Operator.

LEGAL

Privacy Policy

Operator processes account, business, workflow and connected-service information needed to provide an AI workforce platform.

1. Information we process

Depending on how you use Operator, we may process account identifiers and authentication information; subscription and entitlement information; business context; tasks and notes; CRM leads, deals and revenue information; approvals; activity and execution records; onboarding information; usage information; notifications; error events; public prospect research; outreach drafts and delivery records; response activity; follow-up scheduling; and information made available through connected services.

2. Connected-service data

Google Workspace: Operator is configured with per-user OAuth scopes for Gmail read access, Gmail sending and Google Calendar access. Slack: Operator is configured with per-user OAuth scopes for channel reading and message sending. The current application UI also lists Notion, HubSpot, Stripe, Calendly and Shopify as integration options, but the currently implemented external-action adapters verified in the application are Google Gmail/Calendar and Slack; other listed integrations should not be treated as operational until their adapters are implemented and verified. Provider-specific terms and privacy policies continue to apply.

3. How information is used

Information is used to authenticate users; provide the AI Executive and specialist agents; maintain Business Brain context; execute authorized workflows; manage CRM and revenue features; create approvals and audit/activity records; enforce plan and AI-action limits; administer Stripe subscriptions and entitlements; provide support; maintain security; troubleshoot errors; and comply with legal obligations.

4. AI processing

Operator is configured through Hatchable's managed AI gateway for Google Gemini, OpenAI and Anthropic Claude. The application currently uses Google Gemini as the default execution provider and can be configured to prefer other configured providers; execution code also contains fallback handling among Gemini, GPT and Claude when available. The application acceptance suite verifies a Gemini response. The exact provider used for a particular customer request may therefore depend on configuration and provider availability. Provider retention/training terms, processing locations and applicable contracts must be confirmed before final publication.

5. AI agents and approvals

Operator may process authorized information so its AI Executive and specialist agents can plan and perform work. Safe/read-only actions may be automatic. Consequential external actions are routed through an approval workflow. Payments, transfers, purchases, destructive deletion and contract signing are blocked by the current safety policy.

6. Billing

Stripe is Operator's sole billing and entitlement provider. Operator uses Stripe subscription and entitlement information to determine the plan and paid features available to an account. Payment-card processing is handled through Stripe's payment infrastructure rather than Operator's application database.

7. Customer control

Users control which supported accounts they connect. Disconnecting an integration stops future access through that connection, but does not necessarily immediately delete information previously processed. Customers should avoid placing unnecessary sensitive information into connected workflows.

8. Security

Operator uses authenticated and user-scoped data routes, server-side integration credentials, permission policies and approval gates for consequential actions. No internet-connected system can guarantee absolute security.

9. Retention and deletion

Operator retains information as reasonably necessary to provide the service, maintain security and auditability, administer subscriptions, resolve disputes and comply with law. Specific retention periods, backup deletion periods and the exact deletion workflow must be completed by the Operator team and approved by counsel.

10. South African privacy review

For South African operations, Operator's final privacy framework should be reviewed against POPIA, including lawful processing, transparency, security safeguards, data-subject participation, operator/subprocessor arrangements and cross-border information flows.

11. Your rights

Subject to applicable law, users may have rights to access, correct, delete or object to processing of personal information and other statutory rights. Requests should be directed to the final privacy contact below.

12. Contact

Operator is currently operated as a sole proprietorship / sole-trader business rather than a registered company. The individual owner is the person responsible for the business and for responding to privacy requests, subject to applicable law.

Trading name: Operator
Legal owner: Siphosihle Gift Jama
Business registration number: Not applicable unless separately registered with the relevant authority
Business address: 125 Nyanda Street, KwaNobuhle, 6242, South Africa
Privacy email: siphosihle.sj.jama@gmail.com
Support email: OperatorAI7@proton.me
Information Officer / privacy contact: Siphosihle Gift Jama — OperatorAI7@proton.me

Legal review required before commercial launch. This page is an Operator-specific draft and is not legal advice.

Terms · Legal Center · Pricing · App

Built on Hatchable