Security

Your data stays yours.

Operelio handles spreadsheets that contain real customer records, pipeline numbers and contact details. Every part of the platform is built around that responsibility, and all of it runs inside the UK and the EU.

Last updated 6 August 2026

Where it runs

Everything stays in the UK and the EU

Your files never leave the UK and the EU. That is not a preference or a best effort, it is how the platform is configured. The one thing derived from a file that goes further is Bridgeant's structural summary, described in the AI operator section below: headers and counts, never your rows or cell values.

The website and the app: run on Vercel in London.

The database: runs on Neon in London.

Your files: stored in Cloudflare R2, in a bucket restricted to the European Union. R2 jurisdictions are a hard limit, not a routing hint.

Processing: runs on a worker in Amsterdam.

Some of the services we use to run Operelio are US companies. Our sign-in and payment providers receive account and billing details, never your files, and where a US-owned provider hosts our infrastructure, the service itself runs in the UK and the EU. Our sub-processor page names every one, says exactly what it receives, and gives the legal basis for each transfer.

Protection at the edge. Vercel's firewall sits in front of the application with always-on DDoS mitigation, and automated traffic that does not behave like a real browser is monitored. Verified search engine crawlers are excluded, so this never gets in the way of legitimate access.

Recovery. The database supports point-in-time restore, so we can roll it back to any moment in the previous seven days. Your files themselves are temporary by design and are not archived, which is why you should download anything you need to keep.

Encryption

Encrypted in transit and at rest

Every connection to Operelio is encrypted with TLS 1.2 or higher. Plain HTTP is never served: requests are redirected to HTTPS before anything is processed.

Your files and your database records are encrypted at rest by the providers that store them. Uploaded files are scoped to your workspace and are not reachable from any other account.

CRM credentials get extra treatment. When you connect HubSpot, Salesforce or Pipedrive, the access tokens are encrypted with AES-256-GCM before they are stored, using a key held separately from the database. They are never written to logs, never shown in the product after setup, and deleted immediately when you disconnect.

API keys. Keys you create for the public API are hashed before storage, shown to you once at the moment of creation, and rate limited.

Billing is handled entirely by Stripe, a PCI Level 1 certified payment provider. Card details are entered directly into Stripe's forms, tokenized, and never transmitted through or stored on our servers. We receive only limited payment metadata from Stripe, such as the card type, the last four digits and the expiry date, and never your full card number or CVV.

Access

Who can reach your files

Every file, job and setting belongs to a workspace. The application checks that ownership on every request, so one account cannot reach another account's data even if it knows the identifier.

Inside a workspace, members are either admins or members. Admins manage billing, team and integrations. Members do the work. Agency client workspaces are separated the same way, so one client's data never appears inside another's.

There is no internal tool that lets our team browse customer files. Access to production systems is limited to the people who maintain them, and is used for operating the service rather than reading your data.

Sign-in is handled by Clerk, which supports social sign-in and multi-factor authentication.

Privacy

We don't monetize your data

Your spreadsheets, your CRM credentials and your processing history are yours. We will never sell, rent or share your data with advertisers or data brokers.

Your files will never be used to train machine learning models. We collect the minimum needed to run the service: your account details, the files you upload, and the settings you choose.

What we do run. We use one analytics product, PostHog, hosted in the EU and configured to store nothing on your device. It tells us which features get used and where errors happen. Session recordings are captured only on the marketing site, never inside the product, so nothing you do with your files is ever recorded. We also run a chat widget so you can reach us. There are no advertising pixels, no retargeting scripts and no social media trackers anywhere on Operelio.

Full detail is in our privacy policy, written without the legalese.

AI operator

The AI sees a summary, never your data

Operelio includes Bridgeant, an assistant you can ask to clean a file or get it ready for your CRM. To plan that work it sends an AI model a summary of your file: the column headers, how full each column is, the row and column counts, and the quality issues found in the data. Your actual cell values and your rows never go to the model.

The model is provided by OpenAI. What reaches it is the summary above, the message you typed, the names of your files, sheets and saved workflows, and the list of actions Bridgeant can take. Your cell values and your rows never leave your workspace, and your files are never used to train a model.

This is built into the code, not left to a policy. The summary is assembled by one function that can only pass through headers and counts, and a second check rejects the request if any raw data has found its way in.

This is verifiable in the product. Under any Bridgeant reply, open “What did Bridgeant see?” to view the exact summary sent for that turn, down to each column header and count, alongside a plain statement of what was not sent.

