Privacy Policy

OpsHero Tools - opshero.tools

Version 1.0 - Effective 20 May 2026

1. Introduction

1.1 This Privacy Policy explains how OpsHero OOD, UIC 202862235, with registered office at Sinanishko ezero 9A str., 1680 Sofia, Bulgaria ("OpsHero", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data in connection with the OpsHero Tools platform available at opshero.tools (the "Platform").

1.2 OpsHero is the controller of the personal data described in this Privacy Policy within the meaning of Regulation (EU) 2016/679 (the "GDPR").

1.3 This Privacy Policy applies to all visitors and users of the Platform (collectively, "you" or the "User"). It should be read together with the OpsHero Tools Terms of Service and the Mutual Non-Disclosure Agreement.

1.4 The Platform is intended for users aged 18 or over. We do not knowingly collect personal data from individuals under 18 years of age.

2. Privacy contact

2.1 OpsHero has not appointed a formal Data Protection Officer under Article 37 GDPR, as the criteria for mandatory appointment do not apply to our processing activities. However, we have designated the following privacy contact for all data protection matters:

Privacy contact: Borislav Borislavov
Email: [email protected]

You may also contact us at:

  • General privacy inquiries: [email protected]
  • Postal address: OpsHero OOD, Sinanishko ezero 9A str., 1680 Sofia, Bulgaria

3. Personal data we collect

3.1 Data you provide

When you access the Platform, we collect the following personal data:

CategoryData collectedPurpose
IdentificationFull nameIdentify users of the Platform, enforce the NDA
ContactEmail addressCommunicate with you about your use of the Platform, deliver confirmation of NDA acceptance
ProfessionalJob roleUnderstand our user base and tailor Tool relevance

3.2 Submitted data (configuration files)

You may upload configuration files to the Tools (such as Terraform code, Kubernetes manifests, CI/CD pipeline definitions). The Mutual NDA and the Terms of Service require that such files do not contain personal data of third parties or sensitive credentials. Where such files are processed:

  • For some Tools, processing occurs entirely within your browser (client-side). In that case, the files are never transmitted to OpsHero's servers.
  • For other Tools, processing occurs on OpsHero's servers (server-side). In that case, files are transmitted, processed, and deleted in accordance with the Mutual NDA.

The Platform indicates the execution model for each Tool.

3.3 Acceptance and audit logs

When you accept our legal agreements (NDA, Terms of Service, Privacy Policy), we record:

  • The date and time of acceptance (UTC)
  • Your IP address at the time of acceptance
  • Your user-agent string (browser and operating system)
  • The version of each document accepted
  • A cryptographic hash of the accepted text

This information serves as evidence of acceptance and is retained for legal defence purposes.

3.4 Data collected automatically

When you visit the Platform, certain data is collected automatically:

  • Strictly necessary data: IP address, browser type and version, operating system, referring URL, pages visited, session identifiers, time and date of visit, error logs.
  • Data collected via cookies and similar technologies: see Section 8.

3.5 Marketing data

If you opt in to receive marketing communications from OpsHero (by ticking a separate, non-pre-ticked checkbox at the time of signup, or by subscribing through other channels), we additionally process:

  • Your email address for delivery of communications
  • Engagement metrics (opens, clicks) for measuring campaign effectiveness
  • Preferences (topics, frequency) you may indicate

4. Purposes and lawful bases of processing

We process your personal data for the following purposes, each with a specific lawful basis under Article 6 GDPR:

#PurposeLawful basisNotes
1Providing access to the ToolsLegitimate interest (Art. 6(1)(f))We have a legitimate interest in identifying users of our Platform for abuse prevention, audit trail, and enforcement of the NDA. A Legitimate Interest Assessment has been documented.
2Processing Submitted Data to generate OutputsLegitimate interest (Art. 6(1)(f))The processing is necessary to deliver the Tool functionality you have requested.
3Maintaining acceptance and audit logsLegitimate interest (Art. 6(1)(f))Necessary for defence of legal claims, regulatory compliance, and proof of contractual acceptance.
4Operational security (IP logging, abuse prevention, fraud detection)Legitimate interest (Art. 6(1)(f))Necessary to protect the Platform and other users.
5Service-related communications (security notices, material changes to legal documents)Legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) where applicableWe may need to notify you of important changes affecting your rights or the security of the service.
6Sending marketing communicationsConsent (Art. 6(1)(a))Only with your explicit, prior, opt-in consent. Withdrawable at any time.
7Analytics, session replay, and marketing pixelsConsent (Art. 6(1)(a))Only with your consent through the cookie banner.
8Compliance with legal obligationsLegal obligation (Art. 6(1)(c))E.g. responding to lawful requests from authorities.
9Defending legal claims and enforcing agreementsLegitimate interest (Art. 6(1)(f))Necessary for legal defence and enforcement of the NDA and Terms of Service.

