Back to home

Legal

Privacy Policy

Effective Date: May 1, 2026 · Opus Data, Inc. · San Francisco, CA 94105

1. Introduction

Opus Data, Inc. ("Opus Data," "we," "us") is committed to protecting the privacy of AI Trainers, Enterprise Clients, and website visitors. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you interact with our platform, website (opusdata.ai), and related services. We are headquartered at 548 Market Street, Suite 83200, San Francisco, CA 94104, United States.

2. Information We Collect

2.1 Information You Provide Directly

  • Trainer Applications: full name, email address, phone number, country of residence, professional experience, domain expertise (coding, medical, finance & banking, analytics, customer discovery, multilingual, science), LinkedIn/portfolio URLs, and language proficiencies
  • Enterprise Inquiries: company name, business email, role/title, project requirements, budget range, and timeline
  • Account Profiles: profile photo (optional), bio, certifications, education history, and work samples
  • Payment Information: bank account details, PayPal email, or Wise account information for payout processing
  • Communications: messages sent through our chatbot, support emails, in-app feedback, and survey responses

2.2 Information Collected Automatically

  • Usage Data: pages visited, features used, annotation tasks completed, time spent on tasks, quality scores, and earning history
  • Device Information: browser type and version, operating system, screen resolution, device type (desktop/mobile/tablet)
  • Network Information: IP address, approximate geolocation (city/country level), internet service provider
  • Cookies & Tracking: session cookies for authentication, preference cookies for UI settings, and analytics cookies (see Section 8)

2.3 Information from Third Parties

We may receive information from identity verification services (for trainer onboarding), payment processors (transaction confirmations), and professional networks (LinkedIn profile data when you link your account).

3. How We Use Your Information

  • Platform Operations: process trainer applications, match trainers to projects based on skills and domain expertise, manage task assignments, calculate quality scores, and process weekly payouts
  • Quality Assurance: monitor annotation accuracy, detect fraudulent or low-quality submissions, calibrate inter-annotator agreement, and maintain platform integrity
  • Communications: send application status updates, project notifications, payout confirmations, platform announcements, and respond to support inquiries
  • Platform Improvement: analyze usage patterns to improve our annotation tools, optimize project matching algorithms, and develop new features based on trainer feedback
  • Security: detect and prevent fraud, unauthorized access, abuse, and other security threats to the Platform and its users
  • Legal Compliance: comply with applicable laws, regulations, tax reporting requirements (1099-NEC for US trainers), and respond to lawful data requests from authorities

4. Data Sharing & Disclosure

We never sell your personal information. We share data only in these limited circumstances:

  • Enterprise Clients: We share anonymized/aggregated trainer performance metrics (quality scores, completion rates) with clients. We never share trainer personal contact information, payment details, or identity with clients unless you explicitly consent
  • Payment Processors: Bank account or PayPal details are shared with our payment processor (Stripe, PayPal, Wise) solely to execute payouts. We do not store full payment credentials on our servers
  • Service Providers: Infrastructure providers (AWS, Vercel), email services, analytics tools, and customer support platforms that process data on our behalf under strict data processing agreements
  • Legal Requirements: When required by law, court order, subpoena, or to protect the rights, property, or safety of Opus Data, our users, or the public
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the successor entity with equivalent privacy protections

5. Data Security

Opus Data implements enterprise-grade security measures to protect your information:

  • SOC 2 Type II certified — independently audited security controls covering data handling, access management, and operational procedures
  • AES-256 encryption at rest for all stored data; TLS 1.3 encryption in transit for all network communications
  • Role-based access control (RBAC) with principle of least privilege — employees access only the data required for their role
  • Multi-factor authentication (MFA) required for all internal systems and admin access
  • Regular penetration testing and vulnerability assessments by independent security firms
  • 24/7 security monitoring, automated threat detection, and incident response procedures with 4-hour notification SLA
  • Data centers located in the United States (AWS us-west-2) with physical security, redundancy, and disaster recovery

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide services. Specific retention periods: account profiles and application data are retained for 3 years after account closure; completed annotation data is retained for 5 years for quality assurance and audit purposes; payment records are retained for 7 years per US tax regulations; website analytics data is retained for 26 months in anonymized form. Upon account deletion request, we remove personal identifiers within 30 days while retaining anonymized work product as required.

7. Your Rights

7.1 California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

  • Know what personal information we collect and how we use it
  • Request a portable copy of your data in a structured, machine-readable format
  • Request deletion of your personal information (subject to legal retention requirements)
  • Opt out of the sale of personal information — we do not sell your data, so this right is automatically satisfied
  • Non-discrimination — exercising your rights will not affect your access to or compensation on the Platform

7.2 EU/EEA Residents (GDPR)

Under the General Data Protection Regulation, you additionally have the right to:

  • Access a copy of all personal data we hold about you
  • Rectify inaccurate or incomplete personal data
  • Erasure (right to be forgotten) — request deletion of your data when no longer necessary
  • Restrict processing in certain circumstances (e.g., while a dispute is being resolved)
  • Data portability — receive your data in a structured format and transfer to another service
  • Object to processing based on legitimate interests
  • Lodge a complaint with your local data protection authority

7.3 Kenya (Data Protection Act 2019)

Trainers based in Kenya are protected under the Kenya Data Protection Act, 2019. You have the right to be informed of how your data is used, access your personal data, object to processing, and request correction or deletion. Opus Data complies with the requirements of the Office of the Data Protection Commissioner (ODPC) in Kenya. Cross-border data transfers from Kenya are protected by appropriate safeguards including standard contractual clauses.

8. Cookies & Tracking Technologies

We use the following categories of cookies:

  • Strictly Necessary: Authentication tokens, CSRF protection, session management — cannot be disabled
  • Functional: UI preferences (theme, language), annotation tool settings — enhance your experience
  • Analytics: Anonymous usage statistics via privacy-focused analytics (no cross-site tracking). Used to improve platform features and performance. Can be disabled in account settings

We do not use advertising cookies or share browsing data with ad networks. You can manage cookie preferences through your browser settings or our in-app privacy controls.

9. International Data Transfers

Opus Data operates globally with trainers in the United States, Kenya, and 90+ countries. Personal data may be transferred to and processed in the United States where our servers are located. For EU/EEA and Kenyan trainers, we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission and appropriate safeguards under Kenya's Data Protection Act. We regularly review and update our data transfer mechanisms to comply with evolving international privacy frameworks.

10. Children's Privacy

The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a person under 18, we will promptly delete it and terminate the associated account. If you believe a minor has provided us with personal information, please contact privacy@opusdata.ai immediately.

11. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email to active account holders and prominently displayed on the Platform at least 30 days before taking effect. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy. Previous versions are archived and available upon request.

12. Contact Our Privacy Team

Data Protection Officer

Opus Data, Inc.

548 Market Street, Suite 83200

San Francisco, CA 94104, United States

Privacy inquiries: privacy@opusdata.ai

Data subject requests: dpo@opusdata.ai

Security incidents: security@opusdata.ai

To exercise any of your privacy rights, email privacy@opusdata.ai with the subject line "Privacy Rights Request" and specify which right you wish to exercise. We will respond within 30 days (45 days for complex requests).