Get in Touch

Privacy & Cookie Policy

Privacy & Cookie Policy

15+ YEARS IN BUSINESS
REVIEWED ON ★★★★★ 5.0 RATING
500 + PROJECTS DELIVERED

We take privacy seriously

Last updated: 7th September 2026.

Welcome to Opace Ltd. We respect your privacy and are committed to protecting your personal data. This privacy and cookie policy explains how we look after your personal data when you visit our website, what cookies we use, and your privacy rights under UK law.

1. Introduction

At Opace Ltd, we value your privacy. This policy explains how we handle your personal information when you interact with our website. We strive to protect your data in line with all relevant legal requirements, including the UK General Data Protection Regulation (UK GDPR) and the Privacy and Electronic Communications Regulations (PECR).

2. Who We Are

Opace Ltd (referred to as “Opace”, “we”, “us”, or “our”) operates as the data controller responsible for your personal data.

Contact Information:

  • Email: info@opace.co.uk
  • Phone: 0121 468 0600
  • Mail: Data Protection Officer, Opace Ltd, Park House, Rubery, Rednal, Birmingham, B45 9AH.
  • Company Number: 07314908
  • VAT Number: GB105838711

3. What Data We Collect

We may collect the following types of personal data:

  • Identity Data: Name, username, or any other identifier you provide.
  • Contact Data: Email address, phone number, and postal address.
  • Technical Data: IP address, browser type and version, operating system, time zone, device type, and other technical data automatically collected when you access our website.
  • Usage Data: Information about how you use our website, including pages visited, time spent, and navigation paths.

4. How We Use Your Data

We use your personal data for the following purposes:

  • Service Delivery: To respond to enquiries submitted through our contact form and to deliver our services.
  • Legitimate Interests: To improve our website and to ensure our marketing efforts are effective.
  • Legal Compliance: To meet our legal and regulatory obligations.

We do not sell your personal data to third parties.

5. Data Security

Your data security is paramount. We have implemented robust measures to prevent unauthorised access, misuse, or loss. This includes HTTPS encryption across our entire website, secure form handling, and restricted access to personal data. Our contact form is protected by Google reCAPTCHA to help prevent spam and abuse.

6. Data Retention

We retain your personal data only as long as necessary to fulfil the purposes for which it was collected. Contact form submissions are retained for up to 24 months. Analytics data is retained in aggregated, anonymised form.

7. Your Rights

Under UK GDPR, you have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Erasure: Request the deletion of your personal data.
  • Restriction: Request that we limit how we process your data.
  • Objection: Object to our processing of your personal data.
  • Data Portability: Request the transfer of your data in a structured, commonly used format.
  • Withdrawal of Consent: Where we rely on consent, you can withdraw it at any time.

To exercise any of these rights, please contact us using the details above. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

Our website may contain links to third-party websites. We have no control over these sites and are not responsible for their privacy practices. We recommend reviewing the privacy policies of any external sites you visit.

9. Cookies We Use

Cookies are small text files stored on your device when you visit a website. We use the following cookies:

Essential Cookies

These are necessary for the website to function properly. They cannot be disabled.

CookieProviderPurposeDuration
sticky-cta-dismissedOpace (sessionStorage)Remembers if you dismissed the floating contact bar during your sessionSession

Analytics Cookies

These help us understand how visitors interact with our website. They are set when you use the site. We do not ask for your consent before setting them, and there is no setting on this website that turns them off. If you do not want them, you can block or remove them using your browser’s own cookie and tracking controls, described under Managing Cookies below.

CookieProviderPurposeDuration
_gaGoogle Analytics 4Distinguishes unique users by assigning a randomly generated number. Used to calculate visitor, session, and campaign data for site analytics reports2 years
_ga_<ID>Google Analytics 4Used to persist session state across page views2 years
_gidGoogle Analytics 4Stores and updates a unique value for each page visited. Used to count and track pageviews24 hours
_gatGoogle Analytics 4Used to throttle request rate to limit data collection on high-traffic sites1 minute

Marketing & CRM Cookies

These are used by our customer relationship management platform to provide relevant communications and track the effectiveness of our marketing efforts.

