OpusDone
Log inRequest access

Legal

Privacy Policy

Version 2.1 · Effective 1 October 2026

This policy explains what OpusDone does with personal data — yours, if you are a customer of ours, and your customers’, if you use our assistant to talk to them.

Those two are different, and section 2 explains why the difference decides most of what follows. If you are here because you are about to send us your customers’ conversations, read section 2 first, then 5, then 8.

1. Who we are

OpusDone is a service of Softpact, operated from Spain. Postal address: Carrer de Calàbria, 64, Eixample, 08015 Barcelona, Spain.

For privacy questions, or to exercise any of the rights in section 9, write to privacy@opusdone.com. For anything else, hello@opusdone.com.

We have not appointed a Data Protection Officer. We have assessed the criteria in Article 37 GDPR and concluded that none applies: our core activity is not large-scale systematic monitoring of individuals, nor large-scale processing of special-category data. We keep that assessment under review and will publish a DPO’s details here if that changes. In the meantime the address above reaches a named person responsible for data protection, not an unattended inbox.

Because we are established in Spain, we are not required to appoint an EU representative under Article 27 GDPR. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD).

2. The two roles — read this one

Almost every question about this service has a different answer depending on whose data is being asked about. There are two situations and we are in a different legal position in each.

Your account data — we are the controller

When you sign up, configure an assistant, invite colleagues or pay us, we decide what to collect and why. We are the controller for that data, and this policy is our notice to you about it.

Your customers’ conversations — you are the controller, we are the processor

When someone messages your business and our assistant answers, that conversation is about your relationship with your customer. You decide that the assistant should exist, what it knows, what it may say and how long you keep the result. You are the controller. We are your processor, acting on your documented instructions under Article 28 GDPR.

This is not a technicality. It means two practical things. First, the duty to tell your customers that an AI assistant handles their messages and that those messages are recorded is yours, not ours — we give you the tools to do it and require you to use them, but we have no relationship with your customer through which we could do it ourselves. Second, if one of your customers asks to see or delete their data, the request goes to you; we help you answer it, and we will not act on it unilaterally, because acting on a controller’s data without the controller’s instruction is itself a breach.

The terms governing that relationship are in our Data Processing Agreement, which forms part of your contract with us. If your organisation needs a signed copy, ask and we will provide one.

3. What we collect

a. Account and business data — we are the controller

  • Your name, work email address, and password (stored only as a salted hash — we cannot read it).
  • Your business’s name, address, sector, opening hours, services and prices, and anything else you put into the assistant’s knowledge base so it can answer questions.
  • Your role and which businesses you have access to, plus the record of colleagues you have invited.
  • Your language preference, notification settings, and the record of whether you have completed setup.

b. Website visitors — we are the controller

  • Technical data your browser sends: IP address, user agent, and the approximate country our CDN derives from the IP.
  • The cookies and local storage listed in the Cookie Policy. There are no analytics or advertising trackers on our website.
  • Anything you type into our contact form or into the chat assistant on our own site.

c. Your customers’ conversations — you are the controller

  • The messages themselves, in both directions, and any images, documents or voice notes sent.
  • The channel identifier the platform gives us — a WhatsApp or Telegram number or handle, an Instagram or Facebook user id, or for the website widget an anonymous visitor id and IP address.
  • Whatever the person volunteers in the course of the conversation: a name, a phone number, an email address, a reason for enquiring. We do not choose what this contains. They do, and so does the assistant you configured.
  • Bookings the assistant makes: name, contact details, the service, the time, and any note attached.
  • Whether the conversation was handed to a human, and why.

d. Connected systems

If you connect a calendar (Google Calendar, or Cal.com), we hold the access tokens for it and read the availability and the events we need in order to offer and make bookings. If you connect a messaging channel, we hold that channel’s credentials. We do not read anything in a connected system beyond what the booking or messaging function requires.

e. Billing

Payments are handled by Stripe. Card numbers never reach our servers — we hold a Stripe customer reference, the plan you are on, and your invoice history.

5. How the AI works, and what it sees

This section is the one most privacy policies for AI products leave out. It is also the one your own customers, and your DPO, will ask about.

What is sent to a model provider

To generate each reply, we send a large language model: the conversation so far, the instructions that scope the assistant to your business, and the relevant extracts from the knowledge base you provided. That includes whatever your customer has written in the conversation, which is why what your assistant is used for matters.

