CorpOps.ai

Privacy Policy

Last updated: July 16, 2026

1. What We Collect

  • Email address — for account creation, authentication, and service communication.
  • Email address (marketing) — by creating an account, you agree to receive our monthly newsletter. You can opt out at any time in your Profile settings or via the unsubscribe link in any email.
  • AWS Account ID — the 12-digit identifier you provide to initiate a scan.
  • Scan metadata — timestamp, scan status, and the resulting Infrastructure Health Score.
  • Scan results — findings, dimension scores, and generated reports, stored to operate your account (see Section 4).
  • Billing information — processed entirely by Stripe. We never see or store your credit card details.

2. What We Don't Collect

  • AWS credentials, access keys, or secret keys.
  • Personal data of your customers or end-users.

Scans run from CorpOps EU infrastructure: you deploy a read-only access role (AWS CloudFormation, GCP Workload Identity pool, or Azure Entra app registration) and our scanner uses it to run read-only checks. Findings and reports are stored on CorpOps infrastructure in the EU (Stockholm), encrypted at rest and in transit, for as long as your account is active — after account deletion they are permanently removed within 30 days. Deleting the role, pool, or app registration stops all access instantly.

3. How We Use Your Data

  • To authenticate you and provide access to the CorpOps dashboard.
  • To compute your Infrastructure Health Score and generate your report.
  • To communicate service updates, scan results, and billing notifications.
  • To improve the product — aggregated, anonymized scores may inform our benchmarks.
  • Marketing communications — we use your email to send our monthly newsletter (see Section 1).

Marketing Communications. By creating an account, you agree to receive our monthly newsletter with cloud operations insights, AWS best practices, and product updates. You can opt out at any time via your Dashboard Profile settings or by clicking the unsubscribe link in any email. We use your email address solely for account-related communications and the newsletter.

4. Data Storage & Retention

All data is stored in AWS (eu-north-1 region) using encrypted services (DynamoDB, S3). We retain your scan history for as long as your account is active. Upon account deletion, all associated data is permanently removed within 30 days.

5. Third-Party Services

  • Stripe — payment processing. Stripe Privacy Policy.
  • AWS Cognito — authentication. Data remains in our AWS account.
  • Anthropic / AWS Bedrock — AI executive summary generation from scan results. No training on your data. Zero retention. EU-hosted (eu-north-1).

6. Your Rights (GDPR)

You have the right to access, correct, export, or delete your data at any time. Contact us and we'll respond within 72 hours.

7. Cookies

We use a single session cookie for authentication (Cognito token). When you consent via our cookie banner, we use Google Analytics (GA4) for page-view measurement, Google Ads for conversion tracking, and the Meta Pixel for marketing attribution — no analytics scripts load before you consent, and no personal data is collected beyond standard web analytics. You can manage your preferences at any time via the banner, your browser settings, or your Profile settings.

8. Contact

CorpOps.ai / Digital Future Solutions MB
Vilnius, Lithuania
Contact form
Response time: within 72 hours

Data Processing Agreement (DPA)