Legal documents

Privacy Policy

Updated: July 24, 2026 Version: 1.3

Principles

OpMetrics is analytics of work processes, not surveillance of people. The policy rests on three principles:

  • Minimalism. Only the metadata of work artifacts is processed — exactly as much as the analytics needs.
  • Transparency. Employees know what data is collected and who sees it.
  • Isolation. Each client's data sits in a separate isolated perimeter; never shared with third parties.

What data is processed

Category What is included What is not collected
Tasks Statuses, due dates, assignees, estimates Attachments and private comments
Code Change metadata: who, when, volume, review flow Source code content
Communications Activity metadata: message volume, response time, thread structure Message content
Incidents Monitoring events, recovery time
HR Employment, time off, role, time zone, compensation amount Medical records
Message content and code are neither read nor stored. The system only needs the facts of “what happened and when” — never “what exactly was written”.

Purposes of processing

Data is used for management analytics within your organization: workload and staffing, cost of delivery, process health and the effect of tooling. Data is never shared with third parties and is not used for automated staffing decisions or employee ratings. Anonymized and aggregated indicators may be used by the vendor to support and improve the Product.

Where data is stored

On the cloud plan, the Product runs in the vendor's managed infrastructure with a separate isolated perimeter per client; data is never shared with third parties. On the Enterprise plan, self-hosted or dedicated deployment in the client's infrastructure is available — then data never leaves the client's perimeter.

Who has access

Access is separated by role and area of responsibility: a manager sees their own people and projects, while company-wide figures are visible only to company leadership. Sensitive data (risk signals, compensation amounts) is visible strictly by role. Profile views and admin actions are recorded in an immutable audit log.

Retention

Data is retained while the account is in use. If no one signs into the account for 12 months, it is treated as abandoned and its data is deleted. At the Client's request, data is deleted immediately. Stopping payment does not by itself trigger deletion — the account reverts to the free plan (up to 5 contributors). On the Enterprise plan (self-hosted / dedicated deployment) the Client controls storage and deletion entirely. Data of former employees is hidden from the default views.

Employee rights

  • To know what data about their work is collected — the list is available in this document and in the Product's interface.
  • To request an export of their own data from the company administrator.
  • To dispute the accuracy of the data — via the administrator or the person responsible for data processing in the company.

Data-processing questions: [email protected].