Live product launch · Monday 16 NovemberLive launch · Mon, Nov 16 · 7 PM ET | 6 PM CT | 5 PM MT | 4 PM PT. Key features, shown live in the product.Register for the launch
Legal

Privacy Policy

How DesignOps handles information in your DesignOps Workspace.

Provided by Shuru L.L.C-FZEffective October 7, 2026
On this page

#About this Privacy Policy

This Privacy Policy describes how DesignOps processes Personal Data in connection with the Services. Capitalized terms have the meanings given in our Terms of Service.

For most Customer Data — including information a Customer and its Team Members put into the Workspace, such as Personal Data about the Customer's own clients, Leads and contacts — the Customer is responsible for that information and DesignOps processes it on the Customer's behalf where applicable.

For information relating to a User's DesignOps account, subscription, billing and operation of the Services, DesignOps may act as the controller.

#1. Definitions

TERMMEANING
DesignOps, the ServicesThe DesignOps software-as-a-service application, including its modules, the DesignOps Email Extension, the DesignOps Product Clipper, the DesignOps Assistant and the AI Features.
DesignOps / Shuru L.L.C-FZThe company that provides DesignOps. Registered Address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, UAE
CustomerThe studio or organization that subscribes to DesignOps and owns a Workspace, together with the Team Members who use it under that subscription.
UserAny individual who accesses DesignOps, including a Customer's Team Members.
WorkspaceThe DesignOps environment a Customer creates to run its studio, including Team Members, Brand settings, Plan & billing, connected Third-Party Services, Projects, Leads and related records.
Team MemberA User invited to a Workspace and holding a role that determines their permissions and access.
ProjectA piece of client work within a Workspace, including its Scope of Work, Proposal, Selections, Tasks, Finance and related information.
LeadA potential piece of work captured in the Leads module or through the DesignOps Email Extension, together with associated contact and project information.
Customer DataInformation a Customer or its Team Members submit to or generate in the Workspace, including Leads, Customer Content, Discovery Call transcripts, Suppliers, Products, Procurement records, Finance records, documents and Personal Data contained in them.
Customer ContentCreative and project material within Customer Data, including Inspiration boards, Selections, Scopes of Work, Proposals, images, documents and files.
Personal DataInformation relating to an identified or identifiable individual.
AI FeaturesDesignOps features that use AI to generate drafts, enrichment, suggestions or recommendations for Users to review, including Lead enrichment and fit scoring, outreach drafting, Discovery Call extraction, Scope of Work and Proposal drafting, mood board generation, client-update drafting and the DesignOps Assistant.
DesignOps Email Extension / Lead ExtractorThe browser extension that allows a User to capture relevant Lead information from an open Gmail/Outlook email after the User grants the required permission.
DesignOps Product ClipperA browser extension that allows a User to capture product information from a webpage and add it to the DesignOps Product Library.
Third-Party ServicesServices a Customer chooses to connect to its Workspace through Integrations, currently including Asana, Basecamp, Canva, Pinterest, Plaud, QuickBooks and Dropbox.
Sub-processorA third party engaged by DesignOps to process Personal Data on its behalf in connection with providing the Services.

#2. Information We Collect

We collect information necessary to provide and operate the Services. Where a category depends on a Customer actively using a particular feature, we process that information when the feature is used.

#2.1 Account and Workspace Information

When you create an account or Workspace and invite Team Members, we may collect names, email addresses, Workspace information, Team Member roles and permissions, Brand settings and Plan & billing information. Users may sign in using email/password or Gmail. DesignOps does not store your Google password or email account password.

#2.2 Customer Data and Customer Content

Customer Data may include Leads, client contact information, project information, Discovery Call transcripts, Projects, Scopes of Work, Proposals, Inspiration boards, Selections, Suppliers, Products, Procurement information, Finance information, documents and other information submitted, uploaded, imported, captured, created or otherwise made available through a Customer Workspace.

For purposes of the DesignOps Terms of Service, “Customer Data” means the Customer Data and other information, content, files, documents, images, text, product information, lead information, client information, project information or other materials that a Customer or its authorized Users submit, upload, import, capture, create, connect or otherwise make available through the Services.

Customer Data may contain Personal Data about the Customer's own clients, Leads and contacts. Customers are responsible for ensuring that they have the appropriate rights, permissions and lawful basis to provide that information to DesignOps.