4.1 Legitimate interest assessment

Where we rely on legitimate interest, we have balanced our interests against your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 9). If you object, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests or the processing is necessary for the establishment, exercise, or defence of legal claims.

5. Who we share your data with

We do not sell your personal data. We share it only with the following categories of recipients:

5.1 Service providers (processors)

RecipientPurposeLocationTransfer mechanism
EU-based hosting provider for opshero.toolsHosting the Platform infrastructureEU data centreN/A (within EEA)
Transactional email providerDelivering acceptance confirmations and service-related emailsEU (or covered by SCCs if non-EU)EU SCCs where applicable
Analytics provider (Google Analytics or equivalent)Website analytics, only with your consentUSA / globalEU SCCs + supplementary measures
Session replay / heatmap providerUnderstanding user behaviour, only with your consentUSA / globalEU SCCs + supplementary measures
LinkedIn (LinkedIn Ireland Unlimited Company)Marketing pixel for advertising effectiveness, only with your consentEU (LinkedIn Ireland) with processing in USAEU SCCs + LinkedIn DPA

The processors and sub-processors we currently rely on are listed in the table above. To request the most up-to-date list, or to be notified of changes, contact us at [email protected].

5.2 Marketing tools (only with your consent)

If you opt in to marketing communications, your data may additionally be processed by LinkedIn Marketing Solutions for the purpose of audience targeting and campaign measurement. LinkedIn's processing is governed by LinkedIn's own privacy policy at linkedin.com/legal/privacy-policy.

5.3 Legal and regulatory disclosures

We may disclose personal data:

  • To competent authorities where required by law, court order, or regulatory request;
  • To enforce our Terms of Service or Mutual NDA;
  • To establish, exercise, or defend legal claims;
  • To prevent fraud, abuse, or threats to the security of the Platform.

5.4 Business transfers

If OpsHero is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality obligations and continued application of this Privacy Policy or an equivalent successor policy.

5.5 With your explicit consent

We may share your personal data with other recipients with your explicit consent or at your direction.

6. International transfers

6.1 OpsHero is based in Bulgaria. The Platform infrastructure is hosted within the European Economic Area (EEA).

6.2 However, certain service providers - particularly analytics, session replay, marketing pixel, and similar providers - process personal data outside the EEA, primarily in the United States.

6.3 Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, including:

  1. EU Standard Contractual Clauses (SCCs) as adopted by Commission Implementing Decision (EU) 2021/914;
  2. EU-U.S. Data Privacy Framework where the recipient is certified;
  3. Adequacy decisions where issued by the European Commission;
  4. Supplementary technical and organisational measures such as encryption in transit and at rest.

6.4 You may request a copy of the relevant transfer safeguards by contacting us at [email protected].

6.5 Note that analytics, session replay, and marketing pixel providers only receive your data if you consent through the cookie banner. If you do not consent, no international transfer of your data takes place through these tools.

7. Retention periods

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy. Specific retention periods are as follows:

Data categoryRetention periodReason
Name, email, job role (signup data)5 years from last interactionAligned with NDA term (2 years) + survival period (3 years); defence of legal claims
Acceptance and audit logs (NDA, ToS, Privacy Policy)5 years from acceptanceEvidence of contractual acceptance; defence of legal claims
Submitted Data (server-side processed)Deleted promptly after Output generation, in no case longer than 30 daysAs committed in Section 4.1(a) of the Mutual NDA
Submitted Data (client-side processed)Not retained by OpsHero (processed in your browser)N/A
Marketing data (if you opted in)Until you withdraw consent or 2 years of inactivity, whichever is earlierMarketing consent is event-based and revocable
Cookie-based data (analytics, session replay, pixels)As set in the cookie banner, typically 6–24 monthsAligned with cookie expiration and consent validity
Server logs (IP, user-agent, errors)90 daysSecurity monitoring and abuse prevention
Data required by law (tax, bookkeeping, etc.)As required by applicable Bulgarian law (typically 5–10 years)Legal obligation

After the retention period expires, personal data is securely deleted or anonymised.

