Privacy Policy
OpsHero — opshero.com
Version 2.0 — Effective [SET TO THE PUBLICATION DATE]
1. Introduction
1.1 This Privacy Policy explains how OpsHero OOD, UIC 202862235, with registered office at Sinanishko ezero 9A str., 1680 Sofia, Bulgaria ("OpsHero", "we", "us", or "our"), collects, uses, stores, shares, and protects personal data in connection with the OpsHero website available at opshero.com (the "Website").
1.2 OpsHero is the controller of the personal data described in this Privacy Policy within the meaning of Regulation (EU) 2016/679 (the "GDPR").
1.3 This Privacy Policy applies to all visitors to the Website (collectively, "you"). It should be read together with the Terms of Service.
1.4 We do not knowingly collect special category data (Article 9 GDPR) or personal data relating to children.
2. Privacy contact
2.1 OpsHero has designated a data protection contact for all data protection matters:
- Email: [email protected]
- Postal address: Data Protection Contact, OpsHero OOD, Sinanishko ezero 9A str., 1680 Sofia, Bulgaria
3. Personal data we collect
3.1 Data you provide
None. The Website has no contact form, no sign-up, no newsletter subscription, no account and no upload — there is no field on this site through which you can give us personal data. If you write to one of the addresses in Section 14, we process what you choose to put in that message in order to answer it.
3.4 Data collected automatically
The Website sets no cookies of its own and writes nothing to your browser's local or session storage. It runs no analytics, no session replay, and no advertising or marketing pixel.
Delivering any web page requires the serving infrastructure to process the connection itself. opshero.com is served through Cloudflare, which processes your IP address, your browser's user-agent string, the URL requested and the time of the request in order to return the page and to protect the site against malicious traffic. See Section 8 for the cookie Cloudflare may set.
If you opt in to receive marketing communications from OpsHero (by ticking a separate, non-pre-ticked checkbox at the time of signup, or by subscribing through other channels), we additionally process:
- Your email address for delivery of communications
- Engagement metrics (opens, clicks) for measuring campaign effectiveness
- Preferences (topics, frequency) you may indicate
4. Purposes and lawful bases of processing
We process your personal data for the following purposes, each with a specific lawful basis under Article 6 GDPR:
| # | Purpose | Lawful basis | Notes |
|---|---|---|---|
| 1 | Serving the Website and protecting it against malicious traffic | Legitimate interest (Art. 6(1)(f)) | Connection data is processed at the Cloudflare edge to deliver pages and to block bot and denial-of-service traffic. See Section 3.4. |
| 2 | Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) | E.g. responding to lawful requests from authorities. |
| 3 | Answering enquiries sent to us, and defending legal claims | Legitimate interest (Art. 6(1)(f)) | Where you write to one of the addresses in Section 14, and for the establishment, exercise or defence of legal claims. |
4.1 Legitimate interest assessment
Where we rely on legitimate interest, we have balanced our interests against your rights and freedoms. You have the right to object to processing based on legitimate interest (see Section 9). If you object, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests or the processing is necessary for the establishment, exercise, or defence of legal claims.
5. Who we share your data with
We do not sell your personal data. We share it only with the following categories of recipients:
5.1 Service providers (processors)
| Recipient | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Cloudflare, Inc. | Content delivery, TLS termination, and bot and denial-of-service protection for opshero.com | Global edge network | EU Standard Contractual Clauses |
| Google (Google Workspace) | Appointment scheduling. The booking page embeds Google's appointment-scheduling widget; loading that page discloses your IP address and browser to Google, and any booking you make is created in Google Calendar. | USA / global | EU Standard Contractual Clauses |
If you opt in to marketing communications, your data may additionally be processed by LinkedIn Marketing Solutions for the purpose of audience targeting and campaign measurement. LinkedIn's processing is governed by LinkedIn's own privacy policy at linkedin.com/legal/privacy-policy.
5.3 Legal and regulatory disclosures
We may disclose personal data:
- To competent authorities where required by law, court order, or regulatory request;
- To enforce our Terms of Service;
- To establish, exercise, or defend legal claims;
- To prevent fraud, abuse, or threats to the security of the Website.
5.4 Business transfers
If OpsHero is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to confidentiality obligations and continued application of this Privacy Policy or an equivalent successor policy.
5.5 With your explicit consent
We may share your personal data with other recipients with your explicit consent or at your direction.
6. International transfers
6.1 OpsHero OOD is established in Bulgaria and is registered there under UIC 202862235.
6.2 The service providers named in Section 5.1 operate global networks and may process personal data outside the EEA, including in the United States.
6.3 Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, including:
- EU Standard Contractual Clauses (SCCs) as adopted by Commission Implementing Decision (EU) 2021/914;
- Supplementary technical and organisational measures such as encryption in transit and at rest.