#2.3 DesignOps Email Extension — Lead Extractor

The Lead Extractor operates when the User opens the relevant Gmail or Outlook inbox/email, grants the required Gmail or Outlook permission and actively uses the Lead Extractor.

It may process information from the open email necessary to identify and capture a Lead, including name, email address, phone number, address, budget, project information, product information and other relevant Lead information.

The Lead Extractor does not continuously monitor the User's mailbox and is not designed to read unrelated emails in the background.

The original email body is not stored by DesignOps. The Lead Extractor does not access or store email attachments for Lead extraction.

Email content processed by the Lead Extractor is sent to OpenAI for structured extraction. When Smart AI Fill or lead capture is used, the information sent includes the inquiry email sender name, sender email, subject and complete email body.

If the User extracts information but does not save the Lead, the extracted Lead information is not retained by DesignOps. If the User saves the Lead, the relevant Lead information, including the sender's email address, becomes part of the Customer's Lead data.

#2.4 DesignOps Product Clipper

The Product Clipper is a separate browser extension that allows a User to capture product information from a webpage they choose to clip from and add it to the Product Library.

Clipped information may include product name, description, brand or manufacturer, supplier or vendor, URL, specifications, dimensions, price, SKU/model/reference number, product images and other product attributes available on the source webpage.

Users can review, edit or delete clipped product information.

#2.5 Third-Party Services and Integrations

With Customer authorization, DesignOps exchanges information with connected Third-Party Services. Current integrations include Asana, Basecamp, Canva, Pinterest, Plaud, QuickBooks and Dropbox. Information transmitted to or stored by a Third-Party Service through an Integration is subject to that Third-Party Service's applicable terms, privacy policy and data-handling practices. DesignOps does not control the independent processing of information by a Third-Party Service after that information has been transmitted to the service.

#2.6 Communications and Support

When you contact DesignOps for support, we may process the information included in your communication and our response. DesignOps sends service and product-education communications including account invitations, product updates, support responses, guide modules and training videos. Training and product-education communications are currently sent manually.

#2.7 Usage and Product-Adoption Information

DesignOps uses usage information associated with individual Users to understand product adoption and improve the product experience. Current usage information includes login activity and feature usage. This information is separate from Customer Data and is not shared with Customers as an adoption report.

#2.8 Billing and Payment

DesignOps uses third-party payment services to process payments and billing. DesignOps does not store full payment-card numbers.

#3. How We Use Information

  • Provide, operate and secure the Services and Workspaces.
  • Manage accounts, roles and permissions.
  • Process Plan & billing.
  • Provide the AI Features.
  • Operate the DesignOps Email Extension and Product Clipper when actively used.
  • Synchronize information with Third-Party Services selected by the Customer.
  • Provide customer support.
  • Send service, account and product-training communications.
  • Understand product adoption and improve the Services using usage information.
  • Prevent fraud, abuse and unauthorized access.
  • Enforce our Terms.
  • Comply with applicable law and respond to lawful requests.

DesignOps does not sell Personal Data. DesignOps does not share Personal Data for targeted advertising. DesignOps does not use Customer Data to create its own marketing or prospect database. DesignOps does not independently contact Leads whose information has been entered by a Customer. DesignOps does not use Customer Data to create marketing materials, case studies or similar public materials without separate permission.

#4. AI Features and Your Data

#4.1 AI Processing

AI Features may process relevant information to generate Lead enrichment, Lead fit scores, outreach drafts, Discovery Call information, Scope of Work drafts, Proposal drafts, mood boards, client updates and other AI-assisted recommendations and drafts.

AI Features are generally initiated by User actions or specific product workflows enabled by the User. Certain workflows, including Lead AI enrichment, may run in the background after a Lead is added.

#4.2 AI Recommendations

AI-generated outputs, including Lead enrichment and fit scores, are recommendations and not final decisions. Users are responsible for reviewing AI-generated information and making their own decisions.

DesignOps does not make decisions about individuals that produce legal or similarly significant effects.

#4.3 No AI Training Using Customer Data

DesignOps does not use Customer Data or Customer Content to train, fine-tune, improve or develop general-purpose LLM models.

#4.4 AI Prompts and Outputs

AI prompts submitted through DesignOps are processed to provide the applicable AI Features and are not stored or retained by DesignOps as Workspace data.

AI-generated outputs that are saved or generated as part of a DesignOps workflow may be persisted as Workspace data. This includes outputs such as drafts, enriched leads, extracted products and generated documents. Once persisted, these outputs are treated as Customer Data and are subject to the applicable storage, access, retention and deletion provisions for Customer Data.

