Privacy Policy

Version 1.2 · Last updated: 10 July 2026 · This policy covers the opexone.io website. For the opexONE application, see our Data Processing Agreement and sub-processor list.

1. Controller

plusRS OÜ (a HM Ventures OÜ company)
Harju maakond, Tallinn, Kesklinna linnaosa, Ahtri tn 12, 15551
Registry code: 17182790 · VAT ID: EE103002866
Email: privacy@plusrs.com

We are not required to appoint, and have not appointed, a Data Protection Officer. For any data-protection matter, please contact privacy@plusrs.com.

This policy covers personal data processed via the opexone.io website only. The opexONE product and the customer data processed within it are governed by separate terms (our Data Processing Agreement and Sub-processors list).

2. No Tracking on This Website

The opexone.io marketing website uses no analytics, tracking, or advertising technologies, and sets no tracking cookies. Fonts are self-hosted. We set only strictly-necessary storage required to serve the site securely; we set no analytics or tracking cookies and therefore use no cookie banner (ePrivacy Directive Art. 5(3)). The opexONE application (after login) uses strictly-necessary cookies for authentication — those are documented in-product.

3. What We Process, and Why

a) Server logs

Our hosting provider (Amazon Web Services / AWS Amplify) processes technical data (IP address, timestamp, requested page, browser type) in server logs to deliver the site securely and detect abuse. Legal basis: our legitimate interest in site security, IT integrity, and abuse detection (Art. 6(1)(f) GDPR, Recital 49). Logs are retained for no longer than 30 days, then deleted.

b) Trial signup

When you sign up for a trial, we process the data you provide (company name, your name, work email, optional phone, selected plan) to respond to your request, verify your details, and manually set up your trial workspace. Legal basis: performance of a contract / pre-contractual measures (Art. 6(1)(b) GDPR). No payment or card data is collected on this website. Any phone number you provide is used only to contact you about your trial and account; we will not use it for marketing without your separate prior consent. Providing this data is voluntary, but without it we cannot set up your trial. Your enquiry is sent via Amazon SES and received in our Microsoft 365 mailbox. If a trial does not convert, signup data is deleted within 6 months.

c) Contact form

Messages sent via the contact form (name, email, company, message) are processed solely to handle your enquiry, and are received in our Microsoft 365 mailbox. Legal basis: Art. 6(1)(b) and (f) GDPR. Providing this data is voluntary, but without it we cannot reply to you.

d) Spam and abuse prevention

To protect our forms against spam and abuse we use a hidden honeypot field and IP-based rate-limiting, which briefly process the submitting IP address. Legal basis: our legitimate interest in IT security and abuse prevention (Art. 6(1)(f) GDPR, Recital 49).

e) No automated decision-making

We carry out no automated decision-making or profiling within the meaning of Art. 22 GDPR. IP-based rate-limiting is a purely technical abuse-prevention measure with no legal or similarly significant effect on you.

4. Recipients and Transfers

We rely on the following processors: Amazon Web Services (website hosting via AWS Amplify and outbound email delivery via Amazon SES) and Microsoft 365 — provided by Microsoft Ireland Operations Limited, with Microsoft Corporation as the underlying entity — for receiving and storing our email correspondence in Exchange Online, OneDrive and SharePoint. Where personal data is processed outside the EEA, it is safeguarded by the EU–US Data Privacy Framework — under which Amazon Web Services is covered by the Amazon.com, Inc. certification and Microsoft Corporation is certified — with EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a fallback. Within the opexONE application, sign-in and phone-number verification codes are delivered by SMS through Bird (MessageBird B.V., Netherlands), which receives the recipient's phone number for delivery only — the codes are generated and verified by our own authentication platform. We use no analytics, advertising, or tracking providers, and we do not sell personal data. For the opexONE application's full processor list, see our sub-processor list.

5. Your Rights

Under the GDPR, you have the right to:

  • access the personal data we hold about you (Art. 15)
  • rectification of inaccurate data (Art. 16)
  • erasure (Art. 17) and restriction of processing (Art. 18)
  • data portability (Art. 20)
  • object to processing based on legitimate interest (Art. 21)

Contact privacy@plusrs.com to exercise any right. You may also lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, +372 627 4135, info@aki.ee, aki.ee. You may also complain to the supervisory authority in your country of residence or work.

6. Data Security

This website is served exclusively over TLS. The opexONE platform applies tenant isolation at the database layer (row-level security), encryption in transit and at rest, and comprehensive audit logging.

7. Changes

We may update this policy as the website or legal requirements change. The current version is always available on this page.

See also our terms of service and imprint.