DATA HANDLING

Customer systems remain the sources of truth.

Customer systems stay authoritative. SupraOS processes the operating state required to coordinate, execute and prove approved work from customer-approved sources.

Effective and last reviewed: 16 July 2026

What stays in customer systems

Customer CRM, product, support, contract, finance, identity, work, and evidence systems remain the systems of record. SupraOS stores the scoped state required to coordinate and prove the approved workflow.

Source boundaries and coverage

Revenue and customer sources

CRM, account, renewal, product-usage, support, contract, and finance sources approved for the deployment.

Operational sources

Work queues, tickets, incident, procurement, supplier, field-service, inventory, and internal data sources approved for the workflow.

Evidence sources

Documents, files, logs, attestations, approvals, and customer-provided artifacts used to support a decision or verify an outcome.

Connected

The source and approved objects are available within the current scope.

Limited or pending

Access is partial, field-limited, awaiting customer action, or not yet validated.

Unavailable or blind

Coverage gaps remain visible throughout the run.

Every finding carries provenance.

Every evidence type keeps its source, provenance and confidence label. Confidence does not replace evidence.

What SupraOS stores

Category Purpose
Charters and Work Object state Define the objective, owners, source scope, authority, approval state, and current execution stage.
Evidence references and selected artifacts Support decisions, approvals, verification, and workflow proof where required.
Policy and approval events Show why an action was permitted, held, or blocked and who approved it.
Execution and verification metadata Record the action, connector context, destination-system response, and read-back result.
Receipts and Value Ledger records Preserve workflow proof and clearly labeled value states.

Data path

Customer source Approved record or evidence.
Scoped retrieval Only approved sources and objects.
Work state Charter, evidence, policy, and approvals.
Execution Permitted connector or operator action.
Verification Destination-system read-back confirms connector actions.
Proof Receipt and confirmed value-state record.
Customer system Remains the source of truth.

Data minimization and location

Minimize collection

SupraOS processes the minimum data required to run, secure, support and prove the approved work.

Managed hosting in Europe

SupraOS runs its managed service on European infrastructure. Security diligence covers every provider, processing location and transfer safeguard.

Customer instructions control the deployment

The signed agreement, DPA, security schedule, order form, and deployment documentation define the actual scope.

Retention, deletion and portability

Product retention

Product retention, return, deletion, audit, and legal-hold rules are defined in the applicable customer agreement and deployment schedule.

Website analytics

With analytics consent, raw full IP addresses are retained for no more than 30 days and then removed from the analytics record. Analytics events are retained for no more than 12 months.

Consent record

The cookie-choice record lasts 180 days unless the visitor changes the choice or clears cookies.

Export and deletion requests

Customer export and deletion obligations follow the DPA and deployment documentation. Website privacy requests go to privacy@supraos.co.

Training use

AI data-use rules are published in AI governance.