Last updated: December 9, 2025
At Opsium, your privacy and the security of your data are core priorities.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website (www.opsium.io), use our platform, interact with our APIs, or communicate with us online.

By using our Services, you agree to the practices described in this Privacy Policy.

  1. Overview

Opsium is a software platform that helps service organizations automate operational workflows, analyze profitability, and manage capacity and resources.

We collect only the information necessary to:

  • communicate with customers and partners,

  • maintain the security and performance of our systems,

  • understand how visitors use our website and product,

  • provide and improve our Services.

We never sell or share your personal data with third parties for advertising, and we follow strict security and compliance standards, including GDPR.

  1. Information We Collect

We collect the following types of information:

2.1. Information you provide

When you:

  • request a demo or early access,

  • contact us through forms or email,

  • subscribe to updates or newsletters,

  • engage with Opsium through support or onboarding,

we may collect:

  • name and contact details,

  • company and role,

  • message content and preferences,

  • any additional information you voluntarily provide.

2.2 Information automatically collected

When you visit our website or access our Services, we may collect:

  • browser, device, and OS data,

  • IP address and approximate location (city-level),

  • pages viewed, time spent, and referring URLs,

  • clickstream behavior,

  • performance and diagnostic data, cookies, and similar technologies (see Section 8).

2.3 Information from Platform Usage (Opsium Users Only)

If you use the Opsium platform or API, we may additionally collect:

  • workspace configuration and settings,

  • user actions (for audit and security purposes),

  • integration metadata,

  • technical logs necessary for reliability and support.

We do not access or view your company’s operational or financial data unless explicitly permitted for support or troubleshooting under NDA-level confidentiality.

  1. Legal Basis for Processing (Required by GDPR)

We process personal data based on the following legal grounds:

  • Contractual necessity — to provide demos, respond to requests, offer customer support, and deliver our Services.

  • Legitimate interest — to improve website performance, ensure system security, prevent abuse, and understand product usage.

  • Consent — for newsletters, optional cookies, and marketing communications.

  • Legal obligations — when required to comply with laws or regulatory requests.

  1. How We Use Your Information

We use your information to:

  • respond to demo, contact, or support requests,

  • send updates about Opsium only if you opt in,

  • analyze usage patterns and website performance,

  • secure and maintain our infrastructure,

  • prevent fraud and detect harmful activity,

  • comply with legal and regulatory requirements.

We do not use your data for external marketing or advertising.
We do not sell or rent personal information under any circumstances.

  1. Data Security and Confidentiality

We implement strong technical and organizational measures to protect your data, including:

  • Bank-level encryption

    • Data in transit: TLS 1.2+

    • Data at rest: AES-256

  • Secure cloud infrastructure (AWS) with:

    • automatic backups,

    • redundancy and failover systems,

    • restricted physical and network access.

  • Role-based access control (RBAC) ensures only authorized Opsium staff can access internal systems, and only when necessary for support.

  • Strict confidentiality requirements, equivalent to an NDA:
    Opsium employees and contractors are bound by confidentiality obligations and may not disclose or misuse customer data.

We continuously monitor our systems for vulnerabilities and apply industry-standard security best practices.

6. Confidentiality & NDA Obligations

Opsium is fully committed to maintaining the confidentiality of all Customer Data and personal information processed through the Opsium Services.

6.1. Confidential Information

For this Policy, “Confidential Information” includes:

  • any personal data provided by or on behalf of the Customer;

  • business, operational, financial, or performance information stored in the Opsium platform;

  • internal company configurations, rates, margins, employee details, and organizational data;

  • any non-public information exchanged for onboarding, support, or integration purposes.

All such information is treated as strictly confidential.

6.2 Non-Disclosure Obligations

Opsium agrees to:

  • not disclose Customer Data or Confidential Information to any third party without the Customer’s explicit written consent;

  • not use Customer Data for any commercial purpose unrelated to providing the Opsium Services;

  • ensure all personnel and contractors with access to Customer Data are bound by confidentiality obligations;

  • apply industry-leading security measures to protect the confidentiality, integrity, and availability of data.

