Legal

Privacy Policy

What we collect, why we collect it, who else sees it, and how to make us stop. Written in plain English, and specific to what this product actually does.

Last updated 9 August 2026 · Effective 9 August 2026

01Who we are

Frontier Ops Pvt Ltd ("we", "us", "our") is an Indian company that builds PrimeOps, an IT service management platform. This policy explains what personal data we handle, why, and what you can do about it. It covers https://primeops.in and the PrimeOps application.

We have written this in plain English rather than legal boilerplate. If anything here is unclear, or you think we have got something wrong, write to info@frontierops.in and we will answer.

02Two different roles — this matters

We handle personal data in two distinct capacities, and your rights differ between them.

  • As a data fiduciary, for data you give us directly: when you visit this website, request a trial, or book a demo. We decide why and how that data is processed, and this policy governs it.
  • As a data processor, for data inside a customer's workspace: the tickets, assets, contacts, comments and attachments your organisation puts into PrimeOps. Your employer decides what goes in and why; we only process it on their instructions, under our agreement with them.

If you are an employee raising tickets in your company's PrimeOps workspace and you want your data corrected or deleted, ask your own IT or HR administrator first — they control that workspace, not us. We will support them, but we cannot act on workspace data without their instruction.

03What we collect

We collect only what a specific action needs. We do not buy personal data, and we do not collect data about you from third-party brokers.

WhenWhatWhy
You start a free trialCompany name, your full name, job title, work email, phone number, a password (stored only as a bcrypt hash — we never see it), and optionally the IT challenge you describeTo create and secure your workspace, give you an admin account, and set the workspace up around the problem you told us about
You book a demoCompany name, your name, work email, phone number, company size, preferred date and time, and any note you addTo contact you, agree a slot, and prepare a walkthrough relevant to your size and setup
You arrive from a Google adThe Google Click Identifier (gclid) from the link, held in your browser's session storage and attached to your signup if you convertTo know which ads bring real signups, so we stop paying for the ones that do not
You use the websiteStandard server and analytics data: IP address, browser and device type, pages viewed, referring pageTo keep the site working, understand what people read, and detect abuse
You accept the cookie bannerA first-party record in your browser of how you reached us and which pages you have read, kept across visits. It contains no name, email or phone number, and we cannot identify you from itSo that if you later send us an enquiry, we can see what you were interested in and reply about that rather than sending you something generic. If you never submit a form, it stays in your browser and we never see it
You use the productYour login session, and the workspace content your organisation puts in — tickets, assets, comments, email trails and attachmentsTo provide the service. Here we act on your organisation's instructions, not our own (see above)

We do not ask for sensitive personal data — financial account details, health information, biometrics or government identifiers — anywhere on this website, and you should not put such data into the free-text fields on our forms.

Inside the product it is different. PrimeOps supports HR service delivery, and HR requests can legitimately contain sensitive details such as medical leave, payroll queries or grievances. Where that happens, your organisation decides what is collected and is responsible as the data fiduciary for it; we hold it as a processor, apply the same security controls as to any other workspace data, and only act on your administrators' instructions.

04How we use it

  • To provide the service you asked for — creating your workspace, running your tickets, sending the notifications you configured.
  • To contact you about your trial, your demo, or a support request you raised.
  • To keep the service secure and available: authentication, rate limiting, backups, fraud and abuse detection.
  • To measure our advertising, so we know which campaigns produce genuine signups.
  • To meet legal, tax and audit obligations in India.

We do not sell personal data. We do not share it with advertisers for their own purposes, and we do not use the contents of your workspace to train AI models.

On AI features: PrimeOps agents can run on an AI provider key that you supply, or against a model you host yourself. When you use your own key, your prompts and ticket content go to that provider under your agreement with them, not ours — you stay in control of both the cost and the data path.

05Who we share it with

We use a small number of service providers to run the business. Each one gets only the data it needs to do its job, and none of them may use it for their own purposes.

ProviderWhat it seesWhere
Amazon Web ServicesAll application data — hosting and database infrastructureMumbai, India (ap-south-1)
Cloudflare R2Files and attachments uploaded to tickets and assetsObject storage
Zoho CRMName, work email, phone and company name from trial signups, as a sales leadIndia (zohoapis.in)
Resend and EmailJSEmail addresses and message content, to deliver transactional and notification emailEmail delivery
Google (Tag Manager, Ads)Website usage and advertising measurement data, so we can tell which ads produce real signupsGlobal
Google AnalyticsAggregated website usage. Loads only if you accept on the cookie bannerGlobal
Microsoft ClaritySession analytics on this marketing website — pages viewed, clicks, scrolling and mouse movement — used to find where the site confuses people. It is not used inside the productGlobal

This list is the whole set of sub-processors that touch personal data. If we add or replace one for a service that handles Customer Data, we will update this page and give subscribing customers at least 30 days' notice by email before the change takes effect. If you object to a new sub-processor on reasonable grounds, tell us within that period and you may terminate the affected subscription without penalty and receive a refund of fees paid for the unused term.

We will also disclose data where we are legally required to — a valid order from a court or a competent authority — or to establish or defend a legal claim. If we are ever compelled to hand over customer workspace data, we will tell the affected customer unless the law forbids it.

If the business is ever acquired or merged, personal data would transfer as part of that transaction. We would notify you before it happened and before any new policy applied to you.

