Privacy Policy

Last updated: 20 August 2026

This Privacy Policy describes how Opsly ("we", "us", "Opsly") collects, uses and protects personal data when our clinic clients use the Opsly platform at opsly.ie. It is written for transparency under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

1. Data Controller

Opsly (trading from Ireland) operates opsly.ie. For data we process on behalf of a clinic (patient contact details, appointments, conversations) Opsly acts as a data processor; the clinic is the data controller. For account, billing and platform usage data Opsly acts as the data controller.

Contact for privacy queries: admin@opsly.ie.

2. Data we collect

3. How we use the data

4. Lawful basis

We process patient data under the clinic's lawful basis (typically contract or legitimate interest for appointment management, and consent for marketing communications). Account data is processed under our contract with the clinic.

5. Data retention

Patient conversation and appointment data is retained for the period configured by the clinic (default: 90 days) and then permanently deleted from active systems. Backups are rotated within 30 days. Account data is retained for the life of the customer relationship plus 12 months for legal/billing reasons.

6. Third-party processors (sub-processors)

The following processors help us deliver the service. Each is bound by a data processing agreement:

7. International transfers

Where a processor is established outside the EEA we rely on Standard Contractual Clauses and equivalent safeguards.

8. Your rights

Patients of an Opsly-connected clinic can exercise their GDPR rights (access, rectification, erasure, restriction, portability, objection) by contacting their clinic directly. The clinic will forward the request to us where Opsly processing is involved. Clinic users can contact admin@opsly.ie at any time.

You also have the right to lodge a complaint with the Irish Data Protection Commission (dataprotection.ie).

9. Security

Data in transit is encrypted with TLS. Data at rest is encrypted by the underlying infrastructure providers. Access to production data is restricted to authorised Opsly personnel and logged.

10. Changes

We may update this policy from time to time. Material changes will be notified to clinic account owners by email.

Contact: admin@opsly.ie