Legal

OPSOLE — Privacy & Cookies Policy

Effective Date: 01 January 2026

Company: Opsole Ltd

Contact: [email protected] | [email protected]

1. Overview

Opsole Ltd ("Opsole", "we", "us", "our") is committed to protecting privacy and maintaining transparency when customers use Opsole Migrate, related services, websites, and portals.

This Privacy & Cookies Policy explains how we collect, use, store, protect, and disclose information in connection with our enterprise services.

2. Scope

This policy applies to:

  • Customers using Opsole Migrate
  • Tenant administrators acting on behalf of customers
  • End users whose devices are managed by customers
  • Visitors to the Opsole website and portal

Opsole Migrate is an enterprise service and is not intended for consumer or personal use.

3. Controller and Processor Roles

Customer acts as the data controller for end-user and device data processed through Opsole Migrate.

Opsole acts as a data processor for customer-provided data and as a data controller for account, billing, and website usage data.

4. Data We Collect

4.1 Device & Identity Metadata

  • Device hostname
  • Device serial number and hardware identifiers
  • Username (for operational mapping only)
  • User Security Identifier (SID)
  • Migration logs, execution state, and error information

4.2 Recovery Assurance Data (Only When Enabled)

  • BitLocker recovery key
  • LAPS / Windows LAPS password

These are collected solely to enable device recovery if a system becomes inaccessible during or immediately after migration.

4.3 Admin & Account Data

  • Administrator name and business email
  • Tenant ID
  • Authentication identifiers
  • Access and audit logs

4.4 Website & Portal Data

  • IP address
  • Browser and device type
  • Access and security logs
  • Session cookies

5. What We Do NOT Collect

Opsole does not collect, inspect, or process:

  • User file contents
  • Personal documents or files
  • Emails, messaging data, or browser history
  • Application-level user data

6. Purpose of Data Processing

We process data strictly to:

  • Execute device migration workflows
  • Maintain licensing and entitlement integrity
  • Provide diagnostics and customer support
  • Ensure platform security, integrity, and auditability
  • Support recovery scenarios when enabled
  • Comply with legal and regulatory obligations

Data is processed under the following lawful bases:

  • Contractual necessity — to provide the Service during the subscription term
  • Legitimate interests — platform security, diagnostics, reliability
  • Customer consent — for recovery assurance data where applicable
  • Legal obligations — compliance and record-keeping

8. Security Measures

Opsole applies enterprise-grade security controls, including:

  • Encryption in transit and at rest
  • Role-based access control (least privilege)
  • Multi-factor authentication for internal access
  • Audit logging and continuous monitoring
  • Secure software development practices
  • Controls aligned with SOC 2 Type II and ISO 27001

9. Data Retention

Opsole retains data only for the duration necessary to provide the Service and support customer migration activities.

Because Opsole Migrate is licensed on a one-year subscription basis, data retention is aligned to the active subscription period.

Retention Policy

Device metadata, identity metadata, administrative data, and migration logs

  • Retained for the duration of the active subscription (up to 1 year).
  • Data is removed upon license expiry or earlier if the customer confirms that migration activities have been completed and requests removal.

Recovery assurance data (BitLocker recovery keys and LAPS / Windows LAPS passwords)

  • Retained only while the subscription is active and solely to support recovery and break-glass scenarios.
  • These recovery secrets are removed upon subscription expiry or earlier upon customer instruction confirming migration completion.

Billing and statutory records

  • Retained for the period required by applicable financial and regulatory laws.

Data is securely deleted or anonymized following subscription expiry or customer-initiated removal, in accordance with Opsole’s data protection and security controls.

10. Data Sharing and Subprocessors

  • Opsole does not sell personal data.
  • Data is accessed only by authorized Opsole personnel on a need-to-know basis.
  • Recovery assurance data is never shared with third parties.
  • Trusted infrastructure and service providers (such as cloud hosting) may process data under strict contractual, security, and confidentiality obligations.

11. International Data Transfers

Data may be processed in the United Kingdom, European Union, or United States, using appropriate safeguards such as Standard Contractual Clauses (SCCs) and the UK Addendum where applicable.

12. Your Rights

Subject to applicable law, you may request:

  • Access to personal data
  • Correction or deletion
  • Restriction or objection to processing
  • Withdrawal of consent where applicable

Requests can be submitted to [email protected].

End users must contact their organization (the data controller) to exercise rights.

13. Cookies Policy

  • Essential cookies are used for security and session management.
  • Optional analytics cookies are used only with consent.
  • No advertising or cross-site tracking cookies are used.

Cookie preferences can be managed via browser settings or consent controls where applicable.

14. Security Commitment

Opsole maintains formal information security governance aligned with SOC 2 Type II and ISO 27001 standards to protect all operational and customer data.

15. Changes to This Policy

We may update this policy periodically. Continued use of the Service constitutes acceptance of the updated policy.

16. Contact

Opsole Ltd
[email protected]
[email protected]
71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom