Privacy Policy
This Privacy Policy describes how BedrockOps collects, uses, stores, and deletes personal data when you visit bedrockops.io or use the BedrockOps service.
1. Who we are and our role
BedrockOps is the operational and incident-intelligence layer for Amazon Bedrock production systems. This section explains the roles BedrockOps takes when it handles personal data.
For the account and contact data described below, BedrockOps is the data controller. For the operational telemetry that BedrockOps reads read-only from your AWS account, BedrockOps acts as a data processor on your behalf — you remain the controller of your AWS data. Collection is one-directional: data flows from your AWS account to the BedrockOps SaaS account through a read-only cross-account IAM role. BedrockOps does not write into your AWS account — scoped-write capabilities are deferred to later versions.
2. The data we collect
Account and contact information
The information you provide when you sign up, onboard a team, or contact us — such as your name, work email address, and team details. BedrockOps is the controller of this data.
Authentication identity
Sign-in identity is managed through AWS Cognito in eu-west-3: your email address, your password (stored by Cognito only as a hash — BedrockOps never sees or stores the plaintext), and your optional multi-factor authentication settings.
Session cookies and API tokens
Signed-in sessions on the app domain (app.bedrockops.io) use strictly necessary auth-session cookies (__Host-bops_access / __Host-bops_refresh) set as HttpOnly, Secure, and SameSite=Strict. API tokens (prefixed bops_) are stored only as bcrypt hashes. The bedrockops.io marketing site sets no tracking or advertising cookies. Cookie details are covered by the BedrockOps Cookies Policy.
Operational telemetry from your AWS account
With the read-only cross-account role you provision, BedrockOps reads the following named signals from your AWS account:
- Bedrock invocation logs,
- Bedrock quota and throttling metrics,
- Knowledge Base state and ingestion logs,
- CloudTrail configuration and tier-resolution events,
- inference-profile and model-availability metadata,
- recorded Bedrock Agent reasoning traces (log parsing only — BedrockOps never invokes your agents).
This telemetry can include technical identifiers from your AWS account, such as caller IAM ARNs. BedrockOps processes it as your processor, solely to deliver the service.
Audit logs
State-changing actions in the service are recorded in an append-only audit log: who acted, what changed, and when.
3. How we use data and our legal bases (GDPR Article 6)
We use personal data to:
- Provide and operate the service — delivering the findings, dashboards, and alerts you contracted for (Article 6(1)(b), performance of a contract);
- Secure and improve the service — authentication, session protection, abuse prevention, and audit logging (Article 6(1)(f), legitimate interests in operating and securing the service);
- Where consent applies — if any processing relies on your consent (Article 6(1)(a)), you can withdraw it at any time without affecting prior processing.
4. Data residency and international transfers
BedrockOps is single-region and EU-hosted: all SaaS-side compute and storage run in eu-west-3 (Paris), with EU-hosted LucerisCloud PostgreSQL and Redis in Germany and France. There are no transfers of personal data outside the EU in V1.
5. Sub-processors
BedrockOps uses the following sub-processors:
- Amazon Web Services (AWS) — cloud infrastructure for the BedrockOps SaaS account, in eu-west-3;
- LucerisCloud — EU-hosted PostgreSQL and Redis (Germany and France).
A current list of sub-processors is maintained in the BedrockOps Data Processing Agreement, available to customers on request.
6. Security
We apply the following safeguards:
- Read-only cross-account access. BedrockOps reads through a read-only cross-account IAM role. It never sits in the request path between your application and Bedrock, and deploys no runtime inside your account.
- AWS-managed encryption. SSE-S3 for storage buckets, SSE-SQS for queues, and provider-managed encryption at the database tier — BedrockOps never holds customer-managed encryption keys.
- Confused-deputy defense. After every cross-account role assumption, BedrockOps verifies the assumed account via GetCallerIdentity and the role’s trust policy via iam:GetRole; a failed check aborts access.
- Multi-team isolation. Every team’s rows are isolated with PostgreSQL Row-Level Security enforced at the database role.
- Append-only audit log. Audit entries cannot be updated or deleted at the application database role.
- Hardened sessions. Browser sessions use HttpOnly, Secure, SameSite=Strict cookies; API tokens are stored only as bcrypt hashes.
We apply these safeguards as described. No statement in this policy is a promise of absolute security.
7. Data retention
Hot operational telemetry is retained according to your plan tier: Trial — 7 days; Production — 30 days; Enterprise — 90 days. The audit log is append-only by design. Personal data is deleted through the GDPR data-deletion workflow described in the next clause.
8. Your rights (GDPR Articles 15–22)
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectification of inaccurate personal data;
- erasure (“right to be forgotten”);
- restriction of processing;
- portability of the data you provided;
- objection to processing based on legitimate interests;
- rights regarding automated decision-making, including not being subject to a decision producing legal or similarly significant effects based solely on automated processing.
How to exercise them. A team admin can submit a data-deletion request directly in the product (Settings → Privacy → Data Deletion). The request enters a 30-day grace window during which you can cancel it yourself; after the window, the deletion is confirmed by a BedrockOps operator and every team-scoped record is erased in a single atomic pass. Audit entries documenting the deletion itself are retained in tombstoned form, with diagnostic bodies purged and user identifiers removed. For any other request — access, rectification, restriction, portability, or objection — contact BedrockOps, and we will respond as required by the GDPR. You also have the right to lodge a complaint with a supervisory authority.
9. Breach notification
In the event of a personal-data breach, BedrockOps will notify the competent supervisory authority and, where required, affected data subjects, as required by GDPR Articles 33 and 34.
10. No sale of personal data
BedrockOps does not sell personal data. Customer data is never aggregated across tenants.
11. Automated decision-making
BedrockOps performs no automated decision-making that produces legal or similarly significant effects on data subjects. The product ranks probable causes and surfaces findings for human operators to review — it does not make decisions about people.
12. Children’s data
The service is a business tool for engineering teams. It is not directed to children, and BedrockOps does not knowingly collect children’s personal data.
13. Changes to this policy
Material changes are published on this page and, where required, notified to customers. Continued use of the service after an update takes effect constitutes acknowledgment of the revised policy.
14. Contact and complaints
For privacy questions, or to exercise any of your rights, contact BedrockOps as described in clause 8. You also have the right to lodge a complaint with your local data protection supervisory authority in the EU.
15. GDPR compliance
Evaluate BedrockOps with the same trust posture.
Start the 7-day free trial on AWS Marketplace and connect a read-only cross-account IAM role — your operational data stays in the EU.
Start 7-Day Trial On AWS Marketplace