Version: 1.0.2 - Last updated: June 14, 2026
GuideOps, SASU (“GuideOps,” “we,” “our”) places the utmost importance on the protection of personal data. The purpose of this Privacy Policy (the “Policy”) is to inform you, in a clear, precise, and transparent manner, about the data processing activities carried out when you use the SaaS platform accessible at https://guideops.io, the GuideOps Extension web extension, and the GuideOps Desktop application (collectively, the “Services”).
This Policy expressly distinguishes between situations in which GuideOps acts as a data controller and those in which GuideOps acts as a data processor on behalf of its business customers. This distinction depends on the context in which the Services are used and the nature of the data involved.
This Policy applies to the processing of personal data carried out in connection with the Services. It covers, in particular:
Important: When GuideOps acts as a data processor for a business client, this Policy is not intended to replace that client’s privacy policy regarding its own users, employees, customers, or other data subjects.
Depending on the context, GuideOps may itself determine the purposes and means of processing, or, conversely, process data solely on behalf of a business client and in accordance with its instructions.
| Context of use | Description | Role of GuideOps | Role of the client / user | Data Primarily Involved |
|---|---|---|---|---|
| B2C Use | Use of the Services by an individual for their own personal needs. | Data Controller | Data Subject | Account, billing, usage, and support data, as well as content and data associated with the account, including images, videos, documents, audio, other media, and metadata. |
| B2B Use – Customer Data | Use of the Services by an organization to host, organize, share, operate, or analyze its own content and data via the Services. | Processor | Data Controller | Data and content imported, created, stored, shared, or analyzed via the Services on behalf of the business customer, including text, documents, images, videos, audio recordings, files and associated metadata (collectively, the “Customer Data”). |
| Management of contractual and operational relationships | Management of administrator accounts, contracts, billing, support, security, compliance, and communications with customers, including in a B2B context. | Data Controller | Client / client contact / data subject | Identification data, business contact information, billing data, technical logs, security information, and communications with support. |
Depending on the context of use, the Services may involve the processing of the following categories of data:
Images, videos, and other media may contain personal data directly or indirectly, for example:
This content may be particularly sensitive in practice and, depending on the circumstances, may reveal information falling under special categories of data. Users and clients must therefore exercise heightened caution before any upload or request for analysis.
GuideOps acts as the data controller when it determines the purposes and means of processing itself, particularly in the context of B2C use of the Services and the management of its contractual and operational relationship with its users and customers.
The data concerned is:
| Purpose of processing | Legal basis | Categories of data concerned |
|---|---|---|
| Creation and management of user accounts; general provision of Services | Performance of the contract | Identification data, login credentials, profile information, account preferences, information derived from federated authentication. |
| Hosting, organization, viewing, synchronization, and management of content associated with the account in a B2C context | Performance of the contract | Texts, documents, images, videos, audio files, other media, and associated metadata. |
| Provision of the AI image analysis feature when the user explicitly triggers it | Performance of the contract | Image submitted for analysis, instructions or context provided by the user, metadata necessary for processing the request, and results generated by the feature. |
| Management of the commercial relationship, subscriptions, billing, and payments | Performance of the contract and legal obligation, as applicable | Contact details, subscription information, transaction history, billing and accounting data. |
| Customer support and technical assistance | Contract performance and legitimate interest | Identification data, content of requests, correspondence, files sent to support, and technical logs necessary to process the request. |
| Service security, fraud prevention, incident detection, maintenance, and business continuity | Legitimate interest and, where applicable, legal obligation | IP addresses, connection logs, technical identifiers, usage data, security events, device and browser information. |
| Service improvement and generation of usage statistics | Legitimate interest | Usage data, user feedback, statistics, and aggregated data processed in accordance with applicable regulations. |
| Compliance with legal, accounting, and tax obligations and handling of requests to exercise rights | Legal obligation | Identification data, billing data, correspondence, information relating to legal and regulatory requests. |
When this feature is offered and activated by the user, GuideOps processes the relevant image and associated instructions to provide the requested result (e.g., description, information extraction, summary, classification, analysis assistance, or other processing explicitly triggered by the user in the interface).
Special Caution: You must not submit, via the image analysis feature, any content for which you do not have the necessary rights, permissions, or legal basis. If the image contains third-party data, minors, or sensitive data, heightened caution is required.
