Privacy Policy
Opyris believes that business software should collect only the information it needs, explain clearly how that information is used, and give people meaningful control over their personal information.
We do not sell personal information. We do not rent customer or employee information. We do not use information stored in a customer's Opyris account for third-party advertising.
This Privacy Policy explains how Opyris collects, uses, stores, discloses, exports, and deletes information when people use the Opyris website, applications, and employee scheduling services.
Privacy at a glance
- We collect only information reasonably required to provide, secure, support, and improve Opyris.
- Customers retain control of the information stored within their Opyris tenant.
- Opyris does not claim ownership of Customer Data.
- We do not sell personal information or Customer Data.
- Customers may export or request a copy of their data.
- Individuals may request access to or correction of their personal information.
- Customers may request deletion of their account and associated Customer Data.
- We follow principles similar to those found in the GDPR, including access, correction, portability, data minimization, and the right to request deletion.
- Some information may need to be retained temporarily for legal, security, accounting, fraud-prevention, or backup purposes.
1. Who we are
Opyris provides employee scheduling, availability management, shift management, timekeeping, reporting, and related workforce-management services for businesses.
For privacy questions or requests, contact:
Privacy Officer
Opyris
Box 897
St. George, Brant, Ontario
N0E 1N0
Canada
Email: david@opyris.ca
A dedicated privacy email address may also be published in the future. Messages sent to the address above will reach the person responsible for privacy at Opyris.
2. Scope of this policy
This policy applies to personal information processed through:
- The Opyris public website
- The Opyris signup and account-management services
- The Opyris manager and employee applications
- The Opyris Mobile Ready application experience
- Customer support and business communications
- Product analytics, operational monitoring, and security systems
This policy does not govern the independent privacy practices of an Opyris customer, such as an employer's own collection or use of employee information outside Opyris.
3. The roles of Opyris and its customers
Customer Data
A business that creates an Opyris account decides:
- Which employees and users are added
- What employee information is entered
- Which Opyris features are used
- Why employee information is processed
- How long information should be maintained
- Who within the business may access it
For this information, the customer controls the purpose and use of the information. Opyris processes it to provide the service and to carry out the customer's instructions.
As between Opyris and the customer, the customer retains all rights and control over its Customer Data. Opyris does not claim ownership of that data. Individuals whose personal information appears in Customer Data retain any privacy rights provided to them by applicable law.
Information managed directly by Opyris
Opyris is directly responsible for information used to:
- Establish and administer customer accounts
- Process subscriptions
- Secure and operate the service
- Provide support
- Communicate with customers
- Understand website and product performance
- Meet legal and regulatory responsibilities
4. Information we collect
The specific information collected depends on how Opyris is used.
4.1 Customer account information
We may collect:
- Business name
- Business address and location information
- Account administrator's name
- Work email address
- Business telephone number
- Login credentials and authentication information
- Subscription and account status
- Account preferences and configuration
- Communications with Opyris
- Support requests
We collect this information to establish, maintain, secure, support, and administer the customer account.
4.2 Customer and employee information
Customers may enter or generate information such as:
- Employee names
- Employee work or personal contact information
- Usernames
- Employment roles
- Departments and work locations
- Skills and role eligibility
- Availability
- Time-off requests
- Approved leave
- Shift assignments
- Work schedules
- Open-shift and shift-swap requests
- Clock-in and clock-out records
- Scheduled and actual hours
- Payroll-related identifiers and export information
- Employment-related settings selected by the customer
- Messages or other information submitted through enabled product features
Opyris processes this information only as required to provide the service, carry out customer instructions, secure the service, troubleshoot problems, and comply with applicable law.
Customers should not enter information that is unnecessary for scheduling, workforce management, timekeeping, reporting, or another supported Opyris function.
4.3 Billing information
Payments are processed through Stripe.
Stripe may collect payment-card and billing information in accordance with its own privacy and security practices. Opyris generally receives limited billing information, such as:
- Customer or subscription identifiers
- Transaction status
- Payment status
- Billing contact information
- Limited payment-method details, such as card type or final digits
Opyris does not intend to store complete payment-card numbers in its own application databases.