When a User regenerates an AI output, the current output may be replaced by the newly generated output where supported by the relevant Service functionality.

#4.5 Lead Extractor and Product Clipper

The original Gmail/Outlook email content processed by the Lead Extractor is sent to OpenAI for structured extraction when Smart AI Fill or lead capture is used. Product extraction is also an AI Feature and may send relevant webpage text or uploaded files to OpenAI.

#4.6 AI Providers

DesignOps currently uses OpenAI as its AI provider for certain AI Features. Relevant Customer Data may be processed by OpenAI to provide those AI Features. DesignOps does not use Customer Data or Customer Content to train, fine-tune, improve or develop general-purpose LLM models. DesignOps has contractual data-processing terms in place with OpenAI governing OpenAI's processing of Customer Data. OpenAI acts as a processor for such processing and processes Customer Data for purposes of providing the applicable Services.

#4.7 Third-Party Integrations

DesignOps currently supports integrations with third-party services, including Asana, Basecamp, Dropbox, Canva, Plaud, Pinterest and QuickBooks.

When you connect an Integration, information required to provide the Integration may be transmitted to or received from the applicable Third-Party Service.

Once information is transmitted to a Third-Party Service, that information is subject to the third party's applicable terms, privacy policy and data-handling practices. DesignOps does not control the independent processing of information by those third parties.

Customers should review the applicable third-party terms and privacy documentation before connecting an Integration or transmitting Customer Data through it.

DesignOps' privacy commitments apply to DesignOps' own processing of Customer Data and do not extend to a third party's independent processing after information is transmitted to that third party.

Asana's current AI FAQ provides information about its treatment of Customer Data and AI-related processing: https://help.asana.com/s/article/asana-ai-faq?language=en_US#data-security-and-oversight

Information about 37signals' handling of Basecamp data is available in its Privacy Policy: https://37signals.com/policies/privacy

DesignOps does not make representations regarding the AI-training or other independent data-processing practices of Third-Party Services beyond the commitments expressly stated in this Privacy Policy.

Depending on your location and how you use the Services, applicable privacy and data protection laws may require DesignOps to have a legal basis for processing Personal Data. Where such requirements apply, DesignOps may process Personal Data on the basis of performance of a contract, legitimate interests, compliance with legal obligations, consent where required, or another lawful basis permitted by applicable law.

These legal bases may apply to processing activities such as providing and administering the Services, authenticating users, processing transactions and billing, providing customer support, maintaining and securing the Services, preventing fraud and abuse, improving and developing the Services, processing information through Customer-authorized Integrations, and complying with applicable legal obligations.

Where DesignOps processes Personal Data on behalf of a Customer within a Customer Workspace, the Customer may determine the purposes and legal basis for that processing, and the Customer is responsible for ensuring that it has an appropriate legal basis and any required permissions to provide that Personal Data to DesignOps.

Where consent is relied upon as a legal basis, DesignOps will obtain consent where required by applicable law and will provide appropriate mechanisms to withdraw consent where required.

#6. How We Share Information

#6.1 Within Your Workspace

Customer Data may be available to Team Members within the same Workspace according to their assigned roles and permissions. Workspace owners and authorized administrators can add, remove and modify Team Member permissions.

When a Team Member is removed, their Workspace access is revoked. Information created by that Team Member may remain within the Workspace.

#6.2 Third-Party Services

DesignOps may exchange information with Third-Party Services when a Customer actively connects and authorizes an Integration. The data flow varies by Integration.

#6.3 Integration Data Flows

Asana and Basecamp: project and task information can synchronize bidirectionally, including project information, project users, tasks, task name, description, due date and assignee. Users can create tasks in Asana or Basecamp from DesignOps.

Canva: Users can import images from Canva directly into their DesignOps Inspiration mood boards.

Pinterest: DesignOps can synchronize mood-board information, including relevant images and content, from connected boards.

Plaud: DesignOps can synchronize call transcripts. It does not receive the underlying audio recording.

QuickBooks: DesignOps can synchronize invoice-related information, including invoice and payment status.

Dropbox: files remain stored in Dropbox. DesignOps can access and preview supported files through the Integration.

#6.4 Integration Disconnection

When an Integration is disconnected, future synchronization stops and the relevant authentication credentials or tokens are revoked. Previously synchronized information may remain in DesignOps depending on the Integration.

