Trust & Security

Trust & Security

At OPCX Solutions, trust is earned through transparency, responsible data handling and practical security controls.

Whether we’re providing consultancy services, implementing support technology, or delivering software products, we aim to protect customer data, respect privacy, and be clear about how information is processed.

Security First

We use modern cloud platforms and industry-standard security practices to help protect customer information.

Our approach includes:

  • Encryption in transit and at rest.
  • Access controls based on least-privilege principles.
  • Tenant segregation where customer data is stored within shared platforms.
  • Regular review of suppliers and service providers.
  • Secure handling of credentials, API keys and sensitive information.

Privacy by Design

We design services and solutions to minimise unnecessary exposure to personal information.

Where possible, we:

  • Limit the personal data processed.
  • Redact or anonymise information before analysis.
  • Restrict access to authorised users only.
  • Provide clear retention and deletion processes.

We aim to collect and process only the data required to deliver the agreed service.

Responsible Use of AI

OPCX Solutions uses AI to support analysis, automation and operational insight.

We believe AI should assist human decision-making, not replace it.

Our approach includes:

  • Maintaining transparency about where AI is used.
  • Using commercial AI services that do not use customer content for model training.
  • Applying controls to minimise personal information being included in AI processing.
  • Ensuring customers remain responsible for reviewing and validating decisions based on AI-generated outputs.

Data Ownership

Customers retain ownership of their data.

OPCX Solutions does not acquire ownership rights over customer information, documentation, support tickets, reports or business data provided as part of our services.

Enterprise Readiness

For customers with additional governance, compliance or procurement requirements, OPCX Solutions can provide supporting documentation, including:

  • Non-Disclosure Agreements (NDAs)
  • Data Processing Agreements (DPAs)
  • Data Processing & Security Overviews
  • Data Flow Diagrams
  • Hosting and subprocessor information
  • Data retention information
  • AI processing information

We are happy to work with customer security, legal, procurement and compliance teams to support reasonable due diligence requirements.

Insurance & Compliance

OPCX Solutions:

  • Is registered with the UK Information Commissioner’s Office (ICO).
  • Holds Professional Indemnity Insurance.
  • Holds Public Liability Insurance.
  • Holds Cyber Insurance.
  • Operates in accordance with applicable UK data protection requirements.

Questions?

We believe trust comes from open and honest conversations.

If you have questions regarding security, privacy, AI usage, data processing or supplier management, please contact: contact@opcx.solutions

Support Insights Analysis

Support Insights Analysis has been designed with privacy and security in mind from the outset.

Key principles include:

  • Personal information is redacted before storage and before AI analysis wherever possible.
  • Customer data is logically segregated between organisations.
  • Access is restricted to authorised users and OPCX administrators who require access for support, maintenance or consulting services.
  • Data is encrypted in transit and at rest.
  • AI-generated insights focus on operational trends, recurring issues and improvement opportunities rather than individual customers.
  • Customer content submitted through commercial AI services is not used to train AI models.

Additional technical documentation, including hosting locations, data flows, subprocessors and security controls, is available upon request.