4.4 Usage, performance, and technical information
We collect limited operational information necessary to run, secure, understand, and improve the service.
This may include:
- Pages or features used
- Dates and times of access
- Browser and device type
- Operating system
- Internet Protocol address
- Authentication and session events
- Application errors
- Response times
- Service availability
- Performance measurements
- Number of employees or users in an account
- General account configuration and feature usage
- Security-related events
- Referral or campaign information
We use this information to:
- Maintain service reliability
- Diagnose errors
- Prevent abuse
- Protect customer accounts
- Understand which features are being used
- Plan infrastructure capacity
- Improve usability
- Measure the effectiveness of the Opyris website
- Produce internal business metrics
We do not use Customer Data or usage information to create advertising profiles or sell targeted advertising.
4.5 Mobile and notification information
When a customer or employee uses an Opyris mobile application, we may process information required for application functionality, such as:
- Device type
- Application version
- Push-notification token
- Authentication information
- Notification delivery status
- Error and performance information
Push notifications, where enabled, are delivered through configured notification providers.
Where a customer enables a feature that requires device or workplace-location information, Opyris will process only the information required to provide that feature. Relevant notice should be shown when that information is requested.
4.6 Information provided through support
When someone contacts Opyris, we may collect:
- Name and contact information
- Customer account
- Description of the problem
- Relevant application activity
- Screenshots or files voluntarily supplied
- Communications relating to the request
Customers should avoid sending unnecessary employee information through email or support communications.
5. How we use information
Opyris uses personal information and Customer Data to:
- Create and administer accounts
- Authenticate users
- Generate employee schedules
- Apply customer-defined staffing rules
- Process availability and time-off information
- Publish schedules and notify employees
- Support shift swaps and open shifts
- Record and report employee time
- Produce customer-requested reports and exports
- Process subscriptions and payments
- Provide customer support
- Communicate service information
- Monitor availability and performance
- Diagnose and correct errors
- Prevent fraud, misuse, and unauthorized access
- Maintain audit and security records
- Develop and improve Opyris
- Meet legal, accounting, and regulatory obligations
We will not use personal information for a materially different purpose without providing appropriate notice and obtaining consent where required.
6. Automatic scheduling
Automatic scheduling is a core Opyris feature.
The Opyris scheduler uses information and rules supplied or approved by the customer, which may include:
- Required staffing levels
- Employee availability
- Approved time off
- Roles
- Skills
- Departments
- Work locations
- Customer-defined scheduling rules
Opyris performs this processing on behalf of the customer.
Customer managers determine the rules, decide when automatic scheduling runs, and remain responsible for reviewing and managing employment decisions. Opyris does not independently determine whether a person should be hired, dismissed, disciplined, promoted, or otherwise subjected to an employment decision.
7. Aggregated and de-identified information
Opyris may combine or de-identify usage and operational information to understand matters such as:
- Service performance
- General feature adoption
- Typical account sizes
- System capacity
- Error rates
- Scheduling activity
- Product trends
We may use aggregated or de-identified information for analytics, planning, security, and product improvement.
We will not attempt to re-identify information that has been properly de-identified, except where reasonably necessary to test or confirm that the de-identification process is effective.
8. When information is shared
Opyris does not sell or rent personal information.
Information may be disclosed in the following circumstances.
8.1 Within the customer's account
Information is made available to customer-authorized users according to their roles and permissions.
For example:
- Employees may access their own schedules and information made available to them.
- Managers may access information within their organization according to their assigned permissions.
- Customer administrators may manage users, settings, schedules, reports, and account data.
8.2 Service providers
Opyris uses service providers to operate the service. These may include providers of:
- Hosting and infrastructure
- Email delivery
- Push notifications
- Payment processing
- Monitoring and error reporting
- Data backup
- Customer communications
Known service providers include Stripe for payment processing and configured notification providers for push delivery where enabled.
