Privacy Policy
Last updated: July 15, 2026
1. Who We Are
Opyrion (“we”, “us”, “our”) is a software service operated from the Republic of Cyprus. We operate the website opyrion.com and the application at app.opyrion.com (collectively, the “Service”). For the purposes of the General Data Protection Regulation (GDPR), we are the data controller of your personal information.
Contact: support@opyrion.com
This Privacy Policy explains how we collect, use, and protect your personal information when you use our Service.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Username
- Email address
- Full name
- Password (stored as a bcrypt hash — we never store or see your plain-text password)
2.2 Business Data
All data you enter into the Service — including clients, suppliers, inventory items, orders, invoices, financial records, tasks, events, and settings — is stored in our database. This data belongs to you and is accessible only to your account.
2.3 Payment Information
Payment processing is handled entirely by Stripe. We do not collect, store, or have access to your credit card number, CVV, or bank account details. We store only your Stripe customer ID and subscription status to manage your account access.
2.4 Technical Data
We may collect standard server logs including IP address, browser type, and access timestamps for security and operational purposes.
2.5 Google Calendar Data
If you choose to connect Google Calendar, Opyrion requests access only for the calendar sync feature. We may access the list of Google calendars you own so you can choose a destination calendar, and we may create, read, update, and delete Opyrion-created calendar events in that selected Google Calendar.
The Google Calendar event data handled by Opyrion may include event titles, dates, times, locations, descriptions, status, and private event properties used to identify events created by Opyrion. We do not access Gmail, Google Drive, Google Photos, Google Contacts, or other Google services through this feature.
Google OAuth access tokens are processed in your browser for the sync session. We do not store Google Calendar access tokens on our servers. We do not create aggregated or anonymized analytics datasets from your Google Calendar data.
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service
- Authenticate your identity and manage your account
- Process subscription payments via Stripe
- Communicate with you about your account or the Service (e.g. password resets, billing issues)
- Protect the security and integrity of the Service
- Sync your Opyrion tasks and events to your selected Google Calendar when you connect Google Calendar
3.1 Lawful Basis for Processing
We process your personal data under the following lawful bases (GDPR Article 6):
- Contract performance (Art. 6(1)(b)) — processing your account information and business data is necessary to provide the Service you have signed up for.
- Legitimate interests (Art. 6(1)(f)) — server logs and security monitoring are necessary to protect the Service and our users from abuse and unauthorized access.
- Legal obligation (Art. 6(1)(c)) — we may process data where required to comply with applicable law.
We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use your business data for advertising, profiling, or analytics beyond what is needed to operate the Service.
4. Data Isolation
Each user's data is fully isolated. Your business records (clients, orders, inventory, finances, etc.) are accessible only to your authenticated account. No other user can access, view, or modify your data.
5. Data Storage & Security
- All data is transmitted over HTTPS (TLS encryption in transit)
- Passwords are hashed using bcrypt with a cost factor of 12
- Authentication uses short-lived JWT access tokens (5 minutes) with refresh token rotation
- Session cookies are HttpOnly, Secure, and SameSite=Lax
- All database queries use parameterized prepared statements to prevent SQL injection
6. Third-Party Services
We use the following third-party services:
- Stripe — payment processing. Stripe's privacy policy: stripe.com/privacy
- Google Analytics (GA4) — anonymous website usage analytics on our public landing pages (opyrion.com). Google's privacy policy: policies.google.com/privacy. Google Analytics does not have access to your Opyrion account data. You can opt out at any time using the Google Analytics opt-out browser add-on.
- Google Calendar API - optional one-way calendar sync. When you connect Google Calendar, Opyrion uses Google Calendar data only to list calendars you own, create or update Opyrion task/event entries in the calendar you select, and remove Opyrion-created entries when they are no longer present in Opyrion.
We do not use advertising networks, retargeting services, or sell your data to third parties.
7. Cookies
We use the following cookies:
- opyrion_access_token — short-lived JWT for authentication (5-minute expiry)
- opyrion_refresh_token — longer-lived token for session renewal (7-day expiry)
- _ga, _ga_* — Google Analytics cookies used to distinguish visitors and measure landing page usage (2-year expiry). These are set on opyrion.com only and are not used inside the application.
We do not use advertising cookies or third-party retargeting cookies.
8. Your Rights (GDPR)
If you are in the European Economic Area, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — update your account information through the Settings page
- Erasure — request deletion of your account and all associated data
- Portability — request your data in a machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing of your data
To exercise any of these rights, contact us at support@opyrion.com. We will respond within 30 days.
8.1 Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority. As we are based in Cyprus, the lead supervisory authority is:
Office of the Commissioner for Personal Data Protection (CPDP)
1 Iasonos Street, 1082 Nicosia, Cyprus
Tel: +357 22 818 456
www.dataprotection.gov.cy
commissioner@dataprotection.gov.cy
9. Data Retention
We retain your data for as long as your account is active. If you cancel your subscription, your data remains accessible should you choose to resubscribe. To permanently delete your account and all associated data, contact us at support@opyrion.com.
For Google Calendar sync, Opyrion stores only local browser sync state, such as your selected calendar ID, last sync time, and identifiers for Opyrion-created calendar entries. You can clear this local sync state by disconnecting Google Calendar in the app or clearing your browser data. You can revoke Opyrion's Google access at any time from your Google Account security settings. Account deletion requests also remove Opyrion's server-side tasks and events that would otherwise be used for future syncs.
10. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Cyprus Commissioner for Personal Data Protection within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay.
11. Data Processor Relationship
When you use Opyrion to store information about your own clients, employees, or suppliers, you act as the data controller for that personal data, and Opyrion acts as your data processor. We process that data solely on your instructions (i.e. to operate the Service) and do not use it for any other purpose. This Privacy Policy and our Terms of Service together constitute the data processing agreement between us for the purposes of GDPR Article 28.
12. Google API Limited Use
Opyrion's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell, rent, or transfer raw, aggregated, or anonymized Google Calendar data to advertisers, data brokers, or other third parties. We do not use Google Calendar data for advertising, credit decisions, profiling, or unrelated analytics. We do not use Google Calendar data to develop, improve, or train generalized artificial intelligence or machine learning models, and we do not transfer Google Calendar data to third-party AI/ML services for model training.
13. Children's Privacy
The Service is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by email at least 14 days before they take effect and by updating the "Last updated" date at the top of this page.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
support@opyrion.com