Privacy Policy
Last updated: August 7, 2026
1. Who we are
OPERAFI ("OPERAFI", "we", "us", "our") operates the AI-powered finance operations platform available at operafi.ai. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform or visit our website.
2. Information we collect
We collect information you provide directly to us, including:
- Account registration data (name, work email, company name)
- Financial data you upload or connect to our platform (invoices, transaction records, bank feeds)
- Communications you send us (support requests, demo inquiries)
- Usage data and interaction logs within the platform
We also collect technical data automatically, including IP addresses, browser type, device identifiers, and cookies (see our Cookie Policy for details).
3. How we use your information
We use the information we collect to:
- Provide, maintain, and improve our platform and services
- Process and automate your finance operations as instructed
- Send transactional communications (confirmations, alerts, reports)
- Respond to your inquiries and provide customer support
- Comply with legal obligations and enforce our terms
- Detect and prevent fraud, abuse, and security incidents
4. Legal basis for processing (GDPR)
For users in the European Economic Area, we process your personal data on the following legal bases:
- Contract performance — to deliver the services you have subscribed to
- Legitimate interests — to improve our platform and prevent fraud
- Legal obligation — to comply with applicable laws and regulations
- Consent — for marketing communications and non-essential cookies
5. Data sharing and disclosure
We do not sell your personal data. We may share your information with:
- Service providers — cloud infrastructure, analytics, and support tools operating under data processing agreements
- Integration partners — only the data necessary to fulfil a specific integration you have enabled (e.g. your ERP or bank connection)
- Legal authorities — when required by law or to protect our rights
6. Data retention
We retain your personal data for as long as your account is active or as needed to provide services. Financial transaction data is retained for a minimum of 7 years to comply with accounting regulations. You may request deletion of your account data at any time, subject to legal retention requirements.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict certain processing activities
- Data portability — receive your data in a machine-readable format
- Withdraw consent at any time (where processing is based on consent)
To exercise any of these rights, contact us at [email protected].
8. Security
We implement industry-standard technical and organisational measures to protect your data, including AES-256 encryption at rest, TLS 1.3 in transit, and regular penetration testing. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
9. International transfers
Your data may be processed in countries outside the EEA. Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via an in-app notice at least 30 days before the changes take effect.
11. Contact
For privacy-related questions or to exercise your rights, contact our Data Protection Officer at [email protected].