8. Cookies and similar technologies

8.1 What are cookies

Cookies are small text files placed on your device when you visit a website. We also use similar technologies such as local storage, pixels, and scripts.

8.2 Categories of cookies we use

CategoryPurposeConsent requiredExamples
Strictly necessaryEnable core Platform functionality (session, security, language preference)No (exempt under ePrivacy)Session ID, CSRF token, cookie consent record
AnalyticsMeasure how visitors use the PlatformYes (opt-in)Google Analytics
Session replay / heatmapsUnderstand user behaviour and improve UXYes (opt-in)Session replay tool
Marketing / advertisingMeasure advertising effectiveness, deliver targeted adsYes (opt-in)LinkedIn Insight Tag

8.3 Your cookie choices

When you first visit the Platform, you will be presented with a cookie consent banner that allows you to:

  • Accept all cookies
  • Reject all non-essential cookies
  • Customise your preferences by category

You can change your preferences at any time by clicking the "Cookie Settings" link in the Platform footer.

Rejecting non-essential cookies will not prevent you from using the Platform or the Tools, but some features (such as personalised content or interaction analytics) may not work as designed.

8.4 Do Not Track

We currently respond to browser "Do Not Track" signals by treating them as a request to disable non-essential cookies, equivalent to rejecting all non-essential cookies in our consent banner.

8.5 More information

A detailed Cookie Policy with the full list of cookies used, their purposes, durations, and third-party recipients is available on this site.

9. Your rights under GDPR

As a data subject, you have the following rights under the GDPR:

9.1 Right of access (Article 15)

You may request confirmation of whether we process your personal data, and if so, a copy of that data along with information about the processing.

9.2 Right to rectification (Article 16)

You may request correction of inaccurate personal data or completion of incomplete data.

9.3 Right to erasure (Article 17)

You may request deletion of your personal data where one of the grounds in Article 17 applies (e.g. data no longer necessary, withdrawal of consent, objection without overriding legitimate interest).

9.4 Right to restriction of processing (Article 18)

You may request that we restrict processing of your personal data in certain circumstances.

9.5 Right to data portability (Article 20)

For data processed on the basis of consent or contract and by automated means, you may receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller.

9.6 Right to object (Article 21)

You may object at any time to processing based on legitimate interest, including profiling. You may also object at any time to processing for direct marketing purposes.

9.7 Right to withdraw consent (Article 7(3))

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

9.8 Right not to be subject to automated decision-making (Article 22)

We do not currently engage in automated decision-making with legal or similarly significant effects. The Outputs generated by the Tools are advisory in nature and do not constitute automated decisions about you.

9.9 Right to lodge a complaint (Article 77)

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

For users in Bulgaria, the supervisory authority is:

Commission for Personal Data Protection (Комисия за защита на личните данни - КЗЛД)

You may also lodge a complaint with the supervisory authority in your own EU Member State.

9.10 How to exercise your rights

To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving your request (extendable by two further months for complex requests, in which case we will notify you of the extension). There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive.

We may need to verify your identity before responding to certain requests. We will only request information necessary to confirm your identity.

10. Security

10.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption in transit (TLS 1.2 or higher) for all communications with the Platform
  • Encryption at rest for stored personal data, where technically feasible
  • Role-based access control with multi-factor authentication for administrative access
  • Logging and monitoring of access to personal data
  • Regular vulnerability scanning and security testing
  • Incident response procedures
  • Personnel confidentiality obligations and security awareness training

10.2 No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.

10.3 Data Breach Notification. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

11. Third-party websites

11.1 The Platform may contain links to third-party websites (e.g. LinkedIn, documentation sites, partner sites). This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party site you visit.

12. Changes to this Privacy Policy

12.1 We may update this Privacy Policy from time to time. The current version is identified by version number and effective date at the top of the document.

12.2 Material changes will be communicated by reasonable means, which may include a notice on the Platform or an email to the address you provided. Material changes will take effect no earlier than thirty (30) days after notice.

12.3 Previous versions of this Privacy Policy are available upon request to [email protected].

13. Governing law

13.1 This Privacy Policy is governed by the laws of the Republic of Bulgaria and applicable EU data protection law, including the GDPR.

13.2 Nothing in this Privacy Policy limits your rights under the GDPR or other mandatory data protection law.

14. Contact us

For any questions, requests, or concerns regarding this Privacy Policy or our processing of your personal data:

OpsHero OOD
Sinanishko ezero 9A str.
1680 Sofia, Bulgaria
UIC: 202862235