CookieProviderPurposeDuration
__hsscHubSpotKeeps track of sessions. Used to determine if a new session has started30 minutes
__hssrcHubSpotUsed to recognise if the visitor has restarted their browser. Determines if the visitor is a new sessionSession
__hstcHubSpotTracks visitors across sessions. Contains the domain, a unique user token (hubspotutk), initial timestamp, last visit timestamp, current timestamp, and session number13 months
hubspotutkHubSpotKeeps track of a visitor’s identity. Used when submitting data through a form to link the submission to the visitor record13 months
messagesUtkHubSpotUsed to recognise visitors who chat via the messages widget. Stored so that the visitor does not have to re-identify when returning13 months

Third-Party Cookies

When you interact with embedded content (e.g. YouTube videos), the third-party provider may set their own cookies. These are governed by the respective provider’s privacy policies:

10. Managing Cookies

You can control and manage cookies in your browser settings. Most browsers allow you to:

  • View what cookies are stored and delete them individually
  • Block third-party cookies
  • Block all cookies from specific sites
  • Delete all cookies when you close the browser

Please note that blocking all cookies may affect the functionality of some website features.

Browser-specific guidance:

11. Tracking & Analytics

We use the following tools to understand how visitors use our website:

  • Google Analytics 4 (GA4): We use GA4 to monitor website traffic and user behaviour. GA4 collects data such as pages visited, session duration, and referral sources. This data is used in aggregate to improve our website and services. GA4 operates with IP anonymisation enabled.

  • HubSpot: We use HubSpot as our customer relationship management (CRM) platform. HubSpot tracking allows us to understand how visitors interact with our website and to provide relevant follow-up communications when you submit an enquiry.

  • Google reCAPTCHA v3: Used on our contact form to protect against automated spam submissions. reCAPTCHA may analyse your browsing behaviour to determine whether you are a human visitor.

We do not use Facebook Pixel, Hotjar, Bing Ads, or any other behavioural tracking tools beyond those listed above.

12. GDPR Compliance

We adhere to UK GDPR principles, ensuring your data is:

  • Processed fairly, lawfully, and transparently
  • Collected for specified, explicit, and legitimate purposes
  • Adequate, relevant, and limited to what is necessary
  • Accurate and kept up to date
  • Stored only for as long as necessary
  • Processed securely using appropriate technical measures

13. AI Content Verification, Integrity & Watermark Checker

This section covers the free tool at opace.agency/tools/ai/content-verification-integrity/checker/. Every factual claim in it is checked against the live service, and the evidence behind each claim is dated and referenced.

Who we are. Opace Digital Agency Ltd, a UK company, is the data controller for this tool. You can reach us at info@opace.co.uk or through our contact page.

What we process. When you run the check on the default server route, your browser sends the text you pasted, and only that text, over an encrypted connection (HTTPS) to a server we control on Google Cloud Run in Belgium. The request carries no cookie, no account details and no referrer. There is no sign-in and we do not know who you are. Google, as our hosting provider, sees the request in transit the way any host does; our service keeps no copy of your text and no record of your IP address for these requests.

Why. To do the one thing you asked for: score your draft against our trained classifier and return the result. We do not use your text for anything else. We never train on it.

Our lawful basis. Legitimate interests (UK GDPR Article 6(1)(f)). We considered asking for consent and rejected it, because a “consent” screen you must accept before the tool works is not a real choice, and the ICO says so. Instead you get an actual choice: one click switches the checker to run entirely in your browser, and then nothing is sent anywhere. Our interest is running a free, open tool that publishes its own error rates; your interest is getting the answer you asked for; and the balance holds because nothing about your submission is kept, nothing is linked to you, the text spends only a few seconds in server memory, and you can remove the transmission altogether with one click. If you paste text about other people, that is your responsibility: only send what you have the right to share, and use the in-browser option for anything confidential or sensitive.

How long we keep your draft. We don’t. The text is scored in memory and discarded when the response is sent. It is never written to disk, a database or a log. We verified this by measurement, not assumption: on 31 August 2026 we sent traceable marker text through ten request paths of the serving revision (opace-detector-00009-jdw), including refusals and errors, and searched every log for it. No marker appeared anywhere, and the search was first proved able to find a planted one. Each result screen also repeats the server’s own statement of what was sent and what was retained, so you can check the claim on every run.

The in-browser alternative. The same model, at the same threshold, can run on your own device. Select the in-browser option next to the paste box. It downloads the model once (about 35 MB), after which your text never leaves your machine. If you want the check without any transmission, use this route.

Where the processing happens. The server is in Belgium (Google Cloud, europe-west1). For UK visitors this is a transfer to the EU, which the UK Government has formally recognised as providing adequate data protection, so no further safeguard is needed. Google acts as our processor under its Cloud Data Processing Addendum.

