GDPR and your data at BrandOps9
How BrandOps9 handles your personal data under the GDPR: what we process and why, who we share it with, how long we keep it, and how to use your rights.
Where you stand
BrandOps9 is run and hosted inside the EU, and the GDPR applies to how we handle your personal data. This guide explains in plain language what we process, who we share it with, how long we keep it and the rights you have. It is not legal advice.
What we process and why
To run your workspace we process account details (your name and email), who is in your workspace, the brand details and website text you bring in, campaign briefs and created content, schedules, credit balances and activity logs. When you connect a social account we store its access keys encrypted.
We rely on two legal bases: performing our contract with you and our legitimate interest in running, securing and improving the service. We do not sell your personal data.
No tracking cookies
BrandOps9 sets no advertising or analytics cookies and runs no third-party tracking pixels. The only browser storage we use keeps you logged in and remembers basic preferences, so there is no cookie banner to click through.
Who we share it with
To deliver the service we use a small set of vetted sub-processors: AI providers to create content and to run Get found by AI checks; Google, Meta, LinkedIn and X when you connect those accounts; Stripe for payments; and an email provider for service emails. Content sent to AI providers is used only to produce your output and is not used to train their models.
Some providers are in the United States, so some processing happens outside the EEA under safeguards such as Standard Contractual Clauses. The full list is on the Sub-processors page, and a Data Processing Agreement is available on request.
Your rights and how to use them
You can ask us for a copy of your data, to correct it, export it, delete it, restrict how we use it, or object to certain processing. Email contact@brandops9.com and we respond within 30 days. You can update your name and photo from the account menu, and "Privacy & data" in the same menu shows your options. Owners can manage and remove who has access to a brand.
How long we keep your data
We keep workspace data while your account and brands exist, with these limits:
- Activity and security logs: up to 12 months.
- Visits to public content (visitor address and browser): up to 90 days.
- Assistant chat logs: up to 6 months (visitor addresses are stored scrambled, not in plain form).
- Billing and credit records: as long as accounting and tax law require, anonymised after you delete your account.
Deleting your account
When you delete your account we remove your identifying data (name, email, photo and login details) and delete your brands and their content. We keep the financial records of past purchases, anonymised so they no longer identify you, because the law requires it.
Good to know
This guide explains how BrandOps9 is designed to support your compliance; it is not legal advice. If GDPR compliance is critical for your organisation, have your own counsel review your use and ask us for a Data Processing Agreement.

