Skip to content
operine
MethodWhat we buildInsightsFitAbout
Book a callFree diagnosis

Legal

Privacy Policy

Effective 2026-05-28

This policy explains what data we collect when you use this website, why we collect it, and your rights over it. It’s written to be readable; if anything isn’t clear, write to us.

Who we are

Operine — tailor-made operational systems. For any of the matters in this policy, reach us through our booking page.

What we collect

When you take the diagnostic, we collect:

  • The business one-liner you write.
  • The painpoint you describe in your own words.
  • Your answers to the AI’s follow-up questions.
  • Quantitative answers (people, hours, hourly cost, frequency).
  • Readiness signals (your role, company size, timeline, budget).
  • Your name, work email, and company.
  • Your consent to be contacted, plus a timestamp.

If you use voice mode on the diagnostic, your microphone audio is streamed to our AI provider (OpenAI) in real time for transcription and response. We do not record or store the raw audio — only the text transcript is saved, the same as if you typed.

If you book a scope call, we store your name, email, company, the time slot you picked, and an optional one-line context note. We send a calendar invite to your email and alert our team. Cancellations and reschedules are handled by replying to the booking email.

We also collect technical data (server logs and a single session cookie used only on our private admin dashboard — see our Cookie Policy). For visitor analytics we use a first-party, cookielesssystem: a per-session anonymous UUID held in your browser’s sessionStorage (not a cookie, resets when you close the tab), used to count aggregate funnel steps and page views. No third-party analytics, advertising trackers, fingerprinting, or social media pixels.

Why we collect it (purposes and lawful basis)

  • To compute and show your diagnosis — performance of the service you’ve requested.
  • To follow up about it (call, message) — your consent (the checkbox) plus legitimate interest.
  • To run and protect the service (logging, abuse prevention) — legitimate interest.
  • To improve the diagnostic over time — legitimate interest, applied to aggregated / anonymised data only.

Who processes your data

We use a small, carefully chosen set of processors:

  • Supabase — stores your submission (EU region).
  • OpenAI— runs the AI questioning, the voice conversation, and the summary. In text mode we send the workflow, your business one-liner, your painpoint, and the conversation; in voice mode your microphone audio is streamed live for real-time transcription. To prepare for a possible call, we also send your company name and the public homepage content of your email’s domain so the model can draft a short research brief. We do not send your name or email address to OpenAI. The OpenAI API terms forbid using your data for model training.
  • Telegram — used only to alert our team when a new lead arrives or requests a call. We send your name, company, score, and a short AI summary. No email or phone is sent.
  • Vercel — web hosting; receives standard request metadata.
  • Resend— transactional email delivery (your diagnosis confirmation and booking confirmation with calendar invite). We send the message body, your email address and your name. Resend does not use your data to train anything; it’s a pipe.

We do not sell or share your data with anyone else.

How long we keep it

  • Diagnostic submissions and contact data: up to 36 months from your last interaction, then deleted.
  • Abuse / rate-limit logs: 24 hours.
  • Aggregated / anonymised data: kept for product improvement.

You can ask us to delete your data at any time — see “Your rights” below.

Your rights (GDPR)

  • Access the data we hold about you.
  • Correct anything that’s wrong.
  • Delete your data (“right to be forgotten”).
  • Restrict or object to certain processing.
  • Take your data with you (portability).
  • Withdraw consent at any time — this doesn’t affect prior lawful processing.
  • Lodge a complaint with your data protection authority. In France that’s the CNIL.

To exercise any of these, contact us through our booking page. We aim to respond within 30 days.

Children

The diagnostic is intended for business owners and executives. We do not knowingly collect data from anyone under 16.

How we protect this

  • All traffic is HTTPS-only with strict transport security in production.
  • The database denies all access by default (Postgres row-level security); every read or write goes through a server-only secret key, never your browser.
  • Per-IP and global rate limits on every action that costs money, plus daily budget caps that pause the relevant action automatically if exceeded.
  • Strict Content-Security-Policy, no third-party trackers, no fingerprinting.
  • Voice audio is streamed live to OpenAI and never recorded — only the transcript is saved.
  • Admin access is single-user, password-gated, with HMAC-signed session cookies.
  • Security events (rate-limit hits, bad-origin attempts, failed logins) are logged for monitoring.

International transfers

Our processors are EU-based or operate under standard contractual clauses for international transfers (OpenAI, Vercel). We won’t add new transfers without updating this policy.

Changes to this policy

We’ll update this page when material changes happen and bump the effective date.

operine

Custom business process automation for SMBs and professional firms. We remove the work that shouldn’t exist.

For

  • Audit firms
  • Boutique law firms
  • Private clinics

Company

  • About
  • Free diagnosis
  • Book a call
  • Insights

Legal

  • Privacy
  • Cookies
  • Terms
© 2026 operineBuilt as a system, not a brochure.