Privacy Policy
Last updated: July 2026 · Governing law: Republic of Latvia · GDPR-compliant
Summary: We store your data in the EU only, never sell it, and you can request deletion at any time by emailing azim@theopsivo.com.
1. Who We Are
Opsivo SIA is a software company incorporated in Riga, Latvia. We operate the Opsivo platform — an operational intelligence solution for industrial SMEs. Our registered address is Riga, Latvia. Data protection enquiries: azim@theopsivo.com.
2. What Data We Collect
We collect the following categories of personal data: • Account data: name, email address, job title, company name, country • Operational data: inventory records, goods receipt/issuance logs, QHSE records, BOM data — all entered by you • Usage data: pages visited, features used, session duration, browser type, IP address (anonymised after 30 days) • Communication data: emails and messages you send to us We do not collect payment card data directly — payments are processed by our payment provider (Stripe) under their own privacy policy.
3. How We Use Your Data
We use your data solely to: • Provide, maintain, and improve the Opsivo platform • Send transactional emails (account confirmations, password resets, expiry alerts you configure) • Respond to your support requests • Comply with legal obligations under Latvian and EU law We do not use your data for advertising. We do not sell your data to third parties. We do not share your operational data with any third party except as required to operate the service (see Section 5).
4. Legal Basis for Processing
We process your personal data under the following legal bases (GDPR Article 6): • Contract performance: processing necessary to provide the service you have subscribed to • Legitimate interests: improving platform reliability, preventing fraud, security monitoring • Legal obligation: retaining records as required by Latvian law • Consent: for any optional communications (you may withdraw consent at any time)
5. Data Storage and Transfers
All customer data is stored exclusively in EU-region servers (AWS Frankfurt, Germany). We do not transfer personal data outside the European Economic Area. Sub-processors we use: • Amazon Web Services (AWS) — cloud infrastructure, EU region only • Stripe — payment processing (their privacy policy applies to payment data) • Formspree — contact form submissions Each sub-processor is bound by data processing agreements compliant with GDPR Article 28.
6. Data Retention
• Account and operational data: retained for the duration of your subscription plus 30 days after cancellation, to allow data export • Usage logs: anonymised after 30 days, deleted after 12 months • Support communications: retained for 2 years • Legal/financial records: retained for 7 years as required by Latvian law After the retention period, data is permanently deleted from all systems including backups.
7. Your Rights Under GDPR
As a data subject under GDPR, you have the right to: • Access: request a copy of all personal data we hold about you • Rectification: correct inaccurate or incomplete data • Erasure ("right to be forgotten"): request deletion of your personal data • Portability: receive your data in a machine-readable format (JSON or CSV) • Restriction: ask us to limit how we process your data • Objection: object to processing based on legitimate interests • Withdraw consent: at any time, without affecting prior processing To exercise any of these rights, email azim@theopsivo.com. We will respond within 30 days. You also have the right to lodge a complaint with the Latvian Data State Inspectorate (dvi.gov.lv).
8. Cookies
We use strictly necessary cookies only: • Session cookie: keeps you logged in during your session (deleted when you close the browser) • Preference cookie: stores your cookie consent choice (localStorage, not a cookie) We do not use advertising cookies, analytics cookies, or any third-party tracking cookies without your explicit consent. If you consent via our cookie banner, we may use anonymised analytics to improve the platform.
9. Security
We implement appropriate technical and organisational measures to protect your data: • All data in transit encrypted via TLS 1.2+ • Data at rest encrypted via AES-256 • Access controls: role-based, principle of least privilege • Regular security reviews and penetration testing • Incident response plan in place — we will notify affected users within 72 hours of a confirmed breach
10. Children's Data
Opsivo is a B2B platform intended for use by business professionals. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided us with personal data, please contact azim@theopsivo.com immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 14 days before material changes take effect. The current version is always available at theopsivo.com/privacy. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
12. Governing Law and Contact
This Privacy Policy is governed by the laws of the Republic of Latvia and applicable EU regulations (GDPR). Data Controller: Opsivo SIA Riga, Latvia Email: azim@theopsivo.com For data protection enquiries, please email azim@theopsivo.com. We aim to respond within 5 business days.
Questions about this policy? Email azim@theopsivo.com