6.4 You may request a copy of the relevant transfer safeguards by contacting us at [email protected].
7. Retention periods
The Website collects no personal data directly, so there is nothing it stores to a retention schedule. Where we do hold personal data — a message you have sent us, or a record we are required by law to keep — we retain it only for as long as necessary:
| Data category | Retention period | Reason |
|---|---|---|
| Data required by law (tax, bookkeeping, etc.) | As required by applicable Bulgarian law (typically 5–10 years) | Legal obligation |
After the retention period expires, personal data is securely deleted or anonymised.
8. Cookies and similar technologies
8.1 What are cookies
Cookies are small text files that are placed on your device to help a site provide a better user experience. They enable core functionality such as security, network management and accessibility.
8.2 Categories of cookies we use
| Category | Purpose | Consent required | Examples |
|---|---|---|---|
| Strictly necessary | Bot and denial-of-service protection at the Cloudflare edge | No (exempt under ePrivacy) | __cf_bm, set by Cloudflare, expires after 30 minutes |
| Third-party embed | Cookies set by Google when the appointment-scheduling widget on the booking page loads or is used. These are Google's cookies, not ours, and are governed by Google's own policies. | Not currently collected — the widget loads when you open the booking page | See Section 5.1 |
8.3 Your cookie choices
Because the Website uses no analytics, advertising or tracking cookies of its own, there is no consent banner and nothing to opt out of. You can disable cookies in your browser settings; because the only cookie involved is a security cookie, blocking it may affect the functionality of the site.
8.5 More information
The Cookie Policy on this site covers the same ground in more detail.
9. Your rights under GDPR
As a data subject, you have the following rights under the GDPR:
9.1 Right of access (Article 15)
You may request confirmation of whether we process your personal data, and if so, a copy of that data along with information about the processing.
9.2 Right to rectification (Article 16)
You may request correction of inaccurate personal data or completion of incomplete data.
9.3 Right to erasure (Article 17)
You may request deletion of your personal data where one of the grounds in Article 17 applies (e.g. data no longer necessary, withdrawal of consent, objection without overriding legitimate interest).
9.4 Right to restriction of processing (Article 18)
You may request that we restrict processing of your personal data in certain circumstances.
9.5 Right to data portability (Article 20)
For data processed on the basis of consent or contract and by automated means, you may receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller.
9.6 Right to object (Article 21)
You may object at any time to processing based on legitimate interest, including profiling. You may also object at any time to processing for direct marketing purposes.
9.7 Right to withdraw consent (Article 7(3))
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
9.8 Right not to be subject to automated decision-making (Article 22)
We do not engage in automated decision-making with legal or similarly significant effects.
9.9 Right to lodge a complaint (Article 77)
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.
For users in Bulgaria, the supervisory authority is:
Commission for Personal Data Protection (Комисия за защита на личните данни — КЗЛД)
- Address: 2 Prof. Tsvetan Lazarov Blvd., 1592 Sofia, Bulgaria
- Email: [email protected]
- Website: www.cpdp.bg
You may also lodge a complaint with the supervisory authority in your own EU Member State.
9.10 How to exercise your rights
To exercise any of these rights, contact us at [email protected]. We will respond within one month of receiving your request (extendable by two further months for complex requests, in which case we will notify you of the extension). There is no fee for exercising your rights, except where requests are manifestly unfounded or excessive.
We may need to verify your identity before responding to certain requests. We will only request information necessary to confirm your identity.
10. Security
10.1 We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption in transit (TLS 1.3) and at rest
- Role-based access control via Google Workspace IAM, with multi-factor authentication
- Regular penetration tests
- 24/7 monitoring
10.2 No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
10.3 Data Breach Notification. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
11. Third-party websites
11.1 The Website contains links to third-party websites, including LinkedIn and opshero.tools. This Privacy Policy does not apply to those websites. We encourage you to review the privacy policies of any third-party site you visit.
12. Changes to this Privacy Policy
12.1 We may update this Privacy Policy from time to time. The current version is identified by version number and effective date at the top of the document.
12.2 Significant changes will be communicated by a notice on the Website. Material changes will take effect no earlier than thirty (30) days after notice.
12.3 Previous versions of this Privacy Policy are available upon request to [email protected].
13. Governing law
13.1 This Privacy Policy is governed by the laws of the Republic of Bulgaria and applicable EU data protection law, including the GDPR.
13.2 Nothing in this Privacy Policy limits your rights under the GDPR or other mandatory data protection law.
14. Contact us
For any questions, requests, or concerns regarding this Privacy Policy or our processing of your personal data:
OpsHero OOD
Sinanishko ezero 9A str.
1680 Sofia, Bulgaria
UIC: 202862235
- Data protection contact: [email protected]
