Privacy & data
Transparency noticePrivacy Notice
A role-specific notice covering data categories, purposes, disclosures, international processing, retention, security, and privacy rights.
1. Who we are and scope
Nightvault FZE, offering the Services under the OperalonOS product name (“Nightvault,” “we,” “us,” or “our”), is the legal entity responsible for the controller activities described in this Notice. OperalonOS is a product name and not a separate legal entity.
This Notice applies when an individual visits an OperalonOS website; creates or uses an Account; administers or participates in a Customer Workspace; communicates with us; purchases or administers a subscription; connects a third-party service; uses an AI or automation feature; or otherwise interacts with the Services. The Services are intended for business use by people aged 18 or older.
2. Our privacy roles
- Customer-controlled Workspace data
- Customer generally determines why and how Customer Data is processed. Customer is the controller or business and Nightvault acts as processor, service provider, or contractor. The DPA governs where applicable.
- OperalonOS business data
- Nightvault acts as controller or business for account administration, identity and access, service security, abuse prevention, billing, legal compliance, direct business communications, and its own operations.
- Customer-directed integrations
- Customer directs the data exchange with a connected provider, which may independently act under Customer’s agreement with it. Requests about Customer-controlled data should ordinarily be directed to Customer.
3. Personal Data we process
- Account and identity
- Name, business email, organization, role, permissions, authentication-provider reference, MFA and session status, invitations, recovery, and preferences.
- Workspace and operations
- Configuration, membership, policies, workflow settings, decisions, review outcomes, audit events, tasks, tickets, cases, histories, reports, and analysis.
- Customer content and integrations
- Tickets, messages, profiles, orders, fulfillment, shipping, returns, refunds, collaboration, project, knowledge, call metadata, transcripts where supported, attachments, and Customer policy content.
- Device, usage, and security
- Browser, device, operating system, IP or derived security fingerprint, request metadata, authentication events, alerts, routes, feature use, capacity, diagnostics, errors, and service health.
- AI data
- Prompts, instructions, selected context, supported files or images, generated Output, human review, model and metering information, and safety, quality, and audit evidence.
- Billing
- Business identity, billing email and address, tax IDs supplied by Customer, plan and Boost information, invoices, payments, refunds, disputes, and Stripe object identifiers.
- Direct communications
- Support, sales, security, procurement, feedback, surveys, rights requests, complaints, and dispute records.
4. Unsupported sensitive data
Unless expressly supported by a signed agreement, do not submit:
- card numbers or security codes into tickets, prompts, or free text;
- Social Security numbers, government identity-document numbers, biometric identifiers, protected health information, or precise geolocation;
- children’s data or information revealing race, ethnicity, religion, political opinion, sexual orientation, health, or criminal history; or
- other regulated or highly sensitive information.
Nightvault may request removal, restrict affected processing, or delete unsupported data after a verified review where reasonably necessary to protect people and the Services.
5. Sources, purposes, and legal grounds
We receive Personal Data directly from individuals, Customer administrators and users, Customer-selected connected systems, approved identity providers, payment and billing providers, communications providers, use of the Services, security and incident activity, and lawful public business-contact or compliance sources.
- Provide, secure, maintain, troubleshoot, and support the Services and authorized integrations.
- Authenticate people, enforce permissions, prevent abuse, investigate incidents, and preserve proportionate audit evidence.
- Apply Customer-configured workflows, policies, decision support, and human review.
- Administer contracts, subscriptions, capacity, billing, support, and communications.
- Comply with law and protect rights, safety, and service integrity.
- Measure and improve security, reliability, and usability using appropriately minimized first-party operational and product telemetry, without cross-customer profiling.
Where a legal ground is required, it depends on Nightvault’s role, the individual, data, and jurisdiction. Consent may be withdrawn where it is the basis. Customer Data is not used for a materially incompatible purpose without Customer instructions and any required notice or consent.
6. Artificial intelligence
OperalonOS uses AI for supported functions such as classification, drafting, summarization, OCR, analysis, operational recommendations, and policy-guided decision support. Relevant Input, policy context, and selected Customer Content may be sent to providers identified in the current Provider Notice using context designed to be proportionate to the requested function.
AI Output may be incomplete or unsuitable. Customer is responsible for lawful use, required notices and permissions, appropriate human review, and verifying Output before refunds, financial commitments, employment actions, legal representations, safety actions, or similar decisions. Nightvault does not independently make solely automated legal or similarly significant decisions about people using Account or Customer Data.
Nightvault does not use identifiable Customer Personal Data to train a general-purpose model made available to other customers. Approved model providers process submitted data under their applicable business terms, data-processing terms, and production configuration; no zero-retention promise applies unless separately verified for the relevant feature.
7. Disclosures, sale, and advertising
Personal Data may be disclosed as needed to configured infrastructure, database, identity, AI, payment, email, and integration providers identified in the current Provider Notice; Customer-directed services; confidential professional advisers; lawful authorities; or a corporate successor subject to appropriate safeguards. Provider roles and contractual protections depend on the applicable service and data flow. Nightvault maintains controls designed to prevent intentional disclosure of one Customer’s Customer Data to another Customer.
8. Cookies and international processing
OperalonOS uses essential cookies and browser storage for authentication, security, session continuity, OAuth state, invitation redemption, Workspace preferences, draft recovery, and interface state. The Cookie Notice gives details.
Nightvault is established in the United Arab Emirates and its providers and United States Customers may process data in other countries. Where a restricted transfer requires a mechanism, Nightvault will use an applicable safeguard such as approved contractual clauses, a transfer addendum, adequacy basis, or other lawful mechanism and may restrict the flow until that safeguard is in place.
9. Retention and security
Personal Data is retained only as reasonably needed to provide the Services and follow verified instructions, maintain security, complete billing and legal obligations, resolve disputes, enforce agreements, and preserve narrowly scoped evidence. Feature-specific retention controls and exports apply where available. Broader access, correction, export, restriction, or deletion requests use the verified manual process described below and remain subject to technical feasibility, provider backup cycles, security evidence, dispute preservation, and applicable law. Nightvault does not promise a universal deletion or backup-expiry period unless an activated Order expressly states one.
Nightvault uses technical and organizational measures designed to protect Personal Data, including tenant-scoped authorization, row-level controls, least privilege, secure authentication, encryption in transit, protected handling of selected secrets and content, security logging, rate limiting, request validation, signed webhooks, and controlled incident response. No service can guarantee absolute security.
10. Privacy rights
Depending on applicable law and Nightvault’s role, an individual may have rights to know, access, correct, delete, restrict, object, obtain a portable copy, withdraw consent, opt out of qualifying processing, request human review, appeal, complain to a regulator, and receive non-discriminatory treatment. Rights remain subject to verification and lawful limitations.
Requests about data in a Customer Workspace should normally go to the Customer. Requests concerning OperalonOS controller data may be sent to contact@operalonos.com. Nightvault uses a verified manual request process, may ask for identity, authority, scope, and Workspace information, and records the applicable response or lawful limitation. Available exports are feature-specific rather than a single universal Workspace export.
United States state privacy laws apply only when their own scope and thresholds are met. Nightvault uses a common request framework where reasonably practicable and does not use sensitive Personal Data to infer characteristics for advertising or unrelated profiling.
11. Children, changes, and contact
The Services are not directed to people under 18, and Nightvault does not knowingly offer Accounts to them. Customer must not process children’s data through the Services without express written authorization, a documented lawful basis, and required controls.
Material changes receive a new version and effective date and, where required, reasonable advance notice. A materially incompatible new purpose will not be applied retroactively without a required notice, consent, or lawful ground.