This notice explains our processing and your choices. It is not blanket consent to processing.

1. Who we are and when this notice applies

CORE DUMP CONSULTING LTD, company number 12927321, trading as ShinobiOps, is based in England and Wales. Registered office: 24 Palladian Gardens, London, England, W4 2ER. Contact contact@shinobiops.ai for privacy questions and requests.

This notice covers our website, business contacts, account administration and other processing for which we determine the purposes and essential means. Where a customer directs our processing of personal data in its connected content, Inputs, Output or memory, we normally act as its processor or subprocessor under /dpa. The customer’s notice explains its purposes. Actual activity determines the role; calling information telemetry or support data does not automatically make us its controller.

2. Information and sources

We receive information from you, your organisation’s administrators, authorised integrations and service providers, and lawful public business sources used for requested research. Categories include names, business contact and account details, organisation membership and permissions, billing and transaction records, support communications, connection metadata, selected business documents/messages, Inputs and stored Output, and technical and usage events.

Technical information may include IP address, device/browser information, request and security logs, visited pages and interactions, and advertising click identifiers where the relevant permission is given. IP addresses may indicate approximate region; we do not offer a general purpose for collecting precise location under this notice. The actual connection scopes and processing instructions determine which external content is accessed.

Our contact form asks for your name, company, email and message and sends it to our customer-relationship system so we can respond and manage the enquiry. Please avoid secrets or sensitive content in general contact forms.

3. Purposes and lawful bases

4. Required information and your choices

Account, contact and payment information needed to fulfil a purchase or legal obligation may be required; without it we may be unable to create the account, take payment or provide the requested service. Optional analytics and advertising choices do not determine access to the core website. You can limit connected sources through the permissions and settings available for the integration and ask your administrator about organisational controls.

5. AI processing and customer-specific memory

Requested work may send necessary content to authorised model processors and intermediaries, including routes used for generation, research and embeddings. We do not authorise training of generally available models using Customer Content under the standard agreement. Customer-specific memory and calibration support that customer’s own work; they are not a permission to disclose its content to other customers.

Model brands, versions and suppliers may change subject to the DPA, applicable notices and transfer safeguards. We do not claim every route has zero retention. The relevant supplier schedule identifies retention and processing conditions. A future general-training purpose would require separate specific terms, required permissions and an explanation of withdrawal and the limits of reversing completed training.

Customers determine the instructions, permissions and automation settings used for their workflows. Where supported and enabled by the customer, actions may execute under standing authorisations without individual confirmation. Customers must assess significant decisions about individuals and cannot use the service for prohibited or unauthorised regulated decisions. A human-approval feature does not itself establish that every customer deployment falls outside laws on automated decision-making.

6. Recipients and payments

Information is disclosed as necessary to hosting and infrastructure suppliers, authentication providers, payment processors, support and CRM systems, analytics/advertising providers where permitted, authorised model processors and professional advisers. Supplier roles depend on the activity. See /subprocessors for the provider directory and how to request the supplier schedule for customer-directed processing.

Clerk supports account authentication. Stripe processes payments through its payment interface; we receive subscription, transaction and billing records rather than collecting full card numbers or card security codes in our application. Stripe’s separate processing is described at https://stripe.com/privacy. PostHog supports configured analytics. Google Ads supports advertising measurement when permitted. OpenRouter is used for model routing and embedding routes; the applicable schedule identifies downstream recipients.

We may disclose limited information where legally required, to protect rights or investigate incidents on a lawful basis, or to advisers and parties involved in a corporate transaction subject to appropriate safeguards. Customer-directed content remains subject to the DPA; these categories are not unrestricted permission to disclose it. We do not sell Customer Content or authorise its sharing for cross-context behavioural advertising under the DPA.

7. International processing

Suppliers and authorised personnel may process information in different countries. A UK contracting company or a European hosting location does not mean all processing remains there. For transfers requiring safeguards, we use an applicable adequacy arrangement or appropriate contractual mechanisms, such as EU standard contractual clauses and the UK Addendum or IDTA, with required assessments and supplementary measures. The applicable mechanism must be established before the affected transfer.

Contact us for relevant recipient/location information and a copy or explanation of applicable safeguards, subject to necessary redactions. Visiting the website or accepting the Terms is not consent to an otherwise unlawful transfer.

8. Retention and deletion

Customer-directed content follows the DPA: a standard 30-day export window after termination, earlier return/deletion elections, active deletion within 90 days after an earlier deletion instruction or completed return and no later than day 120 after termination, and backup expiry within 90 days after active deletion and no later than day 210. Deletion includes derived personal data and supplier copies. Limited legal-retention exceptions remain protected and restricted in use.

For our own controller records, retention depends on the purpose: account administration while needed to manage the relationship; enquiries and support while needed to resolve and follow up the matter; security records for the investigation and security need; and billing/statutory records for the period required by the applicable recordkeeping law. Relevant factors include the record’s sensitivity, outstanding disputes, legal obligations and whether a less identifiable record is sufficient. We do not treat those purposes as authority to retain all customer content indefinitely.

CookieYes stores your website consent preferences for up to one year, updated when you change your choice. The advertising-attribution cookie lasts up to 90 days if permitted. Website analytics identifier storage is configured for up to 90 days; cookies and related device storage are explained at /cookies. Device-storage expiry is distinct from the retention of events already received by a supplier. Contact us for the applicable controller or supplier retention detail.

9. Security and restricted information

We apply risk-appropriate organisational and technical measures to protect information and restrict access to authorised purposes. Implementation evolves with the service; specific contractual security commitments are in the DPA and any agreed security schedule. We do not promise absolute security or claim an unverified certification.

The service is intended for business use, not directed at children. Sensitive or sector-regulated information is not permitted as general content unless expressly authorised with the required safeguards. Connected content may nevertheless contain such information; contact us or the relevant customer so it can be handled lawfully rather than assuming it was never collected. Use designated secure connection and payment mechanisms for credentials and payment details.

10. Your rights and how to use them

Depending on the applicable law and circumstances, you may request access, correction, erasure, restriction or portability of personal data, object to processing including direct marketing, and withdraw consent where consent is the basis. Withdrawal does not affect the lawfulness of earlier processing. These rights have conditions and exceptions; objection and withdrawal of consent are different rights.

Email contact@shinobiops.ai with a privacy-request subject line. We may ask for proportionate information to verify identity and locate the data. If we process for your organisation, contact that organisation first; we will pass relevant requests to it and assist under the DPA. We will handle controller requests within applicable statutory periods and explain any permitted extension or refusal. A request does not generally require closing your account.

11. Privacy complaints

You can raise a privacy complaint at contact@shinobiops.ai. We will acknowledge it within 30 days, investigate appropriately, keep you informed as appropriate and communicate the outcome. You may also complain to the UK Information Commissioner at https://ico.org.uk/make-a-complaint/ or the competent authority in your jurisdiction. Our internal process does not remove your right to contact a regulator.

12. Updates and other websites

We may update this notice as processing changes and will show the version and update date. We will provide appropriate direct notice of significant changes affecting individuals and obtain consent where a new purpose requires it. This notice provides information: continued website use is not blanket consent to new purposes, optional tracking or model training.

Other websites and independently supplied services have their own notices. Linking to them does not make their processing part of our notice or remove our responsibility for suppliers processing on our behalf.

Previous Privacy Policy

← Back to home