opexONE App Privacy Policy

Version 1.0 · Last updated: 1 October 2026

Visiting opexone.io?

The Website Privacy Policy covers server logs, the contact form, trial requests and billing contacts.

Open the Website Privacy Policy

Using the opexONE platform or the mobile apps?

Your employer operates your workspace. The opexONE App Privacy Policy explains what plusRS processes on its own responsibility and how to delete your account.

You are reading it

About this notice — this notice explains how personal data is handled in the opexONE platform. Together with the opexone.io Privacy Policy (opexone.io/privacy), it forms the "Privacy Notice (opexONE platform users)" referred to in the opexONE Terms of Use (and the "Privacy Policy" referred to in any signed agreement for opexONE). When we change this notice, we update the version and date; for material changes we will tell you in the app before they take effect.

Who is responsible for your data in this workspace? This opexONE workspace is operated by your employer (or the organisation that invited you) — it is the "controller" of the business records, personal data, and files inside the workspace. It decides what is stored here, who can see it, and how long it is kept. plusRS OÜ (registry code 17182790, Ahtri tn 12, 15551 Tallinn, Estonia; privacy@plusrs.com — we have not appointed, and are not required to appoint, a Data Protection Officer) runs the opexONE platform on that organisation's behalf as its "processor", under a Data Processing Agreement. For questions or requests about workspace content (access, correction, deletion), contact your organisation's administrator or data-protection contact and plusRS will refer such requests to them. Requests to delete your own user account are handled by plusRS directly.

Workspace data the platform and apps handle — depending on how your organisation uses opexONE, the platform and apps store and transmit the records you and your colleagues create or view in the workspace, for example operational records, tasks and checklists, comments, photos and file attachments, locations entered or captured with records, and the names and roles of workspace users. plusRS processes this data only to provide the service to your organisation, on its instructions under the Data Processing Agreement. We do not sell it or use it for advertising. Your organisation decides how long it is kept; when its subscription ends, the data is returned or deleted as set out in the Data Processing Agreement.

What plusRS processes on its own responsibility (as controller):

  • Sign-in and account-security records — sign-in events, session and device information, IP address, and an approximate sign-in location. The location is estimated in our own database (no third-party geolocation service receives your IP) and is shown to you under Account → Security so you can spot suspicious sign-ins. The map displayed there is loaded directly by your browser from OpenStreetMap (OpenStreetMap Foundation, United Kingdom), which receives your IP address and acts as an independent controller of that technical data (see the Sub-processor List, "Third-party embeds"). Sign-in records are retained for a maximum of 12 months, then deleted. Legal basis: Art. 6(1)(f) GDPR (account and platform security).
  • Legal acceptance records — who accepted the Terms, DPA, and policies for the workspace, with timestamp, version, name, email address, and technical metadata of the acceptance (and, for signed agreements, the signed copy), kept as evidence of contract formation for the duration of the contract and for 3 years after it ends (the general limitation period under § 146 of the Estonian General Part of the Civil Code Act), or longer while a claim is pending. Legal basis: Art. 6(1)(f) GDPR (establishing, exercising, or defending legal claims).
  • Billing and contract contacts — if you are named as a billing contact, legal-notice contact, first administrator, or signatory for your organisation's subscription (including in a signed agreement), we process your name, business email, and role, and for billing your organisation's billing address and VAT ID, to conclude and perform the contract with your organisation, take payments, issue invoices, and keep statutory accounts. Card payments are handled by Stripe Payments Europe, Ltd. Card data goes directly to Stripe and never reaches us. Invoices and accounting records are kept in Envoice (Estonian accounting service) for 7 years under the Estonian Accounting Act. Legal bases: Art. 6(1)(f) GDPR (our legitimate interest in concluding and performing our contract with your organisation) and Art. 6(1)(c) GDPR (statutory bookkeeping).
  • Product feedback you choose to submit — if you send feedback through the in-app feedback feature, your report text and technical context are processed to evaluate your feedback and to develop and improve opexONE and our other services. The ideas you submit may be used freely, as set out in § 33.4 of the Terms of Use; your personal data in the report is used only for these purposes. Email addresses are automatically redacted, and the report is stored in our issue-tracking system (GitHub, Inc., USA — EU–US Data Privacy Framework / Standard Contractual Clauses). Please don't include personal data about others in feedback text. Reports are kept while the related issue is open and for up to 12 months after it is closed. Legal basis: Art. 6(1)(f) GDPR.
  • Support requests you send to plusRS — processed to resolve your request (Microsoft 365 mailbox). Support correspondence is kept for up to 12 months after the request is closed, or longer while a legal claim is pending. Legal basis: Art. 6(1)(b)/(f) GDPR.
  • Service usage and diagnostics data — technical and statistical data about how the platform is used and performs (e.g. feature-usage counts, performance metrics, error diagnostics). Where this data is linked to your account or device, it is personal data; it never includes the content of workspace records. We use it to provide, secure, maintain, and improve the platform, to manage capacity and prevent abuse, and to verify compliance with the Terms of Use. Anything we share or publish is aggregated or otherwise non-identifying. Usage data linked to an account or device is kept for up to 12 months, then deleted or aggregated. Legal basis: Art. 6(1)(f) GDPR (operating, securing, and improving the platform).
  • Mobile apps — the opexONE apps for iOS (Apple App Store) and Android (Google Play) give access to the same workspace and are covered by this notice. In addition to the processing described above, the apps process device and operating-system information, app version, push-notification tokens, crash diagnostics to deliver the app, send the notifications you enable, and keep the app secure. Legal basis: Art. 6(1)(f) GDPR (delivering and securing the app).
  • App permissions — the apps ask for device permissions only when you use a feature that needs them: camera (to take photos for records), photos and files (to attach existing images or documents), location (to record where a record was created), notifications (to send the alerts you enable). Each permission is optional; if you decline, only the related feature is unavailable. You can withdraw a permission at any time in your device settings (iOS: Settings → opexONE; Android: Settings → Apps → opexONE → Permissions). Withdrawing does not affect processing that took place before.

Deleting your user account — you can request deletion of your opexONE user account and the personal data associated with it at any time, either in the mobile app (Account → Delete account) or via opexone.io/delete-account, without needing to reinstall the app. plusRS will then delete the account and its associated personal data, except: (i) sign-in and account-security records, kept for up to 12 months as described above; (ii) legal acceptance records, kept as described above; (iii) billing and accounting records, kept as described above; and (iv) data we must keep to establish, exercise, or defend legal claims, for security or fraud prevention, or by law. Deleting your user account does not delete the business records in the workspace, which belong to and are decided on by your organisation. Deactivation of your account by your organisation's administrator is not deletion. As your account is part of your organisation's workspace, we will inform your organisation's administrator when we delete it.

Where data lives: the platform stores workspace data in the European Union (Amazon Web Services, EU region). Service providers that process the plusRS-controlled data above on our behalf are Amazon Web Services (hosting), Microsoft 365 (support mailbox), GitHub, Inc. (feedback), Stripe and Envoice (billing), Bird B.V. (SMS codes) and, for the mobile apps, Apple Push Notification service and Google Firebase Cloud Messaging (notification delivery). Transfers to the USA are covered by the EU–US Data Privacy Framework, with EU Standard Contractual Clauses as fallback. See the Sub-processor List for all providers. Your rights regarding the plusRS-controlled data above: you can request access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and portability (Art. 20) by writing to privacy@plusrs.com. Where we rely on legitimate interests (Art. 6(1)(f)), you have the right to object at any time on grounds relating to your particular situation (Art. 21). You may also lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, info@aki.ee) or the supervisory authority where you live or work. SMS sign-in codes are delivered via Bird B.V. (Netherlands, EU region).

Security — data is encrypted in transit (TLS) and at rest (AES-256), access to production systems is limited to authorised plusRS staff using multi-factor authentication, and our technical and organisational security measures are described in Annex II of the Data Processing Agreement.

See also our website privacy policy, account deletion, and sub-processor list.