OptiSupply logo OPTISUPPLY / SUPPLIER INTELLIGENCE UNIT ← BACK TO SITE
DOCUMENT OS-LEGAL-01 · GDPR COMPLIANT

Privacy Policy

This policy explains how OptiSupply collects, uses, and protects your personal data. It applies to all visitors and users of optisupply.tech.

EFFECTIVE 13 June 2026 LAST UPDATED 13 June 2026 CONTROLLER OptiSupply JURISDICTION Portugal / EU (GDPR)
TABLE OF CONTENTS
  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Cookies & Analytics
  6. Data Retention
  7. Third Parties & Data Sharing
  8. International Transfers
  9. Your Rights Under GDPR
  10. Data Security
  11. Children's Privacy
  12. Changes to This Policy
  13. Contact & Complaints

Who We Are

OptiSupply ("we", "us", "our") is a supplier compliance intelligence company operating under Portuguese law. We provide CSRD-ready due diligence dossiers and ESG risk assessments for EU procurement teams.

For the purposes of the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679), OptiSupply is the data controller responsible for your personal data collected via optisupply.tech.

DETAILINFORMATION
CompanyOptiSupply
CountryPortugal
Websiteoptisupply.tech
Contact Emailcontact@optisupply.tech
Data Protection Contactcontact@optisupply.tech

Data We Collect

2.1 — Data You Provide Directly

When you submit a supplier vetting request or contact us via our website form, we may collect:

2.2 — Data Collected Automatically

When you visit optisupply.tech, we automatically collect limited technical data including:

This data is collected via Google Analytics 4 and is used solely for aggregate site analytics. We do not use it to identify you personally.

2.3 — Data We Do Not Collect

We do not collect sensitive personal data (health, ethnicity, religion, political opinions), financial account numbers, government IDs, or passwords. We do not build personal profiles of website visitors.

How We Use Your Data

PURPOSEDATA USEDLEGAL BASIS
Responding to your supplier vetting request Name, email, company, supplier name/VAT Contract / Legitimate interest
Sending your completed due diligence report Business email address Contract performance
Improving our website and services Anonymised analytics data Legitimate interest
Analytics and traffic measurement Cookies, IP (anonymised), device/browser data Consent
Legal compliance and fraud prevention Any data relevant to the obligation Legal obligation

We will never sell, rent, or trade your personal data to third parties for their own marketing purposes.

Legal Basis for Processing

Under GDPR Article 6, we rely on the following legal bases:

Cookies & Analytics

We use cookies — small text files stored on your device — to make our website function and to understand how visitors use it. Our cookie banner allows you to accept or decline non-essential cookies.

COOKIETYPEPURPOSEDURATION
os_cookie_consent Essential Stores your cookie consent preference 1 year (localStorage)
_ga Analytics Google Analytics — distinguishes unique users 2 years
_ga_* Analytics Google Analytics 4 — session tracking 2 years
_gid Analytics Google Analytics — session identification 24 hours
Google Analytics 4: We use GA4 with IP anonymisation enabled. Google may process data in the USA under EU Standard Contractual Clauses. You can opt out at any time via our cookie banner or by using the Google Analytics Opt-out Browser Add-on.

Declining analytics cookies will not affect your ability to use the website. Essential cookies (like consent storage) cannot be disabled as they are necessary for the site to function.

Data Retention

We retain personal data only for as long as necessary for the purposes described in this policy:

DATA TYPERETENTION PERIODREASON
Supplier vetting request data3 years from date of requestService delivery, legal compliance
Email correspondence3 years from last contactLegitimate business records
Analytics data (GA4)14 months (GA4 default)Site performance analysis
Cookie consent records1 yearGDPR compliance audit trail
Financial / invoicing records10 yearsPortuguese tax law obligation

When data is no longer needed, it is securely deleted or anonymised so that it can no longer be attributed to any individual.

Third Parties & Data Sharing

We share your data with the following trusted service providers, strictly for the purposes described:

PROVIDERPURPOSELOCATIONSAFEGUARD
Google LLC Analytics (GA4) USA / EU EU Standard Contractual Clauses
Vercel Inc. Website hosting & CDN USA / EU Data Processing Agreement
GitHub Inc. Source code repository USA Standard Contractual Clauses

We do not share your data with any other third parties unless required to do so by law, court order, or to protect the rights, safety, or property of OptiSupply or others.

International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:

You can obtain a copy of the relevant safeguards by contacting us at contact@optisupply.tech.

Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at contact@optisupply.tech. We will respond within 30 days.

RIGHT OF ACCESS

Request a copy of the personal data we hold about you (Art. 15).

RIGHT TO RECTIFICATION

Ask us to correct inaccurate or incomplete data (Art. 16).

RIGHT TO ERASURE

Request deletion of your data ("right to be forgotten") where it is no longer needed (Art. 17).

RIGHT TO RESTRICTION

Ask us to restrict processing of your data in certain circumstances (Art. 18).

RIGHT TO PORTABILITY

Receive your data in a structured, machine-readable format (Art. 20).

RIGHT TO OBJECT

Object to processing based on legitimate interest, including for direct marketing (Art. 21).

RIGHT TO WITHDRAW CONSENT

Withdraw consent for analytics cookies at any time via our cookie banner. Withdrawal does not affect prior processing.

RIGHT TO COMPLAIN

Lodge a complaint with the Portuguese data protection authority (CNPD) if you believe your rights have been violated.

Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration, including:

No method of transmission over the internet is 100% secure. In the event of a data breach that is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

Children's Privacy

Our website and services are directed exclusively at business professionals and are not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately at contact@optisupply.tech.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will update the "Last Updated" date at the top of this page.

We encourage you to review this policy periodically. Continued use of our website following any changes constitutes your acknowledgement of the updated policy.

Contact & Complaints

For any questions about this Privacy Policy, to exercise your rights, or to raise a data protection concern, please contact us:

DATA CONTROLLER CONTACT

OptiSupply

EMAIL — contact@optisupply.tech

WEBSITE — optisupply.tech

COUNTRY — Portugal, European Union

If you are not satisfied with our response, you have the right to lodge a complaint with the Portuguese data protection authority: CNPD — Comissão Nacional de Proteção de Dados (cnpd.pt)