Privacy Policy

Last Updated: July 20th, 2026

Introduction

Onapsis, Inc. (“Onapsis”, “we” or “us”) respects your privacy and is committed to protecting it through our compliance with this Privacy Policy (“Policy”). This Policy explains what personal data Onapsis collects on customers, partners, vendors and marketing contacts, and how we use it. By accessing or using the website, you agree to the policies and practices described in this Policy. Onapsis may change this Policy from time to time. Your use of the website at any time indicates your acceptance of the version of this Policy posted on the website at such time, so please check this Policy periodically for updates.

We may collect and process your name, email address, job information, phone number, address and cookie information. Personal data can be collected when voluntarily submitted or provided by you through sales enquiries, marketing events, downloads, use of Onapsis platform, customer portal and website (“Website”) and from third parties.


The information we collect on or through the Website may include information you provide by filling in forms or making other affirmative choices on the Website, details of transactions you carry out through the Website and information we collect through automatic data collection technologies (“Cookies”). As you navigate through and interact with the Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions, and patterns, including (i) details of your visits to the Website, such as traffic data, logs, navigation data and other communication data and the resources that you access and use on Website; and (ii) information about your computer and internet connection, including your IP address, operating system, and browser type.
The information we collect automatically is statistical data and may include personal data, but we may maintain it or associate it with personal data we collect in other ways or receive from third parties. This information helps us to understand our user base and usage patterns, store information about your preferences, allowing us to customize our Website, improve the Website and deliver better service; and recognize you when you return to the Website.

The technologies we use for automatic data collection may include:

  • Browser cookies
    A browser cookie is a small file placed on the storage unit of your device. A cookie file can contain data such as a user ID that the site uses to identify your computer or device and to identify the pages you’ve visited, but the only personal data a cookie can contain is data you supply yourself. Your browser is most likely set to accept cookies. However, if you would prefer not to receive cookies, you can alter the configuration of your browser to refuse cookies. If you choose to have your browser refuse cookies, it is possible that some areas of our Website will not function properly when you view them. Note that third parties collect and use data from Cookies placed on the Website. This Privacy Policy may not describe the privacy practices of such third parties. We encourage you to read the privacy policies of these third parties and, if you prefer to not have data reported by these parties, follow their opt-out processes where these exist.
  • Web beacons
    Pages of the Website may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags, and single-pixel gifs) that permit us to ascertain the effectiveness of our product, service campaigns and marketing programs; allow us to customize the services offered on or through our Website; and help us determine the best use for Website content, and product and service offerings.

To the extent hyperlinks are utilized to access external or third-party sites, you should be aware that these external or third-party sites are not controlled by Onapsis and, therefore, are not subject to this Policy. Onapsis suggests that you check the privacy policies of these sites to determine how your personal data will be utilized by the proprietors of those third-party sites.

If you are a customer or a partner your personal data will be used for contract management, sales administration, Onapsis customer portal access and product updates. This will allow us to fulfil our contractual obligations owed to you and to support our business relationship with you. We will also use your personal data to verify your identity, communicate with you, arrange the delivery or other provision of products and services, provide customer services and respond to your product support requests.

If you provide us with your personal data using one of our Website forms, we will hold this information to track if you visit the Onapsis Website again, and to follow up with you if you request Onapsis to do so. We may also collect information about the use of the Onapsis Website such as the types of information accessed and how many users we receive daily. Onapsis may use this data to help us monitor, improve and protect our products, content, services and for statistical analysis, marketing, or similar promotional purposes.

We may also use your personal data for marketing purposes if we have your consent or a legitimate interest in doing so. We may, from time to time, contact you to keep you informed about our products and services, special offers, events or our selected partners’ products and services. You can unsubscribe from marketing emails at any time.

On other occasions, we may also use your personal data for any other purpose with your consent and we will use the data for the purpose which we will explain at that time.
 
Personal data usage is limited to the purposes mentioned in this policy.

We may share your personal data with other Onapsis companies. Where another Onapsis company processes your information the same principles of this Policy will apply. We may also share your personal data with our suppliers to process your personal data on our behalf. If you would like further information on our suppliers and their privacy policies, please contact us at [email protected]

If Onapsis needs to transfer your personal data to a third party outside of the European Economic Area (“EEA”) or Switzerland, we will ensure that your personal data is appropriately protected through standard contractual clauses approved by the EU Commission or Swiss Federal Data Protection and Information Commissioner (FDPIC), or other means approved by our supervisory authority.

You have the right to:

  • request a copy of the personal data Onapsis holds about you and to have any inaccuracies corrected,
  • to have your personal data removed from our marketing database if you no longer wish to receive marketing communications,
  • to choose your personal data not being shared with third parties,
  • to choose limit the use of your personal data to third parties,
  • to opt out of the processing of your personal data.

Please send your rights requests to [email protected]

These rights may be limited, for example if fulfilling your request would reveal personal data about another person, where they would infringe the rights of a third party (including our rights) or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping. Relevant exemptions are included in the GDPR. We will inform you of relevant exemptions we rely upon when responding to any request you make.

