Privacy Policy
Last updated: 2026. This template must be reviewed by qualified counsel before commercial launch, including for compliance with Indonesia's Personal Data Protection Law (UU PDP No. 27/2022), Singapore's PDPA and Malaysia's PDPA.
1. Who we are
OpportunityRadar ("we") provides an opportunity-intelligence service to business customers. For customer account data we act as a data controller; for data you enter about your own business we process it to provide the service.
2. Data we collect
- Account data: name, work email, password (stored only as a one-way hash), company name.
- Workspace data: company profile, watchlists, preferences, feedback on signals, questions you ask.
- Usage data: pages viewed, actions taken, email opens (via a tracking pixel), IP address and browser type for security.
- Billing data: plan, invoices and payment status. Card or bank details are handled by our payment provider and never stored by us.
3. Public-source intelligence
Signals are derived from publicly available business information (e.g. company announcements, filings, tenders, news). We collect only content that is publicly accessible through permitted means, respect robots.txt and do not bypass access controls. Names of business people may appear where they are part of public business news (e.g. an executive appointment).
4. How we use data
- To provide monitoring, matching, reports and alerts.
- To secure the service (rate limiting, fraud and abuse prevention, audit logs).
- To improve relevance using your feedback within your workspace.
- To send transactional emails and the reports and alerts you choose.
5. AI processing
We use AI models (currently Anthropic Claude) to analyze public-source content and generate summaries. Your company profile may be included in prompts to assess relevance. We do not use your workspace data to train third-party models.
6. Sharing
We share data only with service providers needed to run the service (hosting, database, email delivery, payments, AI processing) under appropriate agreements, or where required by law.
7. Retention
Account and workspace data are kept while your account is active and deleted within 90 days of closure, except where we must retain records (e.g. invoices) by law.
8. Your rights
You may request access, correction or deletion of your personal data, or withdraw consent for marketing, by contacting privacy@your-domain.example.
9. Security
We use encryption in transit, hashed passwords, database-level tenant isolation, access controls and audit logging.
10. Contact
Questions: privacy@your-domain.example (replace with your company contact before launch).