Operaria

Security and GDPR

Your data, and your customers' data

If you automate a process, somebody is going to handle your customers' data. This is exactly who, what for, and for how long.

  • Servers in the European Union
  • Credentials encrypted
  • None of your customers' data in an AI model
The Operaria “Connect your credentials” screen, with the Google Calendar card and the WhatsApp Business card not yet connected
They are your accounts: you grant access here and you can take it away whenever you like. The screenshot is from our demo account, which runs in Spanish.

The four commitments

What we always do, no exceptions

We are processors, not owners

For your customers' data you are the controller and we are the processor (Article 28); for the data you give us when you sign up, we are the controller. They are two different things and the privacy policy deals with them separately. We handle the first on your instructions, under a contract signed when the account is created (Article 28 GDPR), and only for what the process spec says.

Passwords, encrypted

The credentials you give us are encrypted before they touch disk and are only decrypted at the moment they are used. They do not appear in logs, on screens, or in readable backups.

Every action, logged

Everything the process does is written down: what, when and with what result. You can read it and take it with you whenever you like.

Every message says what it is

Any message that goes out automatically says so, as the EU AI Act requires. It cannot be switched off, not even if a customer asks.

Sub-processors

Who else is involved

The full list, deliberately short. Any change is announced thirty days ahead.

WhoWhat forWhere
netcupThe server everything lives onGermany
BrevoSending the service emailsFrance
StripeTaking the fee. It never sees your customers' dataIreland, as a controller in its own right
GoogleYour calendar or your spreadsheet, which you share with our address. The data stays in your accountYour Google account, under your contract with Google
MetaWhatsApp Business: messages go out through your accountYour Meta account, under your contract with Meta
AnthropicOnly when we write your process spec from what you tell us. It never sees your customers' dataUnited States, under standard contractual clauses

No language model sees your customers' data. The day-to-day steps, the automatic repairs and the reports never go near a model: they are code that always does the same thing, which is exactly why they can be rehearsed. A model does one job only: helping us write your spec from what you tell us about your business. And there is a check when the server starts that makes it impossible any other way.

The limits

What we do not do yet

We do not handle health data. A clinic can automate its reminders and its admin, but any process that touches medical records or diagnoses we will not accept until the European route for that kind of data is in place.

We say so here, in the interview and in the spec, because we would rather lose that customer than do it badly.