Privacy Policy
Information pursuant to Art. 13 GDPR · Last updated: June 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
- Controller
-
Mews Group SAS
4 bis rue Brindejonc des Moulinais
31500 Toulouse, France - Email (data protection)
- privacy@opscodex.com
Full publisher details can be found in our Legal Notice.
2. Data Protection Officer
You can reach the controller's Data Protection Officer at:
- Name
- Jean-Philippe Quint
- privacy@opscodex.com
3. General information on data processing
This website is a static information site. We process personal data only to the extent technically necessary to provide the website, and when you contact us by email. Processing is carried out in accordance with the GDPR and applicable data-protection law.
No cookies. No tracking. No third-party content. This website sets no cookies, embeds no analytics or tracking services, and loads no content from third-party servers. In particular, the fonts used are served locally from our own server (no embedding of Google Fonts or similar). A cookie or consent banner is therefore not required.
4. Hosting via Cloudflare Pages
This website is hosted by Cloudflare and delivered through Cloudflare's global content-delivery network (Cloudflare Pages). The provider is Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA.
When you access this website, Cloudflare processes technical connection data on our behalf in order to deliver the content securely and efficiently and to defend against attacks. Cloudflare acts as a processor for us; we have concluded a data processing addendum (DPA) with Cloudflare.
Transfer to the USA: Cloudflare is a US company, and processing in a third country cannot be excluded. The transfer is based on the EU Standard Contractual Clauses pursuant to Art. 46 GDPR; Cloudflare is additionally certified under the EU–U.S. Data Privacy Framework. Further information: cloudflare.com/privacypolicy.
Legal basis is our legitimate interest in the secure and efficient provision of the website (Art. 6(1)(f) GDPR).
5. Server log files
When the website is accessed, our hosting provider (Cloudflare) automatically collects information that your browser transmits. This includes in particular:
- the IP address of the requesting device (processed in shortened/anonymised form where applicable),
- the date and time of access,
- the page or file requested,
- the amount of data transferred and the HTTP status code,
- the referrer URL (previously visited page),
- the browser type and operating system used.
This data is used for the technical provision, security and stability of the site and to defend against attacks. Legal basis is our legitimate interest pursuant to Art. 6(1)(f) GDPR. The log data is stored only for as long as necessary for these purposes (typically a few days) and then deleted.
6. Contact by email
This website contains no contact forms, only email links (demo@opscodex.com and security@opscodex.com). If you contact us by email, we process the information you provide (e.g. your name, email address and the content of your message) in order to handle your enquiry.
Email delivery for these addresses is technically handled via Cloudflare Email Routing (Cloudflare, Inc., USA) and forwarded to a mailbox of Mews Group SAS (brand "Mews Partners"). Cloudflare acts as a processor for the transport of the messages; the same notes on the US transfer as in section 4 apply.
Legal basis for handling your enquiry is Art. 6(1)(b) GDPR (initiation/ performance of a contract) where your enquiry is directed at concluding a contract, otherwise our legitimate interest in responding to your enquiry pursuant to Art. 6(1)(f) GDPR. We delete your enquiries once they are no longer required and no statutory retention obligations apply.
7. OpsCodex Sidekick browser extension
We publish a browser extension, OpsCodex Sidekick, for use alongside an OpsCodex installation. It is not part of this website and plays no role when you browse here. It is described here because the extension is distributed through the Chrome Web Store and this notice serves as its privacy policy.
No data from the extension reaches us. The extension communicates exclusively with the OpsCodex server that you or your employer enter in its options — as a rule an on-premise installation operated by your own organisation. Mews Group SAS receives no data from it. Where such an installation processes personal data, the operator of that installation is the controller for that processing; if that operator is your employer, their own privacy information applies.
What the extension transmits. While its side panel is open, the extension reads two values from your active browser tab and sends them to the configured OpsCodex server in order to look up which approved processes apply to that page:
- the address of the page — origin and path only; query strings and #fragments are removed before transmission, because they routinely carry session tokens or search terms,
- the title of the page.
Nothing else is read or transmitted. The extension injects no content scripts and has no access to page content, form entries or keystrokes. Your browser presents the permission it requires as “read your browsing history”; in practice it is used only for the two values above and to notice when you switch tabs.
What is stored in your browser. The server address you configure remains in the extension’s local storage until you change or remove it. The chat history is held in session storage: it stays in memory, is never written to disk and is discarded when you close the browser. No cookies are set, requests are sent without credentials, and there is no analytics or telemetry of any kind.
You can remove the extension at any time in your browser’s extension settings; the stored server address is deleted with it.
8. Disclosure of data
Your personal data is disclosed to third parties only within the framework described above (processors). Data is not sold or used for advertising purposes. No automated decision-making, including profiling, takes place.
9. Your rights as a data subject
You have the following rights with respect to your personal data:
- right of access (Art. 15 GDPR),
- right to rectification (Art. 16 GDPR),
- right to erasure (Art. 17 GDPR),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR),
- right to object to processing (Art. 21 GDPR).
Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. To exercise your rights, an email to privacy@opscodex.com is sufficient.
10. Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data-protection supervisory authority. As the controller is established in France, the lead supervisory authority is the French data-protection authority:
- Lead supervisory authority
- Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
www.cnil.fr
You may also contact the supervisory authority of your habitual residence or place of work within the EU (Art. 77 GDPR).
11. Changes to this Privacy Policy
We adapt this Privacy Policy whenever changes to our processing make it necessary. The current version published here applies in each case.