GDPR Compliance
Last updated: August 7, 2026
GDPR Compliant
EU 2016/679
AES-256 Encrypted
At rest & in transit
Data Processing
Agreements available
Our commitment to GDPR
OPERAFI is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). As a company processing financial data on behalf of our customers, we take data protection seriously and have implemented comprehensive measures to ensure compliance.
Roles under GDPR
Depending on the context, OPERAFI acts in different capacities:
- Data Controller — when we process data of our customers (e.g. account holders, demo requesters) for our own business purposes
- Data Processor — when we process financial data on behalf of our customers to deliver the Service; in this case, our customers are the Data Controllers
We enter into a Data Processing Agreement (DPA) with all customers who require one. Contact [email protected] to request a DPA.
Your rights as a data subject
Under the GDPR, individuals in the EEA have the following rights:
- Right of access (Art. 15) — request a copy of the personal data we hold about you
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data
- Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten")
- Right to restriction (Art. 18) — request that we limit how we use your data
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interests or for direct marketing
- Rights related to automated decision-making (Art. 22) — not to be subject to solely automated decisions that significantly affect you
To exercise any of these rights, submit a request to [email protected]. We will respond within 30 days.
Technical and organisational measures
We have implemented the following measures to protect personal data:
- AES-256 encryption for data at rest
- TLS 1.3 for all data in transit
- Role-based access controls and least-privilege principles
- Regular security audits and penetration testing
- Employee data protection training
- Incident response and breach notification procedures
- Privacy by design in product development
Data transfers outside the EEA
Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission. We maintain a record of all international transfers and the safeguards applied.
Data breach notification
In the event of a personal data breach that is likely to result in a risk to individuals' rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 GDPR. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay.
Data Protection Officer
OPERAFI has appointed a Data Protection Officer (DPO) responsible for overseeing our data protection strategy and compliance. You can contact our DPO at [email protected].
Supervisory authority
If you believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with the relevant supervisory authority. In Germany, this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI).
Contact
For all GDPR-related enquiries, Data Processing Agreement requests, or to exercise your rights, contact us at [email protected].