Effective date: 14 August 2026 Controller: Opafex Ltd ("Opafex", "we", "us"), 1 Coldbath Square, Farringdon, London, EC1R 5HL, company no. 17330428. Privacy contact: privacy@opafex.com. ICO registration: ZC196031.
This policy explains how we handle personal data for the Opafex platform ("Service"). We act in two roles: as a controller of data about our own account holders, and as a processor of the data our customers route through the AI agents they build. Where we act as a processor, our customer is the controller and our Data Processing Agreement governs that processing.
1. Who this applies to
- Account holders (our customers — businesses and individuals who sign up).
- End individuals whose personal data a customer's agent processes (e.g. the customer's own contacts, email/SMS recipients, leads). For these people, the customer is the controller; contact them first, but you may also contact us at the address above and we will route your request.
2. What we collect and why (controller role)
| Category | Examples | Purpose | Lawful basis (UK/EU GDPR) |
|---|---|---|---|
| Account & identity | email, name, password (hashed), license key | Create and secure your account | Contract (Art 6(1)(b)) |
| Billing | Stripe customer ID, invoices, usage/token counts | Take payment, meter usage, tax | Contract; Legal obligation (tax records) |
| Authentication & security | session tokens, IP address, user-agent, device/location, audit logs | Keep your account secure, detect abuse, meet our security duties | Legitimate interests (Art 6(1)(f)); Legal obligation |
| Support & comms | messages you send us, product emails | Respond to you, operate the Service | Contract; Legitimate interests |
| Product usage | feature/telemetry events, error reports | Operate, debug and improve the Service | Legitimate interests |
We do not sell personal data. We do not use account holders' content to train AI models (see §6).
3. Customer content we process (processor role)
When you use an agent, we process whatever you and your agent's data sources contain — prompts, conversation messages, uploaded documents, knowledge-base content, and data pulled from integrations you connect (e.g. CRM, email, GitHub). This may contain personal data about third parties. You are the controller of that content; you must have a lawful basis and provide any required notices to those individuals. Our handling is governed by the DPA.
4. AI processing and third-party model providers
The Service is powered by AI. When you interact with an agent, you are interacting with an AI system, and your content is sent to third-party large-language-model (LLM) providers to generate responses. By default ("standard tier") these providers are: Anthropic (primary), Google, and OpenAI (see the full Sub-Processor List); PII-bearing calls are pinned to a paid, no-training tier. Groq is available only as a Bring-Your-Own-Key option. Document embeddings use OpenAI unless you are on Private Mode.
You can reduce or eliminate this exposure:
- Bring Your Own Key (BYOK): route AI calls through your own provider account.
- Private Mode: keeps content on your own database, uses your keys and/or a local model, and restricts our telemetry to non-content metadata only. Ask us for current availability and pricing.
5. International transfers
We are based in the UK and serve UK, EU and US users. Some sub-processors — notably the US LLM providers and parts of our infrastructure — process data in the United States.
Our hosting provider, Railway Corporation, stores all platform data at rest. We have an executed Data Processing Addendum with Railway dated 14 August 2026, which incorporates the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, so that transfer is covered by appropriate safeguards.
For the remaining US sub-processors, principally the AI model providers, we rely on the safeguards in each provider's own data processing terms, which incorporate the SCCs and UK Addendum. We are still completing that documentation — the executed agreements and a transfer risk assessment — with external counsel, and not every agreement is yet on file. If the transfer position for a specific provider matters to your decision to use the Service, write to privacy@opafex.com and we will tell you exactly where it stands rather than give you a general assurance. Private Mode, BYOK and local models are available to keep content within your chosen region.
6. Model training
We do not use account holders' content to train our own models, and we will not enable any "improve the model with your data" processing without separate, opt-in consent.
We select AI providers' paid API tiers, whose published terms state that data submitted through the API is not used to train their models, and the platform enforces this in code: calls that may carry personal data are pinned to those paid tiers and are blocked from free/consumer tiers whose terms permit training. We are in the process of obtaining written confirmation of the no-training position from each provider; until that is complete, what we can state is the tier we buy and the control we enforce, not a warranty on the provider's behalf.
7. Retention
We keep personal data only as long as needed for the purposes above, per our internal Data Retention Schedule. Key points: account data is kept for the life of your account and deleted (or anonymised) on closure after a short grace period; security and audit logs are kept up to 24 months; billing records are kept as long as tax law requires (~6–7 years). Customer content is retained per your instructions and the DPA, and deleted on your request or account closure.
8. Your rights
Subject to law, you can request: access to your data, a copy in portable form, correction, deletion,
restriction, objection, and withdrawal of consent. Contact privacy@opafex.com. We respond within
one month. You can complain to the UK ICO (ico.org.uk) or your local EU supervisory authority. US residents
(California and other states): you have rights to know, access, delete, correct, and opt out of "sale"/"sharing"
— we do not sell or share personal data as those terms are defined, and we honour opt-out signals.
9. Security
We use encryption in transit (TLS) and encryption at rest for credentials and API keys (AES-256-GCM), access controls, audit logging, and tenant isolation. No system is perfectly secure; see our Breach Response Plan for how we handle incidents.
10. Cookies
See the Cookie Policy. We use only strictly-necessary cookies for login/session. We set no non-essential or advertising cookies, so no cookie consent banner is required. Error/performance monitoring (Sentry) sets no cookies and does not record your session.
11. Children
The Service is not directed to children under 16 and we do not knowingly collect their data.
12. Changes
We will post changes here and, for material changes, notify account holders. Continued use after the effective date constitutes acceptance.