Legal
Privacy policy - Opustack
What data we process, why, for how long, and with whom.
Version 1.0 · 7 September 2026
This policy describes how MLV GROUP SRL, trading as Opustack (Boulevard Bischoffsheim 39/4, 1000 Brussels, enterprise number BCE 0833.942.355), processes personal data on opustack.co, in the opustack.app client area, in the Opustack mobile applications and in shops hosted on the platform.
Contact for any question about data: privacy@opustack.co.
1. Two situations, two roles
You are a retailer, prospective client or visitor to opustack.co. Opustack is the controller of your data. This policy applies in full.
You are a customer or visitor of a shop hosted by Opustack. The retailer operating the shop is the controller; Opustack acts as a processor on their behalf. You exercise your rights with the retailer, whose contact details appear on their shop. Section 8 describes what Opustack does with this data.
2. Data we collect
Account and contract: surname, first name, business, enterprise number, address, email, telephone number, login credentials, selected plan, billing history and support correspondence.
Payment: we do not store any complete card number or IBAN. Payments are processed by Mollie, which sends us a mandate identifier, transaction status and the last four digits of the payment method.
Service usage: connection logs (IP address, date, device, browser), actions in the client area and the application, and technical data needed for operation and security.
Visit statistics: on opustack.co and in the client area, we use Umami, an audience measurement tool that does not set cookies or collect data that can identify a visitor. No consent banner is necessary.
Mobile application: device identifier for notifications, notification preferences and operating logs. The application does not access contacts, location or photos without an explicit action by you (for example, selecting an image for a product).
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide the service, manage the account and invoice | Performance of the contract |
| Respond to a contact or demonstration request | Pre-contractual steps |
| Send service emails (invoice, incident, monthly report) | Performance of the contract |
| Send information about Opustack updates | Legitimate interest, with the option to unsubscribe at any time |
| Security, fraud prevention and logging | Legitimate interest |
| Anonymous audience measurement | Legitimate interest |
| Accounting and tax obligations | Legal obligation |
We do not sell data or transfer it to any advertiser.
4. Retention periods
- Account data: during the contract, then for three years after it ends.
- Invoices and accounting records: seven years, in accordance with Belgian law.
- Technical logs: twelve months.
- Support correspondence: three years.
- Data of a prospective client with no follow-up: eighteen months after the last contact.
- Shop data after termination: thirty days to allow export, then deletion, subject to statutory obligations.
5. Recipients and processors
Your data is accessible to people at Opustack who need it for their work and to the following categories of providers, each bound by an agreement complying with Article 28 of the GDPR:
- Hosting of websites, applications, servers and databases: Vercel and Railway, with production data hosted in the European Union (see the legal notice).
- Payment: Mollie, European Union. You see it at each payment.
- Shipping: Sendcloud, European Union, when activated by the retailer.
- Transactional and marketing email delivery: providers established in the European Union or in the United States, in the latter case under standard contractual clauses.
- Cookieless audience measurement, hosted by Opustack in the European Union.
- Business management, invoicing and support: providers established in the European Union.
- Automated writing assistance and translation: a provider established in the United States under standard contractual clauses; data is minimised and never used to train models.
Where a provider is established outside the European Union, the transfer is based on the European Commission's standard contractual clauses or an adequacy decision.
The named and up-to-date list of subprocessors is available in the client area and on request at privacy@opustack.co. Clients under contract receive thirty days' notice of any addition and may object on legitimate grounds.
6. Your rights
You may, at any time, access your data, have it rectified or erased, restrict its processing, object to processing based on legitimate interest, receive your data in a structured format and withdraw consent you have given.
Account deletion: in the client area and the application, a “Delete my account” action allows you to request account closure and data erasure, subject to statutory retention obligations and the end of any current contractual commitments. Deletion takes effect within thirty days and is confirmed by email.
To exercise a right: privacy@opustack.co. We respond within one month. You may also lodge a complaint with the Belgian Data Protection Authority, rue de la Presse 35, 1000 Brussels, www.autoriteprotectiondonnees.be.
7. Security
Data encryption in transit (TLS) and at rest, isolation of each shop in its own environment, individual access with strong authentication, access logging, encrypted daily backups retained for thirty days, continuously applied security updates and availability monitoring. In the event of a data breach likely to create a risk, we notify the Data Protection Authority within seventy-two hours and the individuals concerned without undue delay.
8. Buyer data from hosted shops
For our clients' shops, Opustack hosts and processes buyers' data (identity, contact details, orders, browsing) only on the retailer's instructions and to operate their shop: orders, deliveries, service emails, statistics and, if activated by the retailer, marketing emails with one-click unsubscribe.
Opustack does not use this data for its own purposes, combine it across shops or disclose it to any third party other than the processors listed above. For any request concerning this data, contact the retailer; if they do not respond, write to privacy@opustack.co and we will forward your request.
9. Cookies
opustack.co and the client area use only strictly necessary cookies: login session, language preference and security. No advertising or third-party tracking cookies. Umami audience measurement works without cookies.
Our clients' shops may, at the retailer's request, use advertising measurement tools; their privacy policy and, where applicable, their consent banner inform visitors about them.
10. Minors
The service is reserved for professionals and is not intended for people under eighteen. We do not knowingly collect data from minors.
11. Mobile application - information for app stores
- Publisher: MLV GROUP SRL, trading as Opustack.
- Data collected and linked to the user: contact details, identifiers, account content, usage data and diagnostics. No data is used for advertising tracking.
- Notifications: sent only for shop events (order, shipping, incident, report), and can be disabled in the application and in the device settings.
- Account deletion: available in the application, under Account.
- This policy is permanently accessible at opustack.co/confidentialite.
12. Changes
This policy may change. The date at the top indicates the current version. In the event of a substantial change, clients under contract receive thirty days' notice by email.
Contact
Publisher : MLV GROUP SRL
Boulevard Bischoffsheim 39/4, 1000 Bruxelles, Belgique
BCE BE 0833.942.355
privacy@opustack.co