Watchdog data & connector notice
What continuous monitoring reads, stores, shares, and how you stay in control.
Updated 28 July 2026
Watchdog is an ongoing monitoring service, not a 72-hour scanner session. This notice explains the baseline. The authorization screen for each connector and any signed order or data-processing terms may add connector-specific detail.
Your authorization is specific
- •You choose each organization and connector separately. Connecting one system does not authorize access to another.
- •You confirm that you are allowed to grant the selected access for your organization and the people whose work signals may be included.
- •Monitoring is metadata-first and read-oriented. Provider permissions differ, and some read APIs can return content fields or private-resource metadata.
- •If a connector or agreed service needs content-level evidence, OpsLab must describe the purpose and scope and obtain separate approval before enabling that mode.
OAuth and API credentials
- •OAuth is used where a suitable provider flow is available. The provider shows the requested permissions and lets you revoke the grant.
- •For key-based connectors, create a dedicated least-privilege key in the provider and enter it only in the secure Watchdog setup form. Do not send keys in email, chat, or support notes.
- •Connector credentials are stored encrypted for as long as the active connection needs them. Watchdog uses them for validation, scheduled sync, and token refresh where the provider supports it.
- •Use the verified cabinet to clear the local credential and choose preserved history or full connector-data purge. Separately revoke the grant/key at the provider; Watchdog cannot revoke every remote credential on your behalf.
Data Watchdog can retain
- •Account and organization details, service contacts, locale, monitoring targets, escalation settings, and recorded consent/instructions.
- •Connector type, provider/workspace identifiers, scopes, encrypted credentials, connection status, sync cadence, errors, and audit events.
- •Derived metrics, time series, selected evidence, alerts, recommendations, briefs, search indexes/embeddings, and workspace or support messages needed to deliver the service.
- •Plan, entitlement, amount, currency, payment status, provider reference, payer contact, and billing timestamps. OpsLab does not need the card or bank-account details entered on WayForPay’s hosted payment interface.
Continuous monitoring and retention
- •An active connector syncs on the configured cadence until it is paused, disconnected, the service ends, or its authorization stops working.
- •Watchdog account, connector, metric, evidence, alert, support, consent, and billing data does not use the Scanner’s 72-hour deletion schedule.
- •Records are kept while needed to provide and secure the service, document instructions, resolve billing or support issues, and meet applicable contractual, accounting, or legal duties.
- •Use the cabinet for connector disconnection and its local purge choice. For account-level access, export, correction, or broader deletion, contact the privacy address below; we verify the requester and explain any legal, security, dispute, or backup retention.
Service providers
Depending on the feature, data may be processed by Hetzner (production hosting in Germany), Railway (EU test hosting), OpenAI API (analysis, generation, chat, and embeddings), WayForPay (checkout and payment processing), Resend (email), Telegram (login, bot connections, and notifications), and the business platform you connect, such as Google, Slack, Atlassian, GitHub, Notion, or ClickUp. Each receives only the fields needed for its role, but may process them under its own infrastructure and terms, including outside your country.
Site analytics is a separate choice
Optional first-party product analytics is not connector consent. It records limited page, funnel, campaign, and referrer information only when you select “Accept optional” in the site privacy choice. Essential account, security, payment, and connector processing still occurs when needed to provide the service.
Your control checklist
- ✓I selected the correct provider organization/workspace.
- ✓I reviewed the provider permissions and this connector notice.
- ✓I used OAuth or a dedicated least-privilege key rather than a personal password.
- ✓I understand that Watchdog keeps monitoring data beyond 72 hours while the service is active.
- ✓I know local cabinet disconnection and provider-side revocation are separate actions, and I can request broader access, export, correction, or deletion.
This page is a transparency notice, not a blanket authorization for every connector or every data category. The product should record the connector, scope/mode, notice version, tenant, and time when you approve a connection.
Privacy and connector requests
Email janedavydiuk@opslab.uk. Do not include passwords, payment credentials, API keys, or connector secrets.