06Where your data lives

Your workspace database — tickets, assets, contacts, comments and configuration — is stored in India, on AWS infrastructure in the Mumbai region. This is a deliberate choice: for most Indian IT teams, data residency is the question that decides the purchase.

Two categories are handled outside that boundary, and we would rather say so plainly than imply otherwise:

  • Uploaded files and attachments are held in Cloudflare R2 object storage, which is distributed rather than pinned to an Indian region.
  • Email delivery, website analytics and advertising measurement are provided by global services, so the data those need — email addresses, message content, and website usage — is processed outside India.

Where data is processed outside India we rely on the provider's contractual safeguards. If strict in-country residency for attachments is a requirement for your organisation, tell us before you subscribe and we will confirm in writing what we can and cannot commit to.

07How long we keep it

DataKept for
Login sessionsA short window of inactivity, after which you are signed out and the session record is deleted
Expired trial workspacesThe workspace stops at the end of the 14-day trial. We keep the data for 30 days so you can convert without losing your work, then delete it
Paying customer workspacesFor as long as the subscription is active, plus the 30-day export window set out in our Terms of Service. Then deleted from active systems, and from backups as those rotate
Demo and enquiry recordsFor as long as we are in conversation, and a reasonable period afterwards
Invoices and tax recordsAs long as Indian tax and company law requires, regardless of anything else here

You can ask us to delete your data sooner. Where we can, we will; where a law requires us to keep something, we will tell you which one and for how long.

08How we protect it

  • Passwords are stored as bcrypt hashes. Nobody at our company can read your password, and we will never ask you for it.
  • Traffic is encrypted in transit over HTTPS.
  • Each customer's data is separated by tenant, and access within a workspace is limited by role.
  • Sessions are held in server-side storage with an HTTP-only cookie, so session tokens are not readable by scripts in your browser.
  • Access to production systems is limited to the people who need it to operate the service.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the Data Protection Board of India as required by law, and tell you what happened and what we are doing about it.

09Your rights

Under India's Digital Personal Data Protection Act, 2023, you have the right to:

  • Ask what personal data of yours we hold and what we have done with it.
  • Have inaccurate or incomplete data corrected, updated or completed.
  • Have your data erased, where we no longer need it and no law requires us to keep it.
  • Withdraw consent you previously gave — this does not undo processing already carried out lawfully.
  • Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
  • Raise a grievance with us, and escalate to the Data Protection Board of India if our answer does not satisfy you.

To exercise any of these, write to info@frontierops.in from the email address concerned. We will acknowledge your request and respond within the period the law allows. We may need to verify your identity first — we will not hand your data to someone else on your behalf without being sure who they are.

10Cookies and similar technologies

We use as few as we can get away with.

TypeWhat it doesWhen it loads
Essential session cookieKeeps you signed in and secures the session. Without it the product cannot workOnly once you log in
Session storageHolds the Google click identifier and your new workspace URL during signup. Cleared when you close the tabOnly if you arrive from an ad or start a signup
Local storageRemembers your choice on the cookie banner so we stop askingWhen you answer the banner
Google AnalyticsAggregated website statisticsOnly after you accept on the cookie banner
Google Tag Manager, Google Ads and Microsoft ClarityAdvertising measurement and session analytics for this marketing websiteOn page load

To be straightforward about it: today the cookie banner controls Google Analytics only. Google Tag Manager, Google Ads conversion measurement and Microsoft Clarity load when the page does, whatever you choose on the banner. We would rather write that down accurately than claim a consent gate we do not yet enforce.

You can clear or block cookies in your browser settings, and browser-level Do Not Track or tracking-protection settings will also block these scripts. Blocking the essential session cookie will stop you from being able to log in.

11Data Processing Agreement

Where we process personal data inside your workspace, we do so as your processor. Our Data Processing Agreement sets out the details procurement and security teams ask for: the subject matter and duration of processing, the categories of data subject, our confidentiality and security obligations, the sub-processor list and change-notice terms above, how we assist you with data-principal requests and breach notification, and what happens to your data when the contract ends.

The DPA is incorporated into your subscription by reference and applies automatically — you do not need to sign a separate document for it to be effective. If your organisation requires a countersigned copy, or has its own template, write to info@frontierops.in and we will arrange it.

12Emails we send you

  • Service emails — trial details, password resets, ticket notifications, billing and security notices. These are part of the service and you cannot opt out of them while you have an account.
  • Sales and marketing emails — follow-ups after a trial or demo request, and occasional product news. You can opt out at any time, using the unsubscribe link or by replying and asking us to stop.

Opting out of marketing email does not affect service emails, and does not delete your account. To have your data deleted as well, see your rights above or write to info@frontierops.in.

13Children

PrimeOps is a workplace tool sold to organisations. It is not directed at children, and we do not knowingly collect personal data of anyone under 18. If you believe a child has given us personal data, write to us and we will delete it.

14Changes to this policy

When we change this policy we will update the date at the top of the page. If a change materially affects how we handle your personal data, we will tell you directly — by email or in the product — before it takes effect, rather than relying on you to re-read the page.

15Contact and grievances

For any question about this policy, or to exercise a right described above, contact Ashit Karn, Grievance Officer, at info@frontierops.in.

Postal address: Frontier Ops Pvt Ltd, Innov8 Graphix Tower 2, Sector-62, Noida, Uttar Pradesh 201301, India.

If you are not satisfied with how we handle your grievance, you may escalate the matter to the Data Protection Board of India.