Service providers receive only the information reasonably required to perform their services and are subject to their own privacy and security obligations.
8.3 Legal and safety requirements
We may preserve or disclose information where reasonably necessary to:
- Comply with applicable law
- Respond to a valid court order, warrant, subpoena, or lawful government request
- Protect the rights, safety, or property of Opyris, its customers, users, or the public
- Investigate fraud, abuse, or a security incident
- Establish, exercise, or defend legal claims
Where legally permitted, we will attempt to notify the affected customer before disclosing Customer Data in response to a legal demand.
8.4 Business transactions
Information may be reviewed or transferred as part of a proposed or completed financing, merger, acquisition, restructuring, or sale of all or part of the business.
Any recipient must protect the information and use it only for purposes consistent with this policy and applicable law.
9. Processing outside Canada
Opyris is a Canadian business.
Some service providers may process or store limited information in Canada, the United States, or other jurisdictions. Information processed outside Canada may be subject to the laws of the country in which it is processed, including lawful access by courts, governments, or law-enforcement authorities.
Opyris evaluates service providers based on the nature of the service and information involved and seeks to limit the information shared with each provider.
10. Cookies and similar technologies
Opyris uses cookies or similar technologies where necessary to:
- Maintain secure sessions
- Authenticate users
- Remember essential preferences
- Protect against abuse
- Measure website and application performance
- Understand general site usage
Opyris does not use third-party advertising cookies to build advertising profiles.
Where a non-essential cookie or analytics technology requires consent, Opyris will request that consent before enabling it.
Users may be able to limit cookies through their browser settings. Disabling essential cookies may prevent parts of Opyris from working correctly.
11. Data security
Opyris uses administrative, technical, and organizational safeguards appropriate to the nature of the information processed.
Current safeguards include:
- Encryption of connections using HTTPS and TLS
- Password hashing
- Short-lived authentication tokens
- Refresh-token rotation
- Session invalidation
- Authentication rate limiting
- Role-based access controls
- Tenant-level data isolation
- Operational logging and monitoring
- Regular database backups
- Restrictions on administrative access
Each customer tenant is logically isolated from other customer tenants. Customer employees, schedules, reports, and related records are not intentionally made available to another customer.
No internet service can guarantee absolute security. Customers are responsible for maintaining secure passwords, protecting their login credentials, assigning appropriate user permissions, and promptly notifying Opyris of suspected unauthorized access.
12. Data retention
Opyris retains information only for as long as reasonably required to:
- Provide the service
- Maintain the customer account
- Fulfil the purposes described in this policy
- Meet legal, accounting, or contractual requirements
- Resolve disputes
- Prevent fraud or abuse
- Maintain service and security records
- Establish or defend legal claims
Active Customer Data is generally retained while the customer's account remains active.
When an account is closed or deletion is requested, Opyris will delete or de-identify Customer Data from active production systems within a reasonable period, subject to:
- Identity and authority verification
- Legal retention requirements
- Accounting and transaction-record obligations
- Active disputes or legal claims
- Fraud-prevention and security requirements
- Technical backup rotation
Deleted information may remain temporarily in encrypted or access-restricted backups until those backups expire through the normal retention cycle. Information retained in a backup will not be restored to normal production use except as part of a legitimate disaster-recovery process.
If a backup containing deleted data must be restored, Opyris will take reasonable steps to reapply the relevant deletion request.
13. Access, correction, and data export
Individuals may request:
- Confirmation that Opyris processes their personal information
- Access to their personal information
- Information about how it is used
- Information about categories of recipients
- Correction of inaccurate or incomplete personal information
- A copy of personal information in a commonly usable electronic format
- Deletion where appropriate
- Information about applicable retention practices
Customer administrators may also export scheduling data, clock records, and payroll-related information using available Opyris reporting functions.
Requests may be sent to david@opyris.ca.
Opyris may need to verify the requester's identity and authority before providing access, changing information, exporting data, or deleting data.
