Last updated: 15 June 2026 • Governed by UK GDPR and the Data Protection Act 2018
1. Who we are
PublisherOpsAI is a trading name operated by Muhammad Waseem Rafi (“we”, “us”, “our”). We are the data controller for personal data collected through this website and the PublisherOpsAI plugin and services.
You can contact us at any time at info@publisheropsai.com.
2. Data we collect
We collect personal data only when you actively provide it to us or when it is generated as part of your use of this website and our services.
Data you provide directly
- Contact form: your name, email address, and message when you submit an enquiry through the Contact page.
- Account registration: your name and email address when you create a Pro or Agency account.
- Payment: billing name and payment method details when purchasing a paid plan. Payment card details are processed by our payment provider and are never stored on our servers or systems.
Data collected automatically
- Server logs: IP address, browser type, operating system, referring URL, and pages visited. These are retained for security and diagnostic purposes.
- Cookies: session and preference cookies necessary for the website to function. See section 8 for details.
Data we do NOT collect
PublisherOpsAI does not collect, store, or process your WordPress post content. When you use the plugin, your content travels directly from your WordPress site to your chosen AI provider (Anthropic, OpenAI, or Google) using your own API key. Your content never passes through our servers.
3. How we use your data
- To respond to enquiries submitted via the contact form.
- To create and manage your account and process your subscription.
- To send transactional emails (receipts, subscription confirmations, important service updates).
- To diagnose technical issues and maintain the security of our systems.
- To comply with legal obligations.
We do not use your personal data for automated profiling, nor do we sell, rent, or share it with third parties for marketing purposes.
4. Legal basis for processing
- Contract performance (Article 6(1)(b) UK GDPR) — processing your subscription data to deliver the service you have paid for.
- Legitimate interests (Article 6(1)(f) UK GDPR) — server log retention for security, fraud prevention, and service improvement, where our interests are not overridden by your rights.
- Legal obligation (Article 6(1)(c) UK GDPR) — retaining billing records to comply with UK financial and tax regulations.
- Consent (Article 6(1)(a) UK GDPR) — for optional cookies that are not strictly necessary. You may withdraw consent at any time.
5. Data sharing and third parties
We do not sell personal data. We share data only in the following circumstances:
- Payment processor: your billing information is shared with our payment provider (Stripe, Inc.) solely for the purpose of processing transactions. Stripe processes data in accordance with PCI DSS standards.
- Hosting provider: our website is hosted on servers that may process IP addresses and request logs as part of standard hosting operations.
- Legal requirements: we may disclose personal data if required to do so by law or in response to a valid legal request from a competent authority.
Transfers of personal data outside the UK are subject to appropriate safeguards (e.g. Standard Contractual Clauses or adequacy decisions) where required.
6. Data retention
- Contact form submissions: retained for 12 months, then deleted.
- Account data: retained for the duration of your account plus 12 months after closure, then deleted or anonymised.
- Billing records: retained for 7 years to comply with UK financial regulations.
- Server logs: retained for 30 days, then automatically deleted.
7. Your rights
Under UK GDPR you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data where there is no lawful reason to continue processing it.
- Restriction — request that we restrict processing of your data in certain circumstances.
- Portability — request a copy of data you provided to us in a structured, machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at info@publisheropsai.com. We will respond within 30 days. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.
8. Cookies
This website uses cookies. Please see our Cookie Policy for full details of the cookies we use, their purpose, and how to manage them.
9. Security
We take the security of your personal data seriously. We implement appropriate technical and organisational measures to protect data against unauthorised access, disclosure, alteration, or destruction. These include encrypted data transmission (HTTPS), restricted access to personal data, and regular security reviews.
No method of transmission over the internet is 100% secure. If you believe your data has been compromised, please contact us immediately at info@publisheropsai.com.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the “Last updated” date at the top of this page. We encourage you to review this page periodically. Continued use of our services after any changes constitutes acceptance of the updated policy.
For any questions about this Privacy Policy, to exercise your rights, or to raise a data protection concern, please contact us:
Email: info@publisheropsai.com
Trading name: PublisherOpsAI