Privacy Policy

Last updated: June 30, 2026

Welcome to Optower. Optower ("Optower", "we", "our", or "us") is committed to protecting your privacy and processing personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Optower platform, APIs, applications, and related services (collectively, the "Services").

1. Data Controller

The data controller is:

Optower
Email: privacy@optower.com

2. Scope

This Privacy Policy applies to:

  • Visitors of our platform
  • Customers
  • Trial users
  • Authorized users of customer organizations
  • Individuals communicating with us
  • Business partners

3. Personal Data We Collect

Information You Provide

  • Full name
  • Business email address
  • Company name
  • Job title
  • Phone number
  • Country
  • Account credentials
  • Customer support communications

Information Generated While Using Optower

  • User ID and workspace information
  • Audit logs and login history
  • Uploaded files, security questionnaires, and documentation
  • AI prompts and AI-generated responses
  • Policies, procedures, and supporting evidence
  • User activity logs

Technical Information

  • IP address
  • Browser type and operating system
  • Device identifiers
  • Time zone and session identifiers
  • Cookies and usage analytics

4. Special Categories of Data

Optower is not intended to process special categories of personal data under Article 9 GDPR unless explicitly uploaded by the customer. Customers remain solely responsible for determining which information is uploaded into the platform.

5. Purpose of Processing

We process personal data to:

  • Create and authenticate user accounts
  • Provide the Services, including processing questionnaires and building knowledge bases
  • Generate AI-assisted responses and recommend supporting evidence
  • Identify security gaps and recommend remediation activities
  • Provide customer support and improve platform functionality
  • Detect fraud, abuse, and secure the platform
  • Comply with legal obligations

6. Legal Basis for Processing

Depending on the circumstances, we process personal data under one or more of the following legal bases:

  • Performance of a contract (Article 6(1)(b) GDPR)
  • Legitimate interests (Article 6(1)(f) GDPR)
  • Compliance with legal obligations (Article 6(1)(c) GDPR)
  • Consent where required (Article 6(1)(a) GDPR)

7. AI Processing

Optower uses AI to parse questionnaires, classify questions, detect semantically similar questions, search historical responses, generate suggested answers, recommend supporting evidence, identify security gaps, and recommend remediation actions.

AI-generated content is intended solely as decision-support information. Customers remain solely responsible for reviewing, validating, approving, and submitting all responses. Optower does not make automated legal, security, compliance, procurement, or business decisions on behalf of customers.

8. Customer Data

Customers may upload security questionnaires, vendor assessments, RFI, RFP, DDQ, CAIQ, SIG Lite, policies, procedures, risk assessments, penetration test reports, certifications, architecture documentation, and compliance evidence.

Customers retain all ownership rights to their uploaded content. Optower processes customer data solely for providing the Services.

9. Data Retention

We retain personal data only for as long as necessary to provide the Services, maintain customer workspaces, comply with legal obligations, resolve disputes, and enforce contractual rights.

Customers may delete questionnaires, knowledge base entries, uploaded documents, and user accounts. Deleted data will be removed in accordance with our retention procedures.

10. Data Sharing

Optower does not sell personal data. We may share personal data only with:

  • Cloud hosting providers
  • Authentication providers
  • AI service providers
  • Payment providers
  • Customer support providers
  • Professional advisers
  • Government authorities where legally required

All service providers are contractually required to protect customer data and maintain appropriate confidentiality and security measures.

11. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), Optower ensures appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs), Adequacy Decisions, and other lawful transfer mechanisms under GDPR.

12. Information Security

Optower implements appropriate technical and organizational security measures, including:

  • Encryption in transit (TLS) and at rest
  • Multi-factor authentication
  • Role-Based Access Control (RBAC)
  • Audit logging and security monitoring
  • Secure software development lifecycle
  • Vulnerability management and regular security testing
  • Least privilege access

13. Customer Responsibilities

Customers are responsible for:

  • Ensuring they have lawful authority to upload data
  • Managing user permissions
  • Reviewing AI-generated responses
  • Maintaining account security and protecting login credentials

14. Cookies

Optower uses cookies and similar technologies to maintain authenticated sessions, improve platform performance, analyze platform usage, and remember user preferences. Where required by applicable law, users may manage cookie preferences through our cookie consent mechanism.

15. Data Subject Rights

Individuals located within the European Economic Area have the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restriction of processing
  • Right to object
  • Right to data portability
  • Right to withdraw consent
  • Right to lodge a complaint with a supervisory authority

Requests may be submitted to: privacy@optower.com

16. Children's Privacy

Optower is designed exclusively for business and enterprise users. We do not knowingly collect personal information from individuals under the age of 16.

17. Third-Party Services

Our Services may integrate with third-party providers including identity providers, cloud hosting providers, AI service providers, collaboration platforms, and analytics providers. Each third-party provider maintains its own privacy policy and terms.

18. Data Processing Agreement

For customers acting as Data Controllers under GDPR, Optower provides a Data Processing Agreement (DPA) governing the processing of personal data on behalf of customers.

19. Confidentiality

All customer information, uploaded documents, questionnaires, AI prompts, generated responses, knowledge bases, and supporting evidence are treated as confidential. Access to customer information is limited to authorized personnel and subprocessors only where necessary to provide the Services.

20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or business practices. Where required, we will notify users of material changes through the platform or other appropriate communication channels. The "Last Updated" date at the top of this Privacy Policy indicates the latest revision.


21. Contact

If you have any questions about this Privacy Policy or want to exercise your privacy rights, reach us at: privacy@optower.com