Privacy Policy
Last updated: 1 June 2026
This policy explains what personal data Opino processes, why, and the rights you have.
1. Data controller
The controller for EU/EEA and UK visitors is Advanced Internet Technologies, S.L. (CIF B76122035), Avda. de las Palmeras nº 9, Villa 2021, 35508 Costa Teguise, Las Palmas, Spain, which operates the Opino service. For privacy enquiries, to exercise rights or to complain, email privacy@opino.io. If you are in the EU/EEA or UK you may also contact your supervisory authority (in Spain: AEPD, aepd.es).
2. What we collect
When you create a business account: email, name, business name, preferred language, and payment method (processed by our payment provider — we never store card numbers). When you use the product: the customer contact data you add to Opino (email, phone, name, optional metadata), review-request logs (what was sent, when, to whom, delivery status), and generated API keys (stored hashed, never in plaintext). Automatically: standard server logs (IP, user-agent, timestamp) kept 30 days for security and abuse prevention, and aggregate product-usage analytics (no cross-site tracking). We do NOT collect sensitive data (health, politics, biometrics), geolocation more precise than country, or advertising identifiers.
3. Why we collect it
Service delivery: sending the review requests you schedule, showing your dashboard, keeping your data accessible. Account management: authentication, billing, support. Security: abuse prevention, fraud detection, incident response. Legal obligations: invoicing, tax obligations, responding to lawful requests. We do NOT sell your data or your customers’ data, and we do NOT use it to train AI models.
4. Legal bases (GDPR)
Performance of a contract (delivering the service you signed up for); legitimate interest (security, abuse prevention, limited product analytics — you can object); consent (optional marketing emails, opt-in and revocable at any time); and legal obligation (retention required by tax or accounting rules).
5. Who we share data with (processors)
Cloudflare (hosting, CDN, DDoS protection) — processed at global edge nodes; a database provider (Directus-compatible Postgres) located in the EU; an email-delivery provider (transactional emails and review requests); a WhatsApp Business API provider (for the WhatsApp channel); Telnyx (SMS for account verification codes and user-requested demo messages); a payment provider (Stripe) — PCI-compliant, processes charges; and error monitoring (Sentry-compatible) — technical error traces, no customer data. We do NOT share with ad networks, data brokers, or third-party profiling analytics.
6. Retention
Customer contacts and review logs: kept while your account is active; deleted within 30 days of cancellation, or sooner on request. Server logs: 30 days. Billing records: kept as required by tax law (typically 7 years). Backups: encrypted, 30-day rotation; deletions propagate to backups within 35 days.
7. Your rights
Access (request a copy of your data; we respond within 30 days), rectification (correct inaccurate data from the dashboard or by email), erasure (delete your account and data — some records such as invoices are kept as legally required), portability (export your contacts and review logs in JSON or CSV), objection/restriction (to processing based on legitimate interest), withdrawal of consent, and the right to complain to a supervisory authority. Email privacy@opino.io to exercise any right. We verify identity before acting on data requests.
8. If a business contacts you using Opino
If you are a customer of a business that uses Opino, that business is the controller of your data and we act as its processor. Contact the business directly to exercise your rights, or email us and we will route the request. We only process your data on the business’s instructions and under this policy.
9. International transfers
Our infrastructure uses providers with a global presence (Cloudflare, payment processors). Where data leaves the EU/EEA or UK, transfers rely on Standard Contractual Clauses and additional GDPR safeguards.
10. Verified reviews and the EU Omnibus Directive
Opino’s design helps businesses comply with the Omnibus Directive (Directive 2019/2161, in force since 2022), which requires businesses to explain how they ensure published reviews come from real customers. Review requests are sent only to contacts the business confirms as real customers (imported from their customer list, CSV, or captured at point of sale via QR/kiosk). We log which contact received which request and when, providing an audit trail for verification.
11. Children
Opino is not directed at people under 16. We do not knowingly collect data from minors. If you believe a minor has provided us data, email privacy@opino.io and we will delete it.
12. Security
Encryption in transit (TLS) for all connections; encryption at rest for the database and backups; API keys stored as argon2 hashes (a lost key cannot be recovered — you generate a new one); least-privilege internal access with audit logs on production actions. No security system is perfect; in the event of a breach affecting your data we notify affected users and authorities within the timelines required by law.
13. SMS / mobile messaging policy
We do not share your mobile information with third parties or affiliates for marketing. SMS opt-in data and consent are never shared with third parties. When you, as a business user, provide your phone number to Opino, we use it to send the one-time login/verification codes you request and the product demo message you request from your account. Message frequency varies with your activity; message and data rates may apply. Separately, when a business uses Opino to send review requests to its own customers, that business is the controller of its customers’ numbers and is responsible for obtaining consent (via the in-store QR, kiosk, or opt-in form). Opino acts as processor: we deliver those messages, include STOP/HELP in each, and handle opt-outs automatically. Reply STOP to any message to opt out; reply HELP for help. For privacy enquiries, email privacy@opino.io.
14. Cookies and analytics
The marketing site (opino.io) uses essential cookies only (session, language preference). The app (app.opino.io) uses essential cookies for authentication and CSRF protection. We use privacy-respecting aggregate analytics (no cross-site tracking, no advertising IDs).
15. Changes to this policy
We update this policy when the service changes materially. The “last updated” date above reflects the most recent revision. Significant changes are communicated to account holders by email.
16. Contact
Email privacy@opino.io. A subject line of “Privacy” or “Data request” reaches us faster.
17. Operating entities
Opino is operated for your region by Advanced Internet Technologies, S.L. Services in the EU/EEA and UK are provided by Advanced Internet Technologies, S.L. (CIF B76122035, Spain); services in the US by Swips LLC (Wyoming, USA).