Legal

Privacy Policy

Last updated: July 26, 2026

The short version. This site sets no cookies, runs no analytics, and loads no third-party scripts. Nothing about your visit is tracked. If you email or use the contact form, that message is read and kept until it's no longer useful. If you become a client, a separate written agreement covers your infrastructure data, and this page tells you where that boundary sits.

1.Who this is

OpsFox is a small independent consulting practice. It is not a platform, there is no product to log into, and there is no user account system.

The registered legal entity name and address for formal notices are being finalised and will be published here before any paid engagement is signed. Until then, contact goes through the email addresses in section 9. If you need the entity details for procurement or a vendor record, ask and you'll get them directly.

2.This website

The site is a set of static files served from Amazon S3 behind Amazon CloudFront, in the AWS us-east-1 region. That means:

  • No cookies are set. There is no consent banner because there is nothing to consent to.
  • No analytics, no tag manager, no pixels, no session recording, no A/B testing, no fingerprinting.
  • No third-party scripts, fonts, or embeds load from anyone else's server.
  • No advertising networks and no data brokers, now or planned.

Amazon does generate standard delivery logs as part of serving the site — the kind of request metadata any web server produces, including IP address, timestamp, requested path, and user agent. Those logs exist to serve pages and diagnose faults. They are not joined to any other data, not used to build a profile, and not sold or shared.

You can verify every claim in this section yourself. Open your browser's developer tools, load any page, and look at the network and storage tabs. That is a better assurance than this paragraph.

3.If you get in touch

The contact form and any direct email collect only what you type: typically your name, your email address, your company, and your message. That information is used to reply to you and to keep track of an ongoing conversation. It is not added to a marketing list without you asking, and it is never sold or shared.

The weekly dispatch is not running yet — there is no signup form on this site and no issue has been sent, so no addresses are held for it. When it starts it will be opt-in and will store your email address and nothing else, every issue will carry an unsubscribe link that works on the first click, and unsubscribing will delete the address rather than flag it.

4.If you become a client

Delivering an engagement means touching your infrastructure, so a written agreement — not this page — governs that relationship. The principles it encodes:

  • Your configurations, telemetry, and logs stay in your environment. They are not copied out to be held here.
  • Access is an account you create, under your multi-factor authentication, with no standing privileged access and no shared credentials.
  • Commands run against your environment are logged to a store you control and that OpsFox cannot delete.
  • Nothing derived from your environment is published, quoted, or used as a reference without your prior written consent.
  • On termination you keep everything deployed, under a perpetual licence, in your own repository.

5.AI agents and where your data does not go

Automated agents are used to do repetitive work: comparing upstream software releases, ranking findings, and drafting written records. This matters for your privacy, so the boundary is stated precisely rather than described vaguely.

What agents receive: inventory data, software version strings, check results, and findings identifiers.

What agents never receive: your hostnames, IP ranges, credentials, configuration file contents, log contents, or any personal data belonging to you or your customers. Where an identifier is needed, a token is substituted, and the mapping from that token back to a real system is held outside any model context.

Language model inference is provided by Anthropic as a subprocessor. For engagements where no data may leave your network at all, an in-boundary deployment running models on your own hardware is available instead — that is what IRON DEN is for.

6.Subprocessors

The third parties involved in running this practice, and what each one touches:

  • Amazon Web Services — static site hosting and content delivery. Sees request metadata for this website.
  • Anthropic — language model inference for the agent workflows described in section 5. Receives only the categories listed there.
  • Email provider — receives what you send us, because the contact form opens a draft in your own mail client and you send it yourself. There is currently no scheduling provider; the booking page is not live.

A current subprocessor list naming each provider, the data categories involved, the processing region, and retention terms is available on request and is included in the transparency pack sent to prospective clients. If that list changes in a way that affects a client engagement, affected clients are told in writing.

7.How long anything is kept

  • Contact messages and email threads — kept while the conversation is live and for a reasonable period after, then deleted.
  • Dispatch subscriptions — none exist yet; when the dispatch starts, kept until you unsubscribe, then deleted.
  • Client engagement records, invoices, and agreements — kept as long as required for tax and contractual purposes.
  • Delivery logs generated by the hosting provider — retained on that provider's standard schedule.

8.Your rights

You can ask what is held about you, ask for a copy, ask for it to be corrected, or ask for it to be deleted. Since almost nothing is collected, most of these requests are answered in a sentence. Email the address below and you'll get a reply within a few business days.

Depending on where you live, you may have additional statutory rights. Those rights are honoured on request regardless of jurisdiction — it costs nothing to apply the higher standard to everyone when the collected data is this small.

This site is not intended for children and no data is knowingly collected from anyone under 16.

9.Contact and changes

Privacy questions: privacy@opsfox.io. Security reports: security@opsfox.io.

If this policy changes, the date at the top changes with it. A change that materially affects an active client engagement is communicated directly rather than quietly edited in.