EExOpsBack to ExOps

ExOps privacy policy

How the ExOps app handles personal data · Version 2 · 24 September 2026

This policy explains what the ExOps app does with personal data. It covers everyone who comes into contact with it: the companies that use it to run their business, the staff and subcontractors who sign in to it, and the customers of those companies who use the portal or receive an email, a text or a certificate from it.

It is written to be read. If anything in it is unclear, ask us and we will explain it plainly — and if the explanation is needed, the policy needs rewriting, so tell us that too.

Who we are

ExOps is supplied by M J Electrical and Technical Ltd, company number 10155038, of 135 Powell Avenue, Blackpool FY4 3HQ.

Contact for anything in this policy: admin@mjelectricalandtechnical.co.uk or 01253 366033.

We are registered with the Information Commissioner's Office. You can complain to the ICO at ico.org.uk/make-a-complaint or 0303 123 1113. We would rather you came to us first, but you do not have to.

The part that decides everything else: who controls what

Data protection law turns on whether an organisation decides what happens to personal data (the controller) or handles it on somebody else's instructions (the processor). ExOps is both, for different things, and it matters which is which.

The dataControllerOur role
Everything inside a company's account — their customers, jobs, quotes, invoices, certificates, staff records, photographsThat companyWe are their processor. We hold it and run it for them, on their instructions, under a written data processing agreement. We do not use it for our own purposes.
The account itself — who signed the company up, the people we deal with, billing, support conversations, security logsUsWe are the controller of that.

So if you are a customer of a company that uses ExOps and you want your records changed or erased, ask that company: they decide, and the app gives them the tools to do it. If they cannot, they can ask us and we will act for them.

What the app holds, and why

For a company using ExOps, as their processor: names and contact details; site and home addresses; job, quote, invoice and payment records; photographs, videos and site recordings; electrical certificates and test results; employment records including pay, hours, holiday, sickness and training; right-to-work checks; the fact and outcome of a DBS check where one was done; vehicle and location records for vans and clock-ins; subcontractor and supplier details. Special category data (health) and criminal offence data (DBS outcomes) are held only where that company's own policies allow it.

For ourselves, as controller:

WhatWhyLawful basis
The account holder's name, email, phone and company detailsTo run the account, support it and bill for itContract
Billing records and payment referencesTo take payment and keep accountsContract, and legal obligation for tax
Sign-in records, IP addresses, device type, and a log of what was changed and whenSecurity, fraud prevention, and being able to show who did whatLegitimate interests (keeping the service secure), and legal obligation where a record must be kept
Error reports and performance logsTo find and fix faultsLegitimate interests (a working service)
Support emails and messagesTo answer them and to improve the productLegitimate interests
Usage counts per company — jobs created, emails read, AI callsTo bill fairly and size the serviceContract, legitimate interests

We do not sell personal data. We do not show advertising in ExOps and we do not let anyone pay to be promoted inside it. We do not build profiles of individuals for marketing, and nothing in the app makes a decision about a person by itself.

Artificial intelligence

ExOps uses Google's Gemini models, run in Google Cloud's London region, to draft things a person then checks: a risk assessment for a job, a summary of an enquiry email, a transcription of a consumer unit photograph, a short briefing for an engineer.

Three rules apply to all of it. The model is only ever shown records the company already holds. Nothing it writes is sent to a customer or relied on as a record until a competent person has read it. And the data is not used to train Google's models — that is contractual, not a hope.

Who else is involved

We use other companies to run parts of the service. Each is under a written contract, and each is only allowed to do what we tell them.

WhoWhat they doWhere
Google Cloud / FirebaseHosting, database, file storage, phone notifications, and the AI featuresEU and UK (London region)
BrevoSending emails and text messagesEU
StripeCard payments, where a company switches them onUK, EU, US
Xero, Intuit (QuickBooks) or SageA company's own accounts package, only the one they connect and only once they connect itUK and EU
postcodes.ioTurning a postcode into a map position — only the postcode is sentUK
VelocityVehicle tracking, where a company has trackers fittedUK

A browser using ExOps also fetches map tiles from the OpenStreetMap Foundation, software libraries from Cloudflare's public code service, and fonts from Google Fonts. These are not processors: they receive no records, only the request itself and the browser's IP address.

Where your data is held

In Google's European data centres, with processing in London. Where one of the companies above handles data outside the UK, the transfer relies on UK adequacy regulations, the UK Extension to the EU–US Data Privacy Framework, or the International Data Transfer Addendum. We do not move data anywhere else without saying so.

How long we keep it

A company's own records are kept to the retention schedule that company sets — the app supports one and prompts them to review it. Nothing is hard deleted outside an approved review, and every deletion is logged.

For the data we control:

WhatHow long
Account and billing records6 years after the account closes (tax law)
Sign-in and change logs6 years
Support correspondence3 years
Error and performance logs90 days
A closed account's dataAvailable to export for 30 days, then deleted on request; backups roll off within a further 100 days

Cookies and what is stored in your browser

ExOps sets no advertising or tracking cookies and uses no analytics that follow you anywhere. What it stores is what it needs to work, and this is the whole list:

All of it lives on your own device and none of it is read by anyone else. Clearing your browser data removes the lot and signs you out; photographs still waiting to upload are lost with it, so send them before you clear anything.

Your rights

You can ask for a copy of your data, ask for it to be corrected, ask for it to be erased, object to what we are doing with it, ask us to restrict it, or ask for it in a portable form. Where consent is the basis — marketing, for instance — you can withdraw it at any time, and withdrawing it is as easy as giving it.

Ask us and we will answer within one month. There is no charge unless a request is excessive, and we will say so first rather than quietly ignoring it.

If the records you want are inside a company's ExOps account, that company decides — we will pass your request to them and tell you we have done so.

Keeping it safe

Individual named logins, never shared accounts. Two-step sign-in available to everyone and required for administrator access. Server-side rules that decide who may read or write each record, with an automated test suite that must pass before any release goes out. Encryption in transit and at rest. A backup every night and every Sunday, both kept 100 days, plus point-in-time recovery covering every minute of the last seven days; restores are tested rather than assumed. An activity log of who changed what. A breach log, and a procedure to report to the ICO within 72 hours and to the affected company within 24 hours of us knowing.

No system is perfectly safe, and anyone who tells you otherwise is selling something. What we can promise is that we will tell you quickly and honestly if something goes wrong.

Changes to this policy

If we change it we will say what changed and when, and the version and date at the top will move. Anything that materially affects a company using ExOps is told to them at least 30 days beforehand.