GDPR Compliance

Your data rights under the General Data Protection Regulation.

1. Data Controller

Opplon is the "Data Controller" for the personal data processed through its services. For any inquiries regarding your data, contact us at: legal@opplon.com.

2. Legal Basis for Processing (Art. 6 GDPR)

We process your data under the following legal bases:

Consent

When you voluntarily provide your email for the waitlist.

Contractual Necessity

To perform the certification service you request when capturing a photo.

Legitimate Interest

To ensure the security of our platform and prevent fraudulent certifications.

3. Your Rights as a Data Subject

Under the GDPR, you have the following rights:

Right of Access (Art. 15)

Obtain a copy of your personal data.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

Right to Erasure (Art. 17)

Request the "Right to be Forgotten" and have your data deleted.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests.

4. International Data Transfers (Art. 44-46)

Since our infrastructure providers (Supabase) may operate servers outside the European Economic Area (EEA), we ensure all transfers comply with European standards through Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring an equivalent level of data protection.

5. Supervisory Authority

You have the right to lodge a complaint with a data protection authority (e.g., CNIL in France, DPC in Ireland) if you believe our processing of your personal data violates GDPR regulations.

Your GDPR Rights Matter

To exercise any of your rights as a data subject, or to request access to your personal data, please contact us at legal@opplon.com. We will respond to your request within 30 days in accordance with GDPR timelines.