← Home

Privacy Policy

Last updated: September 3, 2026

Introduction

Opesync (“Opesync”, “we”, “us”) provides a workforce automation platform that helps employers onboard staff, plan shifts, handle absences and incidents, deliver trainings, and communicate with their workforce over WhatsApp through an AI assistant. This Privacy Policy explains what personal data the platform processes, why, with whom it is shared, and what rights people have.

This policy covers our website, the Opesync web dashboard used by employer staff, our backend services, and the WhatsApp business conversations operated through the platform.

Our Role: Controller and Processor

Our customers are employers (“Companies”). Companies use Opesync to communicate with and administer their own employees and candidates.

  • Company employee and candidate data — including WhatsApp conversations, onboarding data, shifts, absences, documents and incidents — is processed by us as a data processor on behalf of the Company, which is the data controller. We act on the Company’s documented instructions under a data processing agreement.
  • Company account and dashboard user data, website visitor data, billing data and product telemetry are processed by us as an independent data controller.

If you are an employee or candidate of one of our customers, please direct requests about your data to your employer first. We will assist them in responding.

Data We Process

Dashboard user (account) data

  • Name, email address, phone number, profile image, and language preference
  • Authentication identifiers and session data managed by our identity provider
  • Role, permissions, working hours, and company membership
  • Activity logs of actions taken in the dashboard (who changed what and when)

Employee and candidate data (provided by the Company)

  • Identity and contact details: name, date of birth, gender, nationality, phone number, email, address
  • Employment details: employee number, position, profession, skills, certificates, seniority, contract dates, probation period, employment type, hours per week, hourly rate and surcharges, client or site assignment
  • Planning data: shifts, availability, preferred shifts, vacation requests, sick leaves, replacements
  • Operational records: incidents and follow-ups, trainings and results, HR notes, onboarding progress, document upload history
  • Payment details used for payroll administration by the Company: IBAN, BIC, and account holder name (we do not process payments)
  • Identity documents and national identifiers where the Company’s onboarding flow requires them: a scan of a passport, ID card, residence permit or driving licence, the document number and expiry date, and — for Dutch employers — the citizen service number (BSN). These are special-category or sensitive identifiers and are collected only where the Company has a legal basis to do so.

WhatsApp conversation data

When a Company connects a WhatsApp Business account, we process the messages exchanged between that business number and its employees or candidates:

  • The WhatsApp phone number and display name of the participant
  • Message content, timestamps, delivery status, and message identifiers
  • Media sent in the conversation — images, videos, documents, and voice notes
  • Transcripts of voice messages. Voice notes are transcribed to text so the assistant can understand and respond to them.

We use WhatsApp Business Platform data solely to operate the messaging features the Company has enabled. We do not sell it, do not use it for advertising, and do not combine it with data from other sources for profiling unrelated to the service.

Company and integration data

  • Company profile, branches, clients, locations, and configuration
  • The WhatsApp Business account details and access credentials created when an administrator connects a messaging channel
  • Knowledge base content the Company uploads for the assistant to answer from

Technical data

  • Server logs, IP address, device and browser information
  • Error reports and performance traces used to keep the service reliable and secure

How We Use Data

  • Delivering and operating the platform for the Company that engaged us
  • Running the AI assistant: understanding incoming WhatsApp messages, retrieving relevant knowledge base content, and drafting or sending replies about shifts, sick leave, vacation, onboarding, trainings and incidents
  • Onboarding automation, including optical character recognition of identity documents the user submits
  • Scheduling, absence management, incident reporting, and training administration
  • Sending transactional notifications by WhatsApp and email
  • Authentication, access control, and audit logging
  • Security, abuse prevention, debugging, and service improvement
  • Complying with legal obligations

The assistant may generate automated replies and suggested actions. It does not make decisions that produce legal or similarly significant effects on a person without a human in the loop; a Company user can take over any conversation at any time and confirms consequential actions in the dashboard.

