peryx ← Back to site
Legal

Privacy Policy

Operyx Ltd · Last updated August 2026

This policy covers Operyx's obligations as a data controller. For data we process on behalf of operators, see the Data Processing Agreement.

1Who we are

Operyx Ltd is a company incorporated in England and Wales, registered in London. We operate the Operyx platform — a hospitality operational intelligence service accessible at operyx.co.uk, via the web application at app.operyx.co.uk, and via the Operyx native mobile application.

For the purposes of UK GDPR, Operyx Ltd is the data controller for personal data we collect directly: your account information, your interactions with our website, and your communications with us.

When Operyx processes venue operational data on behalf of an operator, Operyx acts as a data processor. The operator is the data controller for their venue data. That relationship is governed by a separate Data Processing Agreement, not this Privacy Policy.

Contact: tech@operyx.co.uk

2Data we collect as controller

2.1 Account data

When you create an account via Google OAuth, we collect your name, email address, and Google account identifier. Legal basis: Contract (Article 6(1)(b)) — necessary to provide the service.

2.2 Website visitor data

When you visit operyx.co.uk, we collect standard server logs (IP address, browser type, pages visited). We use essential cookies only (session authentication). We do not use advertising or analytics cookies. Legal basis: Legitimate interests (Article 6(1)(f)) — maintaining platform security.

2.3 Communications

If you contact us by email or through the platform, we retain those communications. Legal basis: Legitimate interests (Article 6(1)(f)) — responding to enquiries.

2.4 Payment data

Payment card details are collected and processed exclusively by Stripe Inc. (PCI DSS compliant). Operyx stores only your billing email, subscription status, and payment history references. Legal basis: Contract (Article 6(1)(b)).

2.5 Usage analytics

We collect information about how you use the platform (pages visited, features used). Legal basis: Legitimate interests (Article 6(1)(f)) — improving the platform.

2.6 AI processing

To generate operational intelligence — morning briefs, demand forecasts, cost analysis, and strategic assessments — Operyx sends venue operational data (such as daily revenue, covers, labour costs, and purchases) to Anthropic PBC, an AI provider based in the USA.

Where you submit end-of-day reports by voice, or capture rota photographs, the audio or image is sent to OpenAI Inc. (USA) for transcription and extraction. Audio is not retained by the provider after transcription.

This data is processed solely to return results to you. Neither provider trains its models on data submitted through its API. Operational data may incidentally include staff names, hours, or salary information where an operator enters them. We never send your diners' or customers' personal data to any AI provider.

These transfers are governed by Standard Contractual Clauses, and each provider maintains equivalent safeguards. Where Operyx processes venue data on behalf of an operator, this processing is further governed by the Data Processing Agreement. Legal basis: Contract (Article 6(1)(b)).

3What we do not collect

We do not collect personal data about your customers or diners. We do not use tracking cookies for advertising. We do not sell your data to third parties. We do not retain voice recordings after transcription. We do not send diner or customer personal data to AI providers.

4International transfers & sub-processors

Account and website data is stored on servers in the EU (AWS eu-west-1, Ireland) operated by Supabase Inc. Where data is processed by services outside the EU, the following safeguards are in place:

  • Anthropic PBC (USA) — AI processing of venue operational data to generate intelligence. Standard Contractual Clauses. Does not train models on API data or retain it after processing.
  • OpenAI Inc. (USA) — Voice transcription and rota extraction (Whisper). Standard Contractual Clauses. Audio processed for transcription only and not retained.
  • Supabase Inc. (Ireland) — Database and storage. Data Processing Agreement and Standard Contractual Clauses.
  • Google LLC (USA) — OAuth authentication. Standard Contractual Clauses.
  • Stripe Inc. (USA/EU) — Payment processing. PCI DSS compliant. Standard Contractual Clauses.

We will ensure equivalent safeguards are maintained by all sub-processors, and we notify operators at least 14 days before adding or replacing a sub-processor that handles their venue data.

5Retention

Account data: duration of account + 12 months after closure. Usage logs: 90 days rolling. Communications: 24 months from last contact. Payment references: duration of account + 6 years (HMRC requirement). Voice recordings: not retained after transcription.

6Your rights

Under UK GDPR you have the right to: access your data, rectify inaccuracies, request erasure, restrict processing, data portability, object to processing based on legitimate interests, and withdraw consent where applicable — including withdrawing consent to AI processing, which you can do at any time in the app's settings or by contacting us.

To exercise any right, contact tech@operyx.co.uk. We will respond within one calendar month. If dissatisfied, you may complain to the ICO at ico.org.uk.

7Cookies

The Operyx platform uses only essential session cookies and JWT authentication tokens necessary to keep you logged in. We do not use advertising, tracking, or third-party analytics cookies.

8Security

We protect your data with: encrypted connections (HTTPS/TLS), JWT-based authentication, role-based access controls, row-level security, multi-tenant data isolation, and regular security reviews. In the event of a data breach likely to affect your rights, we will notify you and the ICO within 72 hours.

9Changes

We will notify you of material changes by email at least 14 days before they take effect.

10Contact

Email: tech@operyx.co.uk
Operyx Ltd, London, England