We aim to respond to complete privacy requests within 30 days. Where additional time is permitted and reasonably necessary, we will explain the reason for the extension.
Access may be limited where disclosure would:
- Reveal another person's personal information
- Compromise security
- Reveal confidential commercial information
- Violate legal privilege
- Conflict with a legal obligation
- Be prohibited by law
Where access cannot be provided, Opyris will explain the reason unless prohibited from doing so.
14. Employee privacy requests
Most employee information in Opyris is entered and controlled by the employee's employer.
Employees seeking access, correction, or deletion of information stored by their employer should normally contact their manager or employer first.
When Opyris receives a request concerning Customer Data, we may:
- Verify the requester's identity
- Notify or consult the relevant customer
- Refer the request to the customer
- Assist the customer in locating, exporting, correcting, or deleting the information
Opyris will not delete or alter employer-controlled records solely on an employee's request where doing so would conflict with the customer's lawful instructions, employment-record obligations, the rights of other individuals, or applicable law.
Requests concerning information controlled directly by Opyris may be submitted directly to Opyris.
15. The right to request deletion
Opyris supports the principle commonly called the right to be forgotten.
A verified customer may request deletion of its account and associated Customer Data. An individual may request deletion of personal information controlled directly by Opyris.
Deletion requests will be honoured where the information is no longer reasonably required and no legal or operational exception applies.
The right to deletion is not absolute. Some information may be retained where reasonably necessary for:
- Legal or accounting obligations
- Transaction records
- Fraud and security investigations
- Enforcement of agreements
- Dispute resolution
- Legal claims
- Protection of other individuals' rights
- Temporary backup retention
Where complete deletion cannot immediately be performed, Opyris will explain what information must be retained, why it must be retained, and, where possible, how long it will be retained.
16. Withdrawal of consent
Where information is processed based on consent, an individual may withdraw that consent, subject to legal or contractual restrictions and reasonable notice.
Some information is necessary for Opyris to provide the service. Withdrawing consent to essential processing may mean that the relevant account or feature can no longer be used.
Withdrawal does not invalidate processing that lawfully occurred before consent was withdrawn.
17. Service and marketing communications
Opyris may send service-related communications necessary to operate an account, including:
- Authentication messages
- Security notices
- Schedule and shift notifications
- Account notices
- Billing notices
- Material service changes
- Support responses
These messages are part of the service and may not always provide an unsubscribe option.
Optional promotional communications will provide an unsubscribe method. Unsubscribing from promotional communications will not stop necessary account, security, billing, or operational messages.
18. Security incidents
If Opyris becomes aware of unauthorized access to, loss of, or disclosure of personal information, we will:
- Investigate the incident
- Take reasonable steps to contain and remediate it
- Preserve required records
- Assess the potential impact
- Notify affected customers, individuals, regulators, or other parties where required by law
Where an incident creates a real risk of significant harm, notification will be provided as soon as reasonably feasible in accordance with applicable requirements.
19. Minors
Opyris is intended for use by businesses and their authorized workforce. It is not intended for children to create independent consumer accounts.
Some customers may employ individuals who have not reached the age of majority. The customer is responsible for ensuring that it has lawful authority to enter and process information about those employees and for providing any notices or obtaining any consent required by law.
Opyris will process such information only to provide the services requested by the customer.
20. Privacy complaints
Questions, concerns, or complaints may be directed to:
Privacy Officer
Email: david@opyris.ca
Please include "Privacy" in the subject line.
We will investigate privacy concerns fairly and attempt to resolve them directly.
Individuals may also have the right to contact the Office of the Privacy Commissioner of Canada or another applicable privacy regulator.
21. Changes to this policy
Opyris may update this Privacy Policy to reflect:
- Product changes
- New service providers
- Changes to privacy practices
- Security improvements
- Legal or regulatory requirements
The updated policy will be posted with a revised "Last updated" date.
Where a change materially affects how personal information is collected, used, or disclosed, we will provide additional notice through the service, by email, or by another appropriate method.