Legal
Version 2.1 · Effective 1 October 2026
This policy explains what OpusDone does with personal data — yours, if you are a customer of ours, and your customers’, if you use our assistant to talk to them.
Those two are different, and section 2 explains why the difference decides most of what follows. If you are here because you are about to send us your customers’ conversations, read section 2 first, then 5, then 8.
OpusDone is a service of Softpact, operated from Spain. Postal address: Carrer de Calàbria, 64, Eixample, 08015 Barcelona, Spain.
For privacy questions, or to exercise any of the rights in section 9, write to privacy@opusdone.com. For anything else, hello@opusdone.com.
We have not appointed a Data Protection Officer. We have assessed the criteria in Article 37 GDPR and concluded that none applies: our core activity is not large-scale systematic monitoring of individuals, nor large-scale processing of special-category data. We keep that assessment under review and will publish a DPO’s details here if that changes. In the meantime the address above reaches a named person responsible for data protection, not an unattended inbox.
Because we are established in Spain, we are not required to appoint an EU representative under Article 27 GDPR. Our lead supervisory authority is the Agencia Española de Protección de Datos (AEPD).
Almost every question about this service has a different answer depending on whose data is being asked about. There are two situations and we are in a different legal position in each.
When you sign up, configure an assistant, invite colleagues or pay us, we decide what to collect and why. We are the controller for that data, and this policy is our notice to you about it.
When someone messages your business and our assistant answers, that conversation is about your relationship with your customer. You decide that the assistant should exist, what it knows, what it may say and how long you keep the result. You are the controller. We are your processor, acting on your documented instructions under Article 28 GDPR.
This is not a technicality. It means two practical things. First, the duty to tell your customers that an AI assistant handles their messages and that those messages are recorded is yours, not ours — we give you the tools to do it and require you to use them, but we have no relationship with your customer through which we could do it ourselves. Second, if one of your customers asks to see or delete their data, the request goes to you; we help you answer it, and we will not act on it unilaterally, because acting on a controller’s data without the controller’s instruction is itself a breach.
If you connect a calendar (Google Calendar, or Cal.com), we hold the access tokens for it and read the availability and the events we need in order to offer and make bookings. If you connect a messaging channel, we hold that channel’s credentials. We do not read anything in a connected system beyond what the booking or messaging function requires.
Payments are handled by Stripe. Card numbers never reach our servers — we hold a Stripe customer reference, the plan you are on, and your invoice history.
For the data where we are the controller, this is the Article 6 basis for each purpose.
| What we do | Data | Legal basis |
|---|---|---|
| Give you an account and run the service you signed up for | Account and business data | Contract (Art. 6(1)(b)) |
| Take payment and keep accounting records | Billing data | Contract, and legal obligation for the records we must keep (Art. 6(1)(b), (c)) |
| Keep the service secure — rate limiting, bot checks, abuse investigation, audit logs | Technical data, account data | Legitimate interests: running a service that is not trivially abusable (Art. 6(1)(f)) |
| Answer your support requests | Whatever you send us | Contract, or legitimate interests if you are not yet a customer |
| Non-essential cookies on our website | See the Cookie Policy | Consent (Art. 6(1)(a) and Art. 5(3) ePrivacy). We currently set none. |
| Send you product email about a service you already use | Your work email | Legitimate interests, with an unsubscribe link in every message |
| Reply to a sales enquiry you sent us | Contact form data | Legitimate interests: you asked us to (Art. 6(1)(f)) |
Where we rely on legitimate interests we have carried out the balancing test the GDPR requires and will share the reasoning if you ask.
For your customers’ conversations we are the processor, so the legal basis is yours to establish, not ours. Our basis for processing is your instruction under Article 28. See section 2 and the obligations you accept in the Terms.
This section is the one most privacy policies for AI products leave out. It is also the one your own customers, and your DPO, will ask about.
