NEW · 2026Get the 2026 playbook.Read here
DebtOps

Built to recover cleanly.

DebtOps is built to recover business receivables within the rules that apply in every market we operate. Compliance is not a bolt-on. It lives in the cadence, the tone, and the infrastructure.

The frameworks we work within.

United States

TCPA - Telephone Consumer Protection Act
Voice and SMS outreach respects consent, frequency limits, opt-outs, and calling-time rules. Opt-out requests are honoured immediately and logged. This applies to every US call and message, whatever the debt.

FDCPA and Reg F - consumer-debt rules
The FDCPA and Regulation F govern consumer debt. Our book is commercial, so these apply only where an account is consumer-adjacent, such as a sole trader or a personal guarantor. We flag those accounts and hold them to the consumer standard: contact-frequency caps, required disclosures, and validation handling. No harassment, no misrepresentation, no unfair practices.

New Zealand

Privacy Act 2020
Personal information is collected, used, and stored under the Privacy Act, including our duty to notify the Office of the Privacy Commissioner and affected people if a notifiable breach occurs.

Fair Trading Act 1986
No misleading conduct, no harassment. Communications stay accurate, professional, and fair.

Unsolicited Electronic Messages Act 2007
SMS and email respect consent and carry a working unsubscribe.

The same things that recover more keep us in the rules.

Gentle, consent-aware, fully logged recovery is both the more effective approach and the more compliant one. They are the same design.

Logged and explainable
Every message, call, and decision is recorded with a timestamp and a reason. No black box, you can see exactly what was said and why.

Consent-aware by design
The cadence checks consent and contact preferences before each touch, and stops the moment someone opts out.

Clear about automation
When an AI agent makes contact, it identifies who we are and who we are acting for. Requests to deal with a person are honoured.

Tone that protects relationships
Face-saving language is a compliance asset as well as a recovery one, it keeps communications fair and non-aggressive.

Hardship-sensitive
When an account signals hardship, the cadence shifts to payment plans rather than pressure.

Your receivables data, handled carefully.

Encryption - Data encrypted in transit (TLS) and at rest.

Least-privilege access - Role-based access controls and audited admin actions.

Data minimisation - We pull only the receivables data needed to recover, and retain it only as long as required.

Data location and sub-processors - We tell you where your data is stored and which providers process it, and we handle any cross-border transfer under the privacy rules that apply.

Breach notification - If a notifiable privacy breach occurs, we notify the relevant regulator and affected people as the law requires.

Resilience - Monitored infrastructure with backups and incident response.

This page describes DebtOps' compliance and security posture. It is not legal advice, and it is not a warranty that any specific outcome or standard is met on any given account.

Security or data questions?

Raise them in the demo and we will walk you through how DebtOps protects your data. Book a demo →