When the Services are used in a business context (B2B), GuideOps acts as a data processor for Customer Data that is hosted, accessed, organized, or analyzed via the Services. In this case, the business customer is the data controller.
The details of GuideOps’ obligations in this configuration are set forth in the Data Processing Agreement (“DPA”) when it is entered into between the parties and, in the absence thereof, in the applicable contractual documents. In essence, GuideOps undertakes to:
Client Data may include images, videos, media, files, and other content uploaded to the Services by the business client or its authorized users.
When the AI image analysis feature is used in a B2B context, GuideOps processes the submitted image, the associated instructions, and the generated results on behalf of the business customer and in accordance with the service’s functional parameters activated by that customer or its authorized users.
If a data subject sends us a request directly regarding Customer Data for which GuideOps acts as a processor, we will forward this request to the relevant customer, unless prohibited by law, and we will assist them in accordance with the terms of the contract.
We do not sell or rent personal data. Such data may be disclosed:
Some of our service providers may be located outside the European Economic Area (EEA) or involve access from a third country. In such cases, we ensure that transfers are governed by an appropriate mechanism in accordance with applicable regulations.
| Service Provider | Purpose | Location of processing | Transfer safeguards (if outside the EEA) |
|---|---|---|---|
| Microsoft Ireland Operations Limited | Hosting of infrastructure and databases | European Union | Not applicable |
| Cloudflare, Inc. | Content Delivery Network (CDN), security (WAF), media storage and technical delivery | Primary storage in the EU; transit and caching may occur outside the EEA | Standard Contractual Clauses (SCCs); Data Privacy Framework (DPF) certification |
| Stripe Payments Europe, Ltd. | Payment processing and subscription management | EEA; transfers to the United States possible | STC; Binding Corporate Rules (BCR); DPF certification |
| Google Cloud EMEA Limited | AI features, including AI image analysis when requested by the user, and Google Sign-In authentication | AI: eu; authentication: potentially global | AI: N/A; authentication: CCT; DPF certification |
| GitHub, Inc. (a Microsoft subsidiary) | GitHub Sign-In authentication | United States | CCT; DPF certification |
| Mailgun Technologies, Inc. | Sending transactional emails | EU (Germany); maintenance access possible from the United States | TTC; DPF certification |
The Services may include AI-based assistance features, particularly for generating or analyzing text content and, when requested by the user, for image analysis.
GuideOps implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account, in particular, the nature of the data processed and the risks to the rights and freedoms of data subjects.
These measures include, in particular:
Since no system is entirely risk-free, users and customers must also contribute to the security of the data they entrust to the Services, particularly by properly managing access permissions, sharing, passwords, and the sensitivity of uploaded content.
For data for which GuideOps acts as the data controller, you have the following rights, subject to the conditions set forth in applicable regulations:
To exercise these rights, you may write to us at contact@guideops.io. We commit to responding within the applicable legal timeframe, subject to necessary verifications and any extensions provided for by regulation.
If your request concerns Customer Data processed in a B2B context, you must first contact the relevant data controller (your employer, your organization or the client using the Services). GuideOps will assist this data controller in accordance with the terms of the contract.
You also have the right to file a complaint with the competent supervisory authority. In France, this is the Commission nationale de l’informatique et des libertés (CNIL).
As of the date of the last update to this Policy, we use only technical cookies and trackers that are strictly necessary for the operation of the Services and the provision of a specifically requested feature. These trackers do not require prior consent.
If non-essential trackers were to be deployed at a later date, GuideOps would provide appropriate information and, where required, a mechanism for obtaining prior consent.
For processing operations in which GuideOps acts as the data controller, the responsible entity is:
As of the date of the last update to this Policy, GuideOps has not appointed a Data Protection Officer (DPO) as defined by applicable regulations. If you have any questions regarding this Policy or the processing activities carried out by GuideOps in its capacity as data controller, please contact us using the contact information provided above.
GuideOps reserves the right to amend this Policy at any time, in particular to reflect legal, regulatory, technical, or functional changes to the Services. The applicable version is the one available online on the date of your visit. In the event of a substantial amendment, we will notify you by any appropriate means.