GDPR Article 30 register
OPSP (OPSP) is the data controller for the processing activities described below. Privacy / DSAR contact: support-opsp-3e3bf28a@saas-factory.ai.
| Purpose | Data categories | Lawful basis | Retention | Recipients / processors |
|---|---|---|---|---|
| Account creation and authentication | Email address, name, hashed password (if applicable), OAuth provider identifiers | Art. 6(1)(b) — performance of contract | Active account + 30 days after deletion | Auth provider (SaaS Factory Auth, AWS Cognito, Microsoft Entra, Google, GitHub, or Okta — depending on configured providers) |
| Service operation (the product's core functionality) | Whatever data the user submits to the product, plus diagnostic logs | Art. 6(1)(b) — performance of contract | Active subscription + 30 days; logs 30 days | Vercel (hosting), Neon (database), Cloudflare (CDN) |
| Billing and payment processing | Name, email, billing address, payment method metadata (card last 4, brand) | Art. 6(1)(b) — performance of contract; Art. 6(1)(c) — legal obligation (tax records) | 7 years (tax records) | Calmony Pay (payment processor) — full PAN never touches the controller's systems |
| Customer support and incident response | Email address, name, support ticket content (which may include screenshots) | Art. 6(1)(b) — performance of contract; Art. 6(1)(f) — legitimate interest in operating the service | 3 years from ticket close | Internal support team |
| Product improvement and analytics | Aggregated usage events (page views, feature usage), pseudonymous device identifier | Art. 6(1)(f) — legitimate interest in improving the service | 13 months | Internal analytics only — no third-party analytics processors |
| Security and fraud prevention | IP address, user agent, failed login attempts, suspicious activity flags | Art. 6(1)(f) — legitimate interest in service security | 12 months | Internal security team |
| Layer 1 — storing and displaying the organisation's One Page Strategic Plan (Core Values, Purpose, BHAG, 3–5 year targets, 1-year goals, quarterly Rocks, Critical Numbers, Quarterly Theme) | Company strategic-planning content; where an employee is named as a Rock owner, their name and role | Art. 6(1)(b) — performance of contract with the subscribing organisation; Art. 6(1)(f) — legitimate interest in running the business | Life of the subscription + 30 days; prior quarters retained for trend history (org-configurable) | Internal to the subscribing organisation and its authorised users only |
| Layer 2 — individual employee scorecards: measures, RAG (Super Green/Green/Yellow/Red) thresholds and status history, each traced up to a Rock | Employee name, role, department, scorecard measures (numeric/qualitative), RAG status history | Art. 6(1)(f) — legitimate interest in managing performance against the plan (this is employee performance data, handled with additional care — see Article 22 note below) | Rolling 12 months of scorecard history by default, then archived (org-configurable) | The employee, their manager, and the subscribing organisation's authorised admins |
| Layer 3 — ingesting daily stand-up messages posted in Microsoft Teams and using AI to score each stand-up against the posting employee's scorecard | Teams message content and author identity for the stand-up channels the org connects; AI-generated scores and commentary derived from that content | Art. 6(1)(f) — legitimate interest in monitoring delivery of the plan. This is employee monitoring / profiling: Article 22 safeguards apply, and some group companies may need employee notice or works-council consultation before enabling it — see the note below the table | Raw stand-up text: 90 days by default. AI-derived scores: retained with scorecard history (org-configurable) | Microsoft Teams (source, via the organisation's own connected account — Tether-managed, no vendor keys held by this product); the org's configured AI provider (processes stand-up text to produce a score, also via a Tether-managed connection); the employee and their manager |
| League Table — rolling scorecard + Rock + plan performance up into one ranked, live league table | Employee name, department, and RAG-derived ranking | Art. 6(1)(f) — legitimate interest in transparent, plan-aligned performance management | Same as underlying scorecard history | Internal to the subscribing organisation only — never shared outside the org |
Hosting and processing infrastructure is primarily located within the European Economic Area (Vercel EU regions, Neon EU regions). Where data is transferred outside the EEA — typically to US-based sub-processors — those transfers rely on Standard Contractual Clauses (SCCs) or equivalent safeguards.
EU/UK residents have the right to access, rectify, erase, restrict, port, or object to processing of their personal data, and to withdraw consent for processing based on consent. Exercise these rights by emailing support-opsp-3e3bf28a@saas-factory.ai; we respond within 30 days.
If we fail to address your concerns, you may lodge a complaint with your local supervisory authority. In the UK that is the ICO (ico.org.uk).
The League Table (Layer 3) is produced by AI scoring each employee’s Microsoft Teams stand-up against their own scorecard. Employees have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on them (e.g. a formal performance rating, disciplinary step, or pay decision). Subscribing organisations are responsible for: