01Introduction
This Data Processing & Security Policy (“Policy”) describes how Opei Technologies LLC (“Opei”, “we”, “our”, or “us”) processes, stores, protects and secures information when providing Opei Business Suite (the “Platform”).
This Policy should be read together with our:
- Terms of Service
- Privacy Policy
- Cookie Policy
- Acceptable Use Policy
Where a separate Data Processing Addendum (“DPA”) has been executed between Opei and a customer, the DPA will prevail to the extent of any inconsistency.
02Our Role
Opei Technologies LLC develops and operates business software and technology services.
Except where expressly stated otherwise, Opei does not provide regulated banking, payment processing, money transmission, card issuing, remittance or other regulated financial services.
Where regulated financial services are available through the Platform, those services are provided by independent licensed financial institutions or regulated partners operating under their own legal agreements and privacy obligations.
03Definitions
For the purposes of this Policy:
Customer means the organisation or individual using the Platform.
Customer Data means information uploaded, created, stored or processed through the Platform by or on behalf of a Customer.
Personal Data means information relating to an identified or identifiable natural person, as defined by applicable law.
Processing means any operation performed on data, including collection, storage, use, disclosure, transmission, deletion or destruction.
Subprocessor means a third party engaged by Opei to process Customer Data on Opei's behalf.
04Categories of Data Processed
Depending on the Services used, Opei may process:
Account Information
- Names
- Email addresses
- Telephone numbers
- Usernames
- Roles and permissions
Business Information
- Company details
- Registration information
- Tax information
- Business addresses
- Team information
Customer Content — information uploaded by customers, including:
- invoices
- inventory records
- customer databases
- reports
- documents
- product information
- sales information
Technical Information
- IP addresses
- Browser information
- Device identifiers
- System logs
- Authentication logs
- API logs
- Error reports
05Purpose of Processing
We process information to:
- provide the Platform;
- authenticate users;
- secure customer accounts;
- maintain Platform functionality;
- provide customer support;
- process subscriptions;
- monitor performance;
- improve reliability;
- detect fraud and abuse;
- comply with legal obligations;
- investigate security incidents.
Opei does not use Customer Data for advertising or sell Customer Data to third parties.
06Customer Instructions
Opei processes Customer Data only:
- in accordance with customer instructions;
- as necessary to provide the Services;
- where required by applicable law; or
- where necessary to protect the security and integrity of the Platform.
Customers remain responsible for ensuring they have the legal authority to submit information to the Platform.
07Data Security
Opei maintains commercially reasonable administrative, technical and organisational safeguards designed to protect Customer Data.
Security measures may include:
- encryption of data in transit using TLS;
- encryption of sensitive data at rest where appropriate;
- role-based access controls;
- multi-factor authentication for administrative access where supported;
- least-privilege access principles;
- secure password hashing;
- audit logging;
- intrusion monitoring;
- security patch management;
- secure software development practices;
- regular backups;
- disaster recovery planning.
Security controls are reviewed periodically and updated as appropriate.
08Access Controls
Access to Customer Data is restricted to authorised personnel who require access to perform their duties.
Access is granted based on the principle of least privilege and may be revoked immediately when no longer required.
Administrative access is logged where reasonably practicable.
09Data Encryption
Where appropriate, Opei uses encryption technologies to protect data during transmission and storage.
Encryption standards may evolve over time to reflect industry best practices.
10Subprocessors
Opei may engage trusted third-party subprocessors to support the operation of the Platform.
Examples include providers of:
- cloud infrastructure;
- email delivery;
- customer support;
- monitoring;
- analytics;
- communications;
- identity verification;
- security services.
Opei performs reasonable due diligence before engaging subprocessors and requires them to maintain appropriate security and confidentiality obligations.
A current list of subprocessors may be made available upon request or published on our website.
11International Transfers
Because Opei operates internationally, Customer Data may be processed in multiple jurisdictions.
Where cross-border transfers occur, Opei implements commercially reasonable safeguards appropriate to the applicable legal requirements.
12Confidentiality
Personnel authorised to access Customer Data are subject to confidentiality obligations through employment agreements, contractor agreements or comparable legal commitments.
Confidential information is accessed only where reasonably necessary to provide the Services or fulfil legal obligations.
13Security Incident Management
Opei maintains procedures designed to identify, investigate and respond to security incidents.
Where required by applicable law or contractual obligations, Opei will notify affected customers of confirmed security incidents without unreasonable delay after becoming aware of them.
Notification may include:
- the nature of the incident;
- the categories of information affected;
- known or likely impacts;
- actions taken by Opei; and
- recommended customer actions where appropriate.
14Data Retention
Customer Data is retained only for as long as necessary to:
- provide the Services;
- comply with legal obligations;
- resolve disputes;
- enforce agreements;
- maintain security;
- satisfy legitimate business recordkeeping requirements.
Customers may request deletion of Customer Data subject to applicable law and contractual obligations.
15Data Deletion
Upon termination of Services, Opei may:
- return Customer Data where supported;
- allow customers to export Customer Data during a reasonable transition period;
- securely delete Customer Data after applicable retention periods expire.
Certain information may be retained where required by law, necessary for security investigations or required to protect legal rights.
16Customer Responsibilities
Customers are responsible for:
- configuring appropriate user permissions;
- maintaining secure passwords;
- enabling multi-factor authentication where available;
- managing authorised users;
- complying with applicable privacy laws;
- obtaining any required consents;
- maintaining backups where appropriate.
17Security Testing
Opei may conduct reasonable security testing of its systems, including:
- vulnerability assessments;
- penetration testing;
- code reviews;
- security monitoring;
- infrastructure assessments.
Testing is performed in a manner designed to minimise disruption to customer services.
18Compliance
Opei designs its security programme with recognised security principles in mind and continually evaluates improvements appropriate to the size, complexity and nature of its services.
Nothing in this Policy should be interpreted as a certification or guarantee that the Platform complies with a particular legal or industry framework unless expressly stated by Opei.
19Changes to this Policy
We may update this Policy periodically to reflect changes in technology, legal requirements, business practices or security measures.
Material updates will be communicated through the Platform, by email or by other reasonable means where appropriate.
20Contact
Questions regarding this Policy may be directed to:
Opei Technologies LLC — Privacy & Security Team
Email: privacy@opei.business
Security Reports: security@opei.business
General Enquiries: info@opei.business
Website: https://opei.business
