OpusDone
Request access

Legal

Privacy Policy

Last updated: 18 July 2026

Starting template, not legal advice. A qualified lawyer / DPO should review this before launch — you process EU personal data over messaging channels, so GDPR applies.

1. Who we are

OpusDone (“we”, “us”) provides AI customer-service agents on messaging channels. For data we process on behalf of business clients (their customers’ messages), the client is the data controller and we act as a processor. For our own account and website data, we are the controller. Contact: hello@opusdone.com.

2. Data we collect

Account & contact data (name, work email, business details) when you request access or use the dashboard; business content you upload (services, prices, FAQs); and, when operating an agent, the customer conversations and bookings processed through the channels you connect. We also collect basic technical/usage data from the website.

3. How we use data

To provide and operate the Service (answering messages, making bookings, escalating to humans), to set up and support your account, to communicate with you, to keep the Service secure, and to comply with legal obligations.

4. Legal bases (GDPR)

We rely on performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service and respond to your requests), consent (where required, e.g. certain communications), and legal obligation.

5. Messaging data

Customer messages sent to a business’s agent are processed to generate replies and bookings. We process them on the business’s instructions and do not use them to build unrelated profiles. Messaging providers (e.g. WhatsApp) process data under their own terms.

6. Sharing & subprocessors

We share data with service providers that help us run the Service — for example hosting, AI model providers, messaging providers, and scheduling (Cal.com). They act under contract and only as needed. We do not sell personal data.

7. Retention

We keep personal data only as long as needed for the purposes above or as required by law, then delete or anonymise it. Business clients can request export or deletion of their data.

8. Your rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to certain processing, and you may withdraw consent. You can also complain to your local supervisory authority (in Spain, the AEPD).

9. Cookies

The website uses essential cookies to function, and (where enabled) analytics cookies with your consent. You can manage cookies through your browser and any consent banner we provide.

10. Security

We use technical and organisational measures such as access controls, encryption in transit, and tenant data isolation. No system is perfectly secure, but we work to protect your data and notify you of incidents as required by law.

11. International transfers

Where data is transferred outside the EEA, we use appropriate safeguards such as Standard Contractual Clauses.

12. Contact

Privacy questions or requests: hello@opusdone.com.

Privacy Policy — OpusDone