1. Who we are
The data controller for any personal data collected via this site is:
Ops First Consultancy Ltd
The Granary, Blakelow Road, Macclesfield, SK11 7ED
Email: hello@opsfirst.co.uk
Ops First Consultancy Ltd is registered with the Information Commissioner's Office (ICO) as a data controller. The registration number will be added here once registration completes; until then any data-protection queries should go to the email address above.
2. What we collect, and why
We collect personal data in four ways. None of it is bought, scraped, or otherwise acquired without you giving it to us directly.
Contact form
When you fill in the contact form on /contact we collect your name, email address, company (optional) and the message you write. We use this only to reply to your enquiry.
Legal basis: legitimate interest (responding to your enquiry).
Ops Scorecard
When you take the Ops Scorecard at /scorecard we collect your name, work email, company, position and a small set of business context (years running, headcount, industry, leadership structure, stage, top operational pains). We also store your answers to the maturity questions, your computed score and band, and any optional feedback you leave on the report. This is so we can generate your personalised report and send it to your inbox.
Legal basis: consent (you fill the scorecard in voluntarily to receive the report).
Product launch signups
When you ask to be notified about Ambital or FindYourFractional we collect your name, email, company, and role (e.g. fractional, freelancer, business seeking a fractional). We use this only to send a single notification when the relevant product opens for early access.
Legal basis: explicit consent (you actively asked to be notified).
Analytics and server logs
We use Plausible Analytics to understand how the site is used (pageviews, referrers, devices, anonymised aggregate stats). Plausible is privacy-focused and does not set cookies, does not track individuals, and does not collect any personal data. Our hosting provider (Vercel) keeps short-term server logs that include IP addresses and request times — these are technical and not used for marketing or profiling.
Legal basis: legitimate interest (understanding traffic in aggregate, keeping the site secure).
3. Cookies and tracking
The site uses two analytics tools: Plausible (cookie-free, runs on every visit) and Google Analytics 4 (cookie-based, runs only after you opt in via the cookie banner).
On your first visit a banner appears at the bottom of the page asking for your consent. If you click Accept, Google Analytics loads and sets the standard _ga and _ga_* cookies (used to anonymously identify your session and the device for aggregate traffic stats). Your IP address is anonymised before any data leaves your browser. If you click Reject, no Google script is loaded and no cookies are set.
Your choice is remembered between visits. You can change it at any time via the Cookie settings link in the footer.
Some third parties we link to (e.g. our calendar booking tool) may set their own cookies on their own domains once you click through to them. Those are governed by the respective third party's privacy policy.
4. Who we share data with
We use a small number of trusted third-party processors to actually deliver the service. They process data on our behalf, under contract, and only for the purposes described here.
- · Mailchimp (Intuit, USA) — stores your contact record, sends scorecard report emails, sends launch notifications, manages your unsubscribe preferences.
- · Mailchimp Transactional / Mandrill (Intuit, USA) — sends contact-form submissions and internal notification emails to us.
- · Vercel (USA) — hosts the website and runs the API routes that talk to Mailchimp.
- · Plausible Analytics (Plausible Insights OÜ, Estonia / EU) — anonymous, cookie-free pageview analytics. Runs on every visit.
- · Google Analytics 4 (Google LLC, USA) — cookie-based traffic analytics with IP anonymisation. Loads only after you opt in via the cookie banner.
- · Google Calendar (Google LLC, USA) — handles meeting bookings if you choose to book a call.
We do not sell your data. We do not share it with advertisers. We will not pass it to a third party that isn't on this list without your consent (or unless required to by law).
5. International transfers
Some of our processors are based in the United States (Mailchimp, Mandrill, Vercel, Google Analytics, Google Calendar). Where personal data leaves the UK, we rely on the appropriate safeguards under UK GDPR — typically the UK International Data Transfer Agreement or the EU Standard Contractual Clauses combined with the UK Addendum, plus any additional supplementary measures the providers operate (encryption in transit and at rest, access controls, etc.).
6. How long we keep your data
- · Contact form submissions: kept for two years from your last interaction, then deleted.
- · Mailchimp contact records (Scorecard, launch signups): kept until you unsubscribe or ask us to delete the record. Every email we send includes an unsubscribe link.
- · Records that are part of paid client engagements: kept for six years after the engagement ends, in line with HMRC and statutory record-keeping requirements.
- · Server logs (Vercel): kept for up to 30 days for technical and security purposes.
- · Analytics (Plausible): aggregate, non-personal data; retained according to Plausible's own retention policy.
7. Your rights
Under UK GDPR you have the right to:
- · Access the personal data we hold about you.
- · Correct data that is wrong or out of date.
- · Delete your data ("right to be forgotten").
- · Restrict our processing of your data, or object to it.
- · Receive a portable copy of the data you've provided.
- · Withdraw consent for any processing that's based on consent (without affecting the lawfulness of processing before withdrawal).
To exercise any of these, email hello@opsfirst.co.uk. We'll respond within one calendar month. There's no fee unless a request is clearly excessive or repetitive.
8. Security
The site is served over HTTPS only. All data in transit is encrypted. The third-party services we use (Mailchimp, Vercel, Google) operate to industry-standard security practices including encryption at rest, access controls and regular auditing. Access to the Mailchimp audience is restricted to the company directors. We don't keep raw form submissions or scorecard data anywhere outside the named processors above.
9. Children's data
The site and its services are not directed at children under 16, and we don't knowingly collect personal data from anyone under that age. If you believe a child has provided personal data via the site, contact us and we'll delete it promptly.
10. Changes to this policy
We'll update this policy when we add new tools or change the way we handle data. Material changes will be flagged at the top of the page and the "last updated" date below the title will be revised. The current version is dated 30 April 2026 (GA4 added with consent banner).
11. Complaints
If you're not happy with how we've handled your data, please tell us first — email hello@opsfirst.co.uk and we'll investigate. You also have the right to complain directly to the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113
Web: ico.org.uk