Privacy Policy
How Haredev Ltd collects, uses, and protects personal data across the Opsflow platform — the admin web app, the mobile app, the API, and this site.
Two roles: controller and processor
Opsflow is business-to-business software. A company (a "Tenant") licenses Opsflow and invites its own staff — owners, admins, authors, managers, learners (together, "Users") — to use it. Which relationship applies to you determines who to ask first:
Your employer is the data controller of your personal data in the Service. Haredev is their processor, acting only on the Tenant's documented instructions under a Data Processing Agreement. Start data requests with your employer — Section 11 covers your rights either way.
You browse this site, request a demo, or contact sales/support. Haredev is the controller here, and Sections 3–9 and 11 apply to you directly.
You asked a Tenant’s public programme for a place, without an employer inviting you. That Tenant is the controller of what you give its sign-up form, and Haredev is their processor — the same split as the first card. The Tenant’s legal name and data-request address are shown on the form itself.
What Opsflow is, briefly
Opsflow teaches employees their employer's operating procedures through conversation with an AI Coach, checks whether they can apply it through realistic scenarios (not quizzes), and lets employees report real-world gaps so the knowledge improves. By design, managers never see raw conversation transcripts — only plain competence states (New / Learning / Verified / Fading / Overdue), never percentages, never verbatim text.
Personal data we collect
Account & profile
Name, work email, password (salted hash, never plain text), role, job role, team(s), location, language preference, and an optional free-text "learner profile" that only shapes the Coach's tone — never scoring or assignment.
Authentication
Login timestamps and failed-attempt counters for lockout enforcement. If you use Sign in with Apple/Google, we verify the identity token and read the name/email it carries — never your Apple/Google password.
Coaching interaction
Your messages to the Coach and its replies, for the session and your history. Spoken answers are sent to our speech-to-text sub-processor to transcribe that one answer only — not stored as audio afterward, not repurposed.
Assessment & mastery
A five-state status per concept, scheduling data, and the rubric behind a judgement — never a raw score or percentage, and never surfaced to managers as such.
Field reports
Filed under a one-way cryptographic handle, not your identity — see Section 6.
Tenant content, device & site data
Documents a Tenant's admins/authors upload in the admin web app; a device identifier and location for shared/kiosk devices; and, for visitors to this site, standard web logs (IP, user agent, timestamp), the website analytics described below and, on the public pages only, the advertising measurement described below.
Diagnostics & analytics
Where a Tenant's deployment enables them, Sentry (error monitoring) and PostHog (product analytics) may run inside the admin web and mobile apps. Both are off unless explicitly configured, and neither receives Coach conversation content.
Google Analytics runs on this website and in the admin and employee web apps, and is always on. It records which pages and screens are opened, which buttons are used, and which kind of action was taken — a document published, an invitation sent, a coaching session finished — together with a device type, an approximate location from the IP address, and how you reached the site. Once you are signed in it also receives the account identifier your Tenant's records use, so that the same person on a phone and a laptop is counted once.
It is never given content: no Coach conversation, no question you asked, no document text, no name, email address or phone number, and no search or free-text you typed. What it receives is the shape of the usage, not what was said. It does not run in the iOS or Android app.
Advertising measurement (Meta Pixel)
The public pages of this site — the landing page, the Initiative programme pages and the certificate page, but not the admin or employee apps — also carry the Meta Pixel, so that our own advertising on Instagram and Facebook can be measured, and shown again to people who visited these pages. It receives the page you viewed, which programme it belonged to, and whether a place was requested. It is configured not to read what you type: the email address and phone number on the sign-up form never reach it. Meta may link what it receives to your Meta account under Meta’s own privacy policy.
Initiative sign-up & the optional phone number
When you ask for a place on an Initiative programme, the Tenant running it is the data controller for what you give the form (Section 1), and Haredev stores it for them. The sign-up records your email address, whether you asked to hear about training your team, the date and — if you arrived from one of our advertisements — which advertisement it was. That is all it needs.
The form also offers one optional field that is not used to run the programme: a phone number, labelled "Job offers by WhatsApp (optional)". If you fill it in, you are agreeing that the Tenant running the programme may pass your contact details to businesses looking for staff, including in exchange for payment — see Section 8. The number is stored with the date you gave it, as the record of that consent.
