OpSo · by OpSolid

Privacy Policy

Last updated: 29 August 2026

OpSo is a digital business card and trade-fair networking app with a built-in mini-CRM and page builder, offered under the OpSo/OpSolid brand. This policy explains what data we process, why, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR / DSGVO). It covers the OpSo mobile app, public card pages, custom domains, stored 1:1 messages, safety reports and support communications. The current release is free-only and has no checkout or active payment provider.

1. Who is responsible

The data controller for OpSo is the provider identified in the Legal Notice:

OpSolid - Hasan D??nmez (Inhaber, Einzelunternehmen)
Stolte Ley 12, 59759 Arnsberg, Deutschland
Contact: info@opsolid.de

We process personal data only as described here, and only for the purposes set out below.

2. What data we process

Account data. OpSo primarily uses passwordless email sign-in — there is no password. To create or access your account we process your email address. We send a six-digit one-time code to that address; only a short-lived keyed verification value is stored and the challenge expires after 15 minutes. Where offered, you may instead choose Google sign-in; in that case Google supplies a verified email address and optional profile name. Your account may also hold an optional name, phone number, avatar and language preference.

Your card content. Whatever you choose to put on your digital card: name, role, company, email, phone, bio, profile photo, links, gallery images and video, and visual theme. You control whether each card is public, unlisted, private, or event-only, and whether your email and phone are shown.

Captured contacts and leads. When you save someone you met — or when someone fills in the “leave your details” form on your public card — we store the information provided: name, email, phone, company, role, notes, tags, a qualification and pipeline stage, an optional deal value, and any meeting photos you attach. For public-card capture we also record the exact notice version and hash, selected language, controller, authorized-workspace recipient scope, server timestamp, basis, and the available withdrawal route. The capture consent marker does not store an IP address or device fingerprint. For an accepted connection, we instead record that the connection is mutual; this is not represented as optional consent for unrelated processing.

Media uploads. Images and videos you upload for your card or attach to a contact (profile photos, gallery media, meeting photos). OpSo stores hosted objects privately and delivers them through an access-checking URL. Restricting, archiving, or deleting a card blocks later hosted access; it cannot recall a copy that a visitor or platform already downloaded.

Stored 1:1 messages. OpSo stores messages in a connection or message-request thread so the two participants can send and receive them across devices. The stored record can include text, image and card payloads, participant and connection identifiers, a caller-generated retry identifier, creation and deletion timestamps, read status, and reactions. An image payload can include privately hosted media. Message content is not made public by the messaging feature, but the recipient can save or share what they receive.

Safety controls and reports. If you block another user or report a user, card or message, we process the account and content identifiers involved, report reason and optional details, status and timestamps, and moderation actions, actor identifiers and internal notes. We use this information to enforce interaction boundaries, investigate abuse, document decisions and protect users and the service.

Terms and Community Rules acceptance. When a protected publishing or messaging action requires the current rules, we record the account and optional workspace, document type, version and SHA-256, immutable document URL, acceptance UI language, server acceptance time, protected-action surface, and client and API release. This contract record is not optional consent for analytics, marketing, device access, or unrelated data processing.

Trade-fair data. The service stores the fairs and events you follow or attach contacts to. OpSo also keeps a catalogue of public trade fairs (name, dates, location and organiser) that is not personal data. If you join an event participant list, your participation and public profile details (name, role, company, avatar and card link where available) are shared with other authenticated participants until you leave that list.

Card-owner external media. A card owner can choose an externally hosted image or a YouTube/Vimeo video. Opening that published card can therefore connect the visitor's browser directly to the selected host, which receives ordinary request data such as IP address, user-agent and requested URL. Card owners must have the right to publish that media and must not use tracking pixels or unnecessary personal identifiers in media URLs.

Push notification tokens. If you allow notifications, we store the push token issued by Expo for your device so we can notify you about new captures, connection requests, and similar events.

Technical and usage data. When a public card is viewed we record a basic analytics event — the time, the referring page, the browser user-agent, and the IP address — so the card owner can see view counts. For sign-in security we store your active sessions, each with the device type, IP address, and an expiry. We do not use advertising or cross-site tracking cookies.