#6.5 Sub-processors

DesignOps may use third-party service providers to operate parts of the Services. Current providers and data flows include OpenAI for AI processing, Stripe for billing, BatchData for property enrichment, Cloudflare Turnstile for bot verification on the public lead form, Google for OAuth sign-in and Google Cloud hosting, Resend for transactional communications, and Customer-connected services including Asana, Basecamp, Canva, Dropbox, Pinterest, QuickBooks and Plaud. DesignOps does not currently maintain a public Subprocessor List.

DesignOps may disclose information where required by applicable law or lawful legal process, or where necessary to enforce its Terms or protect rights, safety and property.

#6.7 Business Transfers

If DesignOps is involved in a merger, acquisition, financing, restructuring or sale of assets, information may be transferred as part of that transaction, subject to applicable law.

#7. International Transfers

DesignOps is intended to operate as a global service, including for Customers in the United States. Customer Data is currently stored and processed in Google Cloud Platform's us-central1 (Iowa, USA) region. DesignOps primarily serves U.S. customers today. No Standard Contractual Clauses are currently in place.

#8. Data Retention and Deletion

#8.1 Workspace Deletion

Customer Data remains within the Workspace while the Customer maintains the Workspace, subject to applicable deletion processes. Following termination, supported Customer Data remains available for export for thirty (30) days. After that period, DesignOps will permanently delete the applicable Customer Data within ninety (90) days, subject to applicable law and the retention obligations described in this Privacy Policy.

When a Firm owner deletes a Workspace, the Customer Data in that Workspace is deleted.

DesignOps does not retain a separate copy of deleted Customer Data.

#8.2 Individual Leads

Customers can delete individual Leads. When a Lead is deleted, information related to that Lead is deleted according to the applicable product workflow.

#8.3 Team Member Removal

When a Team Member is removed from a Workspace, their Workspace access is removed. Data they previously created may remain in the Workspace. Their login/account information is deleted according to the account lifecycle.

#8.4 Data Export

Customers may request a copy of their Customer Data maintained in the Services. DesignOps will provide the requested Customer Data in an appropriate export format or through available export functionality, depending on the nature and volume of the data. Certain data or export requests may require manual processing by DesignOps. Individual modules may also provide export functionality where available.

#8.5 Usage and Product Adoption Data

This usage and product-adoption data may be associated with individual User accounts. DesignOps does not use Customer Data itself for product-adoption analytics.

DesignOps uses Google Analytics 4 (GA4) for product analytics and usage measurement and Microsoft Clarity for understanding User interactions and product experience, including session and interaction analysis.

Usage and product-adoption data is separate from Customer Data. DesignOps may collect information about how Users interact with and use the Services, such as login activity, feature usage and other product-adoption activity, for the purpose of understanding product adoption, identifying drop-off points in product workflows and improving the product experience.

#8.6 Account and Billing Information

DesignOps collects and processes information necessary to create and maintain Customer accounts, manage Workspaces, provide the Services, process subscriptions and payments, and maintain billing records. Payment card and billing-address information is stored by Stripe, not DesignOps. DesignOps stores a Stripe customer reference and subscription status and billing-period records.

Account data, including profile, Workspace and project/content data, is retained for the life of the account and is deleted on request or following termination, subject to the export and deletion periods described in this Privacy Policy. Billing, tax and transaction records are retained for five (5) years and then deleted or anonymized, subject to applicable legal requirements. Stripe independently retains payment records in accordance with its own applicable retention policies.

#9. How We Protect Information

DesignOps uses technical and organizational measures intended to protect Personal Data against unauthorized access, loss, alteration and disclosure.

DesignOps uses HTTPS for data transmitted between Users and the Services. Customer Data and infrastructure are hosted on Google Cloud Platform in a GKE Autopilot Kubernetes cluster in us-central1 (Iowa, USA).

Access to Customer Data is restricted to authorized personnel. DesignOps uses role-based access controls for internal access to Customer Data. Persistent storage is encrypted at rest using Google-managed encryption keys. Integration OAuth tokens are additionally encrypted at the application level, and passwords are hashed rather than stored in plaintext.

#9.1 Security Monitoring

DesignOps uses OpenTelemetry for general observability of the Services, including traces and logs. OpenTelemetry is not used for security monitoring or anomalous-access detection.

