Privacy Policy
OpsHero Tools - opshero.tools
Version 1.0 - Effective 20 May 2026
1. Introduction
1.1 This Privacy Policy explains how OpsHero OOD, UIC 202862235, with registered office at Sinanishko ezero 9A str., 1680 Sofia, Bulgaria ("OpsHero", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data in connection with the OpsHero Tools platform available at opshero.tools (the "Platform").
1.2 OpsHero is the controller of the personal data described in this Privacy Policy within the meaning of Regulation (EU) 2016/679 (the "GDPR").
1.3 This Privacy Policy applies to all visitors and users of the Platform (collectively, "you" or the "User"). It should be read together with the OpsHero Tools Terms of Service and the Mutual Non-Disclosure Agreement.
1.4 The Platform is intended for users aged 18 or over. We do not knowingly collect personal data from individuals under 18 years of age.
2. Privacy contact
2.1 OpsHero has not appointed a formal Data Protection Officer under Article 37 GDPR, as the criteria for mandatory appointment do not apply to our processing activities. However, we have designated the following privacy contact for all data protection matters:
Privacy contact: Borislav Borislavov
Email: [email protected]
You may also contact us at:
- General privacy inquiries: [email protected]
- Postal address: OpsHero OOD, Sinanishko ezero 9A str., 1680 Sofia, Bulgaria
3. Personal data we collect
3.1 Data you provide
When you access the Platform, we collect the following personal data:
| Category | Data collected | Purpose |
|---|---|---|
| Identification | Full name | Identify users of the Platform, enforce the NDA |
| Contact | Email address | Communicate with you about your use of the Platform, deliver confirmation of NDA acceptance |
| Professional | Job role | Understand our user base and tailor Tool relevance |
3.2 Submitted data (configuration files)
You may upload configuration files to the Tools (such as Terraform code, Kubernetes manifests, CI/CD pipeline definitions). The Mutual NDA and the Terms of Service require that such files do not contain personal data of third parties or sensitive credentials. Where such files are processed:
- For some Tools, processing occurs entirely within your browser (client-side). In that case, the files are never transmitted to OpsHero's servers.
- For other Tools, processing occurs on OpsHero's servers (server-side). In that case, files are transmitted, processed, and deleted in accordance with the Mutual NDA.
The Platform indicates the execution model for each Tool.
3.3 Acceptance and audit logs
When you accept our legal agreements (NDA, Terms of Service, Privacy Policy), we record:
- The date and time of acceptance (UTC)
- Your IP address at the time of acceptance
- Your user-agent string (browser and operating system)
- The version of each document accepted
- A cryptographic hash of the accepted text
This information serves as evidence of acceptance and is retained for legal defence purposes.
3.4 Data collected automatically
When you visit the Platform, certain data is collected automatically:
- Strictly necessary data: IP address, browser type and version, operating system, referring URL, pages visited, session identifiers, time and date of visit, error logs.
- Data collected via cookies and similar technologies: see Section 8.
3.5 Marketing data
If you opt in to receive marketing communications from OpsHero (by ticking a separate, non-pre-ticked checkbox at the time of signup, or by subscribing through other channels), we additionally process:
- Your email address for delivery of communications
- Engagement metrics (opens, clicks) for measuring campaign effectiveness
- Preferences (topics, frequency) you may indicate
4. Purposes and lawful bases of processing
We process your personal data for the following purposes, each with a specific lawful basis under Article 6 GDPR:
| # | Purpose | Lawful basis | Notes |
|---|---|---|---|
| 1 | Providing access to the Tools | Legitimate interest (Art. 6(1)(f)) | We have a legitimate interest in identifying users of our Platform for abuse prevention, audit trail, and enforcement of the NDA. A Legitimate Interest Assessment has been documented. |
| 2 | Processing Submitted Data to generate Outputs | Legitimate interest (Art. 6(1)(f)) | The processing is necessary to deliver the Tool functionality you have requested. |
| 3 | Maintaining acceptance and audit logs | Legitimate interest (Art. 6(1)(f)) | Necessary for defence of legal claims, regulatory compliance, and proof of contractual acceptance. |
| 4 | Operational security (IP logging, abuse prevention, fraud detection) | Legitimate interest (Art. 6(1)(f)) | Necessary to protect the Platform and other users. |
| 5 | Service-related communications (security notices, material changes to legal documents) | Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) where applicable | We may need to notify you of important changes affecting your rights or the security of the service. |
| 6 | Sending marketing communications | Consent (Art. 6(1)(a)) | Only with your explicit, prior, opt-in consent. Withdrawable at any time. |
| 7 | Analytics, session replay, and marketing pixels | Consent (Art. 6(1)(a)) | Only with your consent through the cookie banner. |
| 8 | Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) | E.g. responding to lawful requests from authorities. |
| 9 | Defending legal claims and enforcing agreements | Legitimate interest (Art. 6(1)(f)) | Necessary for legal defence and enforcement of the NDA and Terms of Service. |
4.1 Legitimate interest assessment
Where we rely on legitimate interest, we have balanced our interests against your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 9). If you object, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests or the processing is necessary for the establishment, exercise, or defence of legal claims.
5. Who we share your data with
We do not sell your personal data. We share it only with the following categories of recipients:
5.1 Service providers (processors)
| Recipient | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| EU-based hosting provider for opshero.tools | Hosting the Platform infrastructure | EU data centre | N/A (within EEA) |
| Transactional email provider | Delivering acceptance confirmations and service-related emails | EU (or covered by SCCs if non-EU) | EU SCCs where applicable |
| Analytics provider (Google Analytics or equivalent) | Website analytics, only with your consent | USA / global | EU SCCs + supplementary measures |
| Session replay / heatmap provider | Understanding user behaviour, only with your consent | USA / global | EU SCCs + supplementary measures |
| LinkedIn (LinkedIn Ireland Unlimited Company) | Marketing pixel for advertising effectiveness, only with your consent | EU (LinkedIn Ireland) with processing in USA | EU SCCs + LinkedIn DPA |
The processors and sub-processors we currently rely on are listed in the table above. To request the most up-to-date list, or to be notified of changes, contact us at [email protected].
5.2 Marketing tools (only with your consent)
If you opt in to marketing communications, your data may additionally be processed by LinkedIn Marketing Solutions for the purpose of audience targeting and campaign measurement. LinkedIn's processing is governed by LinkedIn's own privacy policy at linkedin.com/legal/privacy-policy.
5.3 Legal and regulatory disclosures
We may disclose personal data:
- To competent authorities where required by law, court order, or regulatory request;
- To enforce our Terms of Service or Mutual NDA;
- To establish, exercise, or defend legal claims;
- To prevent fraud, abuse, or threats to the security of the Platform.
5.4 Business transfers
If OpsHero is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality obligations and continued application of this Privacy Policy or an equivalent successor policy.
5.5 With your explicit consent
We may share your personal data with other recipients with your explicit consent or at your direction.
6. International transfers
6.1 OpsHero is based in Bulgaria. The Platform infrastructure is hosted within the European Economic Area (EEA).
6.2 However, certain service providers - particularly analytics, session replay, marketing pixel, and similar providers - process personal data outside the EEA, primarily in the United States.
6.3 Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, including:
- EU Standard Contractual Clauses (SCCs) as adopted by Commission Implementing Decision (EU) 2021/914;
- EU-U.S. Data Privacy Framework where the recipient is certified;
- Adequacy decisions where issued by the European Commission;
- Supplementary technical and organisational measures such as encryption in transit and at rest.
6.4 You may request a copy of the relevant transfer safeguards by contacting us at [email protected].
6.5 Note that analytics, session replay, and marketing pixel providers only receive your data if you consent through the cookie banner. If you do not consent, no international transfer of your data takes place through these tools.
7. Retention periods
We retain personal data only for as long as necessary for the purposes described in this Privacy Policy. Specific retention periods are as follows:
| Data category | Retention period | Reason |
|---|---|---|
| Name, email, job role (signup data) | 5 years from last interaction | Aligned with NDA term (2 years) + survival period (3 years); defence of legal claims |
| Acceptance and audit logs (NDA, ToS, Privacy Policy) | 5 years from acceptance | Evidence of contractual acceptance; defence of legal claims |
| Submitted Data (server-side processed) | Deleted promptly after Output generation, in no case longer than 30 days | As committed in Section 4.1(a) of the Mutual NDA |
| Submitted Data (client-side processed) | Not retained by OpsHero (processed in your browser) | N/A |
| Marketing data (if you opted in) | Until you withdraw consent or 2 years of inactivity, whichever is earlier | Marketing consent is event-based and revocable |
| Cookie-based data (analytics, session replay, pixels) | As set in the cookie banner, typically 6–24 months | Aligned with cookie expiration and consent validity |
| Server logs (IP, user-agent, errors) | 90 days | Security monitoring and abuse prevention |
| Data required by law (tax, bookkeeping, etc.) | As required by applicable Bulgarian law (typically 5–10 years) | Legal obligation |
After the retention period expires, personal data is securely deleted or anonymised.
8. Cookies and similar technologies
8.1 What are cookies
Cookies are small text files placed on your device when you visit a website. We also use similar technologies such as local storage, pixels, and scripts.
8.2 Categories of cookies we use
| Category | Purpose | Consent required | Examples |
|---|---|---|---|
| Strictly necessary | Enable core Platform functionality (session, security, language preference) | No (exempt under ePrivacy) | Session ID, CSRF token, cookie consent record |
| Analytics | Measure how visitors use the Platform | Yes (opt-in) | Google Analytics |
| Session replay / heatmaps | Understand user behaviour and improve UX | Yes (opt-in) | Session replay tool |
| Marketing / advertising | Measure advertising effectiveness, deliver targeted ads | Yes (opt-in) | LinkedIn Insight Tag |
8.3 Your cookie choices
When you first visit the Platform, you will be presented with a cookie consent banner that allows you to:
- Accept all cookies
- Reject all non-essential cookies
- Customise your preferences by category
You can change your preferences at any time by clicking the "Cookie Settings" link in the Platform footer.
Rejecting non-essential cookies will not prevent you from using the Platform or the Tools, but some features (such as personalised content or interaction analytics) may not work as designed.
8.4 Do Not Track
We currently respond to browser "Do Not Track" signals by treating them as a request to disable non-essential cookies, equivalent to rejecting all non-essential cookies in our consent banner.
8.5 More information
A detailed Cookie Policy with the full list of cookies used, their purposes, durations, and third-party recipients is available on this site.
9. Your rights under GDPR
As a data subject, you have the following rights under the GDPR:
9.1 Right of access (Article 15)
You may request confirmation of whether we process your personal data, and if so, a copy of that data along with information about the processing.
9.2 Right to rectification (Article 16)
You may request correction of inaccurate personal data or completion of incomplete data.
9.3 Right to erasure (Article 17)
You may request deletion of your personal data where one of the grounds in Article 17 applies (e.g. data no longer necessary, withdrawal of consent, objection without overriding legitimate interest).
9.4 Right to restriction of processing (Article 18)
You may request that we restrict processing of your personal data in certain circumstances.
9.5 Right to data portability (Article 20)
For data processed on the basis of consent or contract and by automated means, you may receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
9.6 Right to object (Article 21)
You may object at any time to processing based on legitimate interest, including profiling. You may also object at any time to processing for direct marketing purposes.
9.7 Right to withdraw consent (Article 7(3))
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
9.8 Right not to be subject to automated decision-making (Article 22)
We do not currently engage in automated decision-making with legal or similarly significant effects. The Outputs generated by the Tools are advisory in nature and do not constitute automated decisions about you.
9.9 Right to lodge a complaint (Article 77)
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
For users in Bulgaria, the supervisory authority is:
Commission for Personal Data Protection (Комисия за защита на личните данни - КЗЛД)
- Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
- Email: [email protected]
- Website: www.cpdp.bg
You may also lodge a complaint with the supervisory authority in your own EU Member State.
9.10 How to exercise your rights
To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving your request (extendable by two further months for complex requests, in which case we will notify you of the extension). There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive.
We may need to verify your identity before responding to certain requests. We will only request information necessary to confirm your identity.
10. Security
10.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit (TLS 1.2 or higher) for all communications with the Platform
- Encryption at rest for stored personal data, where technically feasible
- Role-based access control with multi-factor authentication for administrative access
- Logging and monitoring of access to personal data
- Regular vulnerability scanning and security testing
- Incident response procedures
- Personnel confidentiality obligations and security awareness training
10.2 No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
10.3 Data Breach Notification. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
11. Third-party websites
11.1 The Platform may contain links to third-party websites (e.g. LinkedIn, documentation sites, partner sites). This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party site you visit.
12. Changes to this Privacy Policy
12.1 We may update this Privacy Policy from time to time. The current version is identified by version number and effective date at the top of the document.
12.2 Material changes will be communicated by reasonable means, which may include a notice on the Platform or an email to the address you provided. Material changes will take effect no earlier than thirty (30) days after notice.
12.3 Previous versions of this Privacy Policy are available upon request to [email protected].
13. Governing law
13.1 This Privacy Policy is governed by the laws of the Republic of Bulgaria and applicable EU data protection law, including the GDPR.
13.2 Nothing in this Privacy Policy limits your rights under the GDPR or other mandatory data protection law.
14. Contact us
For any questions, requests, or concerns regarding this Privacy Policy or our processing of your personal data:
OpsHero OOD
Sinanishko ezero 9A str.
1680 Sofia, Bulgaria
UIC: 202862235
- Privacy contact: Borislav Borislavov - [email protected]
- General privacy inquiries: [email protected]
- Legal inquiries: [email protected]
- Abuse / security reports: [email protected]