Preparing Opera AI
Loading your workspace…
Preparing Opera AI
Loading your workspace…
This Privacy Policy explains how Opera AI collects, uses, discloses, and protects personal data when you use our website and services.
Opera AI is an AI-native ERP and CRM platform. Depending on the data, we act in two distinct roles:
This dual role means that, for tenant customer data, the tenant is primarily responsible for giving notice and obtaining consent from their own customers; we support them with the tools and configuration to do so.
We apply data minimisation and collect only what is necessary. The main categories are:
| Category | Examples | Purpose |
|---|---|---|
| Account & identity | Business name, contact name, email, phone, login credentials (bcrypt-hashed). | Account provisioning, authentication (including optional two-factor), and billing. |
| Tenant customer data | WhatsApp messages, images, voice notes, and customer phone numbers that tenants process through the platform. | Delivering the AI assistant, order, and record-keeping features the tenant has configured. |
| Business records | Products, quantities, invoices, and custom records configured by tenants. | Running the tenant's configured ERP/CRM workflows. |
| Audit & telemetry | Trace identifiers, IP addresses, user-agent strings, and database change logs. | Security monitoring, support, and operational traceability. |
Where the GDPR or UK GDPR applies, we rely on the following lawful bases:
Under India's DPDP Act, 2023, processing is carried out for a lawful purpose on the basis of consent or a recognized legitimate use. Under the CCPA/CPRA, we collect, use, and share personal information for the business and commercial purposes described here.
We use a limited set of third-party sub-processors to deliver the platform. As required by law, the current list is:
We engage sub-processors under written agreements that require comparable protection of personal data, and we remain responsible for their handling of data on our behalf.
Your data may be processed in our primary database region (Singapore) and on global edge infrastructure, and by the sub-processors listed above in their respective regions. Because Opera AI serves users globally, personal data may be transferred to, stored in, or processed in countries other than your country of residence.
Where the GDPR/UK GDPR applies, we put appropriate safeguards in place for such transfers (such as standard contractual clauses or other recognized transfer mechanisms). Under India's DPDP Act, cross-border transfers are permitted except to countries specifically restricted by the government; at the date of this policy no such restrictions apply. We document material transfers under appropriate contractual protections.
We retain personal data only as long as necessary for the purposes described here or as required by law. Retention for conversational data and AI caches is configurable by each tenant administrator. When data is no longer needed and no legal retention obligation applies, we delete or anonymize it. Tenants can request deletion of their workspace data; we action such requests and instruct our sub-processors accordingly.
We use technical and organizational measures designed to protect personal data, including:
No method of transmission or storage is completely secure. These are practices we follow, not a certification (we are not ISO 27001, SOC 2, or PCI-DSS certified).
Depending on where you live and the law that applies, you may have rights over your personal data, subject to verification and lawful exceptions. These commonly include:
For data we process as a controller, contact us using the details in Section 12 and we will respond in line with applicable legal timelines (for example, within one month under the GDPR). For tenant customer data, please contact the relevant tenant, who as controller is responsible for handling the request; we will assist them as required by our agreement.
We aim to maintain procedures to detect and respond to personal data breaches. Where we are legally required to do so (for example, under the GDPR/UK GDPR or India's DPDP Act), we will notify the affected individuals and the relevant supervisory authority or Data Protection Board without undue delay and in line with the timelines the law requires.
Our services are intended for business use and are not directed at individuals under 18 (or the age of digital consent in their jurisdiction). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
We may update this Privacy Policy from time to time. We will indicate the Last updated date above and, for material changes, take reasonable steps to notify affected users.
We have not appointed a dedicated Data Protection Officer or Grievance Officer at this time. For any privacy request, question, or complaint, please contact our support team:
Privacy contact: support@operaai.in
Website: https://operaai.in
This Privacy Policy is governed by, and construed in accordance with, the laws of the Republic of India, and the courts at Rajkot / Ahmedabad, Gujarat, India have exclusive jurisdiction over any disputes arising from it.