Privacy Policy
Last updated: January 2026
At OPUS MGL ("we," "our," or "us"), we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use ourOPUS Material Genealogy Layer platform and related services.
1Information We Collect
We collect information that you provide directly to us, including:
- Account Information: Name, email address, company name, job title, and password when you create an account.
- Profile Data: Additional information you choose to provide in your user profile.
- Manufacturing Data: Material tracking data, production records, quality metrics, and genealogy information you input into our platform.
- Communication Data: Records of correspondence when you contact our support team.
- Payment Information: Billing details and transaction history processed through our secure payment providers.
We also automatically collect certain information when you use our services:
- Usage Data: Information about how you interact with our platform, including features used and time spent.
- Device Information: Browser type, operating system, IP address, and device identifiers.
- Log Data: Server logs, error reports, and performance metrics.
2How We Use Your Data
We use the information we collect for the following purposes:
- Service Delivery: To provide, maintain, and improve our Material Genealogy Layer platform and its features.
- Account Management: To create and manage your account, process transactions, and provide customer support.
- Analytics: To analyze usage patterns and optimize platform performance and user experience.
- Communication: To send service updates, security alerts, and administrative messages.
- Compliance: To comply with legal obligations and enforce our terms of service.
- Security: To detect, prevent, and respond to fraud, security incidents, and technical issues.
We process your data based on legitimate business interests, contractual necessity, legal obligations, or your explicit consent where required by applicable law.
3Data Storage & Security
We implement industry-standard security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. Our security practices include:
- Encryption: All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
- Access Controls: Role-based access controls and multi-factor authentication for all system access.
- Infrastructure Security: Our systems are hosted in SOC 2 Type II certified data centers with 24/7 monitoring.
- Regular Audits: We conduct regular security assessments and penetration testing.
- Data Backup: Automated backups with geographic redundancy to ensure data availability.
Your data is stored in secure data centers located within the European Union and the United States. We retain your information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.
4Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have the following rights regarding your personal data:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure: You may request deletion of your personal data under certain circumstances.
- Right to Restriction: You may request that we limit the processing of your personal data.
- Right to Data Portability: You may request your data in a structured, machine-readable format.
- Right to Object: You may object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the information provided in the Contact Us section. We will respond to your request within 30 days.
6Third-Party Services
We may share your information with third-party service providers who assist us in operating our platform. These providers are contractually obligated to protect your data and may only use it for specified purposes:
- Cloud Infrastructure: Secure hosting and data storage services.
- Payment Processors: Secure handling of billing and payment transactions.
- Analytics Providers: Platform usage analysis and performance monitoring.
- Communication Services: Email delivery and customer support tools.
- Security Services: Fraud prevention and security monitoring.
We do not sell your personal information to third parties. We may disclose information if required by law, to protect our rights, or in connection with a business transfer such as a merger or acquisition.
7Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
You also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the "Last updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.