#9.2 Data Breach Response

If DesignOps identifies a security incident or data breach, DesignOps will follow a basic incident-handling process to detect and assess the incident, investigate the scope and affected systems or data, contain and remediate the issue, and take reasonable steps to prevent recurrence. Where notification is required by applicable law, DesignOps will provide the required notification to affected parties or relevant authorities.

No system can be guaranteed to be completely secure. Customers are responsible for maintaining the security of their account credentials, Team Member permissions and connected third-party accounts.

#10. Your Rights and Choices

Depending on where you are located and which privacy laws apply, you may have rights relating to your Personal Data, including rights to access, correct, delete, restrict or object to certain processing and other rights provided by applicable law.

#10.1 Customer Data

Where Personal Data is contained within Customer Data and processed on behalf of a Customer, the Customer is generally responsible for handling requests relating to that information. If you are a Customer's client or contact and your information is contained within that Customer's Workspace, you should generally direct your request to that Customer. DesignOps will provide reasonable assistance where required by applicable law.

#10.2 Account Information

Users cannot currently change certain core account information, including their account name and email address, through the DesignOps product interface after signup.

#10.3 Lead Deletion

Customers can delete individual Leads and related Lead information from their Workspace.

#10.4 Restriction and Objection

Where applicable privacy law provides a right to request restriction of processing or to object to certain processing activities, Users may submit such requests through the DesignOps support channel at support@getdesignops.ai.

DesignOps will review and respond to applicable requests in accordance with the privacy laws that apply to the request. Where DesignOps processes Personal Data on behalf of a Customer within a Customer Workspace, the request may need to be handled by the relevant Customer or Firm Owner, depending on the nature of the request and DesignOps' role in the processing.

#11. U.S. Privacy Notice

DesignOps is provided for business and professional use only. It is intended for business users, including individual professionals, design studios and companies. DesignOps is not intended for personal, household or consumer use.

Customers may enter Personal Data about their own clients, Leads and contacts into DesignOps. Customers are responsible for ensuring that they have the appropriate rights, permissions and lawful basis to provide that information to DesignOps and to process it through the Services.

DesignOps does not sell Personal Data. DesignOps does not share Personal Data for targeted advertising and does not currently use advertising retargeting technology. DesignOps does not use Customer Data to create its own marketing or prospect database. DesignOps does not independently contact Leads whose information has been entered by a Customer. DesignOps does not use Customer Data to create marketing materials, case studies or similar public materials without separate permission.

Where applicable U.S. privacy laws provide additional rights, those rights will apply subject to the requirements, limitations and exceptions of the applicable law. Requests to exercise applicable privacy rights may be submitted to support@getdesignops.ai.

#12. Communications

DesignOps sends service and administrative communications necessary to provide the Services, including account invitations, product updates, support responses, guide modules and training videos.

Training and product-education communications are currently sent manually. Users may opt out of product-training and tips communications. Essential service and account communications may continue where necessary to operate the Services.

DesignOps does not currently use Customer Data to create marketing material, case studies or other marketing content.

#13. Cookies and Similar Technologies

DesignOps may use cookies and similar technologies through third-party analytics and product-experience tools, including Google Analytics 4 (GA4) and Microsoft Clarity, to understand product usage, measure product adoption and improve the user experience. The specific cookies or similar technologies used may depend on the configuration of these services. The staff-only admin panel uses a signed session cookie, and the Cloudflare Turnstile widget on the public intake form may set its own cookie.

#14. Privacy Complaints

If you have a concern about how DesignOps handles Personal Data, you may contact DesignOps at support@getdesignops.ai. We will review and respond to applicable privacy requests and complaints in accordance with applicable law.

Where applicable privacy law provides a right to lodge a complaint with a supervisory, privacy or data-protection authority, you may exercise that right with the relevant authority in your jurisdiction.

#15. Changes to this Policy

We may update this Privacy Policy from time to time. Where appropriate, material changes will be communicated through both email and the DesignOps product. The Effective Date will be updated when a new version becomes effective. Privacy Policy updates are separate from changes to the DesignOps Terms of Service.

#16. How to Contact Us

For privacy questions or to exercise an applicable privacy right, contact DesignOps at support@getdesignops.ai. Requests relating to Personal Data contained in a Customer Workspace may need to be directed to the relevant Customer or Firm Owner where DesignOps processes that information on the Customer's behalf.

Privacy Contact: support@getdesignops.ai

Address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, UAE