Resources · Trust

Trust and compliance.

Our certification status, where your data is held, and the documents a procurement team asks for. Everything here is checkable.

In progress

ISO/IEC 27001

2022 revision

Implementation phase

The information security management system is being implemented with Sprinto, ahead of an independent audit through a certification body accredited by the International Accreditation Forum. The certificate is published here on issue.

In progress

UK GDPR

Data Protection Act 2018

Readiness assessment

Sprinto is running a readiness assessment against UK requirements, followed by implementation of the practices it identifies. Our supervisory authority is the Information Commissioner’s Office, we are registered with it, and our privacy notices are published.

In progress

EU GDPR

Regulation 2016/679

Readiness assessment

The same engagement covers the EU position. Service data is already hosted in the European Union, and the outcome includes a Data Processing Agreement so customers can use Operify AI as a processor. Transfers outside the EEA rely on standard contractual clauses, listed on the sub-processors page.

Active

ICO registration

Reference ZB905842

Active

Codedevza AI Ltd is registered with the Information Commissioner’s Office as a data controller, registered 30 May 2025. The entry is verifiable on the ICO’s public register.

Today

What is true today

Each of these is either a fact about our infrastructure or a statement in our published privacy policy.

Your data is held in the EU

Service data and uploaded files are hosted in the European Union. The one exception is the AI assistant in the administrative console, processed in the United States under standard contractual clauses, set out in full on our sub-processors page.

Encrypted in transit

Everything moves over HTTPS. Access to production is restricted and administrative access is limited to the people who need it.

No advertising, no tracking

The mobile app carries no advertising and no cross-app trackers, and does not collect a device advertising identifier. This website sets no cookies at all on its public pages and runs no analytics. The fonts are served from our own domain, so loading a page tells nobody else you were here.

No biometric data

Fingerprint and face unlock are handled entirely by the device operating system. We receive a confirmation that authentication succeeded and never receive or store the biometric itself.

AI processing is disclosed and constrained

The administrative console assistant is powered by OpenRouter, configured to exclude providers that retain request data or train on it. It is not part of the mobile app and cannot be reached from it.

Deletion actually works

An operative can delete their account from the app and we action it within 30 days. What is deleted, and what your organisation may be legally required to keep, is written out in full rather than summarised.

Data

Where your data sits

Controller and processor

For workplace records such as shifts, timesheets, incidents and audits, your organisation is the data controller and Operify AI is the processor. We are the controller only for the small set of data needed to run and secure the service itself.

Special category data

Sickness absence, fit notes and injury details in incident reports are Article 9 data. They are processed only under an employment, social security or occupational health condition, and access is restricted accordingly.

Sub-processors

Every category of third party that touches personal data on our behalf is listed, with what it does and where it processes. We update that page when the list changes.

Retention

Retention is set by your instructions as controller and by law. When data is no longer needed it is deleted or anonymised, and residual copies in backups expire on their normal cycle.

Documents

The documents

Everything published, in one place. If a tender asks for something not here, ask us.

Ask us something harder

Security questionnaires, a DPA, penetration test summaries, hosting detail for a tender: email hello@operifyai.co.uk and a person will answer. If you believe you have found a vulnerability, use the same address with "Security report" in the subject line, and give us a reasonable chance to fix it before disclosing.

Bring us the questionnaire.

Thirty minutes, no slides. Bring a contract and the hardest question your client asks you.