Introduction
This Privacy Policy explains how OpTerra (“OpTerra,” “we,” “us,” or “our”) collects, uses, stores, and protects information when you use our project and resource management platform (the “Service”). It also describes the rights and choices available to you.
OpTerra is a business-to-business platform used by licensed companies and their teams. When your organization subscribes to OpTerra, your organization is the controller of the data it puts into the Service, and OpTerra acts as a processor handling that data on your behalf and under your instructions.
By accessing or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Service.
Our Compliance Roadmap
We hold ourselves to recognized international standards for security and privacy. We are actively in the process of pursuing the following certifications and attestations. Where a framework is still in progress, we already operate against its controls while the formal audit and certification process is completed.
ISO/IEC 27001
Information Security Management
SOC 2 Type II
Security, Availability & Confidentiality
GDPR
EU Data Protection Alignment
CCPA / CPRA
California Consumer Privacy
Certification timelines may change as audits progress. We're happy to share our current security documentation and status with customers and prospects under NDA — just reach out.
Information We Collect
We collect only what we need to provide and improve the Service:
- Account & profile data. Name, work email, role, company affiliation, language preference, and authentication credentials.
- Organizational data. Company details, team members, licenses, and configuration set up by your organization’s administrators.
- Operational content. The projects, resources, schedules, reports, and related records you create and manage within your tenant.
- Usage & device data. Log data such as IP address, browser type, pages viewed, and timestamps, used for security, troubleshooting, and analytics.
- Cookies & local storage. Used to keep you signed in, remember preferences, and maintain session security. See the Cookies section below.
How We Use Information
We use the information we collect to:
- Provide, operate, secure, and maintain the Service.
- Authenticate users and protect accounts against unauthorized access.
- Enable the collaboration features you explicitly choose to use.
- Provide customer support and respond to your requests.
- Monitor performance, diagnose issues, and improve the product.
- Comply with legal obligations and enforce our agreements.
We do not sell your personal information, and we do not use your operational content to train third-party advertising models.
Multi-Tenant Data Isolation
Your tenant is your own private space.
OpTerra is a multi-tenant platform, but each organization's data lives inside its own logically isolated tenant. Your data is never commingled with, visible to, or accessible by any other tenant. Put simply: no other company on OpTerra can see, read, query, or retrieve your data.
Isolation is enforced consistently across the platform:
- Logical separation. Every record is bound to its owning tenant, and all access is scoped to that tenant on every request — there is no path for one tenant to reach another’s data.
- Least-privilege access. OpTerra personnel do not browse customer content. Administrative access is restricted, role-based, logged, and used only when necessary to operate the Service or support you.
- Encryption. Data is encrypted in transit and at rest, so even at the infrastructure layer your information is protected.
- Auditability. Sensitive actions are logged, giving a clear, reviewable trail of access and changes.
Explicit Coworking & Sharing
OpTerra includes powerful collaboration features that let companies cowork together on projects and resources. Because these features involve sharing otherwise-private information between organizations, we've designed them around one firm principle: nothing is ever shared implicitly — every share is an explicit choice.
Step 1
Send a connection request
To collaborate with another licensed company, one company sends a connection request to the other.
Step 2
The other company accepts
No connection exists until the recipient explicitly accepts. Either side can decline, and connections can be ended.
Step 3
Choose what to cowork on
Only after connecting can companies explicitly opt to cowork on specific projects or resources — item by item.
Being connected to another company does not mean you can see each other's data. A connection is simply permission to start collaborating. Each company only ever sees the specific projects and resources the other has explicitly chosen to share within a given collaboration — and nothing else.
- Explicit, never implicit. Sharing happens at the level of an individual project or resource, and only when you deliberately enable it.
- Granular by design. Coworking on one project never exposes unrelated projects, resources, or company data.
- You stay in control. You decide what to share, with whom, and you can change or withdraw that sharing.
How We Keep Data Secure
We apply layered, defense-in-depth security practices to protect your information, including:
- Encryption of data in transit (TLS) and at rest.
- Role-based access controls and the principle of least privilege.
- Secure authentication, session management, and token handling.
- Continuous monitoring, logging, and alerting for suspicious activity.
- Regular backups and tested recovery procedures.
- Secure development practices and dependency vulnerability management.
No system can guarantee absolute security, but we work continuously to protect your data and to align with the standards described in our compliance roadmap.
Data Retention
We retain your information for as long as your organization maintains an active account and as needed to provide the Service. When data is no longer required — or upon a valid deletion request from your organization — we delete or anonymize it in accordance with our retention schedules and applicable law. Limited records may be retained where necessary to comply with legal, accounting, or security obligations.
Your Rights & Choices
Depending on your location, you may have rights regarding your personal data, including the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data.
- Request a portable copy of your data.
- Object to or restrict certain processing.
- Withdraw consent where processing is based on consent.
Because OpTerra processes operational content on behalf of your organization, some requests may be directed to your organization's administrator. To exercise your rights, contact us using the details below — we will respond within the timeframes required by applicable law.
Service Providers
We work with a limited set of trusted service providers (subprocessors) — such as cloud hosting, infrastructure, and email delivery — to operate the Service. These providers are bound by contractual obligations to protect your data, may only process it on our instructions, and may not use it for their own purposes. We assess providers for appropriate security and privacy safeguards.
International Transfers
Your information may be processed in countries other than your own. Where data is transferred across borders, we put appropriate safeguards in place — such as recognized transfer mechanisms and contractual protections — to ensure your data remains protected consistently with this Policy and applicable law.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide additional notice. We encourage you to review this Policy periodically.
OpTerra Mobile App
Field engineers can use the OpTerra mobile app (iOS and Android) to work on their organization's projects and expense reports, including while offline. The app is sign-in only — there is no self-registration — and it only touches device features when you actively use something that needs them. Each permission below is requested at that moment, and declining it leaves the rest of the app fully usable.
- Camera. Used only when you choose to take a photo — site and project documentation photos or expense receipts. Nothing is ever captured in the background. Receipt photos are processed to extract expense details (merchant, date, amount) for your expense report.
- Photo library. Used only when you choose to attach an existing image, such as a receipt, a project photo, or your profile picture. The app never scans or uploads your library on its own.
- Location (only while using the app). Read at the moment you geotag a project site or capture a documentation photo, so your organization can verify where field work happened — the coordinates and a timestamp are attached to that record or photo. The app never tracks your location in the background and never uses it for advertising.
- Face ID / biometric unlock (optional). Biometric checks run entirely on your device through the operating system. The app only receives a pass or fail result — your biometric data never reaches us and is never stored by the app.
- On-device storage. To keep working without connectivity, the app stores an offline copy of the work data your account can access. Sign-in credentials are kept in the device’s secure keystore, cached images are encrypted, and changes you make offline are synced back to your organization’s tenant once you are online.
What the mobile app does not do:
- Track your location in the background.
- Record audio or video.
- Access your contacts, calendar, or messages.
- Include advertising or third-party analytics and tracking SDKs.
- Sell or share your personal data.
OpTerra accounts are organization-managed enterprise accounts: they are created, owned, and administered by your employer, and the app offers no in-app sign-up — you can only sign in with an account your organization provisioned. Because your organization controls the account, account closure and data deletion are handled through it. To have your account and associated personal data deleted, ask your organization's OpTerra administrator, or contact us at privacy@opterra.com and we will process the request with your organization. Deleted data is removed or anonymized as described in the Data Retention section above.
Contact Us
If you have questions about this Privacy Policy or how we handle your data, we'd love to hear from you.
Privacy & Data Protection
privacy@opterra.com