Security
Security, hosting and data protection
OpsThread holds the operational data your organisation runs on: records, files and the history behind them. This page sets out where that data lives, who can reach it, and how it’s protected.
Where your data lives
OpsThread runs in the EU. The platform, your records and your uploaded files are hosted in the Frankfurt region, and OpsThread is operated from Germany by a German business.
Some optional channels work differently. If you use WhatsApp to reach people as part of a workflow, that message is delivered by WhatsApp and travels through their infrastructure, which might sit outside the EU. The same applies to certain other optional integrations you choose to switch on.
If you need the specifics for your own data protection assessment, please email privacy@opsthread.com. The full list of providers we rely on forms part of the Data Processing Agreement.
Separation between customers
Each customer has a dedicated database. Your records are held separately from those of every other customer.
There is no route from one customer’s account to another customer’s records, because those records are not held in the same place. Backups, restores and deletion are performed per customer for the same reason.
Who can see what
Access control is enforced by the platform itself, not by the interface. Every request for a record is checked against the role and scope of the person making it before any data is returned. A record someone isn’t entitled to see is never sent to them, whatever route they take to ask for it.
OpsThread runs a dedicated authorisation engine that sits between the application and your data. Every read and every change passes through it, so access rules are applied consistently across the whole platform rather than being implemented separately in each part of it.
Roles are defined around your organisation rather than selected from a fixed set of tiers, and permissions apply to individual records rather than blanket read or write access. That matters for registers where a safeguarding lead sees entries a delivery tutor must not.
Audit history
Every action against a record is written to a traceable history: who did it, what changed, and when. The history exports for review.
This is built for the moment you have to show, after the fact, that a process was followed. An inspection, an investigation, an internal review.
Data protection and GDPR
OpsThread acts as a processor; you remain the controller of your data.
- Registered with the UK Information Commissioner’s Office, reference ZC197406
- A GDPR-compliant Data Processing Agreement is provided with every contract, covering purpose limitation, subprocessors, security measures, breach notification and deletion on termination
- Retention and deletion schedules are configured per customer and enforced by the platform rather than run as a manual annual exercise
- On termination, your data is exported to you and deleted within 30 days
Providers we rely on
OpsThread runs on selected infrastructure and service providers. The full list, with what each one does and where it operates, forms part of the Data Processing Agreement. If you need it before that point, email privacy@opsthread.com and we’ll send it over.
We notify customers before adding or changing a provider that processes their data.
Backups and recovery
Your data is backed up regularly and can be restored. Backups run automatically, are held for a defined retention period, and the restore process is tested rather than assumed.
If you need specific figures for a due diligence questionnaire, email privacy@opsthread.com.
Reporting a security issue
If you believe you’ve found a vulnerability in OpsThread, email security@opsthread.com. We’ll acknowledge within three working days and keep you updated until it’s resolved.
Frequently asked questions
Where is my data stored?
In the EU. The platform and your records are hosted in the Frankfurt region. Some optional channels, such as WhatsApp messaging, might be delivered by providers operating outside the EU.
Is my data separated from other customers?
Yes. Each customer has their own database rather than sharing one with other organisations.
Are you GDPR compliant?
OpsThread acts as your data processor and provides a GDPR-compliant DPA with every contract. We’re registered with the ICO under reference ZC197406.
Can we get our data out?
Yes, at any time and in open formats.
Do you use our data to train AI models?
No. Your data isn’t used to train AI models.
Questions your IT or data protection team need answered?
Send them this page, or book a call and we’ll go through your requirements directly.
Or email hello@opsthread.com directly.