ProviderWhat it is used forWhere it processesTransfer safeguard
Anthropic PBCGenerates the assistant’s replies from the conversation and the business’s knowledge baseUnited StatesStandard Contractual Clauses, together with the provider’s EU–US Data Privacy Framework certification where it applies

Training

Your conversations are not used to train anyone’s models. We do not train models on customer data, and we use our providers under terms that exclude API content from their training. If that ever changes for a provider we use, we will change providers or ask you first — not update this page quietly.

Voice notes

Where voice transcription is enabled, the audio file is sent to a speech-to-text provider and converted to text so the assistant can answer it. The audio is personal data and often reveals more than the words do; if you would rather it never left the platform, transcription can be turned off for your account.

It tells people it is an AI

Article 50 of the EU AI Act requires that a person interacting with an AI system is told so. Our assistants disclose it, and under the Terms you may not configure one to deny being an AI or to claim to be a specific human being.

It can be wrong

A language model produces likely text, not verified fact. The assistant is instructed to answer only from your business information and to hand over to a person rather than invent an answer — but no instruction makes that guarantee absolute. Nothing it says is advice, and the responsibility for what a live assistant tells your customers rests with you as its controller.

6. Who else sees the data

We do not sell personal data. We have never sold personal data. There is no arrangement under which anyone pays us for access to it, and we do not share it for advertising.

We do use service providers — sub-processors — to run the platform. They act only on our instructions, under contract, and are listed with their purpose and location on our sub-processor page. We give 30 days’ notice before adding or replacing one, and during that period a client may object on reasonable data-protection grounds.

The categories are: hosting and database (in the EU), CDN and bot protection, AI model providers (section 5), speech-to-text, email delivery, payment processing, and the messaging platforms themselves — WhatsApp, Telegram, Instagram and Facebook, which are separate controllers for what happens on their own networks and under their own terms.

We will also disclose data where we are legally required to, and to our professional advisers where necessary. If we are ever compelled to hand over customer data, we will tell the affected client unless we are legally prohibited from doing so.

7. International transfers

The platform — application servers, database and file storage — runs in the European Union. Your customers’ conversations are stored in the EU.

Some processing leaves it. The AI model providers in section 5, our speech-to-text provider, and some operational tooling are established in the United States. Those transfers rely on the provider’s certification under the EU–US Data Privacy Framework where it applies, and on the European Commission’s Standard Contractual Clauses where it does not, together with a transfer impact assessment and the technical measures described in section 11.

We will name the specific mechanism for any specific provider on request. A generic assurance that "we use Standard Contractual Clauses" is not a disclosure, and we do not intend this section to be one.

8. How long we keep things

We would rather tell you what the system does today than publish a schedule we have not yet automated.

WhatHow long
Your account and business dataFor as long as you have an account, and then up to 90 days after it is closed so that an accidental cancellation can be reversed.
Your customers’ conversations, bookings and leadsFor as long as you remain a customer, unless you tell us to delete them. You control this: you are the controller, and deletion on your instruction is your right under Article 28(3)(g) and our obligation.
Website visitor technical data attached to widget conversationsRedacted on the schedule configured for your account.
Delivery and webhook event records30 days.
Invoices and accounting recordsAs long as Spanish tax law requires, currently six years, regardless of account closure.
Security and audit logsRetained while needed to investigate abuse, then deleted.
Being straight about this: automated time-based deletion of conversation content is built but not yet switched on for most data types. Until it is, the honest description is the one in the table — data persists while you are a customer and is deleted when you ask. We are turning the automated schedules on, and when we do, this table will state the specific periods and the version at the top of this page will change.

When you close your account we delete or irreversibly anonymise your data within 90 days, except what we must keep for tax or legal reasons. You can ask for an export before you go.

9. Your rights

If we are the controller of data about you — you are a customer, a visitor, or someone who wrote to us — you can ask us to:

  • Give you a copy of the personal data we hold about you, and tell you what we do with it (Art. 15).
  • Correct anything wrong or incomplete (Art. 16).
  • Delete it, where there is no overriding reason for us to keep it (Art. 17).
  • Restrict what we do with it while a dispute about it is resolved (Art. 18).
  • Port it — receive it in a structured, machine-readable format, or have us send it to someone else (Art. 20).
  • Object to processing we base on legitimate interests, including profiling (Art. 21). If you object to direct marketing we will stop, full stop.
  • Withdraw consent where we relied on it — as easily as you gave it (Art. 7(3)). For cookies, the "Cookie settings" link in the footer of every page.

