Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains what data Fortaris's Ops Control platform (the "Service") collects, why, and how it's handled. We act as the data controller for account and business data you provide, and as outlined below, share data with the specific third-party processors needed to run the Service.
1. What we collect
- Account data: name, email, password (hashed) or Google account ID.
- Business data you create: agent configurations and task history, contacts, revenue entries, calendar events, uploaded documents, and messages you send through the platform.
- Connected account data: if you connect Google, we store an encrypted refresh token and use it only for the scopes you explicitly grant (sending email, reading a support inbox, or calendar access), never your Google password.
- Usage data: agent run history, token usage, and timestamps, used for billing and plan enforcement.
2. Third parties we share data with
Processing your data through the Service necessarily involves these providers:
- Anthropic: receives task content and prompts to generate agent output.
- Google: Gmail/Calendar APIs, only for scopes you grant, only for your own account.
- Supabase: hosts our database (all account and business data).
- Resend: sends transactional and campaign email on your behalf where configured.
- Stripe: payment processing for ventures that accept payments, where connected.
- Vercel: hosting and domain registration for ventures you launch, where connected.
We don't sell your data, and we don't share it with anyone beyond what's needed to run the Service.
3. Why we process it
To provide the Service you signed up for (contract), to keep it secure (legitimate interest, e.g. rate limiting, abuse prevention), and, where applicable, to comply with legal obligations (e.g. financial record-keeping for billing).
4. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your account and associated data.
- Export your data in a portable format.
- Withdraw consent for a connected integration (e.g. disconnect Google) at any time from Settings.
To exercise any of these, email hello@fortarisgroup.co.uk, or contact the account owner listed on your Admin page if you're already a customer.
5. Data retention
We retain account and business data for as long as your account is active. After cancellation, data is retained for a reasonable period (to allow reactivation) and then deleted, unless you request earlier deletion.
6. Security
Passwords are hashed, not stored in plaintext. OAuth refresh tokens are encrypted at rest. We apply rate limiting on authentication endpoints. No system is perfectly secure. If we become aware of a breach affecting your data, we'll notify affected account owners without undue delay.
7. Cookies
We use a single essential session cookie to keep you signed in. We don't use tracking or advertising cookies.
8. Changes to this policy
We may update this policy from time to time. Material changes will be noted with an updated "Last updated" date.
9. Contact
Questions about this policy or your data: email hello@fortarisgroup.co.uk, or contact the account owner listed on your Admin page if you're already a customer.
This document is a general-purpose starting template and hasn't been reviewed by a lawyer. If you're taking on clients in the UK/EU, have it reviewed against UK GDPR/GDPR requirements specifically before relying on it, particularly around lawful basis, international data transfers, and a named data protection contact.