Your Choices

If personal data covered by this Policy, including personal data received from the European Union or Switzerland in reliance on the EU-U.S. DPF or the Swiss-U.S. DPF, is to be used for a purpose that is materially different from the purpose for which it was originally collected or subsequently authorized by you, or is to be disclosed to a third party that is not acting as an agent on Onapsis’ behalf, Onapsis will give you the opportunity to choose (opt out) whether your personal data is used or disclosed in that manner.

You can exercise your choices and limit the use and disclosure of your personal data by contacting us at [email protected].

For customers, partners and vendors, we will keep your personal data for up to six years after your contract with us ends or for as long as required pursuant to applicable legal and/or regulatory requirements.

For portal users, we will keep your personal data for as long as you are an active user of our Website and for up to five years after this. For marketing contacts, we will keep your personal data until your request us to stop and for a short period after this (to allow us to implement your request). We will also keep a record of the fact that you have asked us not to send you direct marketing or to process your data indefinitely so that we can respect your request in future.

If you would like to make a complaint about our use of your personal data please send details of your complaint, including the personal data it relates to, to [email protected]. We will investigate your complaint and respond as soon as we can, and no more than one month later. If you have unresolved concerns, you have the right to complain to an EU or Swiss data protection authority where you live, work or where you believe a breach may have occurred.

Data and its protection are becoming increasingly important to individuals and enterprises. On May 25, 2018, the European Union reenacted the most significant piece of legislation intended to protect personal data, the General Data Protection Regulation. The GDPR is designed to establish one set of data protection rules across the EEA. The GDPR applies to organizations that process EEA personal data, even if that organization is established outside of the EEA.

The terms “Data Controller”, “Data Processor”, “Personal Data”, “Processing” and “Subprocessor” shall have the same meaning as defined in the Standard Contractual Clauses and Article 4 GDPR;

Pursuant to Article 28 of the GDPR, Onapsis has certain obligations as Data Processor relating to its processing of personal data and expressly commits to:

  • Only act on written instructions of the Data Controller (i.e. customer set out in a Data Processing Agreement).
  • Implement technical and organizational measures to ensure the adequate protection of Customer’s Personal Data, which measures shall fulfil the requirements of the GDPR and specifically its Article 32.
  • Notify Data Controller, without undue delay, if Onapsis becomes aware of breaches of the protection of personal data and to the data protection authorities within 72 hours.
  • Engage Subprocessors (i.e. contractors) only with prior written authorization of the Data Controller.
  • Provide adequate safeguards to transfer Personal Data to a country outside the EEA (“Third country”), such as the standard contractual clauses.
  • Ensure that persons authorized to process Personal Data have committed themselves to Data Secrecy/Confidentiality Agreements.
  • Inform the Data Controller if Onapsis receives a request from a data protection authority or individuals to exercise data subject’s rights.
  • Upon Data Controller’s instruction, correct, delete or return all the Personal Data after the end of the provision of services.
  • Make available to the Data Controller all information necessary to demonstrate compliance and cooperate in audits.

Data and its protection are becoming increasingly important to individuals and enterprises. On September 1, 2023, Switzerland enacted its revised Federal Act on Data Protection to modernize and strengthen data privacy standards across Switzerland. The Swiss FADP applies to organizations that process personal data of individuals in Switzerland, even if that organization is established outside of Switzerland.

The terms “Data Controller” (or Controller), “Data Processor” (or Processor), “Personal Data”, “Processing”, and “Subprocessor” shall have the same meanings as defined in the Swiss FADP, applicable Data Processing Agreements, or Standard Contractual Clauses.

Pursuant to Article 9 of the Swiss FADP, Onapsis has certain obligations as a Data Processor relating to its processing of personal data and expressly commits to:

  • Only act on written instructions of the Data Controller (i.e., customer as set out in a Data Processing Agreement).
  • Implement technical and organizational measures to ensure the adequate protection of Customer’s Personal Data, fulfilling the data security requirements under the Swiss FADP.
  • Notify Data Controller, without undue delay, if Onapsis becomes aware of breaches of the security or protection of personal data so that appropriate notifications can be made to relevant authorities (such as the Swiss Federal Data Protection and Information Commissioner – FDPIC).
  • Engage Subprocessors (i.e., contractors) only with prior authorization of the Data Controller.
  • Provide adequate safeguards to transfer Personal Data to a country outside of Switzerland (“Third Country”), such as Swiss FDPIC-approved Standard Contractual Clauses or self-certification under the Swiss-U.S. Data Privacy Framework.
  • Ensure that persons authorized to process Personal Data have committed themselves to strict confidentiality agreements.
  • Inform the Data Controller if Onapsis receives a request directly from a Swiss data protection authority or individuals exercising their data subject rights.
  • Upon Data Controller’s instruction, correct, delete, or return all Personal Data after the end of the provision of services.
  • Make available to the Data Controller information necessary to demonstrate compliance and cooperate in audits.

