Privacy
Privacy Policy
How OPĒS handles personal data: what we process, why, for how long, who else sees it and the rights you can exercise at any time.
1. Who is responsible for your data
OPĒS is published and sold by the operator of the app and of the website nfsynq.net (the "Publisher", "we"). Everything this policy covers is handled at a single address: legal@nfsynq.net.
For the purposes of Regulation (EU) 2016/679 (GDPR), the Publisher is the data controller for the processing described here, and carries out no processing on anyone else’s behalf. No data protection officer is designated: requests are read and answered by the Publisher. If you need the Publisher’s identifying details and place of establishment — to make a formal request, or to bring a complaint — ask at legal@nfsynq.net and we send them to you.
This policy covers the OPĒS application for iOS and Android and the website nfsynq.net. It does not cover the NFSynq Enterprise platform (nfsynq.com), which has its own contractual framework and its own data processing agreement.
2. The principle: we do not want your business data
OPĒS answers questions on food safety by consulting a body of public regulatory knowledge. It is not a place where you file your company's records, and it does not need them in order to answer.
We therefore do not ask for, and the app does not collect, your HACCP plans, your suppliers, your recipes, your analysis results, your production or batch records, or data about your own customers. If you choose to paste such information into a question, you do so on your own initiative: see section 5.
There is no advertising in OPĒS, no advertising identifier, no profiling for marketing purposes, and no sale or sharing of personal data with data brokers.
3. What data we process
We process only the following categories of data:
- Account data: your email address and, optionally, a display name — needed to give you access to your subscription across your devices.
- Subscription data: the customer and transaction identifiers returned by Stripe, our payment provider, together with the plan, the start and renewal dates and the status. Stripe also passes on the billing details you give it at checkout — billing name and address, and whatever you add yourself — because they are needed for accounting obligations. We never receive or store your card number.
- The content of the question you ask: it travels to the model, comes back as an answer and ends there. Neither the question nor the answer is retained — there is no archive of conversations. All that remains of usage is a monthly count of how many requests your key has made, with no questions and no answers.
- Technical and diagnostic data: app version, operating system, device model, language and region settings, error logs and the IP address of the request. The app contains no crash-reporting tool of any kind: whatever Apple or Google collect at operating-system level never reaches us.
- Support correspondence: what you write to us through the form on nfsynq.net or by email, and our replies.
- Website: only the technical storage strictly necessary to remember the language and the light/dark theme you chose. No profiling cookies and no third-party analytics.
4. Why we process it, and on what legal basis
- To provide the app and answer your questions — performance of the contract, Art. 6(1)(b) GDPR.
- To manage the subscription, renewals, refunds and invoicing — performance of the contract and legal obligation, Art. 6(1)(b) and (c).
- To keep the service secure and prevent abuse, fraud and automated extraction of the knowledge base — legitimate interest, Art. 6(1)(f).
- To fix defects and improve the accuracy of the answers — legitimate interest, Art. 6(1)(f), on aggregated or pseudonymised data wherever that is sufficient.
- To reply to your support requests — performance of the contract and legitimate interest.
- To comply with accounting, tax and consumer-law obligations — legal obligation, Art. 6(1)(c).
- To send optional messages about new features — your consent, Art. 6(1)(a), which you may withdraw at any time.
5. How the AI works, and what happens to your questions
The model that answers your questions runs on infrastructure operated by the Publisher. Your questions are not sent to any third-party AI provider: there is no external model vendor in the chain, and no one outside the Publisher and its processors ever sees what you ask.
Answers are generated by consulting a regulatory knowledge base built from public sources: the competent authority and framework law of 252 countries and territories, for 240 of them also which act applies and where to read it, with the provenance of the source established, the food law of the European Union — which is today the part where the base also contains the applicable values — and the publications of the national authorities (FDA, CFIA, FSA, FSANZ, MHLW) and of the Codex Alimentarius. Every answer states the source relied on and the reliability level declared for that source.
Questions and answers are not retained. There is no archive of conversations: the question serves to produce the answer and ends there, and there is nothing that could be used to train a model or shown to other users. It is a design decision — and it is also why OPĒS offers no question history.
Please do not include other people's personal data, health data or confidential business information in your questions: OPĒS does not need them to answer.
OPĒS produces informational output, not automated decisions producing legal or similarly significant effects on you within the meaning of Art. 22 GDPR. The decision on how to act always remains with you, or with the professional you rely on.
6. Who else sees the data
- Stripe, our payment provider: it takes the payment, runs the checkout page and the subscriber portal, and issues the receipt. It receives your email address and the billing and payment details you enter at checkout, and it is the only party in the chain that handles your means of payment.
