OpalSpan: privacy and device-storage information
Version: privacy-en-2026-09-28-v4. Language: English.
Identity and purposes
Ready IT ApS, CVR 38769383, c/o Matt Luccas Phaure Jensen, Viften 18, 1. 1, 2670 Greve, Denmark; contact@readyit.dk; telephone +45 22 76 54 06.
Ready IT is controller for its own account administration, service security, billing and required business records. Where it processes customer technical-work data on a customer's behalf, that customer determines the processing instructions and the applicable processing agreement governs Ready IT's role. Where the customer is itself a processor, Ready IT acts within that authorised processing chain. Not every flow has the same controller.
| Controller purpose | Information and legal basis |
|---|---|
| Sign-in, workspace administration and delivery of your subscription | Identity-provider identifier, name/email, membership, role, workspace and order details. GDPR Article 6(1)(b) for a contract with the individual or requested pre-contract steps; Article 6(1)(f) for managing business-customer users and contacts, in the legitimate interests of delivering and administering the authorised service. |
| Protecting access and investigating misuse or service incidents | Authentication and access metadata, device/session identifiers, times, access outcomes and relevant incident reports. Article 6(1)(f), in the legitimate interests of protecting systems, customer data and service reliability and establishing what occurred. |
| Usage administration, payment reconciliation and support | Usage quantities, model/rate references, order/payment references, contact details and correspondence. Article 6(1)(b) where needed for the individual's contract; Article 6(1)(f) for business-account administration, support, reconciliation and resolving disputes. |
| Required accounting, tax and consumer-contract records | Invoice/buyer details, tax information where applicable, payment/refund records, agreement copies, acceptance and rights-request records. Article 6(1)(c) where retention or processing is required by law. Necessary records for legal claims may also be retained under Article 6(1)(f). |
Sign-in identity and access information are needed to provide authenticated service. The information necessary for the order, receipt and payment is needed to complete a purchase and provide its records. Without it Ready IT cannot complete those functions. Optional case content, device evidence and AI context depend on the work you choose to perform; omitting them can limit that work. Do not supply information unrelated to the requested task.
Information comes from you, your authorised workspace users and administrators, Auth0 sign-in, Stripe payment events, and the devices, files and technical evidence selected for authorised work. Customer contacts and people mentioned in case material may therefore be recorded indirectly by a customer or technician, rather than supplying the information themselves. These technical-work sources are customer-supplied or authorised device/workspace material, not a general public-record collection service.
OpalSpan Mech assists technical work; it is not offered as a system for making legally significant decisions about people. Automated access and credit checks enforce the selected service permissions and allowance. They are not an assessment of a person's creditworthiness.
Data and recipients
Depending on the features used, OpalSpan processes account and membership details, customer/contact/company records, case notes and drafts, device links and selected diagnostic/technical-work information. Hosted AI processes supplied context, conversation history and tool evidence through OpenAI.
Conversation history may span cases and devices; authorised workspace use is not confined to one chat folder. Material in another chat is not thereby private from other authorised workspace use. Access audit is metadata, not a recording of every command or transferred file. Conversation and case records can separately contain technical content.
| Recipient | Function and relevant information |
|---|---|
| AWS | Bridge hosting/operations in Lightsail eu-north-1, Stockholm, and the CloudFront front door; hosted service data and request metadata relevant to those functions. |
| Auth0 | Authentication and identity services; sign-in identifiers, identity/contact attributes and authentication metadata. OpalSpan separately controls workspace membership and access. |
| Stripe | Hosted Checkout, payment processing, invoices/history and customer details; buyer/payment information and subscription/payment references. Stripe also processes information for its own payment, fraud-prevention and legal obligations. |
| OpenAI | API model processing for hosted OpalSpan Mech; selected conversation/context and tool evidence, usage and request metadata. |
| Microsoft 365 / Microsoft Graph | The existing contact mailbox and delivery of contract/rights confirmations: recipient address, message content, fixed document attachments and delivery metadata. Messages may also remain in the mailbox's Sent Items. The recipient's own mail provider receives mail addressed to that recipient. |
Suppliers' roles depend on the processing concerned; inclusion here does not make every supplier a subprocessor for every data item. Disclosure to authorities or professional advisers may also be required for an applicable legal obligation or necessary legal claim.
