ISO 27001 Compliant

Privacy Policy

We are committed to protecting your personal data and being transparent about how we collect, use, and safeguard your information.

Last updated: February 22, 2026 · Effective: February 22, 2026

1. Data Controller

Company

Datatent B.V. (trading as OptiStack)
Amsterdam, Netherlands
Chamber of Commerce: pending registration

Data Protection Officer

Email: dpo@optistack.com
Response time: Within 5 business days
For all privacy-related inquiries

2. Personal Data We Collect

We collect and process the following categories of personal data, each with a specific legal basis under GDPR Article 6.

CategoryData CollectedPurposeRetentionLegal Basis
Account InformationName, email address, company name, job titleAccount creation, authentication, communicationDuration of account + 30 days after deletionContract performance (Art. 6(1)(b))
Usage DataLogin timestamps, feature usage, page views, session durationService improvement, analytics, support24 months from collectionLegitimate interest (Art. 6(1)(f))
Technical DataIP address, browser type, device info, OS versionSecurity monitoring, troubleshooting, fraud prevention12 months from collectionLegitimate interest (Art. 6(1)(f))
Connected Platform MetadataCloud resource configurations, query metadata, cost dataCost analysis, optimization recommendationsDuration of account + 90 daysContract performance (Art. 6(1)(b))
Billing InformationPayment method details, billing address, invoicesPayment processing, invoicing, tax compliance7 years (legal obligation)Legal obligation (Art. 6(1)(c))
Communication DataSupport tickets, emails, feedback submissionsCustomer support, service improvement36 months from last interactionLegitimate interest (Art. 6(1)(f))

3. Your Data Subject Rights

Under GDPR, you have the following rights regarding your personal data. To exercise any right, contact us at privacy@optistack.com.

Right of Access

Request a copy of all personal data we hold about you. We will respond within 30 days of your verified request.

Art. 15 GDPR

Right to Rectification

Request correction of inaccurate personal data or completion of incomplete data without undue delay.

Art. 16 GDPR

Right to Erasure

Request deletion of your personal data when it is no longer necessary for the purpose it was collected ("right to be forgotten").

Art. 17 GDPR

Right to Data Portability

Receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV).

Art. 20 GDPR

Right to Restriction

Request restriction of processing while we verify accuracy of your data or assess our legitimate interests.

Art. 18 GDPR

Right to Object

Object to processing based on legitimate interests, including profiling and direct marketing at any time.

Art. 21 GDPR

4. International Data Transfers

OptiStack primarily processes and stores personal data within the European Economic Area (EEA). Where we transfer data outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): EU Commission-approved clauses in all data transfer agreements with non-EEA processors.
  • Adequacy Decisions: We prioritize processors in countries with EU adequacy decisions where possible.
  • Transfer Impact Assessments: We conduct TIAs for all international transfers to assess the level of protection in the recipient country.
  • Supplementary Measures: Encryption in transit (TLS 1.3) and at rest (AES-256) for all transferred data.

5. Sub-Processors

We engage the following third-party processors. We notify customers of sub-processor changes at least 30 days in advance.

Sub-ProcessorPurposeLocationSafeguards
Microsoft AzureCloud infrastructure hostingEU (West Europe)EU data residency
VercelFrontend hosting and CDNGlobal (edge network)SCCs + DPA
StripePayment processingUSASCCs + PCI DSS Level 1
Azure Communication ServicesTransactional email deliveryEU (West Europe)EU data residency
SentryError tracking and monitoringUSASCCs + DPA

6. Cookies & Tracking

We use strictly necessary cookies for authentication and security. Optional analytics and functional cookies are only set with your explicit consent. For full details on cookies we use and how to manage your preferences, see our Cookie Policy.

7. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:

  • We will notify you via email at least 30 days before changes take effect.
  • A prominent notice will be displayed in the OptiStack dashboard.
  • The "Last updated" date at the top of this page will be revised.
  • Where required by law, we will obtain your renewed consent.

Privacy Questions?

If you have questions about this policy or wish to exercise your data subject rights, contact our Data Protection Officer.

Email: dpo@optistack.com · Response within 5 business days