Privacy Policy
Last updated: 20 August 2026
This Privacy Policy describes how Opsly ("we", "us", "Opsly") collects, uses and protects personal data when our clinic clients use the Opsly platform at opsly.ie. It is written for transparency under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1. Data Controller
Opsly (trading from Ireland) operates opsly.ie. For data we process on behalf of a clinic (patient contact details, appointments, conversations) Opsly acts as a data processor; the clinic is the data controller. For account, billing and platform usage data Opsly acts as the data controller.
Contact for privacy queries: admin@opsly.ie.
2. Data we collect
- Patient contact details — name, phone number, email address submitted via the booking widget or imported by the clinic.
- Appointment records — date, time, service, status, internal notes added by the clinic.
- Conversation logs — SMS, web chat and email exchanges between the patient, the clinic and the Opsly AI assistant.
- Clinic account data — staff names, email addresses, role, sign-in events.
- Technical data — IP address, browser type, error/performance logs used to operate the service securely.
3. How we use the data
- Manage bookings, reminders, recalls and waitlists on behalf of the clinic.
- Send SMS and email confirmations, reminders and missed-call recovery messages to patients.
- Generate weekly performance reports for the clinic owner.
- Provide AI-assisted replies in the inbox and booking widget.
- Secure the platform, prevent abuse and meet legal obligations.
4. Lawful basis
We process patient data under the clinic's lawful basis (typically contract or legitimate interest for appointment management, and consent for marketing communications). Account data is processed under our contract with the clinic.
5. Data retention
Patient conversation and appointment data is retained for the period configured by the clinic (default: 90 days) and then permanently deleted from active systems. Backups are rotated within 30 days. Account data is retained for the life of the customer relationship plus 12 months for legal/billing reasons.
6. Third-party processors (sub-processors)
The following processors help us deliver the service. Each is bound by a data processing agreement:
- Supabase — database, authentication, file storage (EU region).
- Google — Google Calendar API for appointment sync and Google OAuth sign-in.
- Twilio — SMS delivery and inbound SMS handling.
- Cloudflare — application hosting, DNS and DDoS protection.
- Lovable — transactional email delivery from
notify.opsly.ie.
7. International transfers
Where a processor is established outside the EEA we rely on Standard Contractual Clauses and equivalent safeguards.
8. Your rights
Patients of an Opsly-connected clinic can exercise their GDPR rights (access, rectification, erasure, restriction, portability, objection) by contacting their clinic directly. The clinic will forward the request to us where Opsly processing is involved. Clinic users can contact admin@opsly.ie at any time.
You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).
9. Security
Data in transit is encrypted with TLS. Data at rest is encrypted by the underlying infrastructure providers. Access to production data is restricted to authorised Opsly personnel and logged.
10. Changes
We may update this policy from time to time. Material changes will be notified to clinic account owners by email.
Contact: admin@opsly.ie