Write to privacy@opusdone.com. We answer within one month, and will tell you if we need longer, which we may for complex requests. It is free. We may ask you to confirm your identity, because handing your data to somebody claiming to be you would be the worse failure.

If you are a customer of a business that uses our assistant, and you want to see or delete the conversation you had with it, the request goes to that business. They decide; we act on their instruction. If you send it to us we will tell you who to contact and let them know you asked, but we cannot delete a controller’s data on our own initiative.

You can also complain to a supervisory authority. Ours is the Agencia Española de Protección de Datos (AEPD)https://www.aepd.es — and you may equally complain to the authority where you live or work. We would rather you told us first, but you are not obliged to.

10. Automated decisions and lead scoring

The platform scores incoming conversations so that a business can see which enquiries look most worth answering first. That score orders a list for a human. It does not decide whether anyone gets a reply, is refused a service, or receives different terms.

We therefore do not consider this a decision producing legal or similarly significant effects under Article 22 GDPR. It is a prioritisation aid with a person at the end of it. If we ever build something that does gate an outcome automatically, that would be a material change, and this section and the version number would change with it.

11. How we protect it

  • Encryption in transit everywhere, with TLS terminated at our CDN and again at the application.
  • Each business’s data is scoped to its own tenant, and every read is access-checked against the signed-in user’s role and the businesses they are assigned to.
  • Passwords are stored only as salted hashes. Nobody at our company can read yours.
  • Sessions are revocable server-side: signing out of all devices ends every session immediately rather than waiting for a token to expire.
  • Credentials for connected calendars and channels are stored encrypted and used only for the function they were granted for.
  • Administrative access is limited to staff who need it, and privileged actions are logged.
  • Bot protection and rate limiting on the public endpoints, including the chat widget.

No system is perfectly secure and we will not claim otherwise. If a breach occurs that is likely to result in a risk to people’s rights, we will notify the supervisory authority within 72 hours as required, and tell affected clients without undue delay so that they can meet their own obligations to their customers.

12. Cookies

Our website stores a small number of things in your browser: your login session, your language choice, short-lived anti-forgery values while you connect an account, a bot check, and the state of a chat if you open one. There are no analytics or advertising trackers.

The full list, with names, purposes and durations, is in the Cookie Policy, which is generated from the same inventory our engineers must update when they add anything. You can change your choices at any time from "Cookie settings" in the footer.

13. Children

This is a service for businesses. It is not directed at children and we do not knowingly collect data from anyone under 16 through our own website or product accounts.

Your customers are a different matter: if your business serves minors, people under 16 may message your assistant. You are the controller for those conversations, and any consent or parental-authorisation requirement that applies is yours to meet. If you tell us a conversation involves a child and should be deleted, we will delete it.

14. Changes to this policy

The version number and effective date at the top of this page change whenever this policy does, and the version history at the bottom says what changed. For material changes affecting customers we email account owners at least 30 days before they take effect.

15. United States — notice at collection

Sections 15 to 21 apply if you are a resident of a US state with a comprehensive privacy law — California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others as they take effect. They sit alongside the rest of this policy rather than replacing it.

US privacy law works the other way round from the EU’s. Rather than requiring permission before collecting, it requires that you are told at the point of collection and that you can opt out afterwards. This section is that notice.

Category (CCPA §1798.140)Do we collect it?WhyKept for
Identifiers — name, email, account id, IP addressYesTo run your account and secure the serviceSee section 8
Customer records — business contact and billing detailsYesTo provide the service and take paymentSee section 8
Commercial information — your plan, usage, invoicesYesBilling and supportSix years for accounting records
Internet activity — pages requested, technical logsYes, minimallySecurity and abuse prevention. No analytics or advertising trackers.See section 8
GeolocationCountry only, derived from IPTo apply the right privacy regime to you, and for securityNot stored beyond the request
Audio, electronic or visual informationOnly what your customers send your assistantTo answer them, on your instruction as controllerYou decide — see section 8
Sensitive personal informationNot deliberatelySee section 17
Biometric information, precise geolocation, government IDsNo
Inferences used to build a profile about youNo

16. United States — we do not sell or share your information

We do not sell personal information, and we do not share it for cross-context behavioural advertising, as the CCPA defines those terms. We have not done so in the preceding twelve months.