Free release and domains. The current OpSo release does not collect payment details or purchase history because it has no checkout or active payment provider. Future plan previews marked “coming soon” are non-binding and have no purchase action. If you connect a domain, we process the hostname, ownership challenge and DNS/TLS provisioning status needed to serve it securely.

Optional AI drafting. If the feature is enabled and you deliberately request a bio, SEO description, or follow-up draft, the text and context you submit for that request (which can include a person's name, company, role, bio, keywords, or meeting notes) is sent to OpenAI to generate the draft. Do not submit special-category or unnecessary confidential data. AI processing is disabled unless the operator explicitly enables it.

3. Why we process it, and the legal basis

  • To run the service — create your account, publish your card, store your contacts and 1:1 messages, operate a domain, and deliver push notifications you opted into. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Terms and Community Rules evidence — enforce the current rules only for protected user-content actions and document the exact agreement without collecting an IP address or device fingerprint. Legal basis: performance and documentation of the service contract (Art. 6(1)(b)); legal-claims necessity can apply in a particular dispute.
  • To send your sign-in code by email — required to log you in without a password. Legal basis: contract (Art. 6(1)(b)).
  • Card-view analytics — to give card owners basic view statistics and to keep the service secure and rate-limited. Legal basis: legitimate interests (Art. 6(1)(f)).
  • Contacts captured from your public card — processed on the consent the visitor gives to OpSolid for sharing the details with authorized members of the card owner's OpSo workspace. Legal basis: consent (Art. 6(1)(a)), bound to the exact localized notice.
  • Security and abuse prevention — sessions, IP logging, rate limiting. Legal basis: legitimate interests (Art. 6(1)(f)).
  • Message delivery and message state - store the thread, deliver content to its participants, synchronize read status and reactions, and send notifications where enabled. Legal basis: performance of the requested service (Art. 6(1)(b)).
  • Reports, blocking and moderation - enforce a user's block, review reported content, prevent abuse, document proportionate action and handle an appeal. Legal basis: legitimate interests in user and service safety (Art. 6(1)(f)); a legal obligation or legal-claims necessity may apply in a particular case.
  • AI-assisted drafting — only when you request a draft and the feature is enabled. Legal basis: performance of the requested service (Art. 6(1)(b)).
  • Legal compliance — where we must retain or disclose data by law. Legal basis: legal obligation (Art. 6(1)(c)).

4. Where your data is stored

The primary OpSo application and PostgreSQL database run on configured hosting infrastructure. Uploaded media is stored in private Cloudflare R2 object storage and may be delivered through Cloudflare's network. Exact processing locations and any required international-transfer safeguards depend on the production provider configuration and are maintained in our processor records. Operational encrypted database backups and private media snapshots may be retained for a limited rolling period. Data in transit is protected with TLS where the service is publicly available.

5. Service providers we use

We never sell your data. The providers used for the relevant feature may include:

  • Hostinger — hosting of the application server and primary database.
  • Cloudflare — R2 media storage/delivery and, when enabled, DNS/TLS edge service for customer domains.
  • Expo (Expo Push Service) — delivery of push notifications to your device. The device push token, sender display name, a shortened message preview or media/card indicator, and the thread identifier can be sent when message notifications are enabled.
  • Email / SMTP provider — delivery of your one-time sign-in code and service notifications by email. Depending on configuration this is Brevo, Resend, or an SMTP provider; the recipient, sender display name, shortened message preview, email content and delivery metadata are involved when an email notification is sent.
  • Google — only if you choose Google sign-in, to verify your identity.
  • Payment providers — no payment or subscription provider is active in the current free OpSo release. Before introducing any paid service, we will update this policy and provide the information and choices required for that service.
  • OpenAI — only when AI drafting is enabled and you request a bio, SEO, or follow-up draft; it processes the submitted prompt context to return that draft.

