OpiScope — Platform Privacy Policy
OpiScope — Platform Privacy Policy
Status: DRAFT Effective: [DATE] Version: 0.2 Last updated: 2026-08-311. Introduction
OpiScope ("we", "us", "our") is a multi-product platform for survey creation, management, directory listing, and research analysis. This Privacy Policy explains how we collect, use, store, and protect your personal data.
OpiScope is operated by ThePrimeContact, a Tunisian legal entity (or specify jurisdiction). We act as the data controller for platform-level personal data and as the data processor for certain product-level processing (see Section 7).
This policy applies to:
- Platform-level data — your account, authentication, billing, and platform usage
- All products built on OpiScope — each product has its own Privacy Notice that supplements this policy
2. Definitions
These terms are used throughout this policy and all OpiScope legal documents:
| Term | Definition |
|---|---|
| Controller (or "Data Controller") | The legal entity that determines the purposes and means of processing personal data, as defined in Art. 2 of Organic Law 2004-63. In our product interface, this is called "Organization." In our marketing materials, this is called "Publisher." |
| Organization | The product-interface term for the entity that owns surveys and acts as data controller. |
| Publisher | The marketing/commercial term for the Organization. |
| Org Owner | The natural person authorized to bind the Organization and accept legal documents on its behalf. |
| Team Member | An employee or agent of the Organization acting under its authority. |
| Survey Creator | A Team Member or the Org Owner with permission to create surveys on behalf of the Controller. |
| Processor | An entity that processes personal data on behalf of the Controller. OpiScope acts as Processor for product data. |
| Respondent | A natural person who participates in a survey by providing responses. |
| Personal Data | Any information relating to an identified or identifiable natural person (Art. 2, Organic Law 2004-63). |
| Sensitive Data | Data relating to health, religion, politics, race, union affiliation, genetic or biometric data (Arts. 47-49, Organic Law 2004-63). |
| Anonymized Data | Data that cannot identify any natural person by any means reasonably likely to be used. Anonymized data is NOT personal data and falls outside the scope of Organic Law 2004-63. |
| INPDP | Instance Nationale de Protection des Données Personnelles — Tunisia's national data protection authority. |
3. Scope
This Privacy Policy covers the OpiScope Platform — the common infrastructure that all products build on. Each product has its own Privacy Notice (linked in Section 10) that describes product-specific data handling.
| Layer | What's covered |
|---|---|
| Platform (this policy) | Account, authentication, billing, session, usage, support |
| Products (product-specific notices) | Survey data, directory data, mailing data, AI interpretation data |
By using any OpiScope product, you agree to both this Platform Privacy Policy AND the applicable Product Privacy Notice.
4. Data Controller Information
| Field | Detail |
|---|---|
| Controller | ThePrimeContact |
| Jurisdiction | Tunisia |
| Data Protection Authority | Instance Nationale de Protection des Données Personnelles (INPDP) |
| Applicable Law | Organic Law No. 2004-63 (Tunisia), and other applicable regulations |
| INPDP Declaration | [Registration number to be added after filing] |
5. Personal Data We Collect
5.1 Account Data
When you create an OpiScope account, we collect:
- Email address — used for authentication, notifications, and account recovery
- Name — displayed in the platform and communications
- Password — stored as a cryptographic hash; we cannot read it
- Avatar/profile image (optional) — displayed in the platform
5.2 Authentication & Session Data
- Session tokens — stored as secure, httpOnly cookies
- Login timestamps — for security monitoring
- IP address — for security and fraud prevention
- User agent — browser/device information for compatibility and security
5.3 Billing & Subscription Data
- Payment information — processed by our payment processor (Stripe); we do not store full card numbers
- Subscription plan — what products you have access to
- Billing address — for invoicing and tax compliance
- Payment history — for accounting and support
5.4 Usage Data
- Platform navigation — which features you access, when, and how often
- Product usage — which products you activate and use
- Error logs — technical errors for debugging and improvement
- Preferences — language, notification settings, display preferences
5.5 Support Data
- Support requests — emails, chat logs, and ticket content
- Feedback — surveys, feature requests, bug reports
5.6 Marketing Communications Data (with consent)
- Email engagement — opens, clicks (only if you opt in to marketing)
- Campaign responses — which campaigns you interact with
6. Legal Bases for Processing
| Purpose | Legal Basis | Retention |
|---|---|---|
| Account creation & authentication | Contract performance | Duration of account + 1 year |
| Billing & subscription management | Contract performance | Duration of account + 7 years (tax law) |
| Security monitoring (IP, logs) | Legitimate interest | 1 year |
| Platform improvement (analytics) | Legitimate interest (anonymized) | 2 years |
| Marketing communications | Consent | Until withdrawn |
| Legal compliance (tax, regulatory) | Legal obligation | As required by law |
| Support & customer service | Contract performance | 3 years after resolution |
7. How We Use Your Data
7.1 Providing the Platform
- Create and manage your account
- Authenticate your sessions
- Process subscriptions and billing
- Provide access to products you're entitled to
7.2 Security & Integrity
- Detect and prevent fraud, abuse, and unauthorized access
- Monitor for security incidents
- Enforce our Terms of Service
7.3 Improvement
- Analyze platform usage to improve features and UX
- Fix bugs and technical errors
- Develop new products and features
7.4 Communication
- Send transactional emails (account, billing, security)
- Send product updates and announcements
- Respond to support requests
- Send marketing communications (only with your consent)
7.5 Legal Compliance
- Comply with Tunisian and applicable international laws
- Respond to lawful requests from authorities
- Exercise or defend legal claims
8. Data Controller vs. Processor Roles
8.1 OpiScope as Data Controller
We are the data controller for:
- Account data (name, email, password hash)
- Billing and subscription data
- Platform usage data
- Session and authentication data
- Support communications
8.2 OpiScope as Data Processor
We act as the data processor for:
- Survey response data — when a Controller creates a survey, they are the data controller for respondent data; OpiScope processes on their behalf
- Directory listing data — survey metadata published to the directory is controlled by the Controller
- Product-specific data — each product defines its own controller/processor relationship in its Product Privacy Notice
8.3 OpiScope as Controller for Platform Operations
OpiScope acts as an independent data controller for:
- Platform infrastructure data — IP addresses, server logs, security data
- Insights production — when OpiScope processes anonymized/aggregated data to produce insights and analytics (see Section 8.4)
8.4 Insights Production from PublicSurveys
For PublicSurveys (surveys listed in OpiScopeDirectory), OpiScope co-owns the rights to anonymized/aggregated response data and processes it to produce insights, analytics, and research products.
