Privacy Policy
Last updated: 2026. This Privacy Policy explains how OPSQAI processes personal data on opsqai.de (the marketing website and the Customer Portal used by our customers' designated contacts to download the installer and manage their licence).
Deployment model — what this policy does not cover
OPSQAI is a Windows-native, self-hosted product. Once a customer installs OPSQAI on their own dedicated Windows Server, all customer content — documents, SOPs, embeddings, chat questions and answers, audit logs — is processed and stored entirely on the customer's own machines, using the AI provider the customer configures with their own keys. None of that data is transmitted to OPSQAI or to opsqai.de. The customer is the sole controller and processor of that data on their premises. This policy therefore only covers the limited personal data we process on opsqai.de.
Who we are
The operator of opsqai.de is identified in the Impressum. Contact for privacy matters: notify@opsqai.de.
What we collect on opsqai.de
- Customer Portal account — for the customer contacts we designate at contract signature: work email address and hashed password (managed via our authentication provider), plus their name and role at the customer company.
- Contact-form messages — if you write to us via the contact form or by email: your name, work email, company and the content of your message. Used to reply and for pre-sales / support correspondence.
- Minimal server logs — for each HTTP request: timestamp, IP address, HTTP method, path, response status and user-agent. Used strictly for security, abuse prevention and incident investigation.
What we do NOT collect
- No web analytics — no Google Analytics, Plausible, PostHog, Matomo or equivalent. opsqai.de has no analytics vendor embedded.
- No advertising or marketing trackers — no Meta Pixel, LinkedIn Insight Tag, Google Ads, retargeting pixels, or newsletter open/click tracking.
- No product telemetry from the self-hosted instance — the OPSQAI software running on the customer's Windows Server does not send usage telemetry to us. The only outbound call to our infrastructure is a periodic licence heartbeat to the Management Center, which carries the licence identifier and heartbeat timestamp; no customer content and no end-user identifiers.
- No AI subprocessing by OPSQAI — opsqai.de does not use AI. The AI provider used by the self-hosted product is chosen and paid for by the customer, under the customer's own agreement with that provider.
Legal basis (GDPR Art. 6)
- Performance of contract (Art. 6(1)(b)) — to operate the Customer Portal for our contractual counterparties.
- Legitimate interest (Art. 6(1)(f)) — security logging and responding to pre-sales enquiries.
Retention
- Customer Portal accounts: for the duration of the customer agreement.
- Contact-form messages: up to 24 months after the last correspondence, then deleted, unless a subsequent commercial relationship justifies longer retention.
- Server logs: rolling 14 days, then automatically overwritten.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, port or object to the processing of your personal data, and to withdraw consent where processing is based on consent. Contact notify@opsqai.de to exercise these rights. You may also lodge a complaint with your local data protection authority.
International transfers
Personal data collected on opsqai.de is processed within the European Economic Area. Where a subprocessor of the marketing site (for example, the email service used to reply to your contact-form message) processes data outside the EEA, transfers are safeguarded by Standard Contractual Clauses under Article 46 GDPR or an equivalent adequacy mechanism.
Changes
We update this policy when our practices change. Material changes will be announced on this page with an updated date.