Customer systems remain the sources of truth.
Customer systems stay authoritative. SupraOS processes the operating state required to coordinate, execute and prove approved work from customer-approved sources.
Effective and last reviewed: 16 July 2026
What stays in customer systems
Customer CRM, product, support, contract, finance, identity, work, and evidence systems remain the systems of record. SupraOS stores the scoped state required to coordinate and prove the approved workflow.
Source boundaries and coverage
Revenue and customer sources
CRM, account, renewal, product-usage, support, contract, and finance sources approved for the deployment.
Operational sources
Work queues, tickets, incident, procurement, supplier, field-service, inventory, and internal data sources approved for the workflow.
Evidence sources
Documents, files, logs, attestations, approvals, and customer-provided artifacts used to support a decision or verify an outcome.
Connected
The source and approved objects are available within the current scope.
Limited or pending
Access is partial, field-limited, awaiting customer action, or not yet validated.
Unavailable or blind
Coverage gaps remain visible throughout the run.
Every evidence type keeps its source, provenance and confidence label. Confidence does not replace evidence.
What SupraOS stores
| Category | Purpose |
|---|---|
| Charters and Work Object state | Define the objective, owners, source scope, authority, approval state, and current execution stage. |
| Evidence references and selected artifacts | Support decisions, approvals, verification, and workflow proof where required. |
| Policy and approval events | Show why an action was permitted, held, or blocked and who approved it. |
| Execution and verification metadata | Record the action, connector context, destination-system response, and read-back result. |
| Receipts and Value Ledger records | Preserve workflow proof and clearly labeled value states. |
Data path
Data minimization and location
Minimize collection
SupraOS processes the minimum data required to run, secure, support and prove the approved work.
Managed hosting in Europe
SupraOS runs its managed service on European infrastructure. Security diligence covers every provider, processing location and transfer safeguard.
Customer instructions control the deployment
The signed agreement, DPA, security schedule, order form, and deployment documentation define the actual scope.
Retention, deletion and portability
Product retention
Product retention, return, deletion, audit, and legal-hold rules are defined in the applicable customer agreement and deployment schedule.
Website analytics
With analytics consent, raw full IP addresses are retained for no more than 30 days and then removed from the analytics record. Analytics events are retained for no more than 12 months.
Consent record
The cookie-choice record lasts 180 days unless the visitor changes the choice or clears cookies.
Export and deletion requests
Customer export and deletion obligations follow the DPA and deployment documentation. Website privacy requests go to privacy@supraos.co.