Last updated: 25 July 2026
True Observer Media Ltd. (“we”, “our”, “us”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, publish, share and safeguard information when you use OPserver,
the Reputation Profile Hub, our desktop software, account services, claim forms, chat tools and related services.
1. Who We Are
True Observer Media Ltd.
Registered in England & Wales
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Company Number: 16688440
Email: info@trueobservermedia.com
For data protection purposes, True Observer Media Ltd. is the controller of personal data collected through OPserver and our services, unless we clearly state otherwise.
2. Scope of This Policy
This policy applies to:
- the public website at opserver.app;
- the OPserver desktop and operational platform;
- public and private pages in the Reputation Profile Hub;
- licensing, account, ownership-claim, payment and support workflows; and
- TOBI, contact forms, communications and related integrations presented through OPserver.
3. What Data We Collect
We may collect the following categories of data:
- Contact and account information: name, email address, phone number, organisation, role, licence details, account identifiers and communication preferences.
- Operational and case data: case descriptions, assignments, notes, source links, observations, evidence, screenshots, timestamps, platform identifiers and audit records used within authorised operational workflows.
- Reputation profile data: company, venue or profile names; public ratings and reviews; public-source links; on-site observations; dates; score components; profile status; images; supporting screenshots; and public-safe summaries.
- Private review and ownership-claim data: access-card codes, business and legal names, company number, postcode, representative or director details, work email, phone number, authority information and evidence submitted to confirm ownership or representation.
- Communications: messages, email records, chat transcripts, uploaded files and any information you choose to provide through TOBI, support or forms.
- Payment and transaction data: purchase history, invoice details, payment status and transaction references. Full payment-card details are normally processed by our payment provider and are not stored by us.
- Technical and security data: IP address, browser, device and operating-system information, approximate location, referral URL, pages visited, login and access logs, cookie identifiers and consent preferences.
Case material may include sensitive or special-category information where an incident, public allegation, workplace concern,
legal claim or safeguarding matter makes that information relevant. We ask users to provide only what is necessary and apply
additional access controls where sensitive information is processed.
4. How We Use Your Data
We process personal data only for specific and legitimate purposes, such as:
- providing, licensing, securing and supporting OPserver;
- creating, reviewing and maintaining reputation profiles, scores, reports and evidence packages;
- publishing approved public-safe observations and responding to correction or right-of-reply requests;
- operating private review links, ownership checks and approved account access;
- processing purchases, subscriptions, invoices and transaction records;
- routing enquiries and assisting with support through TOBI, chat, forms and email;
- preventing misuse, spam, fraud, unauthorised access and security incidents;
- improving our website, software, workflows and user experience; and
- meeting legal, regulatory, accounting, insurance and governance obligations.
5. Legal Basis for Processing (UK GDPR / GDPR)
Depending on the activity, we rely on one or more of the following grounds:
- Contractual necessity: to provide licences, accounts, reports, subscriptions, purchases or services you request.
- Legitimate interests: to operate and secure OPserver, undertake proportionate public-interest or commercial reputation research, publish approved public-safe information, protect evidence, manage relationships and improve services, provided your rights do not override those interests.
- Consent: for optional analytics, marketing or another activity where consent is the appropriate basis.
- Legal obligations: to comply with tax, accounting, court, regulatory or law-enforcement requirements.
- Special-category conditions: where sensitive data is necessary, an applicable condition such as explicit consent, legal claims or substantial public interest.
6. Reputation Profile Hub: Public and Private Pages
Public profiles
Public reputation profiles may be published at a readable address such as /reputation/business-name.
They may be searchable and indexed by search engines. A public profile contains only fields approved for public release,
such as a profile name, score, public-source rating, public-safe observation, selected image or status. Search engines may
retain cached results for a period after information is changed or removed.
Private card-code reviews
A private review uses a separate unguessable card code at an address such as /r/CODE. We apply
noindex, nofollow, noarchive and no-store controls to these routes. These measures reduce
discovery and caching but do not replace account authentication: anyone who receives the working link or code may be able
to open the selected preview. Recipients should keep it confidential.
Private previews may tease blurred content. Sensitive evidence, internal notes, private contact details and restricted
operational material remain behind ownership, account, payment or additional approval controls. A CSS blur is only a visual
presentation control; restricted originals are not intentionally delivered to an unauthorised browser.
Claims, corrections and right of reply
A representative may submit a claim to confirm that they act for an organisation. We may compare submitted details with
Companies House, a company-domain email, our private case record or other proportionate evidence. Matching information does
not guarantee access. You may request correction of inaccurate personal data or submit relevant context and a right of reply.
7. AI-Assisted Tools and Human Review
TOBI and other AI-assisted tools may help with intake, triage, drafting, summarisation, classification and routing.
Messages and relevant context may be sent to an AI service provider, including OpenAI, to generate an output. These tools
support our team and do not replace human responsibility for case handling, publication, verification or final decisions.
Do not submit passwords, payment-card details, private keys or unnecessary sensitive information.
