| Effective / Last updated | 8 October 2026 |
|---|---|
| Website | https://operisinsight.app |
| Operis is a business-to-business operational reporting and intelligence platform provided by Bigeen Solutions. This Policy explains the privacy practices that apply when organisations and authorised users access or use Operis. |
|---|
1. Who we are and scope
Operis ("Operis", "the Service") is developed and operated by Bigeen Solutions ("Bigeen", "we", "us" or "our"). This Privacy Policy applies to the Operis web application, related authentication services, support interactions, and public pages available at https://operisinsight.app.
Operis is designed primarily for organisations, including healthcare organisations, to collect, consolidate, analyse, and report operational information. This Policy should be read together with any customer agreement, Data Processing Agreement (DPA), security schedule, or other contract that applies to a customer organisation.
2. Our roles under data protection law
For information that a customer organisation enters into Operis for its own operational purposes, the customer will ordinarily determine why and how the information is processed and will typically act as the data controller. In those circumstances, Bigeen will generally act as a data processor and process the information on the customer's documented instructions.
Bigeen may act as a data controller for limited information required to manage Operis itself, such as account administration, business communications, platform security, support, billing, and legal or compliance records.
Where healthcare or other sensitive personal data is processed, the customer and Bigeen must ensure that the processing is authorised, necessary, proportionate, and supported by the appropriate lawful basis and safeguards under applicable law, including the Nigeria Data Protection Act 2023 (NDPA).
3. Information we may collect or process
The categories of information processed through Operis depend on the customer's configuration and how authorised users use the Service. They may include:
Account and identity information, such as name, work email address, user identifier, job role, branch or facility, and authentication information.
Organisation and operational information, including facility, department, service activity, performance, referral, payer, occupancy, incident, issue-resolution, and related reporting information.
AI Insight inputs and outputs, where a user requests an explanation, summary, or interpretation of operational metrics.
Technical and security information, such as session information, authentication events, IP or device information, where generated by our infrastructure, error logs, and audit information.
Support and communications information, including information provided when a user or customer contacts Bigeen for assistance.
Information received from identity providers such as Google or Microsoft when a user chooses federated sign-in.
| Data minimisation principle: Operis should not be used to enter patient-identifying, clinical, or other sensitive information where the business purpose can reasonably be achieved using aggregated, coded, or non-identifying information. |
|---|
4. Information from Google and Microsoft sign-in
If a user chooses to sign in with Google or Microsoft, Operis may receive basic identity information that the user and identity provider make available for authentication, such as name, email address, unique account identifier, and basic profile information.
Operis does not require access to Gmail messages, Google Drive files, Microsoft mailbox contents, calendars, or similar content for ordinary sign-in. If a future feature requires additional permissions, users and customers will be informed before those permissions are requested.
Information obtained through Google APIs is used only for the user-facing functionality for which access is granted and is handled in accordance with applicable Google API Services User Data Policy requirements, including Limited Use requirements.
5. How we use information
We may process information for the following purposes:
To authenticate users and manage authorised access to Operis.
To provide dashboards, reports, comparisons, trends, operational intelligence, exports, and other requested features.
To generate AI-assisted explanations or summaries of operational metrics when a user requests that functionality.
To maintain security, prevent misuse, investigate incidents, and preserve auditability.
To provide customer support, troubleshoot technical issues, and maintain or improve reliability.
To administer customer accounts, contractual relationships, billing, and service communications.
To comply with applicable legal, regulatory, professional, or contractual obligations.
6. Lawful bases and sensitive data
Depending on the context and our role, processing may be based on performance of a contract, compliance with a legal obligation, legitimate interests that are not overridden by individual rights, consent where required, or another lawful basis recognised by applicable law. When Bigeen acts as a processor, the customer is responsible for identifying the lawful basis for the processing it instructs Bigeen to perform.
Health information and certain other categories of information may be treated as sensitive personal data. Such information should only be processed in Operis where the customer has determined that it is necessary, lawful, and appropriately safeguarded. Bigeen may require additional contractual or technical controls before supporting higher-risk processing.
7. Artificial intelligence and automated insights
Operis includes an AI Insights capability that can generate explanations, summaries, or interpretations of operational metrics and trends. AI output is intended to support operational understanding and decision-making; it is not intended to make autonomous clinical decisions, diagnose patients, prescribe treatment, or replace professional judgement.
Bigeen applies data-minimisation principles to AI functionality. AI requests should contain only the information reasonably necessary to generate the requested insight, and direct patient identifiers or unnecessary sensitive information should not be included where the purpose can be achieved with aggregated or non-identifying data.
