Privacy Policy

Version: 1.0.2 - Last updated: June 14, 2026

GuideOps, SASU (“GuideOps,” “we,” “our”) places the utmost importance on the protection of personal data. The purpose of this Privacy Policy (the “Policy”) is to inform you, in a clear, precise, and transparent manner, about the data processing activities carried out when you use the SaaS platform accessible at https://guideops.io, the GuideOps Extension web extension, and the GuideOps Desktop application (collectively, the “Services”).

This Policy expressly distinguishes between situations in which GuideOps acts as a data controller and those in which GuideOps acts as a data processor on behalf of its business customers. This distinction depends on the context in which the Services are used and the nature of the data involved.

1. Purpose and Scope

This Policy applies to the processing of personal data carried out in connection with the Services. It covers, in particular:

Important: When GuideOps acts as a data processor for a business client, this Policy is not intended to replace that client’s privacy policy regarding its own users, employees, customers, or other data subjects.

2. Allocation of roles under the GDPR

Depending on the context, GuideOps may itself determine the purposes and means of processing, or, conversely, process data solely on behalf of a business client and in accordance with its instructions.

Context of use Description Role of GuideOps Role of the client / user Data Primarily Involved
B2C Use Use of the Services by an individual for their own personal needs. Data Controller Data Subject Account, billing, usage, and support data, as well as content and data associated with the account, including images, videos, documents, audio, other media, and metadata.
B2B Use – Customer Data Use of the Services by an organization to host, organize, share, operate, or analyze its own content and data via the Services. Processor Data Controller Data and content imported, created, stored, shared, or analyzed via the Services on behalf of the business customer, including text, documents, images, videos, audio recordings, files and associated metadata (collectively, the “Customer Data”).
Management of contractual and operational relationships Management of administrator accounts, contracts, billing, support, security, compliance, and communications with customers, including in a B2B context. Data Controller Client / client contact / data subject Identification data, business contact information, billing data, technical logs, security information, and communications with support.

3. Categories of data processed

Depending on the context of use, the Services may involve the processing of the following categories of data:

3.1. Focus on images, videos, and other media

Images, videos, and other media may contain personal data directly or indirectly, for example:

This content may be particularly sensitive in practice and, depending on the circumstances, may reveal information falling under special categories of data. Users and clients must therefore exercise heightened caution before any upload or request for analysis.

4. Processing carried out by GuideOps in its capacity as data controller

GuideOps acts as the data controller when it determines the purposes and means of processing itself, particularly in the context of B2C use of the Services and the management of its contractual and operational relationship with its users and customers.

4.1. Source of the data

The data concerned is:

Purpose of processing Legal basis Categories of data concerned
Creation and management of user accounts; general provision of Services Performance of the contract Identification data, login credentials, profile information, account preferences, information derived from federated authentication.
Hosting, organization, viewing, synchronization, and management of content associated with the account in a B2C context Performance of the contract Texts, documents, images, videos, audio files, other media, and associated metadata.
Provision of the AI image analysis feature when the user explicitly triggers it Performance of the contract Image submitted for analysis, instructions or context provided by the user, metadata necessary for processing the request, and results generated by the feature.
Management of the commercial relationship, subscriptions, billing, and payments Performance of the contract and legal obligation, as applicable Contact details, subscription information, transaction history, billing and accounting data.
Customer support and technical assistance Contract performance and legitimate interest Identification data, content of requests, correspondence, files sent to support, and technical logs necessary to process the request.
Service security, fraud prevention, incident detection, maintenance, and business continuity Legitimate interest and, where applicable, legal obligation IP addresses, connection logs, technical identifiers, usage data, security events, device and browser information.
Service improvement and generation of usage statistics Legitimate interest Usage data, user feedback, statistics, and aggregated data processed in accordance with applicable regulations.
Compliance with legal, accounting, and tax obligations and handling of requests to exercise rights Legal obligation Identification data, billing data, correspondence, information relating to legal and regulatory requests.

4.3. AI image analysis at the user’s request

When this feature is offered and activated by the user, GuideOps processes the relevant image and associated instructions to provide the requested result (e.g., description, information extraction, summary, classification, analysis assistance, or other processing explicitly triggered by the user in the interface).

Special Caution: You must not submit, via the image analysis feature, any content for which you do not have the necessary rights, permissions, or legal basis. If the image contains third-party data, minors, or sensitive data, heightened caution is required.