Key distinction:- If data is truly anonymized (irreversible, no re-identification possible), it is NOT personal data and falls outside Organic Law 2004-63.
- If data is pseudonymized (can be re-identified with a key), it remains personal data and OpiScope may act as controller or joint controller for that processing.
8.5 Controller Chain (Delegated Surveys)
When a Controller (e.g., a bank) delegates survey creation to a third party (e.g., a consultant):
| Role | Legal status |
|---|---|
| Controller (e.g., the bank) | Data controller — files prior declaration, obtains authorizations, informs respondents |
| Consultant | If acting under Controller's instructions = processor. If adding own purposes = joint controller |
| OpiScope | Processor — processes data on behalf of the Controller |
9. Data Sharing & Third Parties
9.1 Subprocessors
We use the following categories of subprocessors to operate the platform:
| Category | Purpose | Examples |
|---|---|---|
| Cloud infrastructure | Hosting, storage, compute | [To be specified — e.g., AWS, Hetzner, OVH] |
| Payment processing | Subscription billing | Stripe |
| Email delivery | Transactional emails | [To be specified — e.g., Brevo, SendGrid] |
| Analytics | Platform improvement (anonymized) | [To be specified] |
| Support | Customer support | [To be specified — e.g., Chatwoot] |
| AI/ML | Product features (e.g., AskOpiScope) | [To be specified] |
All subprocessors are bound by Data Processing Agreements requiring appropriate protection. A current list is available at [URL] or upon request.
9.2 Legal Disclosures
We may disclose data when required by law:
- To comply with Tunisian legal obligations (INPDP, courts, tax authorities)
- To comply with lawful requests from public authorities
- To protect the rights, property, or safety of OpiScope, our users, or the public
- In connection with a merger, acquisition, or sale of assets (with notice to users)
9.3 We Do NOT
- Sell your personal data to third parties
- Share your data for third-party advertising
- Share your data for any purpose other than described here
10. Cross-Border Data Transfers
10.1 Data Location
Platform data is stored in [specify region — e.g., EU/EEA (Germany), Tunisia, or both]. The specific data residency depends on deployment configuration.
10.2 Transfer Mechanisms
When data is transferred outside Tunisia, INPDP authorization is ALWAYS required (Art. 52, Organic Law 2004-63). We use:
- INPDP authorization — mandatory for ALL transfers outside Tunisia
- Adequacy decisions — INPDP Decision No. 3 (2018) lists countries with adequate protection (includes EU/EEA). Even for adequate countries, INPDP authorization is still required.
- Standard Contractual Clauses (SCCs) — for transfers to countries without adequacy, as supplementary measures
- Explicit consent — for transfers where no other mechanism applies (with full information about risks)
10.3 Self-Hosted Deployments
If you deploy OpiScope on your own infrastructure, you are responsible for your own data residency and transfer compliance. We provide tools to help you configure data residency.
