Privacy Policy
Last updated: July 27, 2026
This Privacy Policy explains how BNMA ("OpSyDian," "we," "us," or "our") handles personal information in connection with the OpSyDian platform and website (the "Service").
1. Two different roles
This distinction matters, so it comes first.
We are a service provider (processor) for ERP data. When our customers connect their INxSQL deployment, the Service synchronizes their business records — orders, quotes, customer contacts, inventory, and related data. Some of that includes personal information about our customers' own customers and contacts. We process it only on our customer's instructions, to provide the Service. The customer decides what data is synchronized, how long it is kept, and who may access it. If you are a contact of a business that uses OpSyDian and you want your information accessed, corrected, or deleted, contact that business directly. We will refer such requests to them and support them in responding.
We are a controller for our own business data. This covers the accounts of users who log into OpSyDian, people who request a demo through our website, and visitors to opsydian.io. The rest of this policy describes that data.
2. Information we collect
Information you give us
- Account information — name, work email address, job title, organization name, and password credentials
- Demo requests and inquiries — the contents of forms you submit and correspondence you send us
- Billing information — billing contact, billing address, and purchase history. Payment card details are collected and stored by our payment processor, not by us
- Support communications — messages, attachments, and diagnostic details you send when requesting support
Information collected automatically
- Usage data — features used, pages viewed, actions taken in the Service, and timestamps
- Device and connection data — IP address, browser type and version, operating system, and referring page
- Log data — authentication events, errors, and system activity, retained for security and troubleshooting
- Cookies and similar technologies — see Section 6
Information from your organization. If your employer creates an account for you, we receive your name, email, role, and permission assignments from them.
3. How we use information
We use personal information to:
- Provide, operate, maintain, and support the Service
- Authenticate users and manage permissions
- Communicate about your account, including service, security, and billing notices
- Respond to demo requests, support tickets, and other inquiries
- Monitor for and investigate security incidents, fraud, and abuse
- Analyze usage to improve reliability, performance, and product design
- Send product and marketing communications where permitted, which you can opt out of at any time
- Comply with legal obligations and enforce our Terms of Service
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
4. How we share information
We do not sell your personal information, share it for advertising, or disclose it to any third party for that party's own purposes.
We use a small number of vendors solely to host and operate the Service — for example, cloud infrastructure. They act on our instructions under contracts that prohibit using the information for anything other than providing services to us. A current list is available on request.
Beyond that, information is disclosed only in these limited circumstances:
Your organization. Administrators of your organization's account can access your account information, permission settings, and activity within the Service.
Legal and safety. We may disclose information where we believe in good faith it is necessary to comply with law or valid legal process, to enforce our agreements, or to protect the rights, property, or safety of OpSyDian, our customers, or the public. Where lawful and practicable, we will notify the affected customer before disclosing their data.
Business transfers. In a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify affected customers and this policy will continue to apply until replaced.
5. United States only
OpSyDian is offered solely to businesses in the United States, and all information is collected, stored, and processed in the United States. We do not knowingly offer the Service to, or market it to, individuals or organizations located in the European Economic Area or the United Kingdom. If you are located outside the United States, please do not use the Service or submit information to us.
6. Cookies
We use:
- Strictly necessary cookies — authentication, session management, and security. These cannot be disabled without breaking the Service
- Preference cookies — remembering settings such as display options
- Analytics cookies — understanding how the Service is used, so we can improve it
You can control cookies through your browser settings. We do not currently respond to browser Do Not Track signals. We do honor Global Privacy Control signals where required by law.
7. Retention
We keep account information for as long as your account is active and for 12 months afterward, unless a longer period is required for legal, tax, or dispute-resolution purposes. Log and security data is retained for 12 months. Customer Data synchronized from a customer's ERP is retained according to that customer's agreement with us, and is available for export for 30 days following termination before deletion.
Backups containing deleted data are overwritten on a rolling 35-day cycle.
8. Security
We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, role-based access controls, least-privilege access for our personnel, logging of administrative actions, and periodic review of our security practices.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law and without undue delay.
9. Your rights
If you are in California, the CCPA/CPRA gives you the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; to opt out of sale or sharing (we do neither); and to be free from discrimination for exercising these rights. You may designate an authorized agent to make a request on your behalf. We verify requests using the email address associated with your account.
Other jurisdictions — including Colorado, Connecticut, Virginia, Utah, Texas, and others with comprehensive privacy laws — provide comparable rights, which we extend to residents of those states.
To exercise any of these rights, submit a request through the contact form at https://opsydian.io/contact. We respond within the timeframe required by applicable law, typically 30 to 45 days. Again: if your information reached us because a business that uses OpSyDian synchronized it from their ERP, direct your request to that business.
10. Marketing communications
You can opt out of marketing emails using the unsubscribe link in any message or by submitting a request through the contact form at https://opsydian.io/contact. We will still send transactional and service messages about your account, billing, and security.
11. Children
The Service is a business tool and is not directed to anyone under 18. We do not knowingly collect personal information from children. If we learn we have, we will delete it.
12. Changes to this policy
We may update this policy. We will post the revised version with a new "Last updated" date, and for material changes we will provide notice by email or in-product notice at least 30 days in advance.
13. Contact
Questions, requests, or complaints:
BNMA, 2292 Faraday Ave #59, Carlsbad, CA 92008
Or contact us through the contact form at https://opsydian.io/contact.