Trust & data
Automated messages carry your name. We treat that with the seriousness it deserves.
The strongest thing an automation company can tell you is what it will not do. Four rules are built into every Operscale system, enforced by the software itself, not promised in a meeting. Each one removes a category of risk before it can ever attach to your business.
The four rules.
No message goes out without a lawful basis.
Keeps you on the right side of the law in every market we sell into, where the fines are measured in millions.
Before the assistant messages anyone, the system checks it is allowed to: they contacted you first, they are an existing customer, or they have opted in. Sole traders and one-person businesses are treated as individuals wherever the local rules require it. "STOP" halts everything, instantly, across every channel.
We always say when it is an AI.
Honesty by design, and aligned with incoming AI transparency rules.
Your customers are never tricked into thinking they are talking to a person. It is disclosed, plainly, in the first message. An assistant that pretends to be human is a reputation problem waiting to happen, so ours never does.
We never score, rank or auto-judge people.
Keeps you out of automated-decision territory in every market we sell into.
Nothing we run rates a human being: not job applicants, not customers, not anyone. Software that judges people drags its operator into a category of legal exposure we simply design out. People keep the judgment; the assistant keeps the admin.
We never handle medical or other sensitive personal data.
Keeps special-category data, and its obligations, out of the system entirely.
Health records, and the other categories data-protection law treats as special, never flow through our systems. There is no breach surface to defend because the data is never there. If your business needs that handled, we will say so honestly and point you elsewhere.
Wherever you operate
The same four rules. The local law on top.
The rules above are ours and they do not change by country. What changes is the law we check against before a message goes out, so here is that, plainly.
United Kingdom
Marketing messages in the UK are governed by UK GDPR and PECR, and the regulator is the ICO. We check a lawful basis before anything goes out.
- UK GDPR and PECR
- Before the assistant messages anyone, the system checks it is allowed to: they contacted you first, they are an existing customer, or they opted in. Sole traders are treated as individuals under PECR, exactly as the ICO requires. "STOP" halts everything, instantly, across every channel.
- Your data, handled properly
- Your customer data is covered by a signed data processing agreement, and we only ever use enquiry details to reply to you.
European Union
In the EU, GDPR governs personal data and consent, and the ePrivacy rules govern electronic marketing. The posture is the same as the UK because we built for the stricter reading.
- GDPR
- A lawful basis is checked before any marketing message. Consent, where it is the basis, means a real affirmative action: never a pre-ticked box, never assumed from silence. Withdrawal is honoured instantly.
- Automated decisions
- Nothing we run makes an automated decision about a person. That is a rule we designed in, and it keeps you clear of the hardest part of GDPR entirely.
United States
In the US, calls and texts are governed by the TCPA, commercial email by the CAN-SPAM Act, and business texting by the carriers themselves through A2P 10DLC registration. Several states add their own rules on top.
- TCPA, and state rules on top of it
- Automated calls and texts need the right consent, and quiet hours are respected. Several states run their own stricter version, so we work to the strictest rule that applies to you rather than the loosest.
- CAN-SPAM
- Every commercial email identifies who it is from, says where you are, and carries a working opt-out that we honour promptly. No misleading subject lines, ever.
- A2P 10DLC
- Business texting in the US has to be registered with the carriers before it will reliably deliver. We handle that registration as part of your setup, so your messages arrive instead of being silently filtered.
What this means for you
In practice, for your business.
On your customer messages
Text-backs, replies, reminders and chases go to people who contacted you, booked with you, or bought from you, which is the safest ground to stand on in every market we sell into. Marketing beyond that, win-backs, reorder nudges, is sent only where consent or a customer relationship is on record, checked automatically before sending. STOP or unsubscribe ends contact instantly, everywhere.
On your data and your customers' data
Your customer data is processed under a signed data processing agreement, with sub-processors named and our obligations as processor set out in writing. Nothing we run scores or judges a person, no automated decision is made about anyone, and special-category data such as health information never enters the system at all.
The paper trail
Everything in writing, nothing on trust.
Data processing agreement
Signed on every engagement: how your data is handled, by whom, with the sub-processors named in writing, and an exit that returns or deletes everything.
AI disclosure, in the contract
A standing commitment that automated messages are always disclosed as automated to the people they reach. It is in the agreement, and it is in the messages themselves.
The message log
Every message sent, and the lawful basis it was sent under, kept in a tamper-proof record. If a question is ever raised, the answer is a lookup, not a reconstruction.
Agreement templates available on request before you sign.
Bring your data questions to the call.
The pilot maps exactly which rules apply to your workflows, so you know where you stand before anything is built.