Privacy Policy

How Saneops handles personal data. Self-hosted by default; your alert data never leaves your network.

Effective date: 2026-05-09

This Privacy Policy explains how Omprakash Kumar, sole proprietor trading as "Saneops" ("we", "us", "our", "Saneops") collects, uses, discloses, and protects information about visitors and customers of the Saneops website (saneops.in), hosted application (app.saneops.in), and self-hosted Docker distributions (collectively, the "Services").

This policy is designed to comply with:

If you have questions, contact privacy@saneops.in.


1. Who we are

Data controller / Data Fiduciary for our website and hosted service (app.saneops.in): Omprakash Kumar, sole proprietor trading as "Saneops", Daiguutu, Mango, Jamshedpur, Jharkhand 831012, India. Contact: privacy@saneops.in.

Grievance Officer (DPDP Act, s. 8(10) / s. 10(2)(g)): Omprakash Kumar — privacy@saneops.in. We acknowledge data principal grievances within 7 days and respond on the merits within 30 days.

For self-hosted deployments, the customer is the controller of any personal data their Saneops instance processes; we act as the processor under our Data Processing Addendum (see DPA). For the hosted service at app.saneops.in, the customer is the controller of alert / incident data their tenant ingests; Saneops is the processor of that data and the controller of account-level metadata (email, name, billing info).

2. What we collect

a) Information you give us

b) Information collected automatically (hosted service)

c) Information our customers feed in

When you ingest alerts via webhook, the alert payload may include:

This data is YOURS. We process it on your behalf (see DPA). We do not look at, share, or sell its content.

3. What we DON'T collect

4. Why we collect (lawful basis)

Purpose Lawful basis (GDPR Art. 6)
Provide the Services Contractual necessity (b)
Bill paid plans Contractual necessity (b)
Send service / security notifications Legitimate interest (f)
Send marketing communications Consent — opt-in only (a)
Detect abuse, fraud, security incidents Legitimate interest (f)
Comply with tax / legal obligations Legal obligation (c)

5. Who we share with

We use the following sub-processors. Each is bound by a written DPA with terms at least as protective as this one:

Sub-processor What they do Where data is processed
Render Services, Inc. Application + Postgres hosting for app.saneops.in Singapore (ap-southeast-1)
Vercel Inc. Marketing site hosting (saneops.in) — static pages only Global edge network (US-headquartered)
Stripe, Inc. Payment processing (paid plans, Q3+) US (with EU / India local processing where supported)
Resend (Resend, Inc.) Transactional email (password reset, signup) US
ImprovMX Inbound email forwarding for support@saneops.in France / EU
GitHub, Inc. Source code hosting + issue tracking (no customer data) US
Anthropic / OpenAI / Google / xAI / DeepSeek / your chosen LLM provider RCA generation — only when you configure your own API key (BYOK). Saneops sends the alert / incident payload to the provider you select; we do not maintain the relationship. per the provider's terms (typically US)

A live sub-processor list is maintained at saneops.in/subprocessors. We do not share personal data with anyone else without your explicit consent, except as required by law.

6. Where we store

The hosted service (app.saneops.in) currently operates from a single Render region in Singapore (ap-southeast-1). All tenant data — account records, alerts, incidents, audit logs — is stored on Render's managed Postgres in that region. We do not currently offer regional data residency; if you require EU or US residency, please contact us before signing up so we can plan a regional deployment.

Self-hosted customers process data wherever they choose to deploy.

7. How long we keep it

Category Retention
Account data While your account is active + 90 days post-cancellation
Audit logs 1 year
Operational telemetry 90 days
Customer alert/incident data (hosted) Per your subscription tier (90 days–1 year by default)
Billing records 7 years (legal/tax obligation)
Support emails 3 years

After retention, data is permanently deleted within 30 days unless you've requested a different schedule via DPA.

8. Your rights

Under GDPR, DPDP, CCPA, and LGPD you can:

To exercise these rights, email privacy@saneops.in. We respond within 30 days (GDPR / DPDP) or 45 days (CCPA). EU/UK residents have the right to lodge a complaint with their data-protection supervisory authority; Indian residents may also approach the Data Protection Board of India under the DPDP Act if their grievance is not resolved.

California residents (CCPA/CPRA): we do not sell or share personal information for cross-context behavioural advertising; we have not done so in the prior 12 months. You may exercise your right to know, delete, correct, and opt-out by emailing privacy@saneops.in. Authorised agents may submit requests with verifiable written authorisation.

9. Security

See our /security page. Highlights:

In the unlikely event of a breach affecting personal data, we will notify affected customers within 72 hours of becoming aware (GDPR Art. 33) and the relevant supervisory authority as required.

10. Children

Saneops is a B2B operations tool and is not intended for any individual under 18. We do not knowingly collect data from children under the age applicable in your jurisdiction (16 in the EU/UK, 18 in India under DPDP, 13 in the US under COPPA). If you believe we have, contact privacy@saneops.in and we will delete it immediately.

11. Cookies

We set a minimum of two cookies:

Name Purpose Lifetime
session Authenticate logged-in users 12 hours
as_csrf CSRF protection 12 hours

Both are first-party, HTTP-only (session) and SameSite=Lax. We do not use Google Analytics or other third-party trackers by default.

12. International transfers

Because the hosted service operates from Singapore today, EU/UK and Indian customer data may be transferred outside its region of origin when you sign up. We rely on:

The EU SCCs and UK IDTA are incorporated by reference into our DPA and are available on request at privacy@saneops.in.

13. Changes to this policy

We post the current policy at our website. Material changes are announced 30 days in advance via email to admins of paid plans.

14. Contact

What Where
Privacy / data subject requests privacy@saneops.in
Grievance Officer (DPDP Act) Omprakash Kumar — privacy@saneops.in
Security disclosures security@saneops.in — see /security
Customer support support@saneops.in
EU representative (Article 27 GDPR) Not appointed in beta. We will appoint an EU representative before processing personal data of EU residents at scale or before our first paid EU customer. Until then, EU residents may contact privacy@saneops.in directly.
Legal entity Omprakash Kumar (sole proprietor) trading as "Saneops", Daiguutu, Mango, Jamshedpur, Jharkhand 831012, India