This Privacy Policy explains how Health Monk s.r.o. handles personal data in connection with Opelli — the marketing site at opelli.dev, the beta sign-up, and the Opelli application itself. A key distinction runs through this policy: for some data we decide the purposes and means of processing (we are the controller); for the data our customers put into Opelli about their own people and contacts, we act only on their instructions (we are the processor). Section 2 explains which is which.
Who we are
The controller responsible for the personal data described in this policy (except where we act as a processor — see section 2) is:
Health Monk s.r.o.
Korunní 2569/108, Vinohrady, 101 00 Praha 10, Czech Republic
Company ID (IČO): 21042039 · DUNS: 984015947
Privacy contact: privacy@healthmonk.ai
We have not appointed a statutory Data Protection Officer, as we are not required to. You can reach our privacy team at the address above for any question about this policy or your personal data.
When we are the controller vs the processor
Opelli is a platform our customers use to run their operations. That creates two roles:
- We are the controller for the personal data we handle to run our business and provide the Service — for example, the details of the people who create and administer accounts, sign in, contact support, or sign up for the beta, and the technical logs the Service generates. Sections 3–5 and 8–15 describe this data.
- We are the processor for the personal data our customers choose to put into Opelli about their team members, contractors, CRM contacts, mailing-list recipients, form respondents and similar (“Customer Content”). Here the customer is the controller; we process it only on their documented instructions under a Data Processing Agreement. Section 6 describes this data. If you are a data subject whose personal data appears in a customer's workspace and you want to exercise your rights over it, please contact that customer (the controller); we will assist them as our agreement requires.
Personal data we collect (as controller)
Account and profile data
When you are invited to and sign in to Opelli, we receive from Google (via OAuth/OpenID Connect) your name, email address, a stable account identifier, and profile picture. Within your profile you or your administrator may add further details such as job title, contact details, skills and reporting lines.
Beta sign-up data
If you request early access through the sign-up form on opelli.dev, we collect the email address you provide. (The form also contains a hidden “company” field that is a spam honeypot — genuine visitors never fill it, and submissions that do are discarded.)
Communications and support
If you contact us by email or through the Service, we keep your messages and the information you choose to include, so we can respond and keep records.
Usage, device and log data
When you use the Service, our systems automatically record technical information such as IP address, browser and device type, timestamps, the pages or API endpoints requested, and diagnostic and security logs. The Service also maintains internal activity and audit logs of actions taken within an account (for traceability and security).
How and why we use personal data — and our legal bases
As controller, we process personal data for the following purposes, each with a legal basis under Article 6(1) GDPR:
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing, operating and maintaining the Service and your account | Account/profile, usage/log data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) for users acting for an organizational customer |
| Authenticating sign-in and securing accounts | Google account identifier, session data, API-key/token metadata | Contract; legitimate interests in security |
| Responding to your beta request and inviting you to the beta | Beta sign-up email | Consent (Art. 6(1)(a)) / steps prior to a contract (Art. 6(1)(b)) |
| Providing support and communicating about the Service (including important service notices) | Contact and communication data | Contract; legitimate interests |
| Securing the Service, preventing abuse, and keeping audit/activity logs | Usage, device and log data | Legitimate interests (Art. 6(1)(f)) in the security and integrity of the Service |
| Improving and developing the Service | Aggregated/technical usage data; feedback | Legitimate interests |
| Complying with legal obligations and enforcing our terms | As relevant | Legal obligation (Art. 6(1)(c)); legitimate interests in establishing or defending legal claims |
Where we rely on legitimate interests, we have balanced them against your rights and freedoms. You may object to processing based on legitimate interests as described in section 12. Where we rely on consent, you may withdraw it at any time.
Data we process on behalf of our customers (as processor)
When our customers use Opelli, they submit Customer Content that may contain personal data about their own team members, contractors, customers and contacts, mailing-list recipients, and people who respond to their public forms. Depending on how the customer configures the Service, this can include names, email addresses and phone numbers, job titles, project and task assignments, time entries, CRM notes and deal information, marketing-list membership, form answers, and GDPR-compliance records (such as consent logs and data-subject requests) that the customer maintains within the Service.
For all such data, the customer is the controller and Health Monk is the processor. We process it only to provide the Service and on the customer's documented instructions, under a Data Processing Agreement that reflects Article 28 GDPR. We do not use Customer Content for our own purposes, and we do not sell personal data. If your personal data is held in a customer's Opelli workspace and you wish to access, correct or delete it, please contact that organization directly; Opelli also provides customers with tools (a privacy centre, a personal-data locator and consent ledger) to help them respond.
