1. Introduction
Opynex is the trading brand of Himox Limited (“Opynex”, “we”, “us”, “our”).
We design and implement operational automation, workflow orchestration, AI-enabled systems and related technology and professional services for businesses.
Privacy and data protection are important to the systems we build and to the way we operate our own business.
This Privacy Policy explains how we collect, use, disclose, retain and otherwise process personal data when you:
- visit the Opynex website;
- contact us;
- request information or a consultation;
- communicate with our team;
- become or represent a customer, prospect, supplier or business partner;
- receive business communications from us;
- participate in an event, survey or other interaction;
- use services where Opynex determines the purposes and means of processing personal data; or
- otherwise interact with Opynex in circumstances where this Privacy Policy applies.
Where Opynex processes personal data solely on behalf of a customer under the customer's instructions, the customer will generally determine the purposes and means of that processing and Opynex may act as a processor. Those activities are governed by the relevant customer agreement and, where applicable, a Data Processing Agreement.
2. Who We Are
Legal entity: Himox Limited Trading name: Opynex Website: opynex.com
For processing activities where Himox Limited determines why and how personal data is processed, Himox Limited acts as the controller.
For certain customer engagements, Himox Limited may instead process personal data on behalf of a customer as a processor.
Our role depends on the actual processing activity.
3. Our Privacy Principles
We aim to design our processing activities around the following principles:
Purpose limitation
Personal data should be collected and used for identified purposes rather than used indiscriminately.
Data minimization
We seek to process only the personal data reasonably required for the relevant purpose.
Access control
Access to personal data should be limited according to operational need and the systems involved.
Security
Appropriate technical and organizational safeguards should be considered in relation to the nature and risk of the processing.
Transparency
Individuals should be able to understand how their personal data is being used.
Retention discipline
Personal data should not be retained indefinitely without an appropriate business or legal reason.
Accountability
Where Opynex participates in a customer processing environment, responsibilities should be established between the relevant parties.
4. Personal Data We May Collect
Depending on how you interact with Opynex, we may process the following categories of personal data.
Identity and professional information
This may include:
- name;
- job title;
- employer or organization;
- department;
- professional role; and
- professional profile information.
Contact information
This may include:
- business email address;
- telephone number;
- business address; and
- other contact information you provide.
Business relationship information
This may include:
- correspondence with Opynex;
- meeting information;
- consultation requests;
- sales and procurement discussions;
- proposals;
- contracts;
- account information;
- project records;
- support communications;
- customer feedback; and
- records relating to our commercial relationship.
Website and technical information
Subject to our actual website configuration and applicable consent requirements, this may include:
-
IP address;
-
browser type;
-
device information;
-
operating system;
-
referring pages;
-
pages visited;
-
timestamps;
-
website interaction information;
-
cookie identifiers; and
-
similar technical information.
Transaction and billing information
Where applicable, we may process information relating to:
- purchases;
- subscriptions;
- invoices;
- payment status;
- billing contacts; and
- transaction records.
Payment card information may be processed directly by the relevant payment provider rather than stored by Opynex.
Communications and marketing information
This may include:
- email interactions;
- marketing preferences;
- event participation;
- newsletter subscription information;
- responses to outreach;
- communication history; and
- preferences expressed to us.
Information obtained from public and professional sources
For legitimate business-development, research and relationship-management activities, we may obtain professional information from publicly available sources or business information providers.
This may include:
- corporate websites;
- professional networking platforms;
- company directories;
- public corporate records;
- publicly available professional profiles; and
- business intelligence sources.
Where required by applicable law, we provide appropriate privacy information regarding such processing.
Customer Data
When providing services to customers, Opynex systems may interact with information contained in customer-controlled systems.
The categories of data involved depend entirely on the relevant deployment.
Where Opynex processes that information solely on behalf of the customer and under the customer's instructions, that processing is governed by the relevant customer agreement and Data Processing Agreement rather than solely by this Privacy Policy.
5. How We Use Personal Data
Depending on the circumstances, we may use personal data to:
Operate Opynex
We may process information to administer our company, maintain business records, manage suppliers and contractors, conduct internal reporting and operate our website and systems.
Respond to enquