legal

Privacy notice

Last updated: 23 September 2026

Controller

LayerOps LTD, a company registered in England and Wales, registered address 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, company number 17151973, is the data controller for the personal data described in this notice. Contact us at [email protected].

What we collect

  • Account data: your name, email address, password hash, and two-factor authentication secret if you enable it.
  • Workspace data: workspace name, membership, roles, and approval decisions.
  • Connected vendor credentials: the API keys and secrets you give us to reach your PSA, RMM and other tools, stored encrypted (see below).
  • Usage logs: which tool was called, which integration it belongs to, how long it took, whether it succeeded, and which API key or connection made the call. We do not log the contents of the response.
  • Billing data: handled by Stripe. We hold your plan, status and billing dates, not your card details.
  • Support correspondence: anything you send to [email protected].

Why, and our lawful basis

We process this data to provide the service you have signed up to (performance of a contract): running your workspace, executing tool calls, billing you, and sending service emails like invitations and approval notifications.

We process usage and audit logs on the basis of our legitimate interest in keeping the service secure, investigating misuse, and meeting our own audit obligations.

We do not currently run any marketing communications, so we do not rely on consent for that. If that changes, we will ask first.

Vendor credentials

Every credential you connect is encrypted per field with AES-256-GCM under a key unique to your workspace, and that workspace key is itself wrapped by a root key held in Google Cloud KMS. Nobody at LayerOps, including us, can read a credential without your workspace's key being unwrapped for that purpose. A decrypted credential exists in memory only for the length of the single outbound call it is needed for, then it is discarded. Every decryption is logged. The full technical detail is public on our security page.

Subprocessors

We use the following subprocessors to run LayerOps:

NamePurposeLocation
HetznerApplication and database hostingNuremberg, Germany (EU)
CloudflareCDN, DNS and web application firewallGlobal network
Google Cloud (KMS)Wraps the per-workspace key used to encrypt vendor credentialseurope-west2 (London)
StripeBilling, subscriptions and payment processingUnited States
BrevoTransactional email (verification, invitations, alerts)European Union
SentryError reporting and diagnosticsEuropean Union
OpenAIEndpoint extraction for custom-integration discovery only, store: falseUnited States
Google LLCWebsite analytics (Google Analytics 4), public site only, after consentUSA, EU-US Data Privacy Framework

A data processing agreement is available on request at [email protected].

Retention

  • Webhook events: 7 days.
  • In-app notifications: 14 days.
  • Account, workspace, vendor credential and audit data: for the life of the workspace, and up to 90 days after deletion, to allow recovery from accidental deletion and to close out any billing dispute. This is our current retention policy; it is not yet enforced by an automatic deletion job in the product.

International transfers

Most of your data stays in the EU or UK: Hetzner hosts the application and database in Nuremberg, Germany, and Google Cloud KMS wraps your workspace key in London (europe-west2). Stripe, OpenAI and Cloudflare may process data in the United States or on their global networks. Where that happens, the transfer is covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, as applicable to that subprocessor.

Your rights

Under UK GDPR you can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct data that is inaccurate.
  • Erase your data, subject to what we need to keep for legal or billing reasons.
  • Provide your data in a portable format.
  • Restrict or object to certain processing.

Email [email protected] to exercise any of these. You can also complain to the Information Commissioner's Office (ico.org.uk) at any time.

Cookies

In the app, we use one cookie: the session cookie that keeps you signed in. The app and the sign-in pages never load analytics, advertising or tracking code.

On the public site (layerops.ai), we use Google Analytics 4 to see which pages get read, but only if you accept the banner. Until then nothing from Google loads. Your choice, accept or decline, is kept in your browser's local storage under the name lo_consent. It is not a cookie and is never sent to us.

If you accept, Google Analytics sets the cookies _ga and _ga_*, which last up to two years. They are set on the public site only, never in the app. Google states that Google Analytics 4 does not store IP addresses. Our lawful basis for this is your consent.

To withdraw consent, clear this site's data in your browser. That removes the Google Analytics cookies and your stored choice, and the banner will ask again on your next visit.

Changes

We may update this notice as the product changes. If a change is material, we will email the address on your account before it takes effect.

Contact

Questions about this notice, or a request under your rights above, go to [email protected].