Legal

Mobile app and platform privacy policy

How we handle personal data in the Operify AI app and platform: what we collect, our legal bases, who sees it, and how to get it removed. If you are looking for what this website collects, read the website privacy policy instead.

Last updated 22 July 2026

This Privacy Policy explains how Codedevza AI Ltd ("Operify", "we", "us", or "our"), the company that operates the Operify AI app, collects, uses, shares, and protects information when you use the Operify AI mobile application (the "App") and related services (together, the "Service").

Please read it carefully. If you do not agree with it, please do not use the App.

Note for reviewers and users: Operify AI is workplace software provided to you by your employer or the organisation you work with ("your Organisation"). You need an invitation from your Organisation to create an account and sign in. Much of the data in the App is entered, managed, and controlled by your Organisation.

1. Who is responsible for your data (controller and processor)

Because Operify AI is provided to you through your Organisation, responsibility for your personal data is shared:

  • Your Organisation is the "data controller" for most of the personal data processed in the App (for example, your work profile, shifts, tasks, timesheets, attendance, incidents, and audits). Your Organisation decides why and how that data is used, in line with its own policies and its employment or engagement relationship with you.
  • Operify acts as a "data processor" for that data. We process it on your Organisation's behalf and under its instructions, to provide the Service.
  • Operify is the "data controller" only for a limited set of data we need to run and secure the Service itself (for example, account sign-in records and technical logs).

If you have questions about how your Organisation uses your data, or you want to exercise your data rights over Organisation-controlled data, please contact your Organisation first. We will support your Organisation in responding to such requests.

2. Information we collect

The App's features will evolve over time; the examples below are illustrative of the categories of data the Service processes. Where a new feature materially changes our data practices, we will update this Policy.

We collect the following categories of information:

2.1 Account and identity information

  • Your email address, which is used with a password to sign you in. Passwords are stored securely hashed and are never kept in plaintext.
  • Your name, role/job title, and the Organisation you belong to.
  • Contact details you provide during onboarding, such as your phone number and postal address.
  • Your date of birth and, where your Organisation's onboarding requires it, your National Insurance number (or equivalent tax/identity reference).
  • Emergency contact details you choose to provide (that person's name, relationship, and phone number).

2.2 Employment, payroll and right-to-work information

Where your Organisation's onboarding requires it, and only for those purposes, we process:

  • Bank/payroll details you enter (account name, sort code, and account number) so your Organisation can pay you.
  • Identity and eligibility documents you upload, such as proof of address, right-to-work documents, and photo ID.

2.3 Work and operational information

  • Shifts, jobs, tasks, checklists, and forms you view or complete.
  • Time and attendance data, including clock-in and clock-out times and timesheets.
  • Checkpoint scans (QR) used to confirm you are at a location. These record a checkpoint identifier and time, not your continuous movements.
  • Incidents, quality audits, inspections, and safety records you create or contribute to.
  • Leave/time-off requests and recognition ("kudos") you send or receive.
  • Photos, notes, and signatures you add as part of tasks, incidents, evidence, or acknowledgements.

2.4 Health-related information (special category data)

Some features involve health information, which is treated as "special category" data under UK/EU data-protection law and processed only under the conditions in Section 3:

  • Sickness absence. When you request sick leave, we process the fact and dates of that absence and any fit note (medical certificate) you choose to upload.
  • Incident and accident reports may include injury or health information about you or other people involved.

2.5 Location information

  • We collect your device's precise location only at the moment you clock in or out (and when you complete a location-verified audit or report), to help verify that you are on site. We do not track your location continuously and we do not monitor your location between such events. See Section 4 for details.

2.6 Device and technical information

  • Basic device and app information (such as app version, device model, and operating system) needed to operate and troubleshoot the Service.
  • Diagnostics and crash information. We use an error-reporting tool to detect and fix crashes and technical problems. It collects technical information such as app version, device type, and error logs, hosted in the European Union. Where we later enable product-analytics tooling to understand app usage and improve the App, we will process it on the same EU-hosted, no-advertising basis and update this Policy. None of this data is used for advertising or cross-app tracking, and the App does not collect a device advertising identifier.

2.7 Information we do not collect

  • We do not collect your biometric data. Fingerprint or face unlock, if you enable it, is handled entirely by your device's operating system; Operify only receives a confirmation that authentication succeeded and never receives or stores your fingerprint or face data.
  • We do not use your data for advertising, and the App does not contain ads.
  • We do not sell your personal data.

3. How we use your information and our legal bases

We use the information above to:

  • Create and secure your account and sign you in.
  • Provide the core features of the App (shifts, tasks, time and attendance, incidents, audits, and related workplace functions).
  • Verify on-site presence at clock-in/clock-out (see Section 4).
  • Communicate with you about the Service (for example, in-app notifications and updates).
  • Keep the Service safe, prevent misuse, and diagnose and fix technical problems.
  • Comply with legal and regulatory obligations.

Where the UK GDPR and EU GDPR apply, we (and your Organisation) rely on one or more of the following legal bases:

  • Performance of a contract or your Organisation's employment/engagement relationship with you.
  • Legitimate interests of your Organisation and Operify in running a safe, accountable, and efficient operation (for example, verifying attendance and maintaining safety and audit records), balanced against your rights.
  • Legal obligation, where processing is required by law (for example, working-time or health-and-safety record-keeping).
  • Consent, where we specifically ask for it (for example, the operating-system permission you grant for location).