8. Data Sharing and Processors
We do not sell or trade personal data. We may share limited data with:
- Hostinger and its authorised subprocessors for VPS hosting, storage, backups, networking and server security;
- Firebase / Google Cloud or similar infrastructure providers for authentication, database, storage, messaging and operational workflows;
- OpenAI and other AI or automation providers where needed to operate assisted intake, routing, summarisation or analysis;
- email, communications, analytics, automation, payment and accounting providers used to deliver the service;
- authorised staff, vetted volunteers, contractors, agents or specialist advisers who need access for an approved purpose and are subject to confidentiality and access controls;
- platforms, publishers, insurers, legal advisers, regulators or authorities where a report, notice, evidence handover or legal obligation requires it; and
- a buyer, successor or professional adviser in connection with a genuine corporate transaction, subject to appropriate safeguards.
We limit access to what is necessary for the relevant purpose and use contractual, technical and organisational safeguards where appropriate.
9. Hostinger Hosting and International Transfers
OPserver is hosted on Hostinger infrastructure. Under Hostinger's Data Processing Addendum, the applicable Hostinger entity
acts as a processor for covered hosting services and processes customer data to provide the service and follow documented
instructions. Hostinger may use authorised subprocessors under written data-protection obligations and remains responsible
for their performance under its DPA.
Hostinger describes a shared-responsibility model: it secures the hosting infrastructure, while we remain responsible for
our application configuration, user permissions, credentials and the data we choose to store. Hostinger states that customer
data is deleted after termination in accordance with the relevant service and legal requirements; its general DPA describes
deletion after 30 days unless another obligation applies.
Some providers may process data outside the UK or European Economic Area. Where required, we use safeguards such as adequacy
regulations, Standard Contractual Clauses, the UK International Data Transfer Addendum, data-processing agreements and
transfer-risk assessments. Hostinger's DPA provides for EU Standard Contractual Clauses and the UK Addendum where applicable.
You can read the Hostinger Data Processing Addendum.
10. Cookies, Analytics and Third-Party Content
Our website uses cookies and similar technologies to:
- provide security, consent management, sessions, account access and essential functionality;
- remember preferences and support chat or form continuity;
- measure and improve performance through optional analytics; and
- display third-party content such as YouTube videos where permitted.
Matomo Analytics (self-hosted)
We use self-hosted Matomo to understand how visitors interact with our content. Depending on your consent preferences,
it may use first-party cookies and collect an anonymised IP address, pages visited, device type, operating system and
approximate location.
Embedded YouTube Videos
We use YouTube's privacy-enhanced embed domain where possible. Loading or playing a video may still allow Google/YouTube
to receive technical information such as your IP address, device details, page URL and playback activity under its own terms.
You can manage preferences using the cookie controls on this site or your browser. Disabling non-essential cookies may
limit analytics, video, chat or convenience features.
11. Data Retention
We keep personal data only as long as necessary for the purposes described above or as required by law.
- General enquiries and chat: normally up to 24 months after the last interaction unless incorporated into an operational, client, legal or safeguarding record.
- Accounts and licences: while active and for a reasonable period afterwards for security, support, audit and contractual records.
- Cases, evidence, reports and reputation records: normally up to 6 years after closure or last substantive activity, unless legal, evidential, safeguarding, insurance or dispute reasons require longer.
- Ownership claims: for as long as needed to decide and audit the claim, maintain authorised access and resolve disputes.
- Payment and accounting records: normally at least 6 years.
- Analytics and cookie data: according to the settings of the relevant consent or analytics tool.
We may delete, anonymise, unpublish or archive information earlier where it is no longer required.
12. Your Rights
Under UK GDPR / GDPR and applicable law, you may have the right to:
- access personal data we hold about you;
- request correction or deletion;
- restrict or object to processing;
- request data portability;
- withdraw consent where processing is based on consent;
- object to direct marketing; and
- ask for information about automated decision-making where applicable.
To exercise your rights, request a correction or raise a concern about a profile, email
privacy@trueobservermedia.com. We may need to verify your identity.
Some rights may be limited where information is required for legal claims, security, safeguarding, evidence preservation,
regulatory obligations, freedom of expression or the rights of others.
13. Security and Shared Responsibility
We use proportionate technical and organisational measures including role-based permissions, access controls, strong
authentication, encryption in transit, restricted routes, audit trails, security logging, backups and confidentiality
obligations. Hostinger's DPA describes physical and logical access controls, authentication, encryption and incident
management for its infrastructure. We assess personal-data incidents and notify affected parties or regulators where required.
No online system can be guaranteed completely secure. Keep private card codes and account credentials confidential and do not send passwords, full card details or private keys through chat or ordinary forms.
14. Children and Vulnerable People
OPserver is not directed at children. Where an operational matter involves a child, young person or vulnerable person,
provide only information necessary for the authorised purpose. We may apply additional safeguarding and access restrictions.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with the
“last updated” date.
16. Contact Us
If you have any questions about this Privacy Policy or your personal data, please contact:
Data Protection Officer
True Observer Media Ltd.
Email: privacy@trueobservermedia.com
If you are not satisfied, you may also contact the UK Information Commissioner’s Office (ICO) or your local
data protection authority.