Opelli
Terms ← opelli.dev

Legal

Privacy Policy

How Health Monk s.r.o. collects, uses, shares and protects personal data in connection with Opelli — and the rights you have over your data under the GDPR.

Effective: 23 July 2026 Last updated: 23 July 2026 Version: 1.0

Contents

  1. Who we are
  2. Controller vs processor
  3. Data we collect
  4. How & why we use it
  5. Cookies
  6. Data we process for customers
  7. Sub-processors
  8. When we share data
  9. International transfers
  10. How long we keep it
  11. How we protect it
  12. Your rights
  13. Children
  14. Changes
  15. Contact & complaints

This Privacy Policy explains how Health Monk s.r.o. handles personal data in connection with Opelli — the marketing site at opelli.dev, the beta sign-up, and the Opelli application itself. A key distinction runs through this policy: for some data we decide the purposes and means of processing (we are the controller); for the data our customers put into Opelli about their own people and contacts, we act only on their instructions (we are the processor). Section 2 explains which is which.

Who we are

The controller responsible for the personal data described in this policy (except where we act as a processor — see section 2) is:

Health Monk s.r.o.

Korunní 2569/108, Vinohrady, 101 00 Praha 10, Czech Republic

Company ID (IČO): 21042039 · DUNS: 984015947

Privacy contact: [email protected]

We have not appointed a statutory Data Protection Officer, as we are not required to. You can reach our privacy team at the address above for any question about this policy or your personal data.

When we are the controller vs the processor

Opelli is a platform our customers use to run their operations. That creates two roles:

  • We are the controller for the personal data we handle to run our business and provide the Service — for example, the details of the people who create and administer accounts, sign in, contact support, or sign up for the beta, and the technical logs the Service generates. Sections 3–5 and 8–15 describe this data.
  • We are the processor for the personal data our customers choose to put into Opelli about their team members, contractors, CRM contacts, mailing-list recipients, form respondents and similar (“Customer Content”). Here the customer is the controller; we process it only on their documented instructions under a Data Processing Agreement. Section 6 describes this data. If you are a data subject whose personal data appears in a customer's workspace and you want to exercise your rights over it, please contact that customer (the controller); we will assist them as our agreement requires.

Personal data we collect (as controller)

Account and profile data

When you are invited to and sign in to Opelli, we receive from Google (via OAuth/OpenID Connect) your name, email address, a stable account identifier, and profile picture. Within your profile you or your administrator may add further details such as job title, contact details, skills and reporting lines.

Beta sign-up data

If you request early access through the sign-up form on opelli.dev, we collect the email address you provide. (The form also contains a hidden “company” field that is a spam honeypot — genuine visitors never fill it, and submissions that do are discarded.)

Communications and support

If you contact us by email or through the Service, we keep your messages and the information you choose to include, so we can respond and keep records.

Usage, device and log data

When you use the Service, our systems automatically record technical information such as IP address, browser and device type, timestamps, the pages or API endpoints requested, and diagnostic and security logs. The Service also maintains internal activity and audit logs of actions taken within an account (for traceability and security).

The Opelli marketing site at opelli.dev sets no cookies, runs no analytics or advertising trackers, and loads no third-party scripts. The only network request it makes on your behalf is submitting the beta sign-up form when you choose to.

How and why we use personal data — and our legal bases

As controller, we process personal data for the following purposes, each with a legal basis under Article 6(1) GDPR:

PurposeData usedLegal basis
Providing, operating and maintaining the Service and your accountAccount/profile, usage/log dataPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for users acting for an organizational customer
Authenticating sign-in and securing accountsGoogle account identifier, session data, API-key/token metadataContract; legitimate interests in security
Responding to your beta request and inviting you to the betaBeta sign-up emailConsent (Art. 6(1)(a)) / steps prior to a contract (Art. 6(1)(b))
Providing support and communicating about the Service (including important service notices)Contact and communication dataContract; legitimate interests
Securing the Service, preventing abuse, and keeping audit/activity logsUsage, device and log dataLegitimate interests (Art. 6(1)(f)) in the security and integrity of the Service
Improving and developing the ServiceAggregated/technical usage data; feedbackLegitimate interests
Complying with legal obligations and enforcing our termsAs relevantLegal obligation (Art. 6(1)(c)); legitimate interests in establishing or defending legal claims

Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You may object to processing based on legitimate interests as described in section 12. Where we rely on consent, you may withdraw it at any time.

Cookies and similar technologies

The Opelli application uses a single strictly necessary cookie: a signed, HttpOnly, SameSite=Lax session cookie that keeps you signed in. It is essential to the Service and cannot be switched off while you are using the app. We do not use advertising, profiling or third-party analytics cookies. As noted above, the marketing site sets no cookies at all. Because we use only strictly necessary cookies and no tracking, no cookie-consent banner is required.

Data we process on behalf of our customers (as processor)

When our customers use Opelli, they submit Customer Content that may contain personal data about their own team members, contractors, customers and contacts, mailing-list recipients, and people who respond to their public forms. Depending on how the customer configures the Service, this can include names, email addresses and phone numbers, job titles, project and task assignments, time entries, CRM notes and deal information, marketing-list membership, form answers, and GDPR-compliance records (such as consent logs and data-subject requests) that the customer maintains within the Service.

For all such data, the customer is the controller and Health Monk is the processor. We process it only to provide the Service and on the customer's documented instructions, under a Data Processing Agreement that reflects Article 28 GDPR. We do not use Customer Content for our own purposes, and we do not sell personal data. If your personal data is held in a customer's Opelli workspace and you wish to access, correct or delete it, please contact that organization directly; Opelli also provides customers with tools (a privacy centre, a personal-data locator and consent ledger) to help them respond.