Sub-processors and service providers
We rely on a small number of trusted providers to deliver the Service. They process personal data on our behalf under contracts that impose appropriate data-protection obligations. Our current sub-processors are:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, file/object storage, and transactional & campaign email delivery (Amazon SES) | European Union (Frankfurt, eu-central-1) |
| Google (Google Ireland Ltd) | Sign-in (OAuth / OpenID Connect) and outbound email relay via Workspace SMTP | EU with possible transfer to the US (Standard Contractual Clauses) |
| Cloudflare, Inc. | DNS, edge/CDN network and hosting of the marketing site | Global edge network; US-based provider (Standard Contractual Clauses) |
| Toggl OÜ | Time-tracking synchronisation — only if an individual user connects their own Toggl account | European Union (Estonia) |
Some features integrate with services that you operate or connect, and which are not our sub-processors — for example, a Mattermost server you run, a GitHub repository whose webhooks you configure, or a public lookup to the Czech ARES business register. Data exchanged with those services is governed by your own arrangements and their terms.
We may update our sub-processors as the Service evolves. For customers, our Data Processing Agreement sets out how we give notice of new sub-processors and how objections are handled. To receive sub-processor change notices, contact privacy@healthmonk.ai.
International data transfers
Our primary hosting and storage of application data — including Customer Content and account data — takes place within the European Union (AWS Frankfurt, eu-central-1). Some sub-processors (such as Google and Cloudflare) are established in, or may process data in, countries outside the European Economic Area. Where personal data is transferred outside the EEA, we rely on an appropriate transfer mechanism under Chapter V GDPR — in particular the European Commission's Standard Contractual Clauses, together with supplementary measures where needed. You can request more detail about the safeguards in place by contacting us.
How long we keep personal data
We keep personal data only as long as necessary for the purposes described in this policy:
- Account and profile data — for as long as your account is active, and for a reasonable period afterwards to wind down the relationship, resolve disputes and meet legal obligations.
- Customer Content (as processor) — for the duration of the customer's use of the Service; on termination it is made available for export for a limited period and then deleted or de-identified in line with our Data Processing Agreement, subject to routine backup rotation.
- Beta sign-up email — until we complete the beta invitation process or you ask us to remove it, whichever is earlier.
- Security and system logs — for a limited period appropriate to their security and diagnostic purpose.
- Backups — encrypted backups are rotated on a regular cycle, so residual copies may persist for a short time after deletion from the live systems.
We may retain certain information longer where required to comply with legal obligations or to establish, exercise or defend legal claims.
How we protect personal data
We implement appropriate technical and organizational measures to protect personal data, including:
- authentication through Google OAuth with PKCE and server-side verification of ID tokens; accounts are pinned to a stable Google identifier, and there is no password store and no authentication bypass;
- encryption in transit (TLS) and encryption of data and backups at rest through our cloud provider;
- signed,
HttpOnly,SameSite=Laxsession cookies, an origin/CSRF check on state-changing requests, and a strict content-security policy; - a granular permission model (per-feature access levels and per-project row scope) that governs the web app, the API and connected AI agents identically, so no integration can exceed the access of the person using it;
- API keys stored only as SHA-256 digests (never retrievable after creation), scoped to specific modules, and revocable/rotatable;
- strict per-tenant data isolation, secrets held in a managed secrets store, and least-privilege access for our systems.
No method of transmission or storage is completely secure, but we work to protect personal data and to detect and respond to incidents. Where we act as processor and become aware of a personal-data breach, we will notify the affected customer without undue delay so they can meet their own obligations.
Your rights
Subject to the conditions and exceptions in applicable data-protection law, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data (the “right to be forgotten”);
- restrict or object to certain processing, including processing based on our legitimate interests;
- data portability — receive certain data in a structured, commonly used, machine-readable format;
- withdraw consent at any time where we rely on consent, without affecting processing already carried out.
To exercise these rights in relation to data for which we are the controller, contact privacy@healthmonk.ai. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting. If your data sits in a customer's Opelli workspace, the customer is the controller — please direct your request to them, and we will support them as required.
Children
Opelli is a business tool intended for use by professionals. It is not directed at children, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us and we will take appropriate steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the “Last updated” date and, where appropriate, provide additional notice (for example, within the Service or by email to account administrators). We encourage you to review this page periodically. The current version is always available at this address.
How to contact us and your right to complain
Health Monk s.r.o.
Korunní 2569/108, Vinohrady, 101 00 Praha 10, Czech Republic
Company ID (IČO): 21042039 · DUNS: 984015947
Privacy: privacy@healthmonk.ai
Web: healthmonk.ai
If you have a concern about how we handle your personal data, please contact us first — we will do our best to resolve it. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), Pplk. Sochora 27, 170 00 Praha 7. You may also contact the supervisory authority in your country of residence or work.