4.4. Retention Periods

5. Processing carried out by GuideOps as a data processor

When the Services are used in a business context (B2B), GuideOps acts as a data processor for Customer Data that is hosted, accessed, organized, or analyzed via the Services. In this case, the business customer is the data controller.

The details of GuideOps’ obligations in this configuration are set forth in the Data Processing Agreement (“DPA”) when it is entered into between the parties and, in the absence thereof, in the applicable contractual documents. In essence, GuideOps undertakes to:

5.1. Client Data including images, videos, and other media

Client Data may include images, videos, media, files, and other content uploaded to the Services by the business client or its authorized users.

5.2. AI Image Analysis on Behalf of a Business Customer

When the AI image analysis feature is used in a B2B context, GuideOps processes the submitted image, the associated instructions, and the generated results on behalf of the business customer and in accordance with the service’s functional parameters activated by that customer or its authorized users.

5.3. Requests from Data Subjects in a B2B Context

If a data subject sends us a request directly regarding Customer Data for which GuideOps acts as a processor, we will forward this request to the relevant customer, unless prohibited by law, and we will assist them in accordance with the terms of the contract.

6. Sub-processors, Recipients, and Transfers

We do not sell or rent personal data. Such data may be disclosed:

Some of our service providers may be located outside the European Economic Area (EEA) or involve access from a third country. In such cases, we ensure that transfers are governed by an appropriate mechanism in accordance with applicable regulations.

Service Provider Purpose Location of processing Transfer safeguards (if outside the EEA)
Microsoft Ireland Operations Limited Hosting of infrastructure and databases European Union Not applicable
Cloudflare, Inc. Content Delivery Network (CDN), security (WAF), media storage and technical delivery Primary storage in the EU; transit and caching may occur outside the EEA Standard Contractual Clauses (SCCs); Data Privacy Framework (DPF) certification
Stripe Payments Europe, Ltd. Payment processing and subscription management EEA; transfers to the United States possible STC; Binding Corporate Rules (BCR); DPF certification
Google Cloud EMEA Limited AI features, including AI image analysis when requested by the user, and Google Sign-In authentication AI: eu; authentication: potentially global AI: N/A; authentication: CCT; DPF certification
GitHub, Inc. (a Microsoft subsidiary) GitHub Sign-In authentication United States CCT; DPF certification
Mailgun Technologies, Inc. Sending transactional emails EU (Germany); maintenance access possible from the United States TTC; DPF certification

7. Artificial Intelligence Features

The Services may include AI-based assistance features, particularly for generating or analyzing text content and, when requested by the user, for image analysis.

8. Data Security

GuideOps implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account, in particular, the nature of the data processed and the risks to the rights and freedoms of data subjects.

These measures include, in particular:

Since no system is entirely risk-free, users and customers must also contribute to the security of the data they entrust to the Services, particularly by properly managing access permissions, sharing, passwords, and the sensitivity of uploaded content.

9. Your Rights

For data for which GuideOps acts as the data controller, you have the following rights, subject to the conditions set forth in applicable regulations:

To exercise these rights, you may write to us at contact@guideops.io. We commit to responding within the applicable legal timeframe, subject to necessary verifications and any extensions provided for by regulation.

If your request concerns Customer Data processed in a B2B context, you must first contact the relevant data controller (your employer, your organization or the client using the Services). GuideOps will assist this data controller in accordance with the terms of the contract.

You also have the right to file a complaint with the competent supervisory authority. In France, this is the Commission nationale de l’informatique et des libertés (CNIL).

10. Cookies and Other Trackers

As of the date of the last update to this Policy, we use only technical cookies and trackers that are strictly necessary for the operation of the Services and the provision of a specifically requested feature. These trackers do not require prior consent.

If non-essential trackers were to be deployed at a later date, GuideOps would provide appropriate information and, where required, a mechanism for obtaining prior consent.

11. Identity and Contact

For processing operations in which GuideOps acts as the data controller, the responsible entity is:

As of the date of the last update to this Policy, GuideOps has not appointed a Data Protection Officer (DPO) as defined by applicable regulations. If you have any questions regarding this Policy or the processing activities carried out by GuideOps in its capacity as data controller, please contact us using the contact information provided above.

12. Changes to the Policy

GuideOps reserves the right to amend this Policy at any time, in particular to reflect legal, regulatory, technical, or functional changes to the Services. The applicable version is the one available online on the date of your visit. In the event of a substantial amendment, we will notify you by any appropriate means.