Opally Logo

Privacy Policy

This privacy policy explains in detail how Opally ApS ("Opally", "we", "us", "our") collects, processes, stores, and protects personal data in connection with our website, web platform, any supported mobile applications we make available, and the delivery of our AI-powered guest communication platform, including Email AI, Chat AI, Voice AI, and Agent Actions. The policy is designed in accordance with applicable data protection legislation, including the General Data Protection Regulation (GDPR).

1. Data Controller

Opally ApS
CVR: 45976904
Tyrolsgade 19, 4th
2300 Copenhagen S, Denmark
Contact: info@opally.com

1.1. Our Roles under GDPR

This privacy policy describes how we process personal data where Opally is the data controller. This applies to information about visitors to our website and users who create or access an account through our web services or a supported mobile application (e.g., staff members).

When our customers use Opally to process data about their guests, Opally acts as a data processor on behalf of the customer, who is the data controller. Our obligations as a data processor are governed by a separate Data Processing Agreement (DPA), which is entered into with each customer.

2. Purpose and Use

Opally offers an AI-powered guest communication platform that integrates with email clients (e.g., Outlook, Gmail), chat widgets, phone systems, booking systems (PMS), and other relevant systems. The platform includes Email AI, Chat AI, Voice AI, and Agent Actions. The purpose is to automate and streamline guest communications across multiple channels, improve the guest experience, and reduce administrative burdens for staff.

3. What Personal Data Do We Process?

We process the following categories of personal data where we are the data controller:

3.1. Mobile Sessions and Push Notifications

When you use a supported Opally mobile application, sign-in and session information may be stored on your device and processed by Opally to keep you authenticated, protect the account, and connect activity to the correct workspace. The exact data depends on the app version, device, and features you use.

If you choose to enable push notifications, the data used for that feature may include a device-specific push token, a generic service alert, an opaque reference used to open the relevant item after sign-in, and delivery or error metadata. The token and limited delivery data may pass through the notification infrastructure of your mobile operating-system provider and a service provider used to transmit the notification. The particular notification infrastructure depends on the supported app version and device.

You can change notification permission in your device settings. Turning notifications off does not delete your account or other personal data, and deleting the app from your device does not by itself close your account.

4. How Is Information Collected?

5. Purpose and Legal Basis for Processing

We process your personal data for the following specific purposes and with the following legal bases:

6. Sharing of Personal Data

We never sell your personal data. We only share your data with trusted third-party providers (sub-processors) to the extent necessary to deliver and improve our service. All sub-processors are bound by agreements that ensure GDPR compliance.

We may also disclose information if required by law, court order, or in connection with a business transaction (e.g., a merger).

7. Data Storage and Security

Storage and Transfers: We primarily process and store data within the EU/EEA (e.g., Frankfurt). However, we use trusted third-party service providers (e.g., for payments or customer support) that may process data in the USA. We ensure these transfers are legal by using valid transfer mechanisms, such as the EU-U.S. Data Privacy Framework (DPF) or Standard Contractual Clauses (SCCs).

Security measures: We use industry-standard security measures, including:

Retention period: We store your personal data only as long as necessary for the purposes stated in this policy or as required by law. Specifically:

8. Your Rights

Under GDPR, you have the following rights:

To exercise any of these rights, contact us at info@opally.com. Our mobile support and account-deletion page explains the contact-based request process.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to improve your experience on our website. You can manage your cookie preferences in your browser.

10. Use of Third-Party AI Services

Opally integrates with third-party AI services to power its features. The AI services we use include:

When these services process data on behalf of Opally, they act as sub-processors. Data sent to these providers is limited to what is necessary to generate the requested output (e.g., email content for drafting a reply). We do not use Google Workspace user data to train any third-party AI models.

If you have a preference for which AI provider is used to process your data, please contact us at info@opally.com. We will accommodate your preference where technically feasible.

Additionally, our AI Visibility feature uses the Google Analytics Data API (read-only) to help hotel operators understand how much of their website traffic originates from AI assistants such as ChatGPT, Claude, and Gemini. This feature only reads aggregate session metrics (e.g., sessions, active users, engagement rate) filtered by AI referrer sources — it does not modify any Google Analytics data.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of material changes via email or through a notice on our platform.

12. Contact Us

If you have questions about this privacy policy or how we process your personal data, contact us at:

Email: info@opally.com
Address: Tyrolsgade 19, 4th, 2300 Copenhagen S, Denmark

You also have the right to lodge a complaint with your local data protection authority if you believe we have processed your personal data unlawfully.

Last updated: 30 July 2026