1. Who We Are
Opsync ('we', 'us', 'our') operates opsync.digital and the Opsync SaaS platform. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with Singapore's Personal Data Protection Act 2012 (PDPA 2012) and Malaysia's Personal Data Protection Act 2010 (PDPA 2010). By using Opsync, you consent to the practices described herein. For customers registered outside Singapore and Malaysia, we process your personal data in accordance with generally accepted data protection principles (purpose limitation, data minimisation, and security safeguards), and, where applicable, the data protection law of your country of registration.
2. Data We Collect
Account data: name, email address, company name, phone number, and billing address provided during registration. Identity verification data: to approve your account we may collect identity and business-registration documents (such as an NRIC or identity document and your company registration certificate); these are stored securely, accessed only to verify your account, and retained only as long as necessary for that purpose. Usage data: pages visited, features used, login timestamps, and IP addresses. Business data: invoices, client records, financial documents, and other data you input — this data is owned entirely by you.
3. How We Use Your Data
To provide, maintain, and improve the Opsync platform; to authenticate your identity and secure your account; to respond to support requests; to send service-related communications (not marketing without your consent); to comply with legal obligations; and to analyse aggregated, anonymised usage patterns to improve the product.
4. Data Sharing & Subprocessors
We do not sell your data. We share data only with trusted subprocessors necessary to deliver the service: Supabase Inc. — database, storage, and authentication; Vercel Inc. — web hosting and content delivery (global CDN); Resend — transactional email delivery (such as invoices, invitations, and notifications); Anthropic — AI-assisted features (such as expense categorisation and receipt data extraction), processing only the specific data required for each request. All subprocessors are contractually bound to maintain confidentiality and security.
5. Data Residency & International Transfer
Your data is hosted on Supabase's managed cloud infrastructure in the South Asia (India) region. Our email, AI, and hosting subprocessors may process data in other jurisdictions, including the United States. This means your personal data is transferred to and stored outside Singapore and Malaysia. Where data is transferred internationally, we ensure a comparable standard of protection through data processing agreements with each subprocessor, as required under PDPA 2012 (SG) and PDPA 2010 (MY). For customers outside Singapore and Malaysia, your data is subject to the same hosting and subprocessor arrangements described above; by using Opsync you consent to this international transfer regardless of your country of registration. Contact us at hello@opsync.digital if you have questions about data location.
6. Data Retention
Your data is retained for as long as your account is active. Upon account termination or deletion request, data is removed within 30 days, excluding records required by law or forming part of an immutable audit trail.
7. Your Rights Under PDPA 2012 (SG) & PDPA 2010 (MY)
Singapore users (PDPA 2012): You have the right to access, correct, and withdraw consent for use of your personal data. Malaysian users (PDPA 2010): You have the right to access your personal data, request correction of inaccurate data, withdraw consent, and request deletion. Users registered outside Singapore and Malaysia have the same practical rights described above (access, correction, withdrawal of consent, deletion) regardless of whether a local data protection statute mandates them. Submit requests to hello@opsync.digital — we will respond within 14 business days.
8. Security
We implement TLS 1.2+ encryption in transit, AES-256 encryption at rest, row-level security database policies, and role-based access controls. See our Security page for full details.
9. Changes to This Policy
We may update this policy periodically. Significant changes will be communicated via email or in-app notification at least 14 days in advance. Continued use after changes constitutes acceptance.
10. Contact
Privacy enquiries: hello@opsync.digital — please include 'Privacy' in the subject line.