Effective 18 August 2026
Humble Operations Corporation (“Humble”, “we”, “us”) is a United States company providing an intelligent operations platform to manufacturing and industrial customers. We are remote-first and operate no offices or data centres of our own.
This notice explains how we handle personal information for which we decide the purpose, meaning we are the controller. It does not cover the operational content inside a customer’s Humble deployment. For that content the customer is the controller, it decides what is collected and why, and its own privacy notice applies to its people.
What this notice covers
We are the controller for personal information about visitors to humbleops.com, people who contact us or whose business contact details we obtain for sales outreach, our customers’ administrative and billing contacts, authentication records and security logs, support correspondence, and our own personnel and contractors.
If you are an employee of a Humble customer and want to know how your data is used inside your employer’s system, contact your employer. We will refer any such request to them.
What we collect from website visitors
This site runs on Framer and uses Framer’s built-in analytics. We also run a Google Tag Manager container that loads the following:
Google Analytics 4. Your IP address, device and browser, pages viewed, referring page, approximate location derived from your IP, and interaction events. We use this to understand how the site is used and to improve it.
Google Ads and DoubleClick. Advertising and remarketing identifiers and conversion events, used to measure our advertising and to show you our ads on other sites.
Meta Pixel. Advertising identifiers and page and conversion events, used to measure our advertising and to show you our ads on Meta services.
LinkedIn Insight Tag. Advertising identifiers, page and conversion events, and professional attributes LinkedIn associates with you, used to measure our advertising and to show you our ads on LinkedIn.
RB2B. Identification of individual visitors by name, work email address, company, professional profile, and the pages viewed.
Please read that last line carefully. RB2B attempts to resolve an anonymous visit to this website to a named individual and a work email address, even if you never filled in a form. If you would rather we did not do that, email privacy@humbleops.ai and we will suppress your details, or use the opt-out described under Your rights and choices.
Our legal basis is consent where consent is required, and otherwise our legitimate interest in understanding site usage and marketing our services to business audiences.
People we contact about our services
We collect business contact details, either given to us directly, obtained from public professional sources such as LinkedIn, or supplied by RB2B from your visit to this website. The categories are name, work email address, phone number, company, and role, together with a record of our correspondence. Our legal basis is our legitimate interest in business development, and you can object at any time.
Where the GDPR or UK GDPR applies and we did not obtain your details from you directly, we will tell you the source when we first contact you, or within one month at the latest.
Customer contacts, authentication, logs, and support
For the people who administer a customer account we hold name, work email address, unique login ID, and role assignment. Our systems generate authentication events and security and audit logs recording administrative actions, logon attempts, permission and role changes, and data deletions. We hold support correspondence and ticket content. We use these to provide authenticated access, to keep the service secure, and to meet our audit obligations. Our legal basis is performance of the customer agreement, our legitimate interest in security, and our legal obligations.
Our own personnel
We hold employment and contracting records for our staff, contractors, and applicants. Those individuals receive a separate personnel privacy notice describing that processing in full.
Sale, sharing, and targeted advertising
We do not sell personal information for money. We do disclose personal information to advertising partners, specifically Google, Meta, and LinkedIn, in ways that United States state privacy laws define as sharing for cross-context behavioural advertising, or as targeted advertising. We also disclose website visit data to RB2B, which enriches it and returns identified contact records to us. You can opt out at any time, as described under Your rights and choices.
Who else receives your information
Service providers acting on our instructions: Framer for website hosting and analytics, Google Workspace for email and documents, Slack for communication, Amazon Web Services for product hosting and email delivery, and our compliance and error-monitoring vendors. Advertising and analytics partners, listed above, some of which act as independent controllers under their own terms. Professional advisors such as counsel and accountants where needed. Authorities, where we are legally required to disclose, or to establish or defend legal claims. And a successor, if we are involved in a merger, acquisition, or sale of assets, who remains bound by this notice for information collected under it.
A current list of the service providers that process personal information on our behalf is available on request at privacy@humbleops.ai. The subprocessors used to deliver the platform to a customer are listed separately in that customer’s agreement.
Where your information is held
We operate from the United States. Our product infrastructure runs in Amazon Web Services, in a region the customer selects at onboarding. The website, our business systems, and our advertising partners run on their own providers’ infrastructure, largely in the United States. If you contact us from outside the United States, your information is transferred to and processed in the United States. For transfers from the EEA or Switzerland we rely on the European Commission’s Standard Contractual Clauses. For transfers from the United Kingdom we rely on the UK International Data Transfer Agreement or the UK Addendum, as applicable.
How long we keep it
Google Analytics data. No longer than 14 months, after which Google deletes it.
Advertising partner identifiers. Per each partner’s own retention terms. We hold no copy.
RB2B identified visitor records. Up to 24 months from the visit, or until you ask us to delete them.
Business contact records and correspondence. For the duration of the relationship and for three years after our last contact, then reviewed and deleted if no longer needed.
Support tickets and correspondence. Retained while needed for support history, reviewed annually.
Authentication and security logs. One year.
Customer administrative contact records. For the duration of the customer agreement, then up to 90 days.
Personnel records. As required by our employment, tax, and audit obligations.
Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to receive a portable copy, to restrict or object to processing, to withdraw consent, to opt out of sale, sharing, and targeted advertising, to limit the use of sensitive personal information where applicable, and to appeal a decision we make on your request. We do not discriminate against anyone for exercising a right.
To opt out of advertising and visitor identification, email privacy@humbleops.ai. We will suppress your details with RB2B and exclude you from our advertising audiences.
To exercise any other right, email privacy@humbleops.ai. We acknowledge within 5 business days. We respond within 45 calendar days where United States state privacy law applies, extendable once by a further 45 days, and within one month where the GDPR or UK GDPR applies, extendable by a further two months for complex requests. We will tell you before any extension. We may need to verify your identity, and we ask only for what verification requires. An authorised agent may act for you with written proof of authority.
If we deny your request you may appeal by replying to our decision, and we will respond to the appeal in writing. You may also complain to your state attorney general, or in the EU to your national data protection authority, or in the UK to the Information Commissioner’s Office.
Cookies and similar technologies
The technologies described above set cookies and similar identifiers. Most browsers let you block or delete cookies, and you can use your browser’s settings to do so, though parts of the site may then work less well. You can also email privacy@humbleops.ai to opt out of advertising and visitor identification.
Children
This site and our services are directed to businesses, not to children, and we do not knowingly collect information from them.
Security
We have completed a SOC 2 Type II examination of our information security program. Data is encrypted in transit and at rest, access is role-based and least-privilege with multi-factor authentication on privileged access, and we test our controls through annual independent penetration testing and continuous monitoring. No system is perfectly secure, but we handle personal information under the controls we apply to our most sensitive data.
Changes to this notice
We will update this notice when our practices change, and we will revise the effective date at the top. Material changes will be communicated through this website.
Contact us
Humble Operations Corporation. Email privacy@humbleops.ai. Our privacy contact is Radu Spineanu, Chief Executive Officer.