OperatorHQ policies · July 2026

Compliance & Data Processing

How OperatorHQ aligns with data-protection frameworks, which subprocessors handle workspace data, and how to request a Data Processing Agreement.

Early Access · Beta: OperatorHQ is in early access. These policies apply today and may be updated as formal legal review completes; material changes are announced before they take effect.

Roles under data-protection law

For content you process through a workspace — client briefs, uploads, run inputs, and generated outputs — you (the customer) act as the data controller and OperatorHQ acts as the data processor. OperatorHQ processes that content only on your documented instructions, as required by frameworks such as the GDPR (EU), CCPA (California), and PDPO (Hong Kong).

For account, billing, and security telemetry data, OperatorHQ acts as an independent data controller and handles that data under the Privacy Policy. TODO: legal review — counsel to confirm the controller/processor split wording per jurisdiction.

Subprocessors

OperatorHQ engages the following subprocessors to provide the service: xAI (Grok models), Moonshot AI (Kimi models), and DeepSeek as AI providers; Stripe for payment processing; Vercel for hosting and edge delivery; and Neon for managed database storage.

AI providers are engaged under terms that prohibit training on customer content. The current subprocessor list is maintained on this page; material changes are announced before they take effect.

International transfers

Workspace data is processed in United States and Singapore regions, depending on the configured infrastructure. Where personal data crosses borders, OperatorHQ relies on appropriate transfer mechanisms.

Standard contractual clauses (SCCs) are available on request for customers that require them. TODO: legal review — attach the executed SCC template reference once counsel finalizes it.

Retention & deletion

Workspace data is deleted on verified request within 30 days. Retention is configurable per workspace, and deletion covers projects, runs, uploads, and approvals.

Audit exports remain available for 90 days after cancellation so you can retain your own compliance records; after that window the underlying data is purged.

DPA requests

To request a Data Processing Agreement, email legal@useoperatorhq.com from the address associated with your workspace. Include your workspace name and the jurisdictions you operate in so the request can be routed correctly.