Public requests that reach SupraOS are recorded in a pseudonymized server ledger for security, reliability, audience measurement and gap detection. Network information is masked; raw IP addresses and full user-agent strings are not retained in the visitor ledger.
Privacy Policy.
This policy explains how SupraOS handles website, analytics, deployment request, preview-access, security-report, and business-communication data across SupraOS’s listed operational locations.
Effective and last reviewed: 1 August 2026
1. Who we are
SupraOS operates supraos.co, the first-party analytics endpoint, and the SupraOS product infrastructure. SupraOS is the controller for website visitor, form, analytics, and business-communication data described in this policy. Customer product-data roles are defined in the applicable customer agreement and DPA.
2. What this policy covers
This policy covers supraos.co, deployment request and demo requests, preview and access pages operated by SupraOS, email communications, security reports, and other pre-contract or business interactions. Customer product data is governed by the applicable customer agreement, DPA, security schedule, order form, and deployment documentation.
3. Personal data we collect
Information you provide
Name, work email, company, role, selected workflow, systems context, free-text submissions, communications, security reports, and materials you choose to send.
Website and analytics data
IP address, visitor/session identifiers after analytics consent, browser, device, language, timezone, page path, page title, referrer without raw query parameters, approved UTM fields and advertising click identifiers, clicks, scroll depth, form-start/submit events, and active time.
Security and operational data
Server, access, authentication, abuse-prevention, request, and error metadata used to operate, secure, diagnose, and defend the site and services. Preview access records can include the work email entered at login, workspace, result, time, country, device, masked network address, first source, and pseudonymous visitor and session identifiers. Production customer access records are kept separately and can include access-check, CSRF, authentication-result, rate-limit, coarse network, and security-event metadata. Passwords and raw access-check proofs are not included in analytics records.
Business sources
Professional information from your company, public business sources, referrals, event interactions, or other lawful business contacts.
No form-field analytics
Optional first-party analytics does not record what you type into fields. When you submit a form or authenticate to a preview, SupraOS processes the information you provide separately and may connect it to the first-party visit that produced the request. Credentials, customer-access fields, access-check proof payloads, and customer security events are excluded from marketing analytics.
No advertising profile
This implementation does not use advertising cookies, marketing pixels, or Google Analytics.
4. Why we use personal data
| Purpose | Typical legal basis |
|---|---|
| Respond to deployment request, demo, diligence, security, privacy, legal, and business requests | Steps requested before a contract; legitimate interests in responding to business communications. |
| Operate, secure, troubleshoot, and defend the site and services | Legitimate interests in service operation, security, fraud prevention, and legal claims; legal obligations where applicable. |
| Record and administer preview access, authentication results, and authorised-user activity | Service operation, security, fraud prevention, pre-contract steps, contract performance, and legitimate interests. |
| First-party analytics after the visitor chooses Accept analytics | Consent. |
| Maintain consent records and comply with law | Legal obligation and legitimate interests in demonstrating compliance. |
| Administer contracts, customer evaluations, and deployments | Contract performance, pre-contract steps, legal obligations, and legitimate interests. |
| Send product or business communications | Consent where required, or legitimate interests for relevant business communications with an available opt-out. |
5. Cookies and first-party analytics
Optional first-party analytics starts only after the visitor selects Accept analytics. Selecting Reject analytics leaves only the necessary cookie used to remember the choice. Visitors can reopen Cookie settings from the footer at any time.
Preview access and authentication security records are separate from optional public-site analytics. They are recorded when an access page is used so SupraOS can operate and protect the workspace, confirm authorised access, and investigate failures or abuse.
supraos_cookie_consent · 180 days
Necessary cookie that remembers whether analytics was rejected or accepted.
supraos_vid · 180 days
Optional first-party visitor identifier, created only after analytics consent.
supraos_sid · 30 minutes
Optional first-party session identifier, refreshed during an active analytics session.
Preview visitor identifier · 180 days
A first-party pseudonymous identifier used across authorised SupraOS preview workspaces to distinguish returning access from a new visitor.
Preview session identifier · 30 minutes
A rolling first-party session identifier used to connect access, authentication outcome and workspace activity within one visit.
Invitation attribution
An opaque invitation reference may connect a preview visit to the invitation that opened it. It does not by itself confirm who used the link.
supraos_customer_access_gate · up to 5 minutes
A necessary, opaque first-party token showing that the browser completed the production customer access check. It does not authenticate a customer or grant workspace access.
supraos_customer_csrf · up to 15 minutes
A necessary anti-forgery token used to protect customer-access requests. A customer session cookie is issued only when a real customer identity provider is provisioned and authentication succeeds.
6. Retention
Raw analytics IP address · up to 30 days
Raw IP addresses are removed no later than 30 days after collection; only the limited prefix may remain.
Analytics events · up to 365 days
First-party analytics events are removed no later than 365 days after collection.
Deployment request and business requests
Retained while the inquiry, evaluation, commercial relationship, legal requirement, or defensible business need remains active, then reviewed for deletion.
Security and access records
Raw preview access logs are retained for up to 30 days. Privacy-minimised preview access events and reconstructed session evidence are retained for up to 365 days. Production customer-access challenges, token hashes, rate-limit counters, and security events are retained only for the configured operational and security period and are stored separately from marketing analytics. Records required for an active security investigation or legal obligation may be retained longer.
7. Recipients and international transfers
Personal data may be accessed by authorized SupraOS personnel, managed infrastructure providers, deployment-specific providers disclosed in customer documentation, professional advisers, and authorities where lawfully required. The current managed application infrastructure is in Europe. Where EEA or UK transfer rules apply, SupraOS uses the EU Standard Contractual Clauses, the UK Addendum, or the UK International Data Transfer Agreement as applicable.
8. AI-assisted internal processing
SupraOS may use approved internal or third-party tools to classify, summarize, triage, or assist with business requests. SupraOS never uses customer data to train a model shared across customers; customer processing is governed by the signed DPA and deployment documentation.
9. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. Contact privacy@supraos.co, monitored by the SupraOS privacy team. You may also lodge a complaint with the competent supervisory authority in your jurisdiction.
10. Security, children, and changes
Security
SupraOS uses technical and organisational measures appropriate to the scope and risk. No internet service can be guaranteed completely secure.
Children
The public site and business services are not directed to children.
Changes
Material updates will be posted on this page with a revised effective date.
Server request records and optional browser engagement are separate.
Clicks, active duration, scroll depth, forms and Demo interactions are recorded only through the first-party browser analytics choice described on this site.
Referrer and geographic information are shown only when supplied by the browser, network or local geolocation data. Unavailable information is not inferred or invented.