Skip to content
SupraOS
LEGAL

Privacy Policy.

This policy explains how SupraOS handles website, analytics, deployment request, preview-access, security-report, and business-communication data across SupraOS’s listed operational locations.

Effective and last reviewed: 1 August 2026

1. Who we are

SupraOS operates supraos.co, the first-party analytics endpoint, and the SupraOS product infrastructure. SupraOS is the controller for website visitor, form, analytics, and business-communication data described in this policy. Customer product-data roles are defined in the applicable customer agreement and DPA.

2. What this policy covers

This policy covers supraos.co, deployment request and demo requests, preview and access pages operated by SupraOS, email communications, security reports, and other pre-contract or business interactions. Customer product data is governed by the applicable customer agreement, DPA, security schedule, order form, and deployment documentation.

3. Personal data we collect

Information you provide

Name, work email, company, role, selected workflow, systems context, free-text submissions, communications, security reports, and materials you choose to send.

Website and analytics data

IP address, visitor/session identifiers after analytics consent, browser, device, language, timezone, page path, page title, referrer without raw query parameters, approved UTM fields and advertising click identifiers, clicks, scroll depth, form-start/submit events, and active time.

Security and operational data

Server, access, authentication, abuse-prevention, request, and error metadata used to operate, secure, diagnose, and defend the site and services. Preview access records can include the work email entered at login, workspace, result, time, country, device, masked network address, first source, and pseudonymous visitor and session identifiers. Production customer access records are kept separately and can include access-check, CSRF, authentication-result, rate-limit, coarse network, and security-event metadata. Passwords and raw access-check proofs are not included in analytics records.

Business sources

Professional information from your company, public business sources, referrals, event interactions, or other lawful business contacts.

No form-field analytics

Optional first-party analytics does not record what you type into fields. When you submit a form or authenticate to a preview, SupraOS processes the information you provide separately and may connect it to the first-party visit that produced the request. Credentials, customer-access fields, access-check proof payloads, and customer security events are excluded from marketing analytics.

No advertising profile

This implementation does not use advertising cookies, marketing pixels, or Google Analytics.

4. Why we use personal data

Purpose Typical legal basis
Respond to deployment request, demo, diligence, security, privacy, legal, and business requests Steps requested before a contract; legitimate interests in responding to business communications.
Operate, secure, troubleshoot, and defend the site and services Legitimate interests in service operation, security, fraud prevention, and legal claims; legal obligations where applicable.
Record and administer preview access, authentication results, and authorised-user activity Service operation, security, fraud prevention, pre-contract steps, contract performance, and legitimate interests.
First-party analytics after the visitor chooses Accept analytics Consent.
Maintain consent records and comply with law Legal obligation and legitimate interests in demonstrating compliance.
Administer contracts, customer evaluations, and deployments Contract performance, pre-contract steps, legal obligations, and legitimate interests.
Send product or business communications Consent where required, or legitimate interests for relevant business communications with an available opt-out.

5. Cookies and first-party analytics

Optional first-party analytics starts only after the visitor selects Accept analytics. Selecting Reject analytics leaves only the necessary cookie used to remember the choice. Visitors can reopen Cookie settings from the footer at any time.

Preview access and authentication security records are separate from optional public-site analytics. They are recorded when an access page is used so SupraOS can operate and protect the workspace, confirm authorised access, and investigate failures or abuse.

supraos_cookie_consent · 180 days

Necessary cookie that remembers whether analytics was rejected or accepted.

supraos_vid · 180 days

Optional first-party visitor identifier, created only after analytics consent.

supraos_sid · 30 minutes

Optional first-party session identifier, refreshed during an active analytics session.

Preview visitor identifier · 180 days

A first-party pseudonymous identifier used across authorised SupraOS preview workspaces to distinguish returning access from a new visitor.

Preview session identifier · 30 minutes

A rolling first-party session identifier used to connect access, authentication outcome and workspace activity within one visit.

Invitation attribution

An opaque invitation reference may connect a preview visit to the invitation that opened it. It does not by itself confirm who used the link.

supraos_customer_access_gate · up to 5 minutes

A necessary, opaque first-party token showing that the browser completed the production customer access check. It does not authenticate a customer or grant workspace access.

supraos_customer_csrf · up to 15 minutes

A necessary anti-forgery token used to protect customer-access requests. A customer session cookie is issued only when a real customer identity provider is provisioned and authentication succeeds.

6. Retention

Raw analytics IP address · up to 30 days

Raw IP addresses are removed no later than 30 days after collection; only the limited prefix may remain.

Analytics events · up to 365 days

First-party analytics events are removed no later than 365 days after collection.

Deployment request and business requests

Retained while the inquiry, evaluation, commercial relationship, legal requirement, or defensible business need remains active, then reviewed for deletion.

Security and access records

Raw preview access logs are retained for up to 30 days. Privacy-minimised preview access events and reconstructed session evidence are retained for up to 365 days. Production customer-access challenges, token hashes, rate-limit counters, and security events are retained only for the configured operational and security period and are stored separately from marketing analytics. Records required for an active security investigation or legal obligation may be retained longer.

7. Recipients and international transfers

Personal data may be accessed by authorized SupraOS personnel, managed infrastructure providers, deployment-specific providers disclosed in customer documentation, professional advisers, and authorities where lawfully required. The current managed application infrastructure is in Europe. Where EEA or UK transfer rules apply, SupraOS uses the EU Standard Contractual Clauses, the UK Addendum, or the UK International Data Transfer Agreement as applicable.

8. AI-assisted internal processing

SupraOS may use approved internal or third-party tools to classify, summarize, triage, or assist with business requests. SupraOS never uses customer data to train a model shared across customers; customer processing is governed by the signed DPA and deployment documentation.

9. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Contact privacy@supraos.co, monitored by the SupraOS privacy team. You may also lodge a complaint with the competent supervisory authority in your jurisdiction.

10. Security, children, and changes

Security

SupraOS uses technical and organisational measures appropriate to the scope and risk. No internet service can be guaranteed completely secure.

Children

The public site and business services are not directed to children.

Changes

Material updates will be posted on this page with a revised effective date.

Essential server records

Public requests that reach SupraOS are recorded in a pseudonymized server ledger for security, reliability, audience measurement and gap detection. Network information is masked; raw IP addresses and full user-agent strings are not retained in the visitor ledger.

Optional browser engagement

Clicks, active duration, scroll depth, forms and Demo interactions are recorded only through the first-party browser analytics choice described on this site.

Available source data

Referrer and geographic information are shown only when supplied by the browser, network or local geolocation data. Unavailable information is not inferred or invented.