Controllers and purposes
Opina365 acts as a platform and, depending on the contractual context, as a processor for organisations collecting feedback. The organisation determines the purposes of follow-up and marketing.
Legal
Informational version for the Opina365 product, updated on 30 July 2026. The contracting entity must adapt and validate the wording that applies to its processing activities.
Opina365 acts as a platform and, depending on the contractual context, as a processor for organisations collecting feedback. The organisation determines the purposes of follow-up and marketing.
Responses, comments, limited technical security data and, optionally, a name, phone number or email address may be processed. Ratings do not require identification.
Consent is granular and not preselected. It records the purpose, displayed wording, version, source and time. It may be withdrawn without affecting prior lawful processing.
Retention periods are configurable and must reflect need and legal obligations. Personal data can be erased or anonymised without deleting anonymous metrics; financial data and minimum audit records may have separate retention periods.
Data subjects may request access, rectification, portability, objection, restriction or erasure through the contact provided by the responsible organisation.
Vercel, Supabase, Stripe, Resend and Cloudflare may support service delivery. Configuration should prioritise European regions, DPAs and valid transfer mechanisms.
Access controls, RLS, encryption in transit, contact segregation, redacted logging, auditing and incident response are used. No system can eliminate risk entirely.