Stripe supplies invoices and payment receipts separately from OpalSpan's contract and rights confirmations.
International processing
The Stockholm Bridge region does not establish EU-only processing. CloudFront has an international edge network; identity, payments, AI and email involve separate supplier processing and access arrangements.
AWS supplies the Stockholm hosting and international edge services under Ready IT's ordinary AWS account terms. The applicable AWS data-processing terms and standard contractual clauses are incorporated through those terms for the transfers they cover.
Hosted Mech uses OpenAI Ireland Ltd. under the ordinary OpenAI Services Agreement, updated 1 December 2025 and effective 1 January 2026. Section 5.3 incorporates OpenAI's DPA. Ready IT's API project uses Global residency and the Standard service tier, not an EU-only route. DPA section 4.1 provides for onward transfers from the EEA under agreements containing standard contractual clauses or an applicable GDPR Article 45 adequacy decision. See https://openai.com/policies/services-agreement/ and https://openai.com/policies/data-processing-addendum/.
Microsoft 365 Exchange Online and Graph are governed by the ordinary Microsoft agreement and incorporated Products and Services DPA. Microsoft's May 2026 DPA provides for processing in the United States and other countries where Microsoft or its subprocessors operate, subject to its stated location commitments. Its Data Transfers section applies the 2021 standard contractual clauses to transfers out of the EEA; the described transfer arrangement includes Microsoft Ireland Operations Limited and Microsoft Corporation. The DPA also records Microsoft's Data Privacy Framework commitments. This is not a claim that all mail processing stays in the EU. The DPA is available through https://www.microsoft.com/licensing/docs/view/Microsoft-Products-and-Services-Data-Protection-Addendum-DPA.
Auth0, supplied by Okta, processes sign-in identity and authentication data from an EU tenant. OpalSpan separately controls workspace membership and access. Supplier support and onward processing may occur outside the EEA. Okta's published processing and transfer information is available at https://www.okta.com/legal/trustandcompliance/.
Contact contact@readyit.dk to request information about the applicable transfer safeguards or a copy of the relevant safeguards.
Hosted AI retention
OpalSpan keeps conversation history for the authorised workspace. Hosted Mech sends relevant context and tool evidence to OpenAI's API to answer and carry out requested work. Stored Responses output is disabled, and Ready IT has not opted API inputs or outputs into model training, feedback or evaluation sharing. When you request hosted Python analysis, OpalSpan sends the selected conversation file and analysis question to an isolated OpenAI Code Interpreter container. OpalSpan returns the finding and any generated files to the same private conversation and requests deletion of the container after the run. Failed deletion is retried; OpenAI expires a container after 20 minutes without activity. OpenAI's separate API retention described below still applies. OpenAI may retain data for abuse monitoring for up to 30 days by default, or longer where its published terms permit, and encrypted prompt-cache state for up to 24 hours. These provider periods are separate from OpalSpan's own records; the service does not claim zero retention or EU-only processing. See https://developers.openai.com/api/docs/guides/your-data.
Retention
| Information | Retention period or criteria |
|---|---|
| Account and workspace administration | Kept while needed for the active account, memberships and service, then subject to applicable erasure, legal-record and dispute requirements. Cancelling a paid plan and returning to Free does not close the workspace or delete its records. |
| Customer directory, cases and conversation history | Kept for continuing authorised workspace work and case history. Directory/case records have no general automatic expiry timer. Closing a case or stopping payment is not an erasure instruction. For on-behalf processing, return/deletion follows the customer's instructions and the processing agreement. |
| Access-session/audit metadata | Ended access periods and ordinary audit metadata are removed according to the workspace's audit-retention setting, which defaults to 90 days. Cleanup runs in batches, so removal may occur after the configured period. Active periods and separately retained release, acceptance or other required evidence have different lifetimes. |
| Mistake History | An append-only accountability record without automatic expiry. Continued retention depends on the accountability/incident or legal-record purpose; applicable correction, erasure and restriction rights remain. |
| Mech files | Temporary scratch files expire after seven days of inactivity by default, with cleanup at startup and daily. Active runs can protect files from expiry; retained files follow their own policy. File removal does not remove a conversation or required financial record. |
| Usage, contract and financial records | Kept for reconciliation, required accounting/tax and contract evidence, and necessary dispute or legal-hold periods. Quantities and payment references may outlive conversation payloads; they do not require keeping every prompt. |
| Contact and confirmation email | Kept while needed to handle the enquiry, establish the contract or rights request, and meet associated legal-record/dispute requirements. Copies can remain with the recipient's mail provider. |
| Provider logs/application state | Subject to the relevant supplier flow; the OpenAI limits above are separate from OpalSpan's own records. |
| Recovery copies | Automatic service snapshots retain the latest seven daily generations. Separate manual recovery copies have no automatic expiry and are reviewed individually. During ongoing service, a copy may remain after live data is removed. A return or deletion request includes relevant recovery copies; any legally required retention exception is explained. Before restored data is returned to use, completed deletion and restriction instructions are reconciled. |
For access, correction, return, deletion or restriction requests, Ready IT verifies the requester's authority and the affected workspace and records. Live service data, recovery copies and records held for legal obligations may need different treatment. Ready IT records the action and explains any remaining copies or exceptions for the specific request. Cancelling renewal or removing access does not itself delete records. Contact contact@readyit.dk; requests about customer-controlled data are handled with the relevant controller.