Special category and sensitive data. Some information, in particular health information (such as sickness records, fit notes, and any health or injury details in incident reports), is "special category" personal data under Article 9 of the UK/EU GDPR. We and your Organisation process it only where a lawful condition applies, in particular where processing is necessary for carrying out obligations and exercising rights in the field of employment, social security, and social protection law (for example, managing sickness absence and statutory sick pay, and meeting health-and-safety obligations), for occupational health purposes, or with your explicit consent. Your bank/payroll details, date of birth, National Insurance number, and right-to-work / identity documents are processed to pay you and to meet tax, payroll, and right-to-work obligations, on the basis of contract, legal obligation, and your Organisation's legitimate interests. We collect only what is needed for these purposes and restrict access accordingly.

4. Location data (important)

  • Location is used for a single purpose: to verify your presence at a work site when you clock in or out.
  • Location is captured only at the moment of a clock-in or clock-out action. It is not collected in the background and not collected while you are simply using other parts of the App.
  • You control the operating-system location permission and can change or withdraw it at any time in your device settings. If you decline location access, you may still be able to clock in, but your Organisation may not be able to automatically confirm your on-site presence.

5. How we share your information

We share information only as described below. We do not sell your personal data.

  • With your Organisation. Your managers and authorised administrators within your Organisation can access the work data associated with you (for example, your attendance, task completion, incidents, and audits). This is the core purpose of the App.
  • With service providers (sub-processors). We use trusted third parties to host and operate the Service on our behalf, such as: cloud hosting and databases, file/object storage for uploaded photos and documents, and email delivery (for account invitations and password resets). Where enabled, we may also use error-monitoring and product-analytics providers. These providers process data only on our instructions and under contractual confidentiality and data-protection obligations. A current list of sub-processors is available on request.
  • AI-assisted features (administrative console). Your Organisation's authorised administrators can use an AI assistant in the Operify administrative console. When they do, their queries and the relevant workspace data needed to answer them, which can include work data about you, such as your profile, shifts, tasks, timesheets, attendance, incidents, and audit records, are processed by our AI infrastructure provider, OpenRouter, Inc., which routes each request to a large-language-model provider solely to generate the assistant's response. We configure OpenRouter to exclude providers that retain request data or use it for model training, and this data is processed on our instructions under data-processing terms. This processing may take place in the United States, protected by appropriate safeguards such as standard contractual clauses. The AI assistant is not part of the mobile App and cannot be accessed from it.
  • For legal and safety reasons. We may disclose information where required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of users, the public, Operify, or your Organisation.
  • In a business transfer. If Operify is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

6. Third-party services

The App relies on the following categories of third-party services to function. The specific providers may change over time:

  • Cloud hosting and database: to run the Service and store your work data.
  • File / object storage: to store photos, documents, and signatures you upload.
  • Email delivery: to send account invitations and password-reset links.
  • Error monitoring and diagnostics (if enabled): to detect and fix crashes and technical issues.
  • Product analytics (if enabled): to understand how the App is used and improve it.
  • AI processing (administrative console): to power the AI assistant available to organisational administrators (see Section 5).

We host and process personal data in the European Union, except that AI-assistant processing (administrative console, Section 5) may take place in the United States under appropriate safeguards, and we require every provider that processes personal data on our behalf to do so only on our instructions and under appropriate security and data-protection safeguards. A current list of sub-processors is available on request and on our Sub-processors page.

7. Data retention

We retain personal data for as long as your account is active and for as long as needed to provide the Service to your Organisation. Retention periods are primarily determined by your Organisation's instructions and by legal requirements (for example, health-and-safety or employment record-keeping). When data is no longer needed, we delete it or anonymise it. Your Organisation may also delete or export data at any time.

8. Security

We use appropriate technical and organisational measures to protect your information, including encryption in transit (HTTPS), access controls, and restricted administrative access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work to protect your data and to address vulnerabilities promptly.

9. International data transfers

We host and process personal data primarily within the European Union (EU/EEA). Because Operify is provided by a UK company and may be used by people in the UK and elsewhere, some data may be transferred between the UK and the EU/EEA; such transfers are covered by adequacy decisions recognised in both directions. If we ever transfer personal data to a country without an adequacy decision, we rely on appropriate safeguards recognised under UK and EU data-protection law, such as standard contractual clauses.

10. Your rights

Depending on where you live, you may have rights over your personal data, including the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete data.
  • Erase your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Data portability: receive your data in a portable format.
  • Withdraw consent where processing is based on consent (for example, location).

Because much of your data is controlled by your Organisation, please contact your Organisation first to exercise these rights. You can also contact us using the details in Section 13, and we will help facilitate your request. If you are in the UK or EEA and believe your rights have been infringed, you may lodge a complaint with your local data-protection authority (in the UK, the Information Commissioner's Office, ico.org.uk).

11. Deleting your account and data

To request deletion of your account and associated personal data:

  • Contact your Organisation, who can remove your account and data, or
  • Email us at hello@operifyai.co.uk with your request, and we will action it in coordination with your Organisation.

We will respond to deletion requests within the timeframes required by applicable law. Some data may be retained where we are legally required to keep it, or for the establishment, exercise, or defence of legal claims.

Full details, including what is deleted and what may be retained: see our Account & Data Deletion page.

12. Children's privacy

Operify AI is workplace software intended for use by adults (18 and over) in a professional context. It is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can remove it.

13. Contact us

If you have questions about this Privacy Policy or our data practices, contact us at:

  • Codedevza AI Ltd (Company No. 16485057, registered in England and Wales)
  • 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
  • Email: hello@operifyai.co.uk
  • Website: operifyai.co.uk

14. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top and, where appropriate, notify you within the App. Your continued use of the App after changes take effect means you accept the updated Policy.