That is a plain statement rather than a hedge because it is straightforwardly true of how the product is built: there are no advertising trackers on our website, no data-broker relationships, and no arrangement under which anyone receives personal data from us for their own purposes.

You will still find a "Your privacy choices" link in the footer. It opens the same controls anyone can use, so that the right to opt out is exercisable even where there is currently nothing to opt out of.

17. United States — sensitive personal information

We do not ask for sensitive personal information and the product has no field for it.

We are nonetheless straightforward about a real possibility: our clients include dental and medical clinics, and a person messaging a clinic may write something about their health in the course of asking for an appointment. That content arrives because your customer typed it, on your instruction as controller, and we process it only to deliver the service.

We do not use or disclose sensitive personal information for any purpose beyond providing the service you asked for, so the CCPA right to limit its use has nothing further to restrict. If your business handles health information subject to sector-specific rules such as HIPAA, note that our standard agreement is not a Business Associate Agreement — talk to us before putting that traffic through the platform.

18. United States — your rights and how to use them

  • Know what we collect, use and disclose about you, and get a copy.
  • Delete what we hold about you, subject to the exceptions the law allows.
  • Correct anything inaccurate.
  • Opt out of sale, sharing, or targeted advertising — see section 16.
  • Limit the use of sensitive personal information — see section 17.
  • Non-discrimination: we will not give you a worse price or service for exercising any of this.
  • Appeal a refusal. If we decline your request, you may ask us to reconsider and we will respond in writing with our reasoning. Colorado, Connecticut, Virginia, Texas, Oregon and Montana require this; we offer it to everyone.

Two ways to ask, as required: email privacy@opusdone.com, or use the "Your privacy choices" link in the footer of any page. We respond within 45 days, and may extend once by a further 45 days where the request is complex, in which case we will tell you.

An authorised agent may act for you if you give them written permission and we can verify it. California Shine the Light (§1798.83): we do not disclose personal information to third parties for their own direct marketing.

19. Global Privacy Control

If your browser or extension sends a Global Privacy Control signal, we treat it as a valid opt-out and apply it automatically. You will not be shown a banner asking a question you have already answered — you will be told the signal was honoured.

GPC is legally binding in California, Colorado and Connecticut. We honour it everywhere, because a preference expressed in a browser setting does not become less real at a state line.

We do not act on the older Do Not Track header. It was never given an agreed meaning, and pretending otherwise would be a claim we could not keep. Use Global Privacy Control.

20. United States — state-specific notes

  • California: rights under the CCPA as amended by the CPRA, including the categories table in section 15, the sale and sharing statement in section 16, and Shine the Light in section 18.
  • Colorado, Connecticut, Virginia, Montana, Oregon, Texas: rights of access, correction, deletion, portability and opt-out, plus the appeal process described in section 18. We honour universal opt-out mechanisms including GPC.
  • Utah: rights of access, deletion and portability, and opt-out of targeted advertising and sale.
  • Nevada: you may direct us not to sell covered information. We do not sell it in any case.

Where a state law grants a right this policy does not mention, you have that right and we will honour it. The list above is a summary, not a limit.

21. Contact

Privacy questions, rights requests, or anything on this page you think is wrong: privacy@opusdone.com. Post: Softpact, Carrer de Calàbria, 64, Eixample, 08015 Barcelona, Spain.

If you think we have got something wrong, tell us before you complain to a regulator — not because you have to, but because we would rather fix it.

Version history

  • 2.12 September 2026. Identified the operator and its postal address. Named the AI model provider that generates replies (Anthropic PBC, United States) and stated the transfer basis, replacing the unfinished placeholder row.
  • 2.01 October 2026. Complete rewrite. Adds the controller/processor split, the AI processing and international transfer sections, a legal-basis table, a US addendum covering CCPA/CPRA and other state laws, Global Privacy Control, and honest retention wording. Replaces the previous template.
  • 1.018 July 2026. Initial template.
Privacy Policy — OpusDone