Privacy Policy

Last updated: 28 August 2026

BossOps provides hospitality operations software for supplier costs, recipes, rotas, attendance, HR records and related business workflows. This policy explains the information processed through BossOps and the controls available to customers and users.

Who is responsible for the data?

For account administration, product support and billing information, BossOps acts as the data controller. When a hospitality business uses BossOps to manage its employees, workers, suppliers or operational records, that business will normally be the controller of that information and BossOps processes it on the business's behalf.

Information we process

How information is used

Information is used to provide the service, authenticate users, store customer records, calculate costs and margins, process approved uploads, operate workforce features, produce exports, administer subscriptions, prevent abuse, troubleshoot the service and respond to support requests.

Invoice and recipe extraction can use automated document processing. Extracted data is presented for human review before it should be relied upon as an approved operational record.

Camera, photos and location

Camera access is requested only when a user chooses a camera-based workflow. Location access may be requested when an authorised customer enables location verification for clocking. Optional attendance photos are tied to the relevant attendance record. These controls should only be enabled by customers where they have a lawful and proportionate basis for using them.

Service providers

BossOps may use service providers for cloud hosting and storage, payment processing, email or messaging delivery and document processing. Access is limited to what is needed to provide the relevant service. Customer data is not sold to advertisers.

Security

BossOps uses account-scoped access controls, role permissions, encrypted HTTPS connections, secure session cookies and cloud-hosted storage. No online service can promise absolute security, so customers should also protect administrator accounts and restrict access appropriately.

Retention and deletion

Operational records are retained while required to provide an active customer account and for reasonable backup, security and billing purposes. Customers can request export or deletion of their workspace data, subject to legal or security retention requirements. Employers remain responsible for deciding appropriate retention periods for employee records they place in BossOps.

Your rights

Depending on the circumstances, UK data-protection law may provide rights to access, correct, delete, restrict or obtain a copy of personal information, and to object to certain processing. Employees whose information is controlled by their employer should normally raise a request with that employer first.

Contact

Privacy and data requests: [email protected]

Website: boss-ops.co.uk