This Privacy Policy explains how Opelli s.r.o. handles personal data in connection with Opelli — the marketing site at opelli.dev, the demo request form, and the Opelli application itself. A key distinction runs through this policy: for some data we decide the purposes and means of processing (we are the controller); for the data our customers put into Opelli about their own people and contacts, we act only on their instructions (we are the processor). Section 2 explains which is which.
Who we are
The controller responsible for the personal data described in this policy (except where we act as a processor — see section 2) is:
Opelli s.r.o.
Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188
Privacy contact: privacy@opelli.dev
We have not appointed a statutory Data Protection Officer, as we are not required to. You can reach our privacy team at the address above for any question about this policy or your personal data.
Language versions. This Policy is published in English and in Czech, and both say the same thing. If your relationship with us is governed by the Czech version of the Terms of Service — Customers seated in the Czech Republic — the Czech version of this Policy is the authoritative one for you; for everyone else it is the English version.
When we are the controller vs the processor
Opelli is a platform our customers use to run their operations. That creates two roles:
- We are the controller for the personal data we handle to run our business and provide the Service — for example, the details of the people who create and administer accounts, sign in, contact support, or ask us for a demo, and the technical logs the Service generates. Sections 3–5 and 8–15 describe this data.
- We are the processor for the personal data our customers choose to put into Opelli about their team members, contractors, CRM contacts, mailing-list recipients, form respondents and similar (“Customer Content”). Here the customer is the controller; we process it only on their documented instructions under a Data Processing Agreement. Section 6 describes this data. If you are a data subject whose personal data appears in a customer's workspace and you want to exercise your rights over it, please contact that customer (the controller); we will assist them as our agreement requires.
Personal data we collect (as controller)
Account and profile data
When you are invited to and sign in to Opelli, we receive from your sign-in provider — Google or Microsoft (via OAuth/OpenID Connect) — your name, email address, a stable account identifier, and profile picture. Within your profile you or your administrator may add further details such as job title, contact details, skills and reporting lines.
Billing data
When an Account is created we collect what we need to bill it — the billing entity's name and address, company and VAT identifiers, and a billing contact — together with the record of the invoices we issued and the payments taken against them. A valid payment card is required for every Account, including one that expects to pay nothing because it stays within its free seats. Payments are processed by Stripe (see section 7): card details are collected and held by Stripe; we never receive or store your card details. The invoice itself is issued by us, as a Czech tax document; any receipt from the payment processor is only a confirmation that a payment was taken.
Demo request data
If you request a demo through the form on opelli.dev, we collect the email address you provide. (The form also contains a hidden “company” field that is a spam honeypot — genuine visitors never fill it, and submissions that do are discarded.)
Communications and support
If you contact us by email or through the Service, we keep your messages and the information you choose to include, so we can respond and keep records.
Usage, device and log data
When you use the Service, our systems automatically record technical information such as IP address, browser and device type, timestamps, the pages or API endpoints requested, and diagnostic and security logs. The Service also maintains internal activity and audit logs of actions taken within an account (for traceability and security).
How and why we use personal data — and our legal bases
As controller, we process personal data for the following purposes, each with a legal basis under Article 6(1) GDPR:
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing, operating and maintaining the Service and your account | Account/profile, usage/log data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for users acting for an organizational customer |
| Authenticating sign-in and securing accounts | Sign-in provider account identifier, session data, API-key/token metadata | Contract; legitimate interests in security |
| Billing an account, taking payment, and issuing and keeping invoices | Billing entity and contact details, company/VAT identifiers, payment and invoice records | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for accounting and tax records |
| Responding to your demo request and arranging the demo | Demo request email | Consent (Art. 6(1)(a)) / steps prior to a contract (Art. 6(1)(b)) |
| Providing support and communicating about the Service (including important service notices) | Contact and communication data | Contract; legitimate interests |
| Securing the Service, preventing abuse, and keeping audit/activity logs | Usage, device and log data | Legitimate interests (Art. 6(1)(f)) in the security and integrity of the Service |
| Improving and developing the Service | Aggregated/technical usage data; feedback | Legitimate interests |
| Complying with legal obligations and enforcing our terms | As relevant | Legal obligation (Art. 6(1)(c)); legitimate interests in establishing or defending legal claims |
Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You may object to processing based on legitimate interests as described in section 12. Where we rely on consent, you may withdraw it at any time.
Data we process on behalf of our customers (as processor)
When our customers use Opelli, they submit Customer Content that may contain personal data about their own team members, contractors, customers and contacts, mailing-list recipients, and people who respond to their public forms. Depending on how the customer configures the Service, this can include names, email addresses and phone numbers, job titles, project and task assignments, time entries, CRM notes and deal information, marketing-list membership, form answers, and GDPR-compliance records (such as consent logs and data-subject requests) that the customer maintains within the Service.
For all such data, the customer is the controller and we are the processor. We process it only to provide the Service and on the customer's documented instructions, under a Data Processing Agreement that reflects Article 28 GDPR. On those instructions the Service also notifies a customer's own users about activity in their workspace, by chat message or email, and each of them can switch those notifications off in their personal settings. We do not use Customer Content for our own purposes, and we do not sell personal data. If your personal data is held in a customer's Opelli workspace and you wish to access, correct or delete it, please contact that organization directly; Opelli also provides customers with tools (a privacy centre, a personal-data locator and consent ledger) to help them respond.
