Skip to content

Legal

Privacy policy

Informational version for the Opina365 product, updated on 30 July 2026. The contracting entity must adapt and validate the wording that applies to its processing activities.

Controllers and purposes

Opina365 acts as a platform and, depending on the contractual context, as a processor for organisations collecting feedback. The organisation determines the purposes of follow-up and marketing.

Data processed

Responses, comments, limited technical security data and, optionally, a name, phone number or email address may be processed. Ratings do not require identification.

Consent

Consent is granular and not preselected. It records the purpose, displayed wording, version, source and time. It may be withdrawn without affecting prior lawful processing.

Retention

Retention periods are configurable and must reflect need and legal obligations. Personal data can be erased or anonymised without deleting anonymous metrics; financial data and minimum audit records may have separate retention periods.

Rights

Data subjects may request access, rectification, portability, objection, restriction or erasure through the contact provided by the responsible organisation.

Processors and transfers

Vercel, Supabase, Stripe, Resend and Cloudflare may support service delivery. Configuration should prioritise European regions, DPAs and valid transfer mechanisms.

Security

Access controls, RLS, encryption in transit, contact segregation, redacted logging, auditing and incident response are used. No system can eliminate risk entirely.