Pursuant to GDPR and Swiss FADP, when a Data Controller or Data Processor wishes to transfer personal data to a Third Country, the third country must ensure that it has an adequate level of protection for the personal data as determined by the European Commission (“Commission”) or provide appropriate safeguards on condition that enforceable data subject rights and effective legal remedies for data subjects are available.

Onapsis will continue to use European Commission-approved Standard Contractual Clauses (“SCC”)   as a legal mechanism to legitimize international data transfers from the EEA and Switzerland to countries that are not deemed to provide an adequate level of protection and has deployed a mechanism that provides appropriate safeguards for the data. Therefore, third country transfer will be based on SCC and incorporated in the form of a Data Processing Agreements (“DPA”s) or other written agreements between Onapsis and its customers. Onapsis will not transfer personal data that processes on Customer’s behalf to any third country, unless and according to the Commission, a mechanism that provides appropriate safeguards for data is properly deployed.

In addition, and for the purposes of providing an additional level of trust for its European customer base and Swiss customer base, Onapsis has self-certified for the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework. The EU-U.S. Data Privacy Framework has been deemed by the European Commission as adequate to enable data transfers under EU law (adequacy decision on the EU-US Data Privacy Framework). The Swiss-U.S. Data Privacy Framework was deemed adequate by the Swiss Federal Council under Swiss law (the Federal Act on Data Protection)

Notice of Certification: Onapsis complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Onapsis has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF. Onapsis has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit the Data privacy framework website.

Scope: This section describes the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework considerations for data privacy and protection.
Onapsis is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.

Compelled Disclosure: Onapsis may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Complaints: In compliance with the EU-U.S. DPF and Swiss-U.S. DPF Principles, Onapsis commits to resolve complaints expeditiously (no more than 45 days) about our collection or use of your personal data. Enquiries or complaints regarding our EU-U.S. DPF and Swiss-U.S. DPF policy should be requested to Onapsis at: [email protected]

Dispute Resolution: If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, Onapsis has committed to refer unresolved EU-U.S. DPF and Swiss-U.S. DPF complaints to JAMS (Judicial Arbitration and Mediation Services, Inc), an alternative dispute resolution provider located in the United States. In either of those cases, please contact or visit https://www.jamsadr.com/dpf-dispute-resolution for more information or to file a complaint. The services of JAMS (Judicial Arbitration and Mediation Services, Inc) are provided at no cost to you.

Arbitration: For residual complaints not fully or partially resolved by other means, you may be able to invoke binding arbitration before the EU-U.S. DPF and Swiss-U.S. DPF Panel as detailed in the Principles. For further information, please see the EU-U.S. DPF and Swiss-U.S. DPF website. To learn more about the EU-U.S. DPF and Swiss-U.S. DPF at the Data privacy framework website.

Liability: In the context of an onward transfer, Onapsis as a EU-U.S. DPF and Swiss-U.S. DPF certified organization has responsibility for the processing of personal data it receives under the EU-U.S. DPF and Swiss-U.S. DPF. Onapsis, as a EU-U.S. DPF and Swiss-U.S. DPF certified organization, shall remain liable under the Principles if its agent processes such personal data in a manner inconsistent with the Principles, unless we prove that it is not responsible for the event giving rise to the damage.

Onapsis will not collect personal data from any person who is actually known to us to be under the age of 16. If we become aware that a person under 16 has provided personal Data, Onapsis will take steps to remove such data and terminate that individual’s account, access and use of the Website. If you believe we might have any information about a child under 16, please contact us at [email protected]

This section provides additional details about the personal information we collect about California residents and their rights under the California Consumer Privacy Act or “CCPA”, and expanded by the California Privacy Rights Act “CPRA”.
For more details about the personal information we have collected over the last 12 months, including the categories of sources, please see the information we collect on section What personal data does Onapsis have?. This information is collected to improve our Website and deliver a better service for contract management, sales administration, Onapsis customer portal access and product updates, described in the How is my personal data used? section. We share this information with third parties as described in the Is my personal data shared with third parties? section. Onapsis does not sell (according to  CCPA’s definition) the personal information we collect, and will not sell it without providing a right to opt out. Please note that we do use cookies to enhance the user experience, monitor and improve performance in our Website and for advertising purposes.

Subject to certain limitations, the CCPA provides California residents the right to request to know more details about the categories or specific pieces of personal information we collect (including how we use and disclose this information), to delete or correct their personal information, to opt out of any “sales” that may be occurring, to limit the use of sensitive personal information, and to not be discriminated against for exercising these rights.

California residents may make a request pursuant to their rights under the CCPA by contacting in an email at [email protected]. To verify your request, government identification may be required. California residents can also designate an authorized agent to exercise these rights on their behalf.

We hope that we can satisfy any queries you may have about the way we process your data. If you have any concerns about how we process your data, or would like to opt out of direct marketing, you can get in touch at [email protected] or by writing to:

Onapsis, Inc.

101 Federal Street, Suite 1800,

Boston, MA 02110