Global Privacy Policy

A transparent overview of how Opintell secures, processes, and respects the privacy of your users and the highly sensitive operational data you upload to our platform.

Last Updated: July 2026

1. Scope of Operational Data Collection

At Opintell, we distinguish between standard Personal Identifiable Information (PII) and Industrial Operational Data (IOD). PII collected is strictly limited to the absolute minimum necessary for enterprise authentication: names, corporate email addresses, and secure hashed passwords. This data is handled exclusively by our specialized authentication provider, Supabase, ensuring industry-standard identity protection.

The core of our platform revolves around your Industrial Operational Data: the PDFs, machine schematics, text files, and standard operating procedures you upload.This data is collected solely for the purpose of powering your private organizational knowledge base. We implicitly understand that this documentation contains trade secrets, factory floor layouts, and proprietary manufacturing processes, and we treat it with the absolute highest degree of confidentiality and technical isolation available in the cloud computing industry.

2. Vectorization & AI Processing Mechanics

To enable instantaneous and accurate retrieval of your manufacturing data, your uploaded documents undergo an automated background processing pipeline. This pipeline extracts the text, segments it into semantic chunks, and generates high-dimensional mathematical representations known as vector embeddings. These embeddings are stored securely within our PostgreSQL pgvector database.

Your operational chat histories and vector embeddings are never utilized to cross-train global AI models or refine algorithms for other Opintell customers.When a user queries the AI assistant, the system performs a localized mathematical search against your specific organizational vectors, retrieves the relevant factory protocols, and securely constructs a localized prompt to generate a highly precise, cited response. This process is mathematically isolated on a per-tenant basis.

3. Third-Party Infrastructure, Data Residency & Sharing Policies

Opintell operates on a principle of absolute minimal data exposure. We do not sell, rent, lease, or commercially broker your corporate data, usage analytics, or uploaded industrial documentation to marketing firms, data brokers, or competitive entities under any circumstances whatsoever.

Data Residency: To comply with strict manufacturing and governmental requirements (including India's DPDP Act), all core document storage and PostgreSQL databases are hosted in the ap-south-1 (Mumbai) region. Your proprietary operational data does not leave this geographic boundary at rest.

To provide our service, we leverage a highly curated list of enterprise-grade sub-processors. Our core database is secured by Supabase (PostgreSQL), our large-scale document storage is hosted on Cloudflare R2 object storage, and our language model inference is processed through isolated Enterprise API endpoints (e.g., Google Vertex AI or Github Enterprise Models) with explicit zero-data-retention agreements. By strictly utilizing Enterprise endpoints, these LLM providers are legally barred from logging your prompts or utilizing your factory data for their own model training purposes.

4. Cryptographic Data Retention & Wiping

We believe you should have absolute control over the lifecycle of your industrial data. When an administrator deletes a document from the Opintell dashboard, a synchronized deletion protocol is instantly triggered across our entire microservice architecture.

This protocol executes a cryptographic wipe of the original PDF from Cloudflare R2, drops all associated text chunks from the PostgreSQL relational tables, and purges the corresponding multi-dimensional vectors from the pgvector database. This ensures that the deleted machinery manual or SOP is permanently and irreversibly eradicated from our systems, leaving no residual forensic trace in the active knowledge base.

5. GDPR & Global Regulatory Compliance

Opintell is deeply committed to aligning with major international data privacy frameworks, including the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). Users possess the immutable right to access, rectify, or demand the complete erasure of their personal accounts and associated chat histories.

For manufacturing entities operating in heavily regulated jurisdictions, we provide necessary compliance exports and facilitate comprehensive Subject Access Requests (SARs) within legally mandated timeframes. Our engineering practices follow the strict principles of Privacy by Design, ensuring that compliance is a foundational architectural component rather than an afterthought.

6. Privacy Operations Contact

If your legal or compliance team requires further clarification regarding our data flow architectures, sub-processor agreements, or tenant isolation methodologies, our specialized Data Protection Officer (DPO) is available to assist you.

Please direct all technical and legal privacy inquiries to admin@opintell.com. We are committed to fostering complete transparency regarding the safeguarding of your operational intelligence.