traffic is monitored.

Resilience

The database supports point-in-time restore covering the previous seven days. Customer files are temporary by design and are not archived.

Segregation

Data is separated by workspace. On the Agency plan, each client workspace is separated from every other.

Personnel

Access to production systems is limited to the people who maintain them, and there is no internal tool that lets anyone browse customer files.

Incident response

Automated alerting on operational failures, provider platform monitoring, and a published status page. Incidents are investigated for root cause, not just symptom. See clause 8 for notification obligations.

Need something for your legal team?

We are happy to answer questions on this agreement, provide a countersigned copy, or complete a security questionnaire.

Operelio Ltd is registered in England and Wales, company number 17343466. Registered office: 66 Paul Street, London EC2A 4NA.