Legal & Trust
Privacy & Data Protection Policy
When a CPA firm works with OPS-Automate, it entrusts us with something serious: access to its clients' books — bank activity, payroll, vendor and customer records. This policy explains, in plain language, how we protect that data. It also covers, briefly, the data of visitors to this website. Our practices are aligned with the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), and we never sell data of any kind.
1. The data firms entrust to us
During an engagement, our accountants work with your firm's accounting data and, through it, your clients' financial data. Our commitments:
- Your systems, your credentials. All work happens inside the software your firm controls — QuickBooks, Xero, your document and practice tools — under user accounts that you create and can revoke at any moment. We never ask for shared or owner logins.
- No local copies. Data stays in your systems. Our accountants do not download client files, export databases, or store your records on personal devices, external drives, or personal email/cloud accounts. Where a task genuinely requires a working file, it lives in a location your firm designates and controls.
- Least-privilege access. Each accountant gets access only to the client files in their assigned scope — not your whole practice. Payment release, money movement, and client communication stay with your firm; we prepare, you approve.
- Monitored workstations. Time Doctor runs on every accountant's workstation for the full shift, with activity monitoring your firm can see. Work happens on managed setups, not anonymous devices.
- Confidentiality in writing. Every OPS-Automate accountant and success manager is bound by written confidentiality obligations covering your data and your clients' data, which survive the end of the engagement.
- Purpose limitation. We use your data only to perform the work you assign. Never for marketing, never for any other client, never for training or any secondary purpose. Under GDPR terms, your firm acts as the data controller and we act on your documented instructions.
- Offboarding is clean. When an engagement ends — or an accountant is replaced — you revoke access, and we certify that no copies of your data remain with us. Our handover process transfers documented workflows, not data.
- If something goes wrong. In the unlikely event of a security incident affecting your data, we notify your firm without undue delay, tell you plainly what happened, and cooperate fully with your response — including any notification duties your firm has to its own clients or regulators.
2. Your clients' rights
If your client exercises a data right (access, correction, deletion) that touches work we performed, we assist your firm in fulfilling it promptly. Requests always route through your firm as the client relationship owner.
3. Website visitors
This website collects very little: information you submit through the contact form (name, firm, work email, your message) and standard aggregate analytics via Google Analytics (pages visited, device type, approximate location). We use this to respond to your enquiry and improve the site. We do not run advertising trackers and we do not sell visitor data. You can block cookies in your browser without losing access to any part of the site.
4. Your rights (GDPR & CCPA)
Whether you are a firm contact or a site visitor, you can request access to, correction of, or deletion of your personal data, ask for a copy (portability), or object to processing. California residents can additionally request to know and to opt out of the sale of personal information — we sell none. Email hello@ops-automate.com; we respond within 30 days.
5. Contact
Questions about this policy or our data practices — including security questionnaires from your firm — are welcome:
OPS-Automate · hello@ops-automate.com · (469) 559-6121