Bigeen does not use customer operational data, patient information, or end-user information to train Bigeen-owned general-purpose AI models. Where third-party AI infrastructure is used to generate a requested response, limited information may be transmitted to that provider for inference, subject to the provider's applicable terms, security controls, and Bigeen's configuration and contractual arrangements. Bigeen does not authorise customer data to be repurposed for unrelated advertising or general-purpose model training.
AI-generated outputs may contain errors or incomplete interpretations. Users remain responsible for reviewing outputs before relying on them for operational, managerial, or clinical decisions.
8. Sharing, service providers, and subprocessors
Bigeen may engage carefully selected service providers to support functions such as cloud hosting, database infrastructure, authentication, application development, monitoring, communications, and AI inference. These providers may process information only to the extent necessary to provide their services and subject to applicable contractual, security, and privacy safeguards.
Bigeen does not sell patient data, customer operational data, or Google/Microsoft authentication data. We may disclose information where required by law, to protect the security or integrity of Operis, to respond to lawful requests, or as part of a legitimate corporate transaction subject to appropriate safeguards.
Enterprise customers may request information about material subprocessors relevant to their deployment and may address subprocessor requirements in a Data Processing Agreement.
9. International data transfers and hosting
Operis is cloud-based and some service providers may process or store information outside Nigeria. Where personal data is transferred internationally, Bigeen and the relevant customer will apply the safeguards, assessments, contractual measures, and transfer conditions required by applicable law, including the NDPA and applicable guidance of the Nigeria Data Protection Commission.
Hosting location, data-residency expectations, and any customer-specific localisation requirements may be documented in the applicable customer agreement or security schedule.
10. Data retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, to provide the Service, to meet contractual requirements, to protect security and auditability, and to comply with applicable legal or regulatory obligations.
Customer data retention and deletion periods may be defined in the applicable agreement or DPA. On termination, Bigeen will handle customer data in accordance with the applicable contract, including agreed export, return, deletion, or backup-retention arrangements. Certain records may be retained where necessary for legal, security, dispute-resolution, or compliance purposes.
11. Security
Bigeen maintains administrative, organisational, and technical measures designed to protect information against unauthorised access, loss, alteration, disclosure, or destruction. Measures are selected according to risk and may include role-based access controls, authentication controls, least-privilege access, secure transmission, logging and monitoring, secrets management, vulnerability review, backup and recovery practices, and controlled project-sharing settings.
No system can guarantee absolute security. Customers and users are responsible for safeguarding credentials, following their organisation's security policies, and promptly reporting suspected unauthorised access or security incidents.
12. Cookies, sessions, and analytics
Operis may use strictly necessary cookies, local storage, or similar technologies required for authentication, session management, security, and core functionality. As of the effective date of this Policy, Lovable visitor analytics is disabled for the production Operis project. If optional analytics or non-essential tracking technologies are introduced, this Policy and any required consent mechanisms will be updated before or at the time of deployment.
13. Individual rights
Subject to applicable law, individuals may have rights relating to their personal data, including rights of access, correction, deletion, restriction, objection, portability where applicable, withdrawal of consent where processing is based on consent, and the right to lodge a complaint with the Nigeria Data Protection Commission or another competent authority.
Where personal data is controlled by a customer organisation, Bigeen may direct the request to that organisation or assist the organisation in responding, as appropriate.
14. Personal data breaches
Bigeen maintains procedures for assessing and responding to suspected personal data breaches. Where Bigeen acts as a processor, it will notify the relevant customer without undue delay after becoming aware of a breach affecting customer personal data, in accordance with the applicable contract and law. The customer, as controller, remains responsible for regulatory and data-subject notifications where required, including applicable NDPA notification timelines.
15. Children
Operis is a business-to-business service and is not intended for use by children as individual consumers. Customer organisations are responsible for ensuring that any information relating to minors is processed only where lawful, necessary, appropriately authorised, and subject to enhanced safeguards.
16. Changes to this Privacy Policy
We may update this Privacy Policy as Operis evolves, our service providers or data practices change, or legal requirements are updated. The current version will be published on the Operis website with the effective date shown at the top of the page. Material changes may also be communicated to customers or users through appropriate channels.
17. Contact us
For privacy questions, data-protection requests, or concerns relating to Operis, contact:
Bigeen Solutions
Email: info@bigeensolutions.com
Website: https://operisinsight.app
Company Website: https://bigeensolutions.com
Where your request relates to information controlled by your employer, hospital, or other customer organisation, you may also contact that organisation directly.