TOD-OPS

Trust and security

TOD-OPS holds your clients, your tickets, your invoices and your team's records. This page sets out plainly where that data lives, how we protect it, how AI is and isn't used, and how to reach us about security.

Certifications and registrations

TOD-OPS is built and run by Type on Data Ltd, a UK company.

ICO registered

Registered with the UK Information Commissioner's Office as a data controller. Registration number C1235739.

UK GDPR

We process your data under UK GDPR and the Data Protection Act 2018. Where we act as your processor, our Data Processing Agreement applies.

Cyber Essentials

Type on Data Ltd is certified under Cyber Essentials, the UK Government-backed scheme covering the basic technical controls that stop most common cyber attacks. Valid until May 2027.

Where your data lives

Your account data - the database, uploaded files and the mailboxes the platform sends and receives email through - is hosted in the United Kingdom by 20i Ltd. A few named services handle specific jobs:

ServiceWhat it doesWhere
20i LtdHosting, database, file storage and platform emailUnited Kingdom
StripeSubscription billing. Card details are entered on Stripe's own checkout and never reach our serversEEA / USA
Companies HouseCompany lookups you ask for when adding a clientUnited Kingdom
Anthropic or OpenAIAI drafting, only if your account switches it on (see below)Optional · USA
Google Fonts, jsDelivrFonts and one calendar component. No account data is sentGlobal

The full list, with exactly what data each one receives, is Annex 2 of our Data Processing Agreement. We tell customers before adding or replacing one.

Security practices

Your account is sealed off

Every record belongs to one account. The platform refuses to show data when it cannot tell whose account is asking, and automated tests check this separation on every change.

Encrypted in transit

All traffic to TOD-OPS uses HTTPS. Sign-in sessions are encrypted and their cookies are marked secure.

Sensitive fields encrypted at rest

Bank details, connection tokens, API keys and email passwords are encrypted in the database. Passwords are never stored - only a one-way hash.

Daily backups

The database is backed up every night and before any release that changes its structure. Backups are kept for 14 days.

Tested before release

Every change runs through an automated test suite and a separate staging copy first. The staging copy never sends email. Only a named person at Type on Data Ltd can release to the live service.

Limited staff access

Only named Type on Data Ltd staff can reach the platform console, each with a defined role. Removing someone's access ends their sessions straight away.

Sign-in protection

Repeated failed sign-ins are slowed down, and password reset emails never reveal whether an account exists.

Your data, your exit

You can export your data at any time. After you cancel, it is kept for 3 months in case you return, then permanently deleted. We email you before that happens.

How TOD-OPS uses AI

AI is optional and off by default. It is used for one thing: helping you bid for tenders and grants, by drafting a response or a guide to how to apply.

You choose the provider

An account switches AI on by adding its own Anthropic or OpenAI API key. Until a key is added, nothing is sent to any AI provider. The key is stored encrypted.

What is sent

Only what a tender draft needs: the tender and its documents, your company profile and knowledge base, any reference material you pick, and your brief.

What is never sent

Your clients' details, tickets, emails, invoices, time records and staff records are never sent to an AI provider.

No training, and you stay in charge

We do not train AI models on your data. Anything AI writes is a draft for you to review and edit - nothing is submitted or sent on its own.

Security contact

Found a security problem? Tell us privately.

Email support@tod-ops.co.uk with "Security report" in the subject. We reply within 2 business days.

  • Say what you found, where, and the steps to see it.
  • Please give us time to fix it before telling anyone else.
  • Please don't access or change other people's data, or disrupt the service.

This address is also published in our security.txt file.