11. Product-Specific Privacy
Each OpiScope product has its own Privacy Notice that supplements this Platform Policy:
| Product | Privacy Notice |
|---|---|
| OpiScopeSurvey | [Link to Product Privacy Notice] |
| OpiScopeDirectory | [Link to Product Privacy Notice] |
| OpiScopeMailing | [Link to Product Privacy Notice — upcoming] |
| AskOpiScope | [Link to Product Privacy Notice — upcoming] |
- What product-specific data is collected
- The controller/processor relationship
- Product-specific retention periods
- Product-specific third-party sharing
12. Data Subject Rights
12.1 Under Tunisian Law (Organic Law 2004-63)
You have the right to:
- Information — know how your data is being processed
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Objection — object to processing, including direct marketing
- Withdraw consent — at any time, without affecting prior processing
12.2 Under GDPR (if you are in the EU/EEA)
You have the right to:
- Access — obtain a copy of your personal data
- Rectification — correct inaccurate or incomplete data
- Erasure ("right to be forgotten") — request deletion of your data
- Restriction — limit how we process your data
- Data portability — receive your data in a structured, machine-readable format
- Objection — object to processing, including direct marketing
- Automated decision-making — not be subject to decisions based solely on automated processing
12.3 How to Exercise Your Rights
- Email: [privacy@opiscope.com]
- In-platform: Account Settings → Privacy → Exercise Rights
- Postal mail: [ThePrimeContact address, Tunisia]
12.4 Complaints
If you believe your rights have been violated:
- Tunisia: File a complaint with INPDP — https://www.inpdp.tn/
- EU/EEA: File a complaint with your local Data Protection Authority
13. Data Retention
13.1 Platform Data
| Data Category | Retention Period | After Account Deletion |
|---|---|---|
| Account data (name, email) | Duration of account + 1 year | Deleted within 30 days |
| Billing records | Duration of account + 7 years (tax law) | Retained as required by law |
| Session logs | 1 year | Deleted within 30 days |
| Usage analytics | 2 years (anonymized) | Anonymized, not deletable |
| Support tickets | 3 years after resolution | Deleted within 30 days |
| Consent records | Duration of consent + 3 years | Retained as proof of consent |
13.2 Product Data
Product-specific retention periods are defined in each Product Privacy Notice.
13.3 Backup Data
Backups are retained for [specify — e.g., 30 days] and then automatically deleted. Data in backups is not available for routine access.
14. Security
14.1 Technical Measures
- Encryption in transit — TLS 1.3 for all data transmission
- Encryption at rest — AES-256 for stored data
- Password hashing — bcrypt/argon2 with salt
- Access controls — role-based access, principle of least privilege
- Monitoring — intrusion detection, anomaly detection
- Backups — encrypted, geographically distributed, regularly tested
14.2 Organizational Measures
- Security training — all staff trained on data protection
- Incident response — documented breach response plan
- Vendor management — subprocessors vetted and contractually bound
- Audits — regular security audits and penetration testing
15. Cookies & Tracking
15.1 Essential Cookies (always active)
| Cookie | Purpose | Duration |
|---|---|---|
| `session_id` | Authentication session | Session |
| `csrf_token` | Security (CSRF protection) | Session |
| `cookie_consent` | Remembers your cookie preferences | 1 year |
| `locale` | Language preference | 1 year |
15.2 Analytics Cookies (with consent)
| Cookie | Purpose | Duration |
|---|---|---|
| `_ga` | Google Analytics (usage patterns) | 2 years |
| `_gid` | Google Analytics (distinguish users) | 24 hours |
15.3 Marketing Cookies (with consent)
| Cookie | Purpose | Duration |
|---|---|---|
| `_li` | LinkedIn Insight Tag (campaign tracking) | 1 year |
15.4 Managing Cookies
- Cookie banner — choose which categories to accept
- Browser settings — block or delete cookies (may affect functionality)
- Do Not Track — we respect browser DNT signals where technically feasible
16. Children's Privacy
- The OpiScope platform is not directed at children under 16
- We do not knowingly collect personal data from children
- If you are a parent/guardian and believe your child has provided data, contact us immediately
- Products that may collect data from children (e.g., educational surveys) require verifiable parental consent and are governed by the applicable Product Privacy Notice
17. Account Statuses
OpiScope may assign the following statuses to your account:
| Status | Meaning | Effect on surveys | Effect on data |
|---|---|---|---|
| Active | Normal operation | Can create, publish, collect | Fully functional |
| In Review | Under investigation (e.g., after a flag) | Paused — no new responses | Preserved — not deleted |
| Suspended | Violation confirmed | Blocked | Retained per policy |
| Terminated | Permanent ban | Deleted | Deleted per retention rules |
18. Changes to This Policy
We may update this Privacy Policy from time to time.
- Material changes — we will notify you by email and in-platform notification at least 30 days before they take effect
- Non-material changes — we will update the "Last updated" date
- Continued use — after changes take effect, continued use constitutes acceptance
19. Contact
| Channel | Detail |
|---|---|
| [privacy@opiscope.com] | |
| Post | [ThePrimeContact address, Tunisia] |
| DPO | [dpo@opiscope.com] (if appointed) |
| Platform | Account Settings → Privacy → Contact |
For product-specific inquiries, contact the product team through the applicable Product Privacy Notice.
20. Governing Law
This Privacy Policy is governed by:
- Tunisian law — Organic Law No. 2004-63 and applicable regulations
- GDPR — for users in the EU/EEA, to the extent applicable
- Other local laws — where required by your jurisdiction
21. Territorial Application
This policy applies to processing by OpiScope as a controller or processor. Under Organic Law 2004-63, Tunisian law applies to:
- Processing carried out on Tunisian territory
- Processing by controllers established in Tunisia
This document is a draft. It must be reviewed by qualified Tunisian legal counsel before publication. It does not constitute legal advice.