It is optional in the ordinary sense of the word: leaving it blank changes nothing about your place, your coaching, or your certificate, and you are not asked again. You can have the number deleted at any time, without giving a reason and without affecting anything else — ask the Tenant running your programme, whose name and address are on the sign-up form, or write to privacy@opsflow.haredev.com and we will route it. See Section 11.
Why we process it, and our legal basis
| Purpose | Typical basis (UK/EU GDPR) |
|---|---|
| Run your account, the Coach, assessments | Performance of the contract with you / your Tenant |
| Manager alerts, verification & reset emails | Tenant's legitimate interest in workforce competence |
| Keep the Service secure | Legitimate interest in preventing misuse and fraud |
| Website and product analytics — understanding how the Service is used, and which of our own campaigns brought people to it | Legitimate interest in measuring and improving the Service / consent, by jurisdiction |
| Measuring our own advertising, and showing it again to people who visited the public pages of this site (Meta Pixel) | Consent where the law of your country requires it for advertising cookies; otherwise legitimate interest in reaching people who showed interest |
| A Tenant passing an Initiative phone number to employers recruiting staff | Consent only — given to that Tenant by filling in the optional field, and withdrawable at any time (Section 3) |
| Legal compliance, enforcement | Legal obligation |
Where Indonesia's UU PDP (Law No. 27/2022) applies, we map each purpose above to an equivalent basis under its Article 20 — typically explicit consent, or performance of a contract you're party to.
Privacy-by-design features specific to Opsflow
Structural guarantees — not settings anyone at your company can switch off.
Managers never see raw transcripts
No role, including the account owner, has an endpoint or export that returns your verbatim conversation. Only a derived, five-state signal is ever visible.
Field-report anonymity is structural
A report is stored under a one-way keyed hash of your identity. There is no "reveal reporter" feature for any role — the system doesn't retain what such a feature would need.
Tenant data is isolated at the database layer
Every Tenant's Users, documents, and conversations carry a tenant identifier enforced by database row-level security — a query or write missing the right tenant id is rejected by the database itself, checked by an automated cross-tenant isolation test suite on every change.
Data residency your Tenant controls
Tenants choose a data region at setup; it's shown to Users on invitation and locked afterward. Moving it later is a deliberate, audited migration.
AI processing & automated decisions
Coach replies, extracted concepts, and assessment judgements are produced by OpenAI, which also provides the embeddings used to find the right part of a document. Your conversation content and relevant documents are sent to OpenAI to generate a response. Voice, when you dictate, goes to Deepgram and nowhere else — see §08.
About AI training, honestly
Haredev is not a model developer and does not itself train models on your content — but that is not a promise that no model is trained on it, because it depends on the provider. Deepgram, our speech-to-text provider, uses the voice audio you submit in Opsflow to train and improve its speech recognition models. OpenAI, which receives your written content, does not: OpenAI's published policy is that data submitted through its API is not used to train or improve its models unless the customer explicitly opts in, and Opsflow does not opt in. OpenAI retains API data for up to 30 days for abuse monitoring and then deletes it.
Assessment outcomes come from an automated process (an AI "Judge" scoring your answer against a rubric). You may ask your Tenant's admin for a human review: it always adds a new, clearly-labelled manual assessment alongside the AI's original — never edits or deletes it.
Who we share data with
| Recipient | Purpose |
|---|---|
| Cloud hosting / database | Running the application |
| Amazon S3 | Storing uploaded knowledge documents |
| Deepgram | Speech-to-text for spoken answers |
| OpenAI | Coach, judging, concept extraction, clustering, document search |
| Mailgun | Transactional email |
| Sentry / PostHog (if enabled) | Error monitoring / usage analytics |
| Google (Google Analytics) | Website and product analytics — page and screen views, actions taken, campaign attribution |
| Meta (Meta Pixel, public pages only) | Advertising measurement and audiences — which public page was viewed, which programme it belonged to, whether a place was requested |
| Apple / Google | Sign-in verification |
| Employers recruiting staff (only if you gave a phone number on an Initiative sign-up form) | Introducing you for work — a disclosure the Tenant makes, for payment, and only with your consent |
Haredev does not sell personal data, and does not share it for third-party advertising. One disclosure made using Opsflow is a sale — it is a Tenant’s to make rather than ours, and it is set out below rather than left to be discovered.
It is opt-in, and it belongs to the Tenant. A Tenant running an Initiative programme offers an optional phone number on its sign-up form, labelled "Job offers by WhatsApp (optional)". If you fill it in, that Tenant may pass your name, email address and that number to businesses recruiting staff, and may be paid for doing so. The Tenant decides whether to do it and is the controller for it; Haredev’s part is storing what you typed and showing it to them. Nothing else about you goes with it: not your coaching conversations, not your assessments, not your certificate, and not your employer.
This never happens to anyone who left that field blank, and it is not a condition of anything: your place on a programme, your coaching and your certificate are identical either way. To have the number deleted, ask the Tenant running your programme — its name and address are on the sign-up form — or write to privacy@opsflow.haredev.com and we will route it. Deleting it stops any further sharing, but cannot reach copies an employer already holds, which is the reason the field is blank until you decide to fill it in.
International data transfers
Haredev is UK-based; Opsflow serves Tenants including in Indonesia. Data may be processed in a Tenant's chosen region and in the countries where our sub-processors operate (which may include the US). Where we transfer personal data internationally, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum and equivalent contractual protections, and — for transfers from Indonesia — the cross-border transfer conditions set out in UU PDP Article 56.
Haredev as processor
For Tenants: Haredev processes User data only on documented instructions, under a separate Data Processing Agreement (available on request) covering sub-processors, security, breach notification, and audit rights under UK GDPR Art. 28 and the equivalent Indonesian UU PDP obligations.
Your rights
Subject to applicable exemptions: access, rectification, erasure, restriction, objection (including to automated assessment decisions), portability, and withdrawal of consent. Complaints: the UK Information Commissioner's Office (ico.org.uk), or in Indonesia the authority designated under UU PDP.
If you're a User invited by a Tenant, ask your employer first — they hold the context to action most requests. You can also reach us at privacy@opsflow.haredev.com and we'll route it.
Retention & security
We keep personal data while your account is active and afterward only as long as needed for legal, dispute, or enforcement purposes. Session tokens expire quickly (access: 15 min, refresh: 7 days) as a security control, not a retention policy. We use encryption in transit, hashed passwords, time-limited document links, lockout after repeated failed logins, and an append-only audit log — no method of transmission is 100% secure.
An Initiative phone number (Section 3) is kept until it is deleted at your request, alongside the date you gave it — that date is the record of your consent, and a consent that cannot be dated is one that cannot be shown to have been given. The Tenant running the programme is the controller for it, so the decision to erase is theirs and carrying it out is ours.
Children's privacy
Opsflow is provisioned by employers for their staff and is not directed at children. Where local law sets a minimum age for independent consent (18 in Indonesia, absent parental consent), that age applies to any direct sign-up flow.
Cookies
The admin and employee apps use storage strictly necessary to keep you signed in. If a Tenant enables PostHog, it may set analytics cookies of its own.
This site and both web apps also set Google Analytics cookies (_ga and _ga_<id>). They hold a randomly generated identifier — not your name or email — so that repeat visits from the same browser are recognised as one visitor rather than several. They last up to two years, and the events they carry are kept for fourteen months.
You can refuse them: block or delete cookies for this site in your browser, use a private window, or install Google's own opt-out add-on, which turns Google Analytics off everywhere. Nothing about the Service stops working if you do — measurement is the only thing you lose. You may also object to this processing, or ask for your analytics data to be deleted, under Section 11.
The public pages of this site also set Meta Pixel cookies (_fbp, and _fbc when you arrived from a Meta advertisement). These are advertising cookies: they let Meta recognise a browser that visited these pages, so that our advertising can be measured and shown again to people who showed interest. They last up to ninety days. They are not set inside the admin or employee apps.
You can refuse them in the same ways, and you can decide how Meta uses what it receives from any website in your Meta account’s ad settings.
Changes to this policy
We'll post changes here with an updated date, and notify Tenants of material changes.
Contact us
Haredev Ltd
124 City Road, London, EC1V 2NX, United Kingdom
Company number 11290798
Email: privacy@opsflow.haredev.com