Opally Logo

Privacy Policy

This privacy policy explains in detail how Opally ApS ("Opally", "we", "us", "our") collects, processes, stores, and protects personal data in connection with the delivery of our AI-powered guest communication platform, including Email Assistant, Chatbot, Voice Assistant, and Agent Actions. The policy is designed in accordance with applicable data protection legislation, including the General Data Protection Regulation (GDPR).

1. Data Controller

Opally ApS
CVR: 45976904
Tyrolsgade 19, 4th
2300 Copenhagen S, Denmark
Contact: info@opally.com

1.1. Our Roles under GDPR

This privacy policy describes how we process personal data where Opally is the data controller. This applies to information about visitors to our website and users who create an account with us (e.g., staff members).

When our customers use Opally to process data about their guests, Opally acts as a data processor on behalf of the customer, who is the data controller. Our obligations as a data processor are governed by a separate Data Processing Agreement (DPA), which is entered into with each customer.

2. Purpose and Use

Opally offers an AI-powered guest communication platform that integrates with email clients (e.g., Outlook, Gmail), chat widgets, phone systems, booking systems (PMS), and other relevant systems. The platform includes Email Assistant, Chatbot, Voice Assistant, and Agent Actions. The purpose is to automate and streamline guest communications across multiple channels, improve the guest experience, and reduce administrative burdens for staff.

3. What Personal Data Do We Process?

We process the following categories of personal data where we are the data controller:

4. How Is Information Collected?

5. Purpose and Legal Basis for Processing

We process your personal data for the following specific purposes and with the following legal bases:

6. Sharing of Personal Data

We never sell your personal data. We only share your data with trusted third-party providers (sub-processors) to the extent necessary to deliver and improve our service. All sub-processors are bound by agreements that ensure GDPR compliance.

We may also disclose information if required by law, court order, or in connection with a business transaction (e.g., a merger).

7. Data Storage and Security

Storage and Transfers: We primarily process and store data within the EU/EEA (e.g., Frankfurt). However, we use trusted third-party service providers (e.g., for payments or customer support) that may process data in the USA. We ensure these transfers are legal by using valid transfer mechanisms, such as the EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).

Security measures: We use industry-standard security measures, including:

Retention period: We store your personal data only as long as necessary for the purposes stated in this policy or as required by law. Specifically:

8. Your Rights

Under GDPR, you have the following rights:

To exercise any of these rights, contact us at info@opally.com.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to improve your experience on our website. You can manage your cookie preferences in your browser.

10. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes via email or through a notice on our platform.

11. Contact Us

If you have questions about this privacy policy or how we process your personal data, contact us at:

Email: info@opally.com
Address: Tyrolsgade 19, 4th, 2300 Copenhagen S, Denmark

You also have the right to lodge a complaint with your local data protection authority if you believe we have processed your personal data unlawfully.

Last updated: January 2026

Ready to transform your hotel?

Join hotels already saving 70% of their admin time with Opally. Start your free trial today.

5-minute setup
GDPR compliant
English support
Privacy Policy | Opally