Privacy Policy
Last updated: June 30, 2026
Welcome to Optower. Optower ("Optower", "we", "our", or "us") is committed to protecting your privacy and processing personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other applicable data protection laws.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Optower platform, APIs, applications, and related services (collectively, the "Services").
1. Data Controller
The data controller is:
Optower
Email: privacy@optower.com
2. Scope
This Privacy Policy applies to:
- Visitors of our platform
- Customers
- Trial users
- Authorized users of customer organizations
- Individuals communicating with us
- Business partners
3. Personal Data We Collect
Information You Provide
- Full name
- Business email address
- Company name
- Job title
- Phone number
- Country
- Account credentials
- Customer support communications
Information Generated While Using Optower
- User ID and workspace information
- Audit logs and login history
- Uploaded files, security questionnaires, and documentation
- AI prompts and AI-generated responses
- Policies, procedures, and supporting evidence
- User activity logs
Technical Information
- IP address
- Browser type and operating system
- Device identifiers
- Time zone and session identifiers
- Cookies and usage analytics
4. Special Categories of Data
Optower is not intended to process special categories of personal data under Article 9 GDPR unless explicitly uploaded by the customer. Customers remain solely responsible for determining which information is uploaded into the platform.
5. Purpose of Processing
We process personal data to:
- Create and authenticate user accounts
- Provide the Services, including processing questionnaires and building knowledge bases
- Generate AI-assisted responses and recommend supporting evidence
- Identify security gaps and recommend remediation activities
- Provide customer support and improve platform functionality
- Detect fraud, abuse, and secure the platform
- Comply with legal obligations
6. Legal Basis for Processing
Depending on the circumstances, we process personal data under one or more of the following legal bases:
- Performance of a contract (Article 6(1)(b) GDPR)
- Legitimate interests (Article 6(1)(f) GDPR)
- Compliance with legal obligations (Article 6(1)(c) GDPR)
- Consent where required (Article 6(1)(a) GDPR)
7. AI Processing
Optower uses AI to parse questionnaires, classify questions, detect semantically similar questions, search historical responses, generate suggested answers, recommend supporting evidence, identify security gaps, and recommend remediation actions.
AI-generated content is intended solely as decision-support information. Customers remain solely responsible for reviewing, validating, approving, and submitting all responses. Optower does not make automated legal, security, compliance, procurement, or business decisions on behalf of customers.
8. Customer Data
Customers may upload security questionnaires, vendor assessments, RFI, RFP, DDQ, CAIQ, SIG Lite, policies, procedures, risk assessments, penetration test reports, certifications, architecture documentation, and compliance evidence.
Customers retain all ownership rights to their uploaded content. Optower processes customer data solely for providing the Services.
9. Data Retention
We retain personal data only for as long as necessary to provide the Services, maintain customer workspaces, comply with legal obligations, resolve disputes, and enforce contractual rights.
Customers may delete questionnaires, knowledge base entries, uploaded documents, and user accounts. Deleted data will be removed in accordance with our retention procedures.
10. Data Sharing
Optower does not sell personal data. We may share personal data only with:
- Cloud hosting providers
- Authentication providers
- AI service providers
- Payment providers
- Customer support providers
- Professional advisers
- Government authorities where legally required
All service providers are contractually required to protect customer data and maintain appropriate confidentiality and security measures.
11. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), Optower ensures appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs), Adequacy Decisions, and other lawful transfer mechanisms under GDPR.
12. Information Security
Optower implements appropriate technical and organizational security measures, including:
- Encryption in transit (TLS) and at rest
- Multi-factor authentication
- Role-Based Access Control (RBAC)
- Audit logging and security monitoring
- Secure software development lifecycle
- Vulnerability management and regular security testing
- Least privilege access
13. Customer Responsibilities
Customers are responsible for:
- Ensuring they have lawful authority to upload data
- Managing user permissions
- Reviewing AI-generated responses
- Maintaining account security and protecting login credentials
14. Cookies
Optower uses cookies and similar technologies to maintain authenticated sessions, improve platform performance, analyze platform usage, and remember user preferences. Where required by applicable law, users may manage cookie preferences through our cookie consent mechanism.
15. Data Subject Rights
Individuals located within the European Economic Area have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
Requests may be submitted to: privacy@optower.com
16. Children's Privacy
Optower is designed exclusively for business and enterprise users. We do not knowingly collect personal information from individuals under the age of 16.
17. Third-Party Services
Our Services may integrate with third-party providers including identity providers, cloud hosting providers, AI service providers, collaboration platforms, and analytics providers. Each third-party provider maintains its own privacy policy and terms.
18. Data Processing Agreement
For customers acting as Data Controllers under GDPR, Optower provides a Data Processing Agreement (DPA) governing the processing of personal data on behalf of customers.
19. Confidentiality
All customer information, uploaded documents, questionnaires, AI prompts, generated responses, knowledge bases, and supporting evidence are treated as confidential. Access to customer information is limited to authorized personnel and subprocessors only where necessary to provide the Services.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or business practices. Where required, we will notify users of material changes through the platform or other appropriate communication channels. The "Last Updated" date at the top of this Privacy Policy indicates the latest revision.
21. Contact
If you have any questions about this Privacy Policy or want to exercise your privacy rights, reach us at: privacy@optower.com