Privacy Policy

OptiTech Automation · Last updated: 17 July 2026

> Reviewed against current UK law; under ongoing internal review. Not formal legal advice.

Last updated: 17 July 2026

We operate the OptitechAutomation platform as a UK sole trader — the personal business of Cristian Moise-Putanu. OptitechAutomation is a business name, not a registered company; there is no Companies House number or registered office. Our principal place of business is Torquay, Devon, United Kingdom.

We handle personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. You can reach our privacy team at privacy@optitechautomation.co.uk.


1. Who We Are and Our Role in Your Data

This policy explains how OptitechAutomation handles personal data. Our role depends on whose data it is. Under UK GDPR there is an important difference between a controller (who decides why and how data is used) and a processor (who handles data on a controller's instructions). The mapping below matches our Data Processing Agreement and our Homeowner Data Notice.

1.1 Where the Business is the controller and OptitechAutomation is the processor

When a trade business ("Business") uses our platform, the Business is the data controller for the personal data of its own customers and workers — for example a customer's name, contact details, postcode, booking details, and a worker's profile and scheduling data. The Business decides why and how that data is collected and used.

OptitechAutomation acts as the Business's data processor for that data. We store and process it on the Business's documented instructions in order to operate the booking technology on their behalf. The terms governing this relationship are set out in our Data Processing Agreement.

If you are a customer or worker of a Business, the Business is your first point of contact for data questions, and the Homeowner Data Notice explains your rights in more detail.

1.2 Where OptitechAutomation is the controller

OptitechAutomation is the data controller only for:

This policy governs the data for which we are the controller. For data where the Business is the controller, this policy is provided for transparency, but the Business's own notices and the DPA govern.

If you have questions about how we handle data for which we are the controller, contact us at privacy@optitechautomation.co.uk.


2. Data We Collect (as controller)

For the data described in Section 1.2, we collect:

Personal data of a Business's own customers and workers is collected through the platform under the Business's control, not ours — see Section 1.1 and the Homeowner Data Notice.


3. Lawful Basis for Processing (data we control)

For the data for which we are the controller, we rely on the following lawful bases under UK GDPR:

We do not rely on a "perpetual" or open-ended licence to your personal data; any use of personal data is limited to the purposes and bases stated here.

Disclosure to authorities. Where we are under a legal obligation to do so, we may disclose personal data to regulators, courts, or law-enforcement bodies acting within their statutory powers — including HM Revenue & Customs (HMRC) exercising its statutory information-gathering powers and the Information Commissioner's Office (ICO). Any such disclosure is limited to what the relevant authority is lawfully entitled to require.

4. Third-Party Sub-Processors

We use the following sub-processors to operate the platform. Each is bound by a Data Processing Agreement or equivalent contractual safeguard:

Supabase — Database, file storage and authentication infrastructure. Personal data is stored in the EU (Republic of Ireland / Dublin, AWS eu-west-1). This UK-to-EEA transfer relies on the UK adequacy regulations for the EEA (UK GDPR Art. 45 / DPA 2018 s.17A). Stripe — Payment processing. Stripe collects and processes payment card data directly under its own privacy policy and PCI-DSS compliance programme. Resend — Transactional email delivery. Email addresses and relevant booking details are transmitted to Resend for delivery purposes only. Anthropic (Claude API) — AI website generation. When a business owner uses our website generator, the business facts the owner submits (such as trade type, town, service areas, selling points and trading history) are sent to Anthropic's Claude API to draft website copy. See the Sub-Processors List for data categories, location and safeguards. Groq — AI drafting and triage for our own sales correspondence. If you email us in response to an outreach message, that correspondence and your business contact details are passed to Groq's API so a reply can be drafted for a person to review. This applies to our own prospective-customer contact only. No Business's customer, worker or booking data is sent to Groq. See the Sub-Processors List for data categories, location and safeguards. hCaptcha (Intuition Machines) — Abuse prevention on public forms such as booking, signup and sign-in. Your IP address, browser and device characteristics and interaction signals are processed to tell genuine visitors apart from automated traffic. See the Sub-Processors List for data categories, location and safeguards.

For the full list of sub-processors, see our Sub-Processors List.


5. Data Retention

We retain personal data for the following periods:


6. Your Rights Under UK GDPR

Under UK GDPR Articles 15–22, you have the following rights:

If your data is held by us as a processor on a Business's behalf (Section 1.1), please direct your request to the Business as controller; we will assist them in responding.

To exercise any of these rights for data we control, contact us at privacy@optitechautomation.co.uk. We will respond within 30 days. There is no charge for exercising your rights.

If you are unsatisfied with our response you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.


7. Cookies

We use the following types of cookies:

We do not use advertising or tracking cookies. You can manage your cookie preferences at any time via the cookie settings link in our footer.

For full details, see our Cookie Policy.


8. International Transfers

Your personal data is primarily stored in the European Economic Area — in the Republic of Ireland (Dublin, AWS eu-west-1) via Supabase. Transfers from the UK to the EEA are covered by the UK's adequacy regulations for the EEA (UK GDPR Article 45, as given effect by the Data Protection Act 2018), so no additional transfer mechanism is required for that hosting.

Some sub-processors operate outside the UK and EEA (principally in the United States). For those transfers we rely, in order of preference, on:

The mechanism relied on for each sub-processor is stated in our Sub-Processors List. We no longer describe these safeguards as "Standard Contractual Clauses approved by the ICO" — the EU SCCs are not, by themselves, a valid UK transfer mechanism; the UK instruments above are.


9. Assignment

We may assign, transfer, or otherwise deal with all or part of our rights and obligations under this Policy to any successor entity without your consent, on 30 days' prior written notice.


10. Changes to This Policy

We will notify you of material changes by posting a notice on the platform at least 14 days before the changes take effect.


11. Contact

OptitechAutomation — Cristian Moise-Putanu (sole trader)

Torquay, Devon, United Kingdom

privacy@optitechautomation.co.uk

TermsPrivacyCookiesContact