To generate each reply, we send a large language model: the conversation so far, the instructions that scope the assistant to your business, and the relevant extracts from the knowledge base you provided. That includes whatever your customer has written in the conversation, which is why what your assistant is used for matters.
| Provider | What it is used for | Where it processes | Transfer safeguard |
|---|---|---|---|
| Anthropic PBC | Generates the assistant’s replies from the conversation and the business’s knowledge base | United States | Standard Contractual Clauses, together with the provider’s EU–US Data Privacy Framework certification where it applies |
Your conversations are not used to train anyone’s models. We do not train models on customer data, and we use our providers under terms that exclude API content from their training. If that ever changes for a provider we use, we will change providers or ask you first — not update this page quietly.
Where voice transcription is enabled, the audio file is sent to a speech-to-text provider and converted to text so the assistant can answer it. The audio is personal data and often reveals more than the words do; if you would rather it never left the platform, transcription can be turned off for your account.
Article 50 of the EU AI Act requires that a person interacting with an AI system is told so. Our assistants disclose it, and under the Terms you may not configure one to deny being an AI or to claim to be a specific human being.
A language model produces likely text, not verified fact. The assistant is instructed to answer only from your business information and to hand over to a person rather than invent an answer — but no instruction makes that guarantee absolute. Nothing it says is advice, and the responsibility for what a live assistant tells your customers rests with you as its controller.
The platform — application servers, database and file storage — runs in the European Union. Your customers’ conversations are stored in the EU.
Some processing leaves it. The AI model providers in section 5, our speech-to-text provider, and some operational tooling are established in the United States. Those transfers rely on the provider’s certification under the EU–US Data Privacy Framework where it applies, and on the European Commission’s Standard Contractual Clauses where it does not, together with a transfer impact assessment and the technical measures described in section 11.
We will name the specific mechanism for any specific provider on request. A generic assurance that "we use Standard Contractual Clauses" is not a disclosure, and we do not intend this section to be one.
We would rather tell you what the system does today than publish a schedule we have not yet automated.
| What | How long |
|---|---|
| Your account and business data | For as long as you have an account, and then up to 90 days after it is closed so that an accidental cancellation can be reversed. |
| Your customers’ conversations, bookings and leads | For as long as you remain a customer, unless you tell us to delete them. You control this: you are the controller, and deletion on your instruction is your right under Article 28(3)(g) and our obligation. |
| Website visitor technical data attached to widget conversations | Redacted on the schedule configured for your account. |
| Delivery and webhook event records | 30 days. |
| Invoices and accounting records | As long as Spanish tax law requires, currently six years, regardless of account closure. |
| Security and audit logs | Retained while needed to investigate abuse, then deleted. |
When you close your account we delete or irreversibly anonymise your data within 90 days, except what we must keep for tax or legal reasons. You can ask for an export before you go.
If we are the controller of data about you — you are a customer, a visitor, or someone who wrote to us — you can ask us to:
Write to privacy@opusdone.com. We answer within one month, and will tell you if we need longer, which we may for complex requests. It is free. We may ask you to confirm your identity, because handing your data to somebody claiming to be you would be the worse failure.
You can also complain to a supervisory authority. Ours is the Agencia Española de Protección de Datos (AEPD) — https://www.aepd.es — and you may equally complain to the authority where you live or work. We would rather you told us first, but you are not obliged to.
The platform scores incoming conversations so that a business can see which enquiries look most worth answering first. That score orders a list for a human. It does not decide whether anyone gets a reply, is refused a service, or receives different terms.
We therefore do not consider this a decision producing legal or similarly significant effects under Article 22 GDPR. It is a prioritisation aid with a person at the end of it. If we ever build something that does gate an outcome automatically, that would be a material change, and this section and the version number would change with it.
No system is perfectly secure and we will not claim otherwise. If a breach occurs that is likely to result in a risk to people’s rights, we will notify the supervisory authority within 72 hours as required, and tell affected clients without undue delay so that they can meet their own obligations to their customers.
This is a service for businesses. It is not directed at children and we do not knowingly collect data from anyone under 16 through our own website or product accounts.
