Privacy

Privacy Notice

Controller and processor privacy information for OptiGPU customers, visitors, and authorised users.

Last updated: July 25, 2026

Controller: Matthew Andrew Terblanche, trading as OptiGPU ("OptiGPU") Torenallee 101, 5617 BR Eindhoven, Netherlands KVK 42060575 · VAT NL005463593B43 Privacy contact: [email protected] Version 2026-07-25-v1

1. About this notice

This notice describes how OptiGPU processes personal data when we act as a controller - that is, account, billing, marketing, security, and support data. When we process data on behalf of our customers in their workspaces (for example, cloud-billing data uploaded for analysis), we act as a processor and the customer's privacy notice and our Data Processing Addendum apply.

2. Personal data we process

CategoryExamplesSource
Account dataName, work email, role, organisation, password hashYou
Billing dataInvoices, payment metadata (last 4 digits, brand), VAT IDYou + Stripe
Usage dataPages viewed, features used, log-in timestampsAutomatic
Support dataTicket content, attachmentsYou
Marketing dataEmail engagement, consent status, sourceAutomatic / opt-in
Security dataIP address, device, session activity, audit logsAutomatic

3. Why and on what lawful basis we process

PurposeLawful basis
Provide the Service and the customer accountPerformance of contract (Art. 6(1)(b) GDPR)
Invoice and collect paymentLegal obligation (Art. 6(1)(c)) + Performance of contract
Security, fraud prevention, abuse detectionLegitimate interest (Art. 6(1)(f))
Service improvement (aggregated analytics)Legitimate interest
Marketing emails (existing customers)Legitimate interest with opt-out (PECR soft opt-in)
Marketing emails (prospects)Consent (Art. 6(1)(a)) where applicable
Tax record-keepingLegal obligation

4. Who we share data with

  • Subprocessors listed at https://optigpu.ai/subprocessors (hosting, email delivery, payments, error monitoring, analytics)
  • Tax authorities as required by law (Belastingdienst, etc.)
  • Law enforcement / regulators where compelled by valid legal process
  • Professional advisors (auditors, lawyers, accountants) under confidentiality
  • In a corporate transaction (merger, acquisition, financing) under confidentiality

We do not sell personal data. We do not share personal data for cross-context behavioural advertising.

5. International transfers

Personal data we process may be transferred to and processed in countries outside the European Economic Area and Switzerland ("Third Country"), including the United States. Our transactional email provider, Twilio SendGrid, currently uses global processing infrastructure; OptiGPU does not represent that transactional email data is stored or processed only in the EU. Email processing is limited to the recipient address, necessary message content, and operational delivery events. OptiGPU disables provider open and click tracking for application-generated transactional email.

Where we transfer personal data to a Third Country that does not have an adequacy decision, we rely on appropriate safeguards including (a) the Standard Contractual Clauses adopted by the European Commission on 4 June 2021; and (b) the Swiss FADP addendum to the EU SCCs. We conduct transfer-impact assessments where required and apply supplementary measures including encryption in transit and at rest, data minimisation, pseudonymisation where feasible, and limiting access on a need-to-know basis. A copy of the transfer mechanism for any specific transfer is available on request to [email protected].

6. Retention

CategoryRetentionTrigger
Account profileActive + 24 months after closureAccount closure
Billing records7 yearsIssuance (NL fiscal retention)
Customer cloud-billing data and tenant reports (as processor)Per customer instructions; primary copies retained while the subscription is active and deleted 30 days after termination by default; managed backups may persist for up to a further 60 daysSubscription end
Public Evidence Report files90 daysReport delivery
Customer-issued savings statements and the minimised business record needed to substantiate them7 yearsStatement issuance
System logs12 monthsLog entry
Support tickets36 monthsTicket closure
Marketing consent recordsUntil opt-out + 24 months for auditOpt-out
Sanctions / KYC screening records7 yearsScreening event

7. Your rights

Under the GDPR you have rights of access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent you may withdraw consent at any time. To exercise your rights, email [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence. In the Netherlands the supervisory authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

8. Cookies

See our Cookie Policy at https://optigpu.ai/cookies. You can manage your preferences via the consent banner.

9. Children's data

We do not knowingly process personal data of persons under 16. If we discover such data we will delete it.

10. Security

We implement appropriate technical and organisational measures including TLS 1.2+ in transit, encryption at rest through managed hosting and database providers, MFA-protected administrative access, least-privilege access, redacted error monitoring, dependency and secret scanning, provider backup controls, and documented incident-response runbooks.

11. Changes

We may update this notice. Material changes will be notified to active customers by email.

12. Region-specific addenda

Switzerland

For the purposes of the Swiss FADP, OptiGPU is the controller. Swiss data subjects may exercise their rights via [email protected] and may lodge a complaint with the Federal Data Protection and Information Commissioner (edoeb.admin.ch).

California

If you are a California resident, you have rights under the CCPA/CPRA to know, access, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. OptiGPU does not sell personal information and does not share personal information for cross-context behavioural advertising. A "Do Not Sell or Share My Personal Information" link is provided in our website footer. We recognise the Global Privacy Control (GPC) signal as a valid opt-out request. To exercise your rights, email [email protected]. We will not discriminate against you for exercising your rights.

Canada

OptiGPU applies privacy controls for PIPEDA and, where applicable, Quebec Law 25. Our privacy officer is reachable at [email protected]. You may file a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Commission d'acces a l'information du Quebec.

Brazil

For LGPD purposes, OptiGPU is the controller. Brazilian data subjects have rights of confirmation, access, correction, anonymisation, portability, deletion, information about sharing, and revocation of consent. Contact [email protected] or the ANPD (gov.br/anpd).

Australia

OptiGPU is bound by the Australian Privacy Principles (APP). For complaints, contact [email protected] or the Office of the Australian Information Commissioner (oaic.gov.au).

Singapore

OptiGPU applies privacy controls for the PDPA. Our designated Data Protection Officer can be reached at [email protected]. Complaints may be filed with the Personal Data Protection Commission (pdpc.gov.sg).

Japan

OptiGPU applies privacy controls for APPI-covered personal data of persons in Japan. You may exercise rights of disclosure, correction, and suspension of use by emailing [email protected].