Compliance

Where we stand

GDPR and UK GDPR. We have a lawful basis for everything we process, set out in our privacy policy. We honor data subject rights and follow the 72-hour breach notification requirement. We are registered with the Information Commissioner's Office.

Data Protection Officer. Article 37 of the UK GDPR does not require a company like ours to appoint one, and we have not. Data protection questions go to hello@operelio.com and reach the people who run the platform directly.

CCPA and CPRA. California residents can request access to or deletion of their personal data. We do not sell personal information.

Data residency. Files are created, stored and processed inside the UK and the EU.

Data Processing Agreement. Ours is at operelio.com/dpa. It applies automatically when you accept our Terms of Service, so there is nothing to request and nothing to sign. It incorporates the transfer terms for every sub-processor outside the UK and EEA.

We complete vendor security questionnaires. Email yours to hello@operelio.com and we will send it back completed.

Lawful basis

Who is responsible for what

When you upload a file, two lawful-processing questions apply. Whether you have a lawful basis to process the personal data in that file is yours to answer. What we are allowed to do with it is ours. This section explains the split.

Your basis to upload. In practice this is usually consent, a contractual relationship, or legitimate interest. The Operelio Terms of Service require you to warrant that you have a lawful basis for every file you upload. We do not ask you to prove it.

Our basis to process. We process your file as your data processor, on your instructions, under our Data Processing Agreement. For the Email Verifier & Finder, that processing is a quality check: we confirm whether an inbox accepts mail, using EU-based providers. If you ask Operelio to recover missing or failed addresses, it rebuilds them only from the email patterns already in your own file, never from an outside contact database, and we never sell or rent your list.

What is shared, and what never is. One thing is shared across customers, and it is worth being precise about: when an address has already been verified anywhere on Operelio in the last 7 days, we reuse that verdict rather than re-checking it. That record holds a one-way hash of the address and the verification outcome: the status, the score, the reason and which provider produced it. No name, no company, no file, no account, and it expires within 7 days. Everything else, your list, your columns, your uploaded send results, stays scoped to your own workspace, and your bounce history only ever tunes your own workspace's scoring.

Where Operelio does not help. Verification is not a consent check. If you upload a list you scraped from the web or bought from a source with no documented consent chain, we will verify which addresses accept mail. We cannot tell you whether you have permission to send to them. That is on you. Every paid plan includes a Do Not Contact list you can suppress against as an additional safeguard, but even that will not replace your own basis to process.

Full details on our role as your processor are in the privacy policy and the Data Processing Agreement. Email hello@operelio.com if your legal team needs to review.

Suppression

Do Not Contact list

For teams that need to honor suppression requests under CAN-SPAM, GDPR, CASL or PECR, every paid plan includes a workspace-scoped Do Not Contact list. Upload your suppression file once, with emails, phone numbers, domains or company names, and Operelio applies it automatically to your CRM pushes and workflow exports. Matching runs on your data inside your account, costs no credits, and never calls an outside service.

You can also block by country: pick countries individually, select a whole region at once, or use the one-click Sanctioned preset, which covers the comprehensively sanctioned countries (Cuba, Iran, North Korea, Russia and Syria). The preset is a convenience, not a substitute for formal sanctions screening.

Health Check flags suppressed rows so you can review them, and the Email Verifier can optionally remove them from a verified list. Free plans do not include the suppression list. Starter stores up to 5,000 entries, Pro up to 25,000, and Agency up to 100,000.

Incident response

If something goes wrong

Problems reach us through user reports, the security contact below, and automated alerts we run on our own systems for operational failures. Underneath that, the providers who host the app, the database and your files run their own platform monitoring. When something is flagged we assess scope and severity, isolate the issue, and begin remediation. Affected customers are notified directly.

For confirmed breaches involving personal data we follow GDPR Articles 33 and 34: notification to the relevant authority within 72 hours where the breach is likely to put people at risk, and direct communication to the people affected where that risk is high, describing what happened, what data was involved, and what we are doing about it.

After an incident we look for the root cause rather than just the symptom, and close the gap before we consider the matter resolved.

You can check current service status any time at operelio.com/status.

Responsible disclosure

Reporting a vulnerability

If you discover a vulnerability, email security@operelio.com with details of the issue. Please do not disclose it publicly until we have had time to investigate and patch.

We will acknowledge your report, investigate it, and keep you updated until the issue is resolved. Critical vulnerabilities take priority over everything else we are working on.

Questions about security?

We are happy to walk through our practices, answer questions in writing, or complete your vendor security questionnaire.

This page describes our current security practices. No security measure is completely effective.