- Our hosting and infrastructure providers, acting as processors under Art. 28 GDPR. Vercel hosts the nfsynq.net website and runs its server functions, so it processes what you send from the forms and the technical logs of the requests, IP address included. Hetzner Online GmbH provides the servers and the database on which your account, your subscription status, your usage count and the assistant that answers you all run: those machines are in Finland, in the European Union, and that is where your data actually sits. Both act on our instructions only, and neither uses your data for its own purposes.
- Our email providers: Resend delivers the emails we send you — confirmation of the withdrawal waiver, support acknowledgements, password recovery — and Cloudflare routes the ones you write to legal@nfsynq.net. If outgoing mail takes the alternative channel, transport is by Apple's iCloud servers. They receive your address and the text of the message.
- Professional advisers, accountants and auditors, only where strictly necessary and bound by confidentiality.
- Public authorities, where disclosure is required by law.
We do not sell personal data and we do not disclose it for third parties' own marketing purposes.
7. Transfers outside the EEA
The servers and the database that hold your account are in the European Union (Finland), so the data at the centre of the service does not leave the European Economic Area. Some of the other recipients listed in section 6 are established outside it, or use infrastructure that is. Where a processor operates outside the European Economic Area, the transfer takes place on the basis of an adequacy decision of the European Commission or of the Standard Contractual Clauses adopted by Decision (EU) 2021/914, together with the supplementary measures required by the case. Write to legal@nfsynq.net and we tell you which processors are involved, where each of them operates and on what basis, and send you a copy of the safeguards in force on the day of your request.
8. How long we keep it
- Account and subscription data: for as long as the account exists. When you delete your account — which you can do yourself, at any hour, at nfsynq.net/delete-account — the email address, the business name, the password, the sessions and the API keys are removed straight away, not after a waiting period. Accounting records of what was bought (plan, price, period) are kept for 10 years as tax law requires, without your email address.
- Questions and answers: not retained, so there is no period to state. All that remains is the monthly count of requests per key, kept for as long as it is needed to manage the subscription.
- Technical logs: 12 months.
- Support correspondence: 24 months from the closure of the request.
- Deletion receipts: kept without a time limit, and containing nothing that identifies you — a random number, a date and a summary of what was removed and what had to stay. It is the proof that a deletion happened, and it survives because nothing else about you does.
9. Your rights
Under Articles 15 to 22 GDPR you have the right to obtain access to your data, its rectification or erasure, the restriction of processing, the portability of the data you provided in a structured, commonly used and machine-readable format, and to object to processing based on our legitimate interest.
Where processing is based on consent, you may withdraw it at any time, without affecting the lawfulness of the processing carried out before the withdrawal.
You can exercise these rights by writing to legal@nfsynq.net. We reply within one month, extendable by two further months for particularly complex requests, as provided by Art. 12(3) GDPR. Erasure does not have to wait for that reply: you can delete your account yourself, at any hour, at nfsynq.net/delete-account — it takes effect immediately, closes any subscription still open and leaves you a receipt number as proof. There is, in any case, no question history to delete, because questions and answers are not retained (section 5).
If you consider that your data is processed unlawfully, you may lodge a complaint with a supervisory authority. Art. 77 GDPR lets you choose the authority of your habitual residence, of your place of work or of the place where the alleged infringement occurred: you never have to find ours in order to be heard. If you would rather address the authority that supervises the Publisher, ask at legal@nfsynq.net and we tell you which one it is.
10. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to a minimum number of authorised persons, logged and protected by multi-factor authentication. We maintain an incident procedure and, where a personal data breach is likely to result in a high risk to your rights, we notify you and the supervisory authority within the terms of Articles 33 and 34 GDPR.
11. Children
OPĒS is a professional tool and is not directed at children. It must not be used by anyone under 16, or under the higher age set by the law of your country for consent to information society services. We do not knowingly collect data of minors; if you believe a minor has created an account, write to legal@nfsynq.net and we will delete it.
12. Cookies and local storage
The nfsynq.net website uses only technically necessary local storage: the language and the light/dark theme you chose, kept in your browser and never sent to us. There are no profiling cookies, no advertising pixels and no third-party analytics scripts, so no consent banner is required.
The app does not use the advertising identifier (IDFA/AAID) and does not take part in any advertising network.
13. Changes to this policy
We may update this policy to reflect changes to the service or to the law. The version and the date of the last update are shown at the top of this page. If a change materially affects how we process your data, we will notify you in the app or by email before it takes effect.
14. Contact
For any question about this policy, or to exercise your rights, write to legal@nfsynq.net. It is one address, read by a person, and it is the only one you need. If a postal address is required — for a formal notice, or because an authority asks for it — request it there and we send it to you, together with the Publisher’s identifying details.