Skip to content

    Privacy Policy

    What we collect, why, and your rights.

    Last updated: August 2026

    This Privacy Policy explains how Opafra (“we”, “us”) collects, uses, and shares personal data, and the rights you have. It applies to our websites and the Opafra service, and is designed to align with the GDPR, UK GDPR, and CCPA/CPRA.

    Controller vs. processor

    We act as a data controller for account and website data we use to run our business (for example, the name and email of the people who sign up). We act as a data processor for personal data contained in Customer Data that you submit to the Service — we process it on your behalf and under your instructions, as described in our Data Processing Addendum (available on request).

    Information we collect

    • Account & organization data: name, email, organization name, roles, and authentication identifiers (including from a single sign-on provider you use).
    • Operational data: inventory metadata (server names, hosts, ports, usernames), plans, schedules, execution history, and redacted logs. We store references to secrets held in your external secret manager, not the secret values — see Security.
    • Usage & device data: log data, IP address, browser/device information, and basic product analytics.
    • Communications: messages you send us (support, sales) and email you receive from us.

    How we collect it

    Directly from you (when you sign up, configure the product, or contact us); automatically (logs, analytics, cookies); and from integrations you connect (e.g. a single sign-on or Git provider), limited to what is needed to provide the Service.

    How we use it & legal bases

    To provide, secure, and improve the Service; authenticate you; process runs and schedules; send transactional email; provide support; prevent abuse and fraud; and comply with law. Where GDPR applies, our legal bases are performance of a contract, our legitimate interests (security, product improvement), your consent (where required), and legal obligations.

    AI processing

    When you use AI features (the plan composer), plan content and metadata may be sent to a third-party AI provider to generate or assist plans. AI features are optional and can be left disabled.

    Sharing & subprocessors

    We use third-party subprocessors to provide the Service — for example cloud hosting, transactional email, and (for AI features) an AI provider — under appropriate data-protection terms. We may also disclose data to comply with law or protect rights and safety. We do not sell personal data or share it for cross-context behavioral advertising. A current list of our subprocessors is available on request at [email protected].

    International transfers

    Where personal data is transferred across borders, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK data), together with supplementary measures where required. A copy of the relevant clauses is available on request.

    Retention

    We retain account and organization data for as long as your account is active. After account closure, we make Customer Data available for export for up to thirty (30) days, then delete or de-identify it within ninety (90) days, unless a longer period is required by law. Operational and execution logs are retained for up to twelve (12) months, and backups are cycled and purged within thirty (30) days. We keep records needed for legal, accounting, or security purposes for as long as required.

    Security

    We protect data with the technical and organizational measures described on our Security page, including encryption at rest and in transit, tenant isolation, access controls, and audit logging.

    Your rights

    Subject to applicable law, you may request to access, correct, delete, port, or export your personal data, and to object to or restrict certain processing; where we rely on consent, you may withdraw it. California residents have rights to know, delete, and correct, and to opt out of “sale”/“sharing” — we do not sell or share personal data as those terms are defined. To exercise rights, contact [email protected]; we will respond within the timeframes required by law. Where we process Customer Data as a processor, we will assist our customer (the controller) in responding to their users' requests.

    Cookies

    We use only strictly necessary cookies and similar technologies to operate the Service — for example, to keep you signed in and to protect against abuse. We do not use advertising or cross-site tracking cookies, so no cookie-consent banner is required. If we introduce non-essential cookies in the future, we will update this Policy and obtain consent where required.

    Children

    The Service is not directed to children and is intended for business use. We do not knowingly collect personal data from children.

    Changes

    We may update this Policy; material changes will be communicated, and the “last updated” date above will change. We will review it at least annually.

    Contact

    Privacy questions or requests: [email protected].