Your rights. You have the usual UK GDPR rights set out at Section 7 above. For the draft itself most of these are satisfied in the strongest possible way, because we hold nothing to disclose, correct or delete once your result is returned. To object to the processing, switch to the in-browser route and the processing stops before it starts. For anything else, or to complain, email info@opace.co.uk or use our contact page. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

One more thing, because it matters. The score is a probability, not a verdict. It carries a measured false-positive rate, printed next to the result. Do not treat it as proof that a person did or did not write something.

A note on this section. It describes our engineering practice, verified against the live service on the dates given. It is provided for transparency and is not legal advice.

14. Opace AI Content Checker & Detector Chrome Extension

This section applies specifically to Opace AI Content Checker & Detector for Chrome, version 1.2.3, published by Opace Ltd, company number 07314908. It describes the extension separately from the online checker in Section 13. Contact info@opace.co.uk with privacy questions.

Content you choose to check. After your explicit action, the extension reads selected text, the requested page’s article text, or a draft you paste. Page capture also handles the page hostname and title in memory to identify the capture. Chosen JPEG, PNG, WebP and PDF files are read locally for Content Credentials checks. These inputs are used only to provide the checks, comparisons and reports you request. The extension does not monitor your browsing, keystrokes or clipboard in the background.

On-device processing. AI analysis, character checks, writing suggestions and chosen-file checks run on your device. The on-device routes do not upload your draft, page content, hostname, title or chosen files. Opace does not receive these inputs for human review, model training, advertising, sale, creditworthiness or lending. The extension contains no advertising or analytics trackers.

Model downloads. With your consent, the extension downloads approximately 34.5 MB of model and vocabulary data from opace.agency. It verifies the expected sizes and SHA-256 fingerprints before use and caches the files on your device. The executable runtime is included in the extension. Download requests omit cookies and do not contain your draft. Opace’s hosting infrastructure receives the network information needed to deliver the files, including your IP address and request metadata; ordinary hosting and security logs may contain that information. This is separate from uploading content for analysis.

Unavailable EU option. Version 1.2.3 displays a separate EU analysis option as unavailable. If you select it, accept its disclosure and grant Chrome access to the named service, the extension can attempt an authorisation request to Opace’s Google Cloud Run service in Belgium. That request includes the extension ID, a randomly generated installation ID, a request ID and a SHA-256 hash of the chosen text. A hash is derived from the text and should not be treated as anonymous data. The hosting provider also receives your IP address and network request metadata. The disabled service rejects this request before the extension uploads the draft for scoring. These technical requests are for service authorisation and abuse prevention, not advertising or tracking your browsing. You can avoid them by using On this device or Quick checks only. Any future enablement of EU scoring requires an updated disclosure describing the actual content transfer.

Storage and retention on your device. Drafts and results are held in the extension’s working memory rather than saved in receipt history. Local storage holds settings and limited technical state, including an installation ID and request timestamps if you attempt the EU option. Session storage holds a text-free interruption marker. Cached model files remain available for later checks. Use Clear everything stored to remove local and session storage and cached model files. Close the extension panel to end its in-memory session. Site permissions are managed separately by Chrome and can be revoked at chrome://extensions.

Exports and sharing. PDF and HTML reports include the passages checked and are created only when you request them. JSON receipts and share summaries omit draft text and source URLs. Content Credentials exports omit filenames and file bytes. Copy controls write only the output you request; the extension never reads your clipboard. Review reports before sharing them. Clearing extension storage does not delete downloaded reports or copies you have saved or shared; remove those separately.

Chrome permissions and Limited Use. Clicking the toolbar icon grants temporary access to the current page. Optional persistent access is requested for one named site at a time. Scripting reads the requested content and highlights passages; the side panel displays the workflow; context menus support selected-text capture; storage retains settings; clipboard write supports explicit Copy actions. The use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Such information is used only for the extension’s stated functionality and is not sold, used for unrelated purposes, advertising, creditworthiness or lending.

Website visits and contact. Opening a link to the Opace website is a separate website visit covered by the website and cookie sections above. Contacting support sends the information you choose to include in your message. The rights and contact details in Section 7 apply to personal data we hold; Opace cannot retrieve drafts that remain only on your device.

15. Changes to This Policy

We may update this policy periodically to reflect changes in our practices or for legal and regulatory reasons. The “Last updated” date at the top of this page indicates when the policy was most recently revised. We encourage you to review this policy regularly.

If you have any questions about this Privacy & Cookie Policy, please contact us at info@opace.co.uk or call us on 0121 468 0600.

Get in Touch

Interested in Working with Us?

We have 100% happy customers, so don't delay. Get in touch today and see how we can help.

SEND US A MESSAGE OPACE · LET'S GET STARTED ·