Sub-processors and service providers

We rely on a small number of trusted providers to deliver the Service. They process personal data on our behalf under contracts that impose appropriate data-protection obligations. Our current sub-processors are:

Sub-processorPurposeLocation of processing
Amazon Web Services (AWS)Cloud hosting, database, file/object storage, and transactional & campaign email delivery (Amazon SES)European Union (Frankfurt, eu-central-1)
Google (Google Ireland Ltd)Sign-in (OAuth / OpenID Connect) and outbound email relay via Workspace SMTPEU with possible transfer to the US (Standard Contractual Clauses)
Cloudflare, Inc.DNS, edge/CDN network and hosting of the marketing siteGlobal edge network; US-based provider (Standard Contractual Clauses)
Toggl OÜTime-tracking synchronisation — only if an individual user connects their own Toggl accountEuropean Union (Estonia)

Some features integrate with services that you operate or connect, and which are not our sub-processors — for example, a Mattermost server you run, a GitHub repository whose webhooks you configure, or a public lookup to the Czech ARES business register. Data exchanged with those services is governed by your own arrangements and their terms.

We may update our sub-processors as the Service evolves. For customers, our Data Processing Agreement sets out how we give notice of new sub-processors and how objections are handled. To receive sub-processor change notices, contact [email protected].

When we share personal data

We do not sell personal data or share it for third-party advertising. We disclose personal data only:

  • to the sub-processors and service providers listed above, to provide the Service;
  • within your organization's account, according to the roles and permissions its administrators configure (Opelli enforces per-user, per-project access controls);
  • where required by law, regulation, legal process, or a lawful governmental request, or to protect the rights, property or safety of Health Monk, our users or others;
  • in connection with a merger, acquisition, financing or sale of assets, in which case we will require the recipient to honour this policy, and will notify you of any change of controller.

International data transfers

Our primary hosting and storage of application data — including Customer Content and account data — takes place within the European Union (AWS Frankfurt, eu-central-1). Some sub-processors (such as Google and Cloudflare) are established in, or may process data in, countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an appropriate transfer mechanism under Chapter V GDPR — in particular the European Commission's Standard Contractual Clauses, together with supplementary measures where needed. You can request more detail about the safeguards in place by contacting us.

How long we keep personal data

We keep personal data only as long as necessary for the purposes described in this policy:

  • Account and profile data — for as long as your account is active, and for a reasonable period afterwards to wind down the relationship, resolve disputes and meet legal obligations.
  • Customer Content (as processor) — for the duration of the customer's use of the Service; on termination it is made available for export for a limited period and then deleted or de-identified in line with our Data Processing Agreement, subject to routine backup rotation.
  • Beta sign-up email — until we complete the beta invitation process or you ask us to remove it, whichever is earlier.
  • Security and system logs — for a limited period appropriate to their security and diagnostic purpose.
  • Backups — encrypted backups are rotated on a regular cycle, so residual copies may persist for a short time after deletion from the live systems.

We may retain certain information longer where required to comply with legal obligations or to establish, exercise or defend legal claims.

How we protect personal data

We implement appropriate technical and organizational measures to protect personal data, including:

  • authentication through Google OAuth with PKCE and server-side verification of ID tokens; accounts are pinned to a stable Google identifier, and there is no password store and no authentication bypass;
  • encryption in transit (TLS) and encryption of data and backups at rest through our cloud provider;
  • signed, HttpOnly, SameSite=Lax session cookies, an origin/CSRF check on state-changing requests, and a strict content-security policy;
  • a granular permission model (per-feature access levels and per-project row scope) that governs the web app, the API and connected AI agents identically, so no integration can exceed the access of the person using it;
  • API keys stored only as SHA-256 digests (never retrievable after creation), scoped to specific modules, and revocable/rotatable;
  • strict per-tenant data isolation, secrets held in a managed secrets store, and least-privilege access for our systems.

No method of transmission or storage is completely secure, but we work to protect personal data and to detect and respond to incidents. Where we act as processor and become aware of a personal-data breach, we will notify the affected customer without undue delay so they can meet their own obligations.

Your rights

Subject to the conditions and exceptions in applicable data-protection law, you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate or incomplete data;
  • erase your data (the “right to be forgotten”);
  • restrict or object to certain processing, including processing based on our legitimate interests;
  • data portability — receive certain data in a structured, commonly used, machine-readable format;
  • withdraw consent at any time where we rely on consent, without affecting processing already carried out.

To exercise these rights in relation to data for which we are the controller, contact [email protected]. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting. If your data sits in a customer's Opelli workspace, the customer is the controller — please direct your request to them, and we will support them as required.

Children

Opelli is a business tool intended for use by professionals. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date and, where appropriate, provide additional notice (for example, within the Service or by email to account administrators). We encourage you to review this page periodically. The current version is always available at this address.

How to contact us and your right to complain

Health Monk s.r.o.

Korunní 2569/108, Vinohrady, 101 00 Praha 10, Czech Republic

Company ID (IČO): 21042039 · DUNS: 984015947

Privacy: [email protected]

Web: healthmonk.ai

If you have a concern about how we handle your personal data, please contact us first — we will do our best to resolve it. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), Pplk. Sochora 27, 170 00 Praha 7. You may also contact the supervisory authority in your country of residence or work.

Opelli Built by Health Monk · © 2026 Terms Privacy Home