Privacy Policy

Last updated: 8 February 2026

1. Data Controller

Opscale Group
CVR: 44583216
Email: info@getopscale.com
Denmark

We are the data controller for all personal data processed through the Opscale platform ("Service"). We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Danish Data Protection Act (databeskyttelsesloven).

2. What Data We Collect

2.1 Account Data

When you create an account, we collect:

2.2 Organization Data

When you create or join an organization, we collect:

2.3 Operational Data

As you use the Service, we process:

2.4 Billing Data

If you subscribe to a paid plan:

Payment card details and billing addresses are processed directly by Stripe and never stored on our servers. Stripe's privacy policy applies to that data.

2.5 Technical Data

We collect limited technical data for the functioning of the Service:

We do not use any third-party analytics, tracking pixels, session recording, or behavioral tracking tools.

2.6 Aggregated Metrics

We generate aggregated, non-personally-identifiable metrics such as daily task completion counts per organization for internal operational reporting. Per-user task completion counts are recorded for organization managers to review team performance.

3. Legal Basis for Processing

We process your personal data on the following legal bases under GDPR Article 6(1):

PurposeLegal Basis
Providing the Service (account, tasks, scheduling)Performance of contract (Art. 6(1)(b))
Processing paymentsPerformance of contract (Art. 6(1)(b))
Sending team invitations on behalf of an organizationLegitimate interest (Art. 6(1)(f))
Aggregated operational metricsLegitimate interest (Art. 6(1)(f))
Per-user task completion trackingLegitimate interest (Art. 6(1)(f)) — the organization's interest in operational oversight; can be disabled by the organization at any time
Technical metadata in feedback submissionsLegitimate interest (Art. 6(1)(f)) — bug diagnosis
Cookies strictly necessary for operationLegitimate interest (Art. 6(1)(f))

4. Data Processors and Third-Party Services

We use the following third-party processors to deliver the Service. Each processor's own terms govern how they handle personal data on our behalf:

ProcessorPurposeData ProcessedLocation
ClerkAuthentication and user managementName, email, password hash, session tokens, organization membershipsUSA
ConvexDatabase, backend logic, file storageAll operational data, uploaded imagesUSA
StripePayment processingPayment card details, billing address, email, subscription metadataUSA / Ireland
VercelWeb hosting and CDNIP address, request metadata (server logs)Global CDN

International Data Transfers

Some of our processors are based in the United States. When personal data is transferred from the EU/EEA to the USA, these providers rely on transfer mechanisms recognized under GDPR, such as the EU-U.S. Data Privacy Framework (DPF) and/or Standard Contractual Clauses (SCCs). You can review each provider's data processing and transfer terms via the links above.

5. Data Retention

6. Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights:

To exercise any of these rights, use the self-service tools in the app or contact us at info@getopscale.com. We will respond within 30 days.

7. Cookies and Local Storage

We use only strictly necessary cookies and local storage for the functioning of the Service. We do not use any tracking, marketing, or analytics cookies. See our Cookie Policy for full details.

NamePurposeDuration
__clerk_*Authentication session managementSession
localeLanguage preference1 year
opscenterOpsCenter mode flag30 days
pin_bypass_okOne-time PIN bypass flagOne-time use

8. Security Measures

We implement appropriate technical and organizational measures to protect your data, including:

9. Data Processing in the Employment Context

When an organization uses Opscale to manage employee tasks, the organization acts as the data controller for their employees' operational data (task completions, initials, scheduling). Opscale acts as a data processor on behalf of the organization for this data. The processing is governed by our Terms & Conditions.

Organizations are responsible for:

10. Children's Privacy

The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child under 16 has provided us with personal data, please contact us and we will delete that data.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or through a notice in the Service. The "Last updated" date at the top of this policy indicates when it was last revised.

12. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet) — www.datatilsynet.dk.

13. Contact

For questions about this privacy policy or your personal data:

Opscale Group
Email: info@getopscale.com

Terms & ConditionsCookie Policy