Privacy Policy
Last updated: July 7, 2026
Effective: July 2026
1. Who We Are
Opedd ("we", "us") is a content-licensing platform connecting publishers and analysts with AI companies. This policy explains how we handle personal data under the UK GDPR and the Data Protection Act 2018.
Data controller. The data controller is Opedd Ltd, a company incorporated in England & Wales (company number 17353806), with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
EU representative. Because we offer services to, and monitor the activity of, individuals in the European Union, we will appoint a representative in the EU under Article 27 of the EU GDPR and publish their contact details here.
Contact. For any privacy matter, or to exercise your rights: hello@opedd.com. We have not appointed a Data Protection Officer, as we are not required to; the contact above is our privacy point of contact.
2. Data We Collect
We collect personal data directly from you when you register, transact, or communicate with us:
- Account data: email address, name, and organisation name when you register.
- Buyer signup data (from 2 May 2026): first and last name, company name, company website, intended use category (e.g. AI training, RAG retrieval, editorial reuse, research), and country of incorporation. Collected once at buyer signup to support tax compliance (including EU VAT), assessment of EU AI Act applicability, and metered-billing tier configuration.
- Transaction data: buyer email, name, organisation, intended use, licence type, and amount for each licence purchase.
- Payment data: processed entirely by Stripe. We never see or store your full card number.
- Usage data: pages visited, features used, and timestamps, used to operate and secure the Service.
- Communications: the content of emails you send us.
3. How We Use Your Data & Legal Basis
Under the UK GDPR we must have a lawful basis for each purpose. This table sets out ours:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Provide and operate the Service (accounts, licence issuance, content delivery) | Account, transaction data | Contract — Art. 6(1)(b) |
| Process payments and issue licence keys | Transaction, payment data (via Stripe) | Contract — Art. 6(1)(b) |
| Send transactional emails (confirmations, receipts, account notifications) | Email, name | Contract — Art. 6(1)(b) |
| Meet tax and accounting duties (including EU VAT); retain records | Transaction data, buyer country | Legal obligation — Art. 6(1)(c) |
| Assess EU AI Act applicability and configure your metered-billing tier | Intended-use category, country | Legitimate interests — Art. 6(1)(f) |
| Operate, improve, and secure the platform; monitor and diagnose errors | Usage data, error logs | Legitimate interests — Art. 6(1)(f) |
| Product analytics — anonymous, cookieless measurement by default; identified analytics only with your consent (see Cookies) | Usage data | Consent — Art. 6(1)(a) |
Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (see Your Rights). We do not sell your personal data.
4. Sub-processors
We use a small number of trusted service providers to run the Service. Each is bound by a data processing agreement, and we do not sell your personal data to anyone.
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database, authentication, hosting | European Union (Frankfurt) |
| Stripe | Payment processing (independent controller for payment data) | United States / global |
| Resend | Transactional email delivery | United States |
| Vercel | Frontend hosting and content delivery | United States / global edge |
| Sentry | Error monitoring and diagnostics | European Union / United States |
| PostHog | Product analytics (anonymous/cookieless by default; identified only on consent) | European Union option |
| Cloudflare | Inbound email routing and parsing (newsletter ingestion), DNS and proxy | Global edge network (US company) |
We also record limited, non-identifying licence data on the Tempo blockchain (see On-Chain Data). We do not sell your personal data to third parties.
5. International Transfers
Our primary data store (Supabase) is hosted in the European Union. Where a provider processes data outside the UK or EU (for example in the United States), that transfer is protected by an appropriate safeguard under the UK GDPR — the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and, for most providers, certification under the EU-US Data Privacy Framework and its UK Extension. You may request further detail on the safeguard for any specific provider using the contact below.
6. On-Chain Data
When a licence is issued, an attestation containing the licence key, a content identifier, and the licence type is recorded on the Tempo blockchain. This record is public and permanent and cannot be erased. It does not include your name, email address, or other identifying personal data. Because this data is immutable by design, the right to erasure cannot be applied to it; we minimise what is written on-chain to non-identifying attestation data for exactly this reason.
7. Automated Decision-Making
We use limited automated processing to assign your metered-billing tier and to assess whether the EU AI Act applies to your intended use, based on the information you provide at signup. These configure billing and compliance handling only; they do not produce legal effects or similarly significant effects on you. We do not carry out solely-automated decision-making with legal or similarly significant effect within the meaning of Article 22 of the UK GDPR.
8. Your Rights (UK GDPR)
You have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Request erasure of your data (subject to legal retention requirements and the immutable on-chain data described above);
- Object to, or request restriction of, processing based on legitimate interests;
- Data portability;
- Withdraw consent at any time, where we rely on consent (this does not affect processing before withdrawal);
- Lodge a complaint with the Information Commissioner's Office (ico.org.uk).
To exercise any right: hello@opedd.com. We will respond within one month.
9. Data Retention
We log IP addresses for security, rate-limiting, abuse prevention, and (where you submit one) DMCA notices; these operational logs are kept only as long as needed for those purposes and are not used for profiling.
We keep transaction and tax records for 7 years, as required for tax and accounting compliance. Account data is retained for as long as your account is active and then until you request deletion. We action deletion requests within 30 days where we are legally permitted to do so; some records may be retained longer where the law requires it.
11. Changes
We may update this policy. Material changes will be communicated by email to registered users. Continued use of the Service after an update constitutes acceptance of the revised policy.
12. Contact
Data controller and privacy contact: hello@opedd.com. You also have the right to complain to the ICO (ico.org.uk).
See also: Terms of Service