Legal Bases (EEA/UK)

  • Performance of a contract — providing the platform to Companies and their authorised users
  • Legitimate interests — securing the service, preventing abuse, improving reliability, and administering our customer relationships
  • Legal obligation — retention and reporting duties, including employment and identity verification duties that apply to our Companies
  • Consent — where the Company relies on consent for optional processing, and for any non-essential cookies

For employee and candidate data, the Company determines and documents the legal basis. Processing of identity documents and national identifiers such as the BSN is carried out only on the Company’s instruction and on the basis it has established under applicable employment law.

AI Processing

The assistant uses third-party large language models, embedding models, and speech-to-text models to interpret messages and generate responses. Message text, voice transcripts, and relevant knowledge base excerpts are sent to these providers for the sole purpose of producing a response. Knowledge base content and message context are also stored as vector embeddings so the assistant can retrieve relevant information.

Our AI providers process this data as our subprocessors under contractual terms that prohibit using it to train their models. We do not use Company or employee data to train models of our own.

Sharing and Subprocessors

We do not sell personal data. We share data only with service providers acting on our instructions, and with the Company whose workspace the data belongs to. Current categories of subprocessors:

  • Messaging — Meta Platforms (WhatsApp Business Platform) and our WhatsApp connectivity provider, for sending and receiving messages
  • AI and search — OpenAI (language, embedding and speech-to-text models), Pinecone (vector search), LangSmith (AI request tracing)
  • Document intelligence — Microsoft Azure AI Document Intelligence, for identity document OCR
  • Identity and access — Clerk, for authentication of dashboard users
  • Hosting and storage — our cloud hosting provider for the application and database, and DigitalOcean Spaces for uploaded files and message media
  • Email delivery — Resend and SendGrid, for transactional email
  • Monitoring — Sentry (error tracking) and Grafana Cloud (logging)

We may also disclose data where required by law, to enforce our terms, or in connection with a merger or acquisition, in which case we will notify affected Companies.

International Transfers

Some subprocessors process data outside the European Economic Area, including in the United States. Such transfers are covered by the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, together with additional technical and organisational safeguards.

Retention

  • Employee, candidate, conversation, and document data is retained for as long as the Company’s workspace is active, and thereafter according to the Company’s instructions and its own retention obligations.
  • On termination of a Company’s subscription we delete or return its data within 90 days, unless a longer period is required by law.
  • Technical logs and error reports are retained for a limited period, normally up to 90 days.

Security

  • Encryption of data in transit and at rest
  • Messaging credentials stored encrypted, and incoming messages verified as authentic
  • Role-based access control, per-company data isolation, and audit logging of dashboard actions
  • Least-privilege access for our staff, granted only where needed for support and operations

No system is perfectly secure. If a personal data breach occurs, we notify affected Companies without undue delay so they can meet their notification duties.

Your Rights

Subject to applicable law, you may request access to your personal data, correction, erasure, restriction of processing, portability, and objection to processing. You may also withdraw consent where processing is based on consent, and lodge a complaint with your local supervisory authority — in the Netherlands, the Autoriteit Persoonsgegevens.

If your data is held on behalf of an employer, contact that employer. If you contact us directly, we will forward your request to the relevant Company and support them in handling it.

Data Deletion Requests

To request deletion of your data, email support@opesync.com from the email address associated with your account, or include the WhatsApp phone number used in the conversation. State that you are requesting deletion and name the employer or business you were messaging with.

We verify each request, forward it to the relevant Company where they are the controller, and complete deletion within 30 days unless the data must be kept to meet a legal obligation. Company administrators can also delete individual employee records, documents, and conversations directly from the dashboard.

Cookies

Our website and dashboard use cookies and similar technologies that are strictly necessary for authentication, security, session management, and language preferences. Any non-essential analytics cookies are used only with your consent.

Changes to This Policy

We may update this policy as the platform evolves. We will update the “Last updated” date above and, for material changes, notify Companies through the dashboard or by email.

Contact

For privacy questions, data protection requests, or a copy of our data processing agreement, contact us at support@opesync.com.