Privacy Policy

    Last updated: July 7, 2026

    Effective: July 2026

    1. Who We Are

    Opedd ("we", "us") is a content-licensing platform connecting publishers and analysts with AI companies. This policy explains how we handle personal data under the UK GDPR and the Data Protection Act 2018.

    Data controller. The data controller is Opedd Ltd, a company incorporated in England & Wales (company number 17353806), with registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.

    EU representative. Because we offer services to, and monitor the activity of, individuals in the European Union, we will appoint a representative in the EU under Article 27 of the EU GDPR and publish their contact details here.

    Contact. For any privacy matter, or to exercise your rights: hello@opedd.com. We have not appointed a Data Protection Officer, as we are not required to; the contact above is our privacy point of contact.

    2. Data We Collect

    We collect personal data directly from you when you register, transact, or communicate with us:

    • Account data: email address, name, and organisation name when you register.
    • Buyer signup data (from 2 May 2026): first and last name, company name, company website, intended use category (e.g. AI training, RAG retrieval, editorial reuse, research), and country of incorporation. Collected once at buyer signup to support tax compliance (including EU VAT), assessment of EU AI Act applicability, and metered-billing tier configuration.
    • Transaction data: buyer email, name, organisation, intended use, licence type, and amount for each licence purchase.
    • Payment data: processed entirely by Stripe. We never see or store your full card number.
    • Usage data: pages visited, features used, and timestamps, used to operate and secure the Service.
    • Communications: the content of emails you send us.

    3. How We Use Your Data & Legal Basis

    Under the UK GDPR we must have a lawful basis for each purpose. This table sets out ours:

    PurposeData usedLawful basis
    Provide and operate the Service (accounts, licence issuance, content delivery)Account, transaction dataContract — Art. 6(1)(b)
    Process payments and issue licence keysTransaction, payment data (via Stripe)Contract — Art. 6(1)(b)
    Send transactional emails (confirmations, receipts, account notifications)Email, nameContract — Art. 6(1)(b)
    Meet tax and accounting duties (including EU VAT); retain recordsTransaction data, buyer countryLegal obligation — Art. 6(1)(c)
    Assess EU AI Act applicability and configure your metered-billing tierIntended-use category, countryLegitimate interests — Art. 6(1)(f)
    Operate, improve, and secure the platform; monitor and diagnose errorsUsage data, error logsLegitimate interests — Art. 6(1)(f)
    Product analytics — anonymous, cookieless measurement by default; identified analytics only with your consent (see Cookies)Usage dataConsent — Art. 6(1)(a)

    Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (see Your Rights). We do not sell your personal data.

    4. Sub-processors

    We use a small number of trusted service providers to run the Service. Each is bound by a data processing agreement, and we do not sell your personal data to anyone.

    ProviderPurposeData location
    SupabaseDatabase, authentication, hostingEuropean Union (Frankfurt)
    StripePayment processing (independent controller for payment data)United States / global
    ResendTransactional email deliveryUnited States
    VercelFrontend hosting and content deliveryUnited States / global edge
    SentryError monitoring and diagnosticsEuropean Union / United States
    PostHogProduct analytics (anonymous/cookieless by default; identified only on consent)European Union option
    CloudflareInbound email routing and parsing (newsletter ingestion), DNS and proxyGlobal edge network (US company)

    We also record limited, non-identifying licence data on the Tempo blockchain (see On-Chain Data). We do not sell your personal data to third parties.

    5. International Transfers

    Our primary data store (Supabase) is hosted in the European Union. Where a provider processes data outside the UK or EU (for example in the United States), that transfer is protected by an appropriate safeguard under the UK GDPR — the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and, for most providers, certification under the EU-US Data Privacy Framework and its UK Extension. You may request further detail on the safeguard for any specific provider using the contact below.

    6. On-Chain Data

    When a licence is issued, an attestation containing the licence key, a content identifier, and the licence type is recorded on the Tempo blockchain. This record is public and permanent and cannot be erased. It does not include your name, email address, or other identifying personal data. Because this data is immutable by design, the right to erasure cannot be applied to it; we minimise what is written on-chain to non-identifying attestation data for exactly this reason.

    7. Automated Decision-Making

    We use limited automated processing to assign your metered-billing tier and to assess whether the EU AI Act applies to your intended use, based on the information you provide at signup. These configure billing and compliance handling only; they do not produce legal effects or similarly significant effects on you. We do not carry out solely-automated decision-making with legal or similarly significant effect within the meaning of Article 22 of the UK GDPR.

    8. Your Rights (UK GDPR)

    You have the right to:

    • Access the personal data we hold about you;
    • Correct inaccurate or incomplete data;
    • Request erasure of your data (subject to legal retention requirements and the immutable on-chain data described above);
    • Object to, or request restriction of, processing based on legitimate interests;
    • Data portability;
    • Withdraw consent at any time, where we rely on consent (this does not affect processing before withdrawal);
    • Lodge a complaint with the Information Commissioner's Office (ico.org.uk).

    To exercise any right: hello@opedd.com. We will respond within one month.

    9. Data Retention

    We log IP addresses for security, rate-limiting, abuse prevention, and (where you submit one) DMCA notices; these operational logs are kept only as long as needed for those purposes and are not used for profiling.

    We keep transaction and tax records for 7 years, as required for tax and accounting compliance. Account data is retained for as long as your account is active and then until you request deletion. We action deletion requests within 30 days where we are legally permitted to do so; some records may be retained longer where the law requires it.

    10. Cookies

    We use only strictly-necessary cookies, for authentication and to maintain your session, plus a small amount of first-party functional storage within the signed-in app. These do not require consent. We do not currently use analytics or advertising cookies. If we introduce product analytics in future, it will be strictly opt-in via a cookie banner, and you will be able to withdraw consent at any time. Full detail is in our Cookie Policy.

    11. Changes

    We may update this policy. Material changes will be communicated by email to registered users. Continued use of the Service after an update constitutes acceptance of the revised policy.

    12. Contact

    Data controller and privacy contact: hello@opedd.com. You also have the right to complain to the ICO (ico.org.uk).

    See also: Terms of Service