1Who we are
Operyx Ltd is a company incorporated in England and Wales, registered in London. We operate the Operyx platform — a hospitality operational intelligence service accessible at operyx.co.uk, via the web application at app.operyx.co.uk, and via the Operyx native mobile application.
For the purposes of UK GDPR, Operyx Ltd is the data controller for personal data we collect directly: your account information, your interactions with our website, and your communications with us.
When Operyx processes venue operational data on behalf of an operator, Operyx acts as a data processor. The operator is the data controller for their venue data. That relationship is governed by a separate Data Processing Agreement, not this Privacy Policy.
Contact: tech@operyx.co.uk
2Data we collect as controller
2.1 Account data
When you create an account via Google OAuth, we collect your name, email address, and Google account identifier. Legal basis: Contract (Article 6(1)(b)) — necessary to provide the service.
2.2 Website visitor data
When you visit operyx.co.uk, we collect standard server logs (IP address, browser type, pages visited). We use essential cookies only (session authentication). We do not use advertising or analytics cookies. Legal basis: Legitimate interests (Article 6(1)(f)) — maintaining platform security.
2.3 Communications
If you contact us by email or through the platform, we retain those communications. Legal basis: Legitimate interests (Article 6(1)(f)) — responding to enquiries.
2.4 Payment data
Payment card details are collected and processed exclusively by Stripe Inc. (PCI DSS compliant). Operyx stores only your billing email, subscription status, and payment history references. Legal basis: Contract (Article 6(1)(b)).
2.5 Usage analytics
We collect information about how you use the platform (pages visited, features used). Legal basis: Legitimate interests (Article 6(1)(f)) — improving the platform.
2.6 AI processing
To generate operational intelligence — morning briefs, demand forecasts, cost analysis, and strategic assessments — Operyx sends venue operational data (such as daily revenue, covers, labour costs, and purchases) to Anthropic PBC, an AI provider based in the USA.
Where you submit end-of-day reports by voice, or capture rota photographs, the audio or image is sent to OpenAI Inc. (USA) for transcription and extraction. Audio is not retained by the provider after transcription.
This data is processed solely to return results to you. Neither provider trains its models on data submitted through its API. Operational data may incidentally include staff names, hours, or salary information where an operator enters them. We never send your diners' or customers' personal data to any AI provider.
These transfers are governed by Standard Contractual Clauses, and each provider maintains equivalent safeguards. Where Operyx processes venue data on behalf of an operator, this processing is further governed by the Data Processing Agreement. Legal basis: Contract (Article 6(1)(b)).
3What we do not collect
We do not collect personal data about your customers or diners. We do not use tracking cookies for advertising. We do not sell your data to third parties. We do not retain voice recordings after transcription. We do not send diner or customer personal data to AI providers.
4International transfers & sub-processors
Account and website data is stored on servers in the EU (AWS eu-west-1, Ireland) operated by Supabase Inc. Where data is processed by services outside the EU, the following safeguards are in place:
- Anthropic PBC (USA) — AI processing of venue operational data to generate intelligence. Standard Contractual Clauses. Does not train models on API data or retain it after processing.
- OpenAI Inc. (USA) — Voice transcription and rota extraction (Whisper). Standard Contractual Clauses. Audio processed for transcription only and not retained.
- Supabase Inc. (Ireland) — Database and storage. Data Processing Agreement and Standard Contractual Clauses.
- Google LLC (USA) — OAuth authentication. Standard Contractual Clauses.
- Stripe Inc. (USA/EU) — Payment processing. PCI DSS compliant. Standard Contractual Clauses.
We will ensure equivalent safeguards are maintained by all sub-processors, and we notify operators at least 14 days before adding or replacing a sub-processor that handles their venue data.
5Retention
Account data: duration of account + 12 months after closure. Usage logs: 90 days rolling. Communications: 24 months from last contact. Payment references: duration of account + 6 years (HMRC requirement). Voice recordings: not retained after transcription.
6Your rights
Under UK GDPR you have the right to: access your data, rectify inaccuracies, request erasure, restrict processing, data portability, object to processing based on legitimate interests, and withdraw consent where applicable — including withdrawing consent to AI processing, which you can do at any time in the app's settings or by contacting us.
To exercise any right, contact tech@operyx.co.uk. We will respond within one calendar month. If dissatisfied, you may complain to the ICO at ico.org.uk.
7Cookies
The Operyx platform uses only essential session cookies and JWT authentication tokens necessary to keep you logged in. We do not use advertising, tracking, or third-party analytics cookies.
8Security
We protect your data with: encrypted connections (HTTPS/TLS), JWT-based authentication, role-based access controls, row-level security, multi-tenant data isolation, and regular security reviews. In the event of a data breach likely to affect your rights, we will notify you and the ICO within 72 hours.
9Changes
We will notify you of material changes by email at least 14 days before they take effect.
10Contact
Email: tech@operyx.co.uk
Operyx Ltd, London, England