Sub-processors and service providers
We rely on a small number of trusted providers to deliver the Service. They process personal data on our behalf under contracts that impose appropriate data-protection obligations. Our current sub-processors are:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, file/object storage, and transactional & campaign email delivery (Amazon SES) | European Union (Frankfurt, eu-central-1) |
| Stripe (Stripe Payments Europe, Ltd.) | Payment processing — the payment card, the billing contact and company details on the account, and the record of payments taken. Card details are collected and held by Stripe; we never receive or store your card details | EU (Ireland) with possible transfer to the US (Standard Contractual Clauses) |
| Google (Google Ireland Ltd) | Sign-in (OAuth / OpenID Connect) and outbound email relay via Workspace SMTP | EU with possible transfer to the US (Standard Contractual Clauses) |
| Microsoft (Microsoft Ireland Operations Ltd) | Sign-in (OAuth / OpenID Connect) — only where an organization enables Microsoft sign-in | EU with possible transfer to the US (Standard Contractual Clauses) |
| Cloudflare, Inc. | DNS, edge/CDN network and hosting of the marketing site | Global edge network; US-based provider (Standard Contractual Clauses) |
| BunnyWay d.o.o. (bunny.net) | Content delivery and edge storage for websites your organization publishes from Opelli — the published files and the visitor request logs of those sites | European Union (Slovenia); global edge network for delivery |
| Toggl OÜ | Time-tracking synchronisation — only if an individual user connects their own Toggl account | European Union (Estonia) |
Some features integrate with services that you operate or connect, and which are not our sub-processors — for example, a Mattermost server or Slack workspace you run, a GitHub repository whose webhooks you configure, or a public lookup to the Czech ARES business register. Data exchanged with those services is governed by your own arrangements and their terms.
We may update our sub-processors as the Service evolves. For customers, our Data Processing Agreement sets out how we give notice of new sub-processors and how objections are handled. To receive sub-processor change notices, contact privacy@opelli.dev.
International data transfers
Our primary hosting and storage of application data — including Customer Content and account data — takes place within the European Union (AWS Frankfurt, eu-central-1). Websites you publish from Opelli are delivered by bunny.net, whose company and storage are in the European Union (Slovenia) and whose delivery network is global — only the files you have chosen to publish, and the request logs of the people who visit them, reach it. Some sub-processors (such as Google, Stripe and Cloudflare) are established in, or may process data in, countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an appropriate transfer mechanism under Chapter V GDPR — in particular the European Commission's Standard Contractual Clauses, together with supplementary measures where needed. You can request more detail about the safeguards in place by contacting us.
How long we keep personal data
We keep personal data only as long as necessary for the purposes described in this policy:
- Account and profile data — for as long as the account exists, including while it is suspended, and for a reasonable period afterwards to wind down the relationship, resolve disputes and meet legal obligations.
- Customer Content (as processor) — for as long as the customer's account exists. Suspending an account deletes nothing: Customer Content is retained intact and unchanged, and remains available to the customer for export on request throughout. Where an account is deleted for non-payment, that happens no earlier than 90 days after suspension and only after at least 30 days' written notice to its administrators (see section 10 of the Terms, which governs that timeline). On termination it is made available for export for a limited period and then deleted or de-identified in line with our Data Processing Agreement, subject to routine backup rotation.
- Billing records and issued invoices — for the retention period required by Czech accounting and tax law, which may outlast the account itself.
- Demo request email — until we have responded and any follow-up is complete, or you ask us to remove it, whichever is earlier.
- Security and system logs — for a limited period appropriate to their security and diagnostic purpose.
- Backups — encrypted backups are rotated on a regular cycle, so residual copies may persist for a short time after deletion from the live systems.
We may retain certain information longer where required to comply with legal obligations or to establish, exercise or defend legal claims.
How we protect personal data
We implement appropriate technical and organizational measures to protect personal data, including:
- authentication through Google or Microsoft OAuth with PKCE and server-side verification of ID tokens; accounts are pinned to a stable provider identifier, and there is no password store and no authentication bypass;
- encryption in transit (TLS) and encryption of data and backups at rest through our cloud provider;
- signed,
HttpOnly,SameSite=Laxsession cookies, an origin/CSRF check on state-changing requests, and a strict content-security policy; - a granular permission model (per-feature access levels and per-project row scope) that governs the web app, the API and connected AI agents identically, so no integration can exceed the access of the person using it;
- API keys stored only as SHA-256 digests (never retrievable after creation), scoped to specific modules, and revocable/rotatable;
- strict per-tenant data isolation, secrets held in a managed secrets store, and least-privilege access for our systems.
No method of transmission or storage is completely secure, but we work to protect personal data and to detect and respond to incidents. Where we act as processor and become aware of a personal-data breach, we will notify the affected customer without undue delay so they can meet their own obligations.
Your rights
Subject to the conditions and exceptions in applicable data-protection law, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (the “right to be forgotten”);
- restrict or object to certain processing, including processing based on our legitimate interests;
- data portability — receive certain data in a structured, commonly used, machine-readable format;
- withdraw consent at any time where we rely on consent, without affecting processing already carried out.
To exercise these rights in relation to data for which we are the controller, contact privacy@opelli.dev. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting. If your data sits in a customer's Opelli workspace, the customer is the controller — please direct your request to them, and we will support them as required.
Children
Opelli is a business tool intended for use by professionals. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date and, where appropriate, provide additional notice (for example, within the Service or by email to account administrators). We encourage you to review this page periodically. The current version is always available at this address.
How to contact us and your right to complain
Opelli s.r.o.
Nové sady 988/2, Staré Brno, 602 00 Brno, Czech Republic
Company ID (IČO): 29850762 · DUNS: 351787000 · Regional Court in Brno, Section C, File 153188
Privacy: privacy@opelli.dev
Web: opelli.dev
If you have a concern about how we handle your personal data, please contact us first — we will do our best to resolve it. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), Pplk. Sochora 27, 170 00 Praha 7. You may also contact the supervisory authority in your country of residence or work.