Your data belongs to you. Here is how we protect it.
What we actually do about hosting, encryption, access and your rights. No jargon, and no promise we cannot keep.
Hosting
The application and your data are hosted on cloud infrastructure located in the European Union, with backups managed by the hosting provider. The marketing website is delivered by a global network and stores no personal data.
Encryption
All traffic goes over HTTPS (TLS). Data is encrypted at rest by the hosting provider. Card data never touches our servers: it is handled by Stripe.
Isolation per company
Every request is checked server-side and scoped to your company: no request can read or change another company's data. Managers only see their locations, employees only their own information.
Roles and access
Three roles: administrator, manager, employee. The time-clock PIN is visible to administrators only. An account can be suspended instantly, and an unused invitation expires.
Authentication
Sign-in with email and password, reset through a link sent to the account address, time-limited sessions. Credentials are strictly personal.
Activity log
Sensitive actions (employee creation and deletion, status changes, subscription, payroll data…) are recorded with their author and date, and can be reviewed by the administrator.
Export and reversibility
The administrator can download the company's entire data (JSON) and CSV exports at any time. After termination, data remains exportable for 30 days.
Deletion
An administrator can delete the company account in self-service; data is then erased, except where legal retention applies (payroll data).
Sub-processors
Cloud hosting provider (European Union), website delivery network, Stripe for payments, an email delivery provider. The named list is available on request at info@opteamer.com.
Report a vulnerability
Found a security issue? Write to info@opteamer.com. We acknowledge within 3 business days and keep you informed of the fix. If an incident affects your data, affected customers are notified without undue delay.
Data Processing Agreement (DPA)
Aligned with Article 28 of the GDPR and the Swiss Federal Act on Data Protection (FADP). Download it, fill in the parties, sign: it becomes part of your contract.
A security question?
We answer every question from your IT or legal contacts, including by video call.
Contact us