Oplisk
ImprintPrivacyTerms
Log in
Privacy notice

What Oplisk records—and why.

A product-specific notice for founders, workspace members, update recipients and data-room guests.

Updated 2026-08-11
On this page
01Who is responsible02Information we handle03Email and room activity04Purposes and legal bases05Service providers and transfers06Retention and deletion07Security and access08Your rights

Who is responsible

Anyjoi GmbH, Köpenicker Straße 45, 12524 Berlin, is the controller for Oplisk account administration, service security, billing and its own communications. Contact contact@anyjoi.com. Full particulars are in the imprint.

A company using Oplisk normally decides which investor contacts it imports, which updates it sends and who receives access to a data room. For that customer content and recipient information, the workspace customer is generally the controller and Oplisk acts on its instructions as processor. Recipients should first contact the sender named in the email or invitation; Oplisk supports verified requests.

Information we handle

Accounts and workspaces

Email address, name, authentication identifiers and security events; company and workspace details; member roles; plan, entitlement and account status; settings, support requests and feedback.

Founder CRM and updates

Contact details supplied by the workspace, firms, tags, notes, tasks, relationship stages, update drafts and frozen sent versions, recipients, delivery state, unsubscribe state and replies.

Data rooms

Room content, files and versions; invited email address; access scope, expiry and revocation state; one-time verification and session state; pages, files and controlled links accessed; download and security events.

Billing and operations

Stripe customer, checkout, subscription, invoice, discount and event references; operational receipts from email, scanning and deployment providers; timestamps and bounded diagnostic information needed to reconcile failures and prevent duplicate processing.

Email and room activity

Investor updates use an individual tracking image and first-party link redirects. Oplisk records when the image is requested and when a tracked link is followed, including time, message or link reference, broad device information and automated-request signals. Raw network addresses are discarded after request processing and are not shown to the sender as an investor profile.

An email open means only that a remote image loaded. Apple privacy relays, mail-security scanners and other automated systems can trigger it. Oplisk keeps suspected proxy or scanner activity separate and never presents an open as proof that a person read the message.

Data-room access records page, file, preview, download and controlled link actions after an invited guest verifies access. This supports room security, revocation and the workspace’s relationship history. The recipient preference link explains update tracking and lets a recipient unsubscribe from future updates; unsubscribing does not erase security or prior delivery records automatically.

Purposes and legal bases

Provide the service
Account, workspace, CRM, update, room and subscription processing required to perform the customer contract or take requested pre-contract steps (Article 6(1)(b) GDPR).
Secure and reconcile it
Authentication, access logs, fraud and abuse controls, malware scanning, provider receipts and incident investigation based on legal obligations and legitimate interests in a secure, accountable service (Article 6(1)(c) and (f) GDPR).
Customer instructions
Contact, update, tracking and room processing performed for the workspace under its documented instructions and data-processing agreement. The customer must establish its own lawful basis for recipient data and communications.
Billing and records
Payment administration, tax and accounting records based on the contract and applicable legal retention duties.

Where consent is legally required for a specific activity, the workspace customer must obtain it before that activity. Oplisk does not offer an untracked update-send mode. A customer that cannot document another applicable legal basis or obtain any consent required under the GDPR, section 25 TDDDG or local communications law must not send that update through Oplisk.

Service providers and transfers

Oplisk uses the following provider categories. The signed agreement and current subprocessor list—not a marketing location label—control the exact legal entity, processing locations and transfer safeguards.

Supabase
Authentication, PostgreSQL database and private object storage; the dedicated Oplisk project is configured in Frankfurt, Germany. Provider DPA
Vercel
Website, functions, content delivery, deployment and runtime logs; primary application functions are configured for Frankfurt. Provider DPA
Postmark / ActiveCampaign
Requested account, update and data-room email delivery, delivery events and replies. Provider DPA
Stripe
Checkout, subscriptions, invoices, payment methods, fraud prevention and billing portal. Oplisk does not store full card details. Provider DPA
Google Cloud
The dedicated malware-scanning service runs in Frankfurt and returns a clean or rejected verdict before a private file can be published. Provider terms
Atlassian
Product feedback selected for the Oplisk feedback board can be mirrored into the internal Jira work queue. Provider DPA

Where a provider or its subprocessor processes data outside the EEA, Oplisk relies on the transfer mechanism in the applicable DPA, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary measures where required.

Retention and deletion

  • A workspace deletion request disables sending and guest access immediately. The owner can recover or export it for 30 days; the permanent purge becomes due after 60 days.
  • Raw provider webhook receipts are scheduled for deletion after 30 days. Normalized activity events and the content of frozen sent update revisions are scheduled for deletion or content purge after 24 months.
  • Data-room invitations and sessions expire at their configured deadline and can be revoked earlier. Guest sessions last no longer than seven days without re-verification.
  • Billing, accounting, fraud-prevention and legal records can be kept longer where law or an active dispute requires it.
  • Provider backups and security logs follow the deletion and rotation periods in the applicable provider contract. Deletion from the active Oplisk service does not imply instantaneous erasure from every encrypted backup copy.

Security and access

Workspaces are tenant-isolated and role-controlled. Private room files use signed, short-lived access; data-room invitations require email verification; access can be revoked; uploads remain unavailable until malware scanning returns a clean verdict. Provider callbacks are authenticated and duplicate events are reconciled rather than counted twice.

Oplisk uses necessary authentication, guest-session and reaction cookies. The public website does not currently load optional advertising or third-party audience analytics. A privacy-enhanced YouTube embed is loaded only when customer content contains such a video.

Your rights

Subject to the GDPR’s conditions, you may request access, rectification, erasure, restriction, portability or objection, and may withdraw consent for the future where processing relies on consent. You also have the right to complain to a data-protection supervisory authority.

Contact the workspace sender for customer-controlled CRM, update or room information. For Oplisk account, billing or service processing, email contact@anyjoi.com. We may need to verify identity or authority before disclosing or changing private records.

© 2026 OpliskClear terms for a relationship product.Back to Oplisk