Privacy Policy
What personal data we process, why, and your rights under GDPR.
This Privacy Policy explains how Haxoria SRL ("Haxoria", "we", "us") processes personal data when you visit our website, create an account, or use The OPP (the "Platform"). For data we process on your behalf about your own customers, see our Data Processing Addendum.
1. Data controller
Haxoria SRL, a Belgian company. Contact: privacy@theopp.be. We have not appointed a Data Protection Officer because we are not legally required to; we have designated a privacy contact at the address above.
2. What we collect
Account data
Name, email address, hashed password, tenant slug and name, locale, role (owner / admin / member), and audit timestamps (account creation, last login). Provided by you when you sign up.
Billing data
Billing address, VAT number, plan tier, subscription status, and payment method tokens. We do not store full card numbers; Stripe processes and stores those as our payment processor.
Usage and operational data
Logs of HTTP requests, agent runs, model token usage, error reports, IP address, user agent, and timestamps. Used to operate, secure, and debug the Platform.
Integration data (when you connect them)
Gmail: OAuth refresh tokens (encrypted at rest), mailbox identifiers, message metadata and bodies of threads you elect to import. IMAP: encrypted credentials for any IMAP-compatible mailbox you choose to connect. GitHub: SSH connectivity to repositories you explicitly link. Odoo source: code we cache on disk for the agent's grounding.
Cookies and similar technologies
Strictly-necessary session cookies for authentication; functional cookies for in-app preferences. We do not use cross-site advertising cookies. See our Cookie Policy.
3. Why we process this data
We process the categories above for the following purposes and on the following legal bases under GDPR Article 6:
- Performance of contract (Art. 6(1)(b)): providing the Platform, processing payments, supporting your usage.
- Legitimate interest (Art. 6(1)(f)): securing the Platform, fraud prevention, debugging, aggregated analytics. We balance these against your interests and freedoms; you may object — see Your Rights below.
- Legal obligation (Art. 6(1)(c)): tax and accounting record retention, responding to law enforcement requests in compliance with applicable law.
- Consent (Art. 6(1)(a)): optional analytics, when offered; marketing emails beyond service announcements. You can withdraw consent at any time without affecting prior lawful processing.
4. Who we share data with (subprocessors)
We rely on a small set of carefully vetted subprocessors. Current list, kept in sync with our DPA:
- Anthropic, PBC (United States) — large-language-model inference for agent outputs. Data flows are short-lived per-request; no training on Customer Data.
- Stripe Payments Europe Ltd. (Ireland) — billing and payment processing.
- Amazon Web Services EMEA SARL (Luxembourg / EU regions) — optional artifact storage (S3) and managed KMS key encryption.
- OVH SAS (France) — hosting infrastructure and DNS management.
- Voyage AI (United States) — text embeddings for retrieval-augmented generation. Snippets from Odoo source and your specs are sent; no Customer payment or auth data.
- Google LLC — only when you connect a Gmail mailbox; data flows are end-to-end between us and your mailbox.
Where data is transferred outside the European Economic Area, we rely on the EU Standard Contractual Clauses and additional safeguards as required by GDPR Chapter V.
5. How long we keep data
- Account data: while your account is active, plus 30 days after closure for restoration purposes.
- Billing data: 7 years, in line with Belgian commercial accounting obligations.
- Operational logs: 90 days for application logs, 365 days for security-relevant audit logs.
- Integration data: tied to the connection — revoked OAuth tokens and disconnected mailboxes are purged within 30 days.
- Generated artifacts (modules, specs): for the life of your account, deleted on request or at closure.
6. How we protect data
Passwords are hashed with Argon2id. OAuth refresh tokens are encrypted at rest. All transport is TLS 1.2 or higher. Database access is restricted by role-based controls and row-level security per tenant. We run regular security reviews, dependency updates, and operate on the principle of least privilege.
We notify affected customers and the competent supervisory authority of any personal-data breach without undue delay, in line with GDPR Article 33–34.
7. Your rights
Under GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise these rights, email privacy@theopp.be. We will respond within one month.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit) at www.dataprotectionauthority.be or with the supervisory authority of your habitual residence.
8. Children
The Platform is intended for business use. We do not knowingly process personal data of individuals under 16. If you believe we have done so, contact us and we will delete the data.
9. Automated decision-making
We do not use Customer Data to make automated decisions that produce legal or similarly significant effects on individuals.
10. Changes to this policy
We may update this policy from time to time. Material changes will be notified to account owners by email at least 14 days before they take effect.
11. Contact
Privacy questions: privacy@theopp.be. Security reports: security@theopp.be. General contact: hello@theopp.be.