Rights and complaints
Where applicable, you may request access, correction, erasure, restriction or portability and object to processing. Where consent is the basis, you may withdraw it without affecting the lawfulness of earlier processing. The relevant conditions and exceptions apply. Contact contact@readyit.dk; a request concerning customer-controlled data is handled with the relevant controller.
You may complain to the Danish Data Protection Agency, Datatilsynet, https://www.datatilsynet.dk/, or another competent supervisory authority.
Cookies and similar technologies
OpalSpan uses an authentication cookie to provide signed-in access. The protected authentication ticket has a fourteen-day lifetime with sliding renewal enabled; continued use can renew it. This is not a promise that every session ends after fourteen days. OpalSpan does not request a persistent browser-cookie expiry for this sign-in path. Browser handling, including session restoration, is separate from the ticket's validity.
Short-lived nonce and correlation cookies protect the sign-in exchange and expire after approximately fifteen minutes. Those are OpalSpan's sign-in cookies, not a description of Auth0's separate SSO cookies. These authentication and challenge operations enable the requested sign-in and its security.
The workspace-selection cookie __Host-ForgeWorkspace remembers your selected
workspace for up to 30 days; the invitation-handoff cookie
__Host-ForgeInvitation lasts up to 20 minutes. These cookies are operated by
Ready IT, protected, Secure and HttpOnly; they do not themselves grant access.
Their technical names remain unchanged during the OpalSpan transition.
The workspace interface also uses local storage to remember your explicitly chosen Simple/Advanced view. This preference has no automatic browser-storage expiry; you can change the view or clear site storage. Enrollment uses session storage to recover the requested enrollment journey, with a progress record identifier rather than a raw enrollment code; it is removed explicitly or with the browser tab/session. Refusing that storage prevents this recovery function. These operations support the requested view or enrollment journey, not advertising. A requested preference does not make unrelated tracking necessary.
Auth0's sign-in journey and Stripe's hosted payment journey operate their own device-storage technologies. Auth0 describes its session, sign-in security, device/attack-protection and, where used, multi-factor cookies at https://auth0.com/docs/manage-users/cookies/authentication-api-cookies. The Auth0 tenant's default session policy is persistent. Persistent sessions have a three-day idle timeout and a seven-day maximum; nonpersistent sessions have a one-day idle timeout and a three-day maximum. These are server-side session limits, not a promise that browser storage is physically erased on the same timetable. They are distinct from OpalSpan's own authentication ticket.
Stripe describes its payment/security and other storage categories at https://stripe.com/legal/cookies-policy, with individual cookie purposes, durations and available consent choices at https://stripe.com/cookie-settings. Stripe's wider website policy is not a claim that every listed analytics or advertising cookie operates in Checkout.
The OpalSpan Agent CLI stores a protected sign-in credential on the technician's device so the authorised user can return without signing in for every command. The current user's Windows Credential Manager protects it on Windows; Linux uses the configured Secret Service or protected-key store. Logging out removes the local profile credential and cache, but does not itself delete server records or revoke every token held by another process.
The browser product uses opalspan.com; installed Agent CLI and device clients
continue to use forge.readyit.dk as a compatible service endpoint.
Native clients also keep configuration and authorised-device state separately.
Clearing browser state does not clear that native state or delete server
records.