6.3 Permitted Disclosures (Legal Exceptions)

Opsium may disclose Confidential Information only when required by:

  • court order or binding government request;

  • applicable law or regulatory obligation;

  • valid law enforcement request where disclosure is legally mandatory.

In such cases, Opsium will provide prior notice to the Customer unless prohibited by law.

6.4 No Sharing or Selling of Data

Opsium:

  • does not sell, rent, trade, or commercially exploit Customer Data;

  • does not share Customer Data with third parties for marketing or advertising;

  • uses Sub-Processors solely for secure, GDPR-compliant service delivery, never for independent purposes.

6.5 Duration of NDA Obligations

Confidentiality obligations remain in effect:

  • for the entire duration of the Customer’s use of the Opsium Services, and

  • for five (3) years after account termination,
    unless applicable law requires a longer retention of confidentiality.

Any data retained by Opsium after termination (e.g., for legal compliance) continues to be protected by the confidentiality terms outlined in this section.

  1. Third-Party Services

We use trusted service providers to support our operations, such as:

  • analytics tools (e.g., Google Analytics, Plausible),

  • CRM and email providers (e.g., HubSpot, SendGrid),

  • hosting and compute infrastructure (AWS, Vercel).

These providers act as data processors, operate under strict contracts, and comply with GDPR.
They may only process your data on our behalf and never for their own purposes.

  1. Cookies and Tracking Technologies

Opsium uses cookies and similar tracking technologies to improve your experience, analyze performance, and ensure the smooth operation of our platform.

Cookies are small files stored on your device that help us remember your preferences, understand how you interact with the site, and provide relevant features. Some cookies are essential for basic functionality, while others help us measure performance and optimize user experience.

You can manage or disable cookies at any time in your browser settings. Please note that disabling certain cookies may limit the functionality of the platform.

Opsium may also use trusted third-party analytics services (such as Google Analytics) to collect aggregated and anonymized usage data that helps us improve performance and usability.

For any questions about how we use cookies or similar technologies, please contact us at privacy@opsium.io.

  1. Data Transfers

Opsium may process your data in the EU or in other jurisdictions used by AWS or our trusted partners.
All transfers outside the EU comply with GDPR, including:

  • Standard Contractual Clauses (SCCs),

  • Binding corporate rules (where applicable),

  • Additional supplemental security measures.

  1. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy, including:

  • responding to inquiries,

  • maintaining account access,

  • supporting legal, audit, or compliance requirements.

You may request deletion of your personal data at any time.

  1. Your Rights

Depending on your location, you may have rights to:

  • Access, correct, or delete your data

  • Withdraw consent to data processing

  • Request a copy of your personal data

To exercise these rights, contact us at privacy@opsium.io.

  1. Children’s Privacy

Our Services are not intended for individuals under the age of 13 (or equivalent age in your jurisdiction). We do not knowingly collect personal data from children.

If we learn that we have done so, we will delete it promptly.

  1. Third-Party Links

Our website may contain links to external sites we do not control.
We are not responsible for their privacy practices or content.
Please review their policies before sharing information.

  1. Changes to This Privacy Policy

We may occasionally update this Privacy Policy to reflect new features or legal requirements.
The date at the top of this page indicates the latest version.
If major updates occur, we’ll notify visitors through the site or by email (if applicable).

  1. Contact Us

If you have any questions about this Privacy Policy or how we handle your data, contact us at:

Opsium Privacy Team
Email: legal@opsium.io


The Operating System For Your Service Business

© Opsium — 2025-2026. All Rights Reserved.

The Operating System For Your Service Business

© Opsium — 2025-2026. All Rights Reserved.

The Operating System For Your Service Business

© Opsium — 2025-2026. All Rights Reserved.