LEGAL
Privacy policy: Internal Operations OS
LAST UPDATED JULY 31, 2026
This describes how information is handled inside the Internal Operations OS platform, built by Merrill Digital Systems LLC for internal business use. For the website itself, see the main privacy policy.
1. Scope
The platform is an internal operations hub for authorised employees and team members of the deploying organisation. It is not a consumer application, and access is restricted to authenticated users with assigned roles.
2. What is collected
- User account data — name, email address, role and authentication credentials, for users provisioned by the organisation.
- Operational data — job records, task assignments, workflow data, reports and notes entered by users in normal use.
- System logs — activity logs, login timestamps and audit trails, kept for security and compliance.
- Device and access data — browser type, IP address and device information, collected during authentication and session management.
3. How it is used
- To run the platform’s core functions — job tracking, task management, reporting and workflows
- To manage accounts and role-based access
- To generate business reports and operational analytics
- To maintain audit logs for security and compliance
- To find and resolve technical problems, and improve performance
4. Who owns the data
All business data entered into the platform belongs to the deploying organisation. Merrill Digital Systems LLC is the technology provider and claims no ownership of client business data. Handling is governed by the agreement between MDS and the organisation.
5. Sharing
Business data is never sold. It is shared only:
- With integrations the organisation configured — for example QuickBooks or a payroll provider — and only as far as those integrations need in order to work;
- With infrastructure providers that host and process data under confidentiality and security obligations;
- Where the law requires it, in response to valid legal process or to protect safety and rights.
6. Security
- Encryption of data in transit and at rest
- Role-based access controls
- Audit logging of access and changes
- Regular security review
These are strong measures, not a guarantee — no system is completely immune to security threats.
7. Retention
Data is retained for as long as the organisation maintains an active deployment. On termination it is handled per the service agreement, including export and deletion options.
8. User rights
If you use the platform, contact your own organisation’s administrator about access, correction or deletion — they control user provisioning and data management. Questions for the technology provider go to [email protected].
9. Changes
This policy may be updated. Material changes are communicated to the deploying organisation, and the date at the top changes with them.
10. Contact
Merrill Digital Systems LLC
West Jordan, UT 84088
[email protected]