Trust and compliance.
Our certification status, where your data is held, and the documents a procurement team asks for. Everything here is checkable.
ISO/IEC 27001
2022 revision
Implementation phase
The information security management system is being implemented with Sprinto, ahead of an independent audit through a certification body accredited by the International Accreditation Forum. The certificate is published here on issue.
UK GDPR
Data Protection Act 2018
Readiness assessment
Sprinto is running a readiness assessment against UK requirements, followed by implementation of the practices it identifies. Our supervisory authority is the Information Commissioner’s Office, we are registered with it, and our privacy notices are published.
EU GDPR
Regulation 2016/679
Readiness assessment
The same engagement covers the EU position. Service data is already hosted in the European Union, and the outcome includes a Data Processing Agreement so customers can use Operify AI as a processor. Transfers outside the EEA rely on standard contractual clauses, listed on the sub-processors page.
ICO registration
Reference ZB905842
Active
Codedevza AI Ltd is registered with the Information Commissioner’s Office as a data controller, registered 30 May 2025. The entry is verifiable on the ICO’s public register.
What is true today
Each of these is either a fact about our infrastructure or a statement in our published privacy policy.
Your data is held in the EU
Service data and uploaded files are hosted in the European Union. The one exception is the AI assistant in the administrative console, processed in the United States under standard contractual clauses, set out in full on our sub-processors page.
Encrypted in transit
Everything moves over HTTPS. Access to production is restricted and administrative access is limited to the people who need it.
No advertising, no tracking
The mobile app carries no advertising and no cross-app trackers, and does not collect a device advertising identifier. This website sets no cookies at all on its public pages and runs no analytics. The fonts are served from our own domain, so loading a page tells nobody else you were here.
No biometric data
Fingerprint and face unlock are handled entirely by the device operating system. We receive a confirmation that authentication succeeded and never receive or store the biometric itself.
AI processing is disclosed and constrained
The administrative console assistant is powered by OpenRouter, configured to exclude providers that retain request data or train on it. It is not part of the mobile app and cannot be reached from it.
Deletion actually works
An operative can delete their account from the app and we action it within 30 days. What is deleted, and what your organisation may be legally required to keep, is written out in full rather than summarised.
Where your data sits
Controller and processor
For workplace records such as shifts, timesheets, incidents and audits, your organisation is the data controller and Operify AI is the processor. We are the controller only for the small set of data needed to run and secure the service itself.
Special category data
Sickness absence, fit notes and injury details in incident reports are Article 9 data. They are processed only under an employment, social security or occupational health condition, and access is restricted accordingly.
Sub-processors
Every category of third party that touches personal data on our behalf is listed, with what it does and where it processes. We update that page when the list changes.
Retention
Retention is set by your instructions as controller and by law. When data is no longer needed it is deleted or anonymised, and residual copies in backups expire on their normal cycle.
The documents
Everything published, in one place. If a tender asks for something not here, ask us.
Ask us something harder
Security questionnaires, a DPA, penetration test summaries, hosting detail for a tender: email hello@operifyai.co.uk and a person will answer. If you believe you have found a vulnerability, use the same address with "Security report" in the subject line, and give us a reasonable chance to fix it before disclosing.
Bring us the questionnaire.
Thirty minutes, no slides. Bring a contract and the hardest question your client asks you.