LEGAL

Privacy Policy.

This policy explains how SupraOS handles website, analytics, Company Scan, preview-access, security-report, and business-communication data across its operations in Europe, the GCC, and East Asia.

Effective and last reviewed: 16 July 2026

1. Who we are

SupraOS Limited operates supraos.co, the first-party analytics endpoint and the SupraOS product infrastructure. SupraOS Limited is the controller for website visitor, form, analytics and business-communication data described in this policy. Customer product-data roles and the applicable operating presence are defined in the customer agreement and DPA.

2. What this policy covers

This policy covers supraos.co, Company Scan and demo requests, preview and access pages operated by SupraOS, email communications, security reports, and other pre-contract or business interactions. Customer product data is governed by the applicable customer agreement, DPA, security schedule, order form, and deployment documentation.

3. Personal data we collect

Information you provide

Name, work email, company, role, selected workflow, systems context, free-text submissions, communications, security reports, and materials you choose to send.

Website and analytics data

IP address, visitor/session identifiers after analytics consent, browser, device, language, timezone, page path, page title, referrer without raw query parameters, approved UTM fields, clicks, scroll depth, form-start/submit events, and duration.

Security and operational data

Server, access, authentication, abuse-prevention, request, and error metadata reasonably required to operate, secure, diagnose, and defend the site and services.

Business sources

Professional information from your company, public business sources, referrals, event interactions, or other lawful business contacts.

No form-field analytics

First-party analytics does not collect the contents typed into form fields. It records only limited form event metadata such as the form identifier and submission event.

No advertising profile

This implementation does not use advertising cookies, marketing pixels, or Google Analytics.

4. Why we use personal data

Purpose Typical legal basis
Respond to Company Scan, demo, diligence, security, privacy, legal, and business requests Steps requested before a contract; legitimate interests in responding to business communications.
Operate, secure, troubleshoot, and defend the site and services Legitimate interests in service operation, security, fraud prevention, and legal claims; legal obligations where applicable.
First-party analytics after the visitor chooses Accept analytics Consent.
Maintain consent records and comply with law Legal obligation and legitimate interests in demonstrating compliance.
Administer contracts, customer evaluations, and deployments Contract performance, pre-contract steps, legal obligations, and legitimate interests.
Send product or business communications Consent where required, or legitimate interests for relevant business communications with an available opt-out.

5. Cookies and first-party analytics

Optional first-party analytics starts only after the visitor selects Accept analytics. Selecting Reject analytics leaves only the necessary cookie used to remember the choice. Visitors can reopen Cookie settings from the footer at any time.

supraos_cookie_consent · 180 days

Necessary cookie that remembers whether analytics was rejected or accepted.

supraos_vid · 180 days

Optional first-party visitor identifier, created only after analytics consent.

supraos_sid · 30 minutes

Optional first-party session identifier, refreshed during an active analytics session.

6. Retention

Raw analytics IP address · up to 30 days

After 30 days, the full IP is removed from the analytics event and only the limited prefix may remain.

Analytics events · up to 12 months

First-party analytics events are removed after 12 months.

Company Scan and business requests

Retained while the inquiry, evaluation, commercial relationship, legal requirement, or defensible business need remains active, then reviewed for deletion.

Security and access records

Retained for the period reasonably necessary to investigate, secure, defend, and comply with legal or contractual obligations.

7. Recipients and international transfers

Personal data may be accessed by authorized SupraOS personnel, managed infrastructure providers, deployment-specific providers disclosed in customer documentation, professional advisers, and authorities where lawfully required. The current managed application infrastructure is in Europe. Where EEA or UK transfer rules apply, SupraOS uses the EU Standard Contractual Clauses, the UK Addendum, or the UK International Data Transfer Agreement as applicable.

8. AI-assisted internal processing

SupraOS may use approved internal or third-party tools to classify, summarize, triage, or assist with business requests. SupraOS does not use customer data to train shared models unless explicitly agreed in writing; customer processing is governed by the signed DPA and deployment documentation.

9. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Contact privacy@supraos.co, monitored by the Head of Privacy & Data Protection. You may also lodge a complaint with the competent supervisory authority in your jurisdiction.

10. Security, children, and changes

Security

SupraOS uses technical and organisational measures appropriate to the scope and risk. No internet service can be guaranteed completely secure.

Children

The public site and business services are not directed to children.

Changes

Material updates will be posted on this page with a revised effective date.