We do not use advertising networks or data brokers. Optional integrations are activated only when configured or chosen for that feature; we update this policy when the set of material processors changes.

6. When data is shared with other people

Your card is shared with whoever you give it to — a public card is, by design, visible to anyone with the link. When you accept a connection request from another OpSo user, the published profile snapshot on each person's card may be added as a contact in the other person's workspace. Pending requests do not disclose private email or phone fields. A private or unlisted card controls public discovery, but data already shared in an accepted connection or retained by a recipient is a separate copy.

A stored 1:1 message is made available to the two thread participants. Hosted message images are delivered through an access-checking URL. Hostinger processes message and thread records as the application/database host; Cloudflare processes hosted message media; and, when the related notification is enabled, Expo or the configured email / SMTP provider receives the limited notification data described in section 5. Reports and moderation records are available only to authorized operational personnel who need them to investigate and act. We may disclose relevant data where law requires it or where necessary to establish, exercise or defend legal claims.

7. How long we keep data

  • We keep your account and content for as long as your account is active.
  • Messages, their delivery/read state and reactions are kept while the relevant account and connection records remain active. Deleting an individual message hides its content from normal thread responses, but the message record and deletion state can remain in restricted storage until the applicable account-deletion or retention cleanup runs.
  • Blocks and safety reports are kept while needed to enforce the safety boundary, investigate and document the report, handle an appeal, prevent repeated abuse, or meet a legal obligation. We remove or de-identify them when they are no longer needed, subject to account deletion, legal duties and legal-claims requirements.
  • Versioned Terms and Community Rules acceptance records remain append-only while the account exists and during the 30-day account-deletion window. The scheduled hard deletion removes them with the account, subject to any specific legal duty or legal-claims retention that applies and is documented for that purpose.
  • When you delete your account, it is deactivated immediately and your data is scheduled for permanent erasure within 30 days.
  • Sign-in codes are short-lived and expire after 15 minutes.
  • Operational backups roll off on their configured retention schedule and are used only for disaster recovery; an erased record can therefore remain in an access-restricted backup until that backup expires.
  • We may keep limited records longer where the law requires it.

8. Your rights (GDPR / DSGVO)

If you are in the EU or EEA you have the following rights over your personal data:

  • Access (Art. 15) — find out what we hold about you.
  • Rectification (Art. 16) — correct inaccurate data.
  • Erasure (Art. 17) — have your data deleted; see section 9.
  • Portability (Art. 20) — export your account, cards, and contacts in a machine-readable format. The account export includes your authored messages and your reactions, but does not expose the other participant's private message content. Contacts can also be exported as CSV or vCard from the app.
  • Restriction and objection (Art. 18, 21) — limit or object to certain processing.
  • Complaint — lodge a complaint with your data protection authority.

To exercise any of these rights, contact info@opsolid.de. We respond within the applicable statutory period, generally one month.

A public-card visitor can withdraw capture consent through the same privacy contact. OpSolid coordinates the request with the recipient workspace, where an authenticated member uses the dedicated consent-erasure action. That action deletes the captured contact and its owned media together and records the acting member, server time, notice version, notice hash, language, and erasure effect without copying the contact details into the audit log. The audit proves the workspace action; it does not claim that the API independently verified the visitor's identity.

9. Deleting your account and data

You can delete your account directly in the OpSo app under Settings → Delete account. This deactivates your account at once, signs out all your devices, disables public cards, and schedules your account, cards, contacts, connection-linked messages and uploaded media for permanent deletion within 30 days, subject to legally required retention and rolling backup expiry. A report about another account can also be affected by deletion or de-identification, while records still needed for a legal duty or legal claim may be retained only for that purpose. You can also request deletion, object to safety processing, or ask about a report by contacting info@opsolid.de.

10. Children

OpSo is a professional networking tool intended for business use. It is not directed at children, and we do not knowingly collect data from anyone under 16.

11. Changes and contact

If we change this policy, we will update the date at the top of this page. For any privacy question, or to exercise your rights, contact info@opsolid.de.

PRIVACY CONTROLS · GDPR & DSGVO