Your customers are a different matter: if your business serves minors, people under 16 may message your assistant. You are the controller for those conversations, and any consent or parental-authorisation requirement that applies is yours to meet. If you tell us a conversation involves a child and should be deleted, we will delete it.
The version number and effective date at the top of this page change whenever this policy does, and the version history at the bottom says what changed. For material changes affecting customers we email account owners at least 30 days before they take effect.
Sections 15 to 21 apply if you are a resident of a US state with a comprehensive privacy law — California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others as they take effect. They sit alongside the rest of this policy rather than replacing it.
US privacy law works the other way round from the EU’s. Rather than requiring permission before collecting, it requires that you are told at the point of collection and that you can opt out afterwards. This section is that notice.
| Category (CCPA §1798.140) | Do we collect it? | Why | Kept for |
|---|---|---|---|
| Identifiers — name, email, account id, IP address | Yes | To run your account and secure the service | See section 8 |
| Customer records — business contact and billing details | Yes | To provide the service and take payment | See section 8 |
| Commercial information — your plan, usage, invoices | Yes | Billing and support | Six years for accounting records |
| Internet activity — pages requested, technical logs | Yes, minimally | Security and abuse prevention. No analytics or advertising trackers. | See section 8 |
| Geolocation | Country only, derived from IP | To apply the right privacy regime to you, and for security | Not stored beyond the request |
| Audio, electronic or visual information | Only what your customers send your assistant | To answer them, on your instruction as controller | You decide — see section 8 |
| Sensitive personal information | Not deliberately | See section 17 | — |
| Biometric information, precise geolocation, government IDs | No | — | — |
| Inferences used to build a profile about you | No | — | — |
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as the CCPA defines those terms. We have not done so in the preceding twelve months.
That is a plain statement rather than a hedge because it is straightforwardly true of how the product is built: there are no advertising trackers on our website, no data-broker relationships, and no arrangement under which anyone receives personal data from us for their own purposes.
You will still find a "Your privacy choices" link in the footer. It opens the same controls anyone can use, so that the right to opt out is exercisable even where there is currently nothing to opt out of.
We do not ask for sensitive personal information and the product has no field for it.
We are nonetheless straightforward about a real possibility: our clients include dental and medical clinics, and a person messaging a clinic may write something about their health in the course of asking for an appointment. That content arrives because your customer typed it, on your instruction as controller, and we process it only to deliver the service.
We do not use or disclose sensitive personal information for any purpose beyond providing the service you asked for, so the CCPA right to limit its use has nothing further to restrict. If your business handles health information subject to sector-specific rules such as HIPAA, note that our standard agreement is not a Business Associate Agreement — talk to us before putting that traffic through the platform.
Two ways to ask, as required: email privacy@opusdone.com, or use the "Your privacy choices" link in the footer of any page. We respond within 45 days, and may extend once by a further 45 days where the request is complex, in which case we will tell you.
An authorised agent may act for you if you give them written permission and we can verify it. California Shine the Light (§1798.83): we do not disclose personal information to third parties for their own direct marketing.
If your browser or extension sends a Global Privacy Control signal, we treat it as a valid opt-out and apply it automatically. You will not be shown a banner asking a question you have already answered — you will be told the signal was honoured.
GPC is legally binding in California, Colorado and Connecticut. We honour it everywhere, because a preference expressed in a browser setting does not become less real at a state line.
We do not act on the older Do Not Track header. It was never given an agreed meaning, and pretending otherwise would be a claim we could not keep. Use Global Privacy Control.
Where a state law grants a right this policy does not mention, you have that right and we will honour it. The list above is a summary, not a limit.
Privacy questions, rights requests, or anything on this page you think is wrong: privacy@opusdone.com. Post: Softpact, Carrer de Calàbria, 64, Eixample, 08015 Barcelona, Spain.
If you think we have got something wrong, tell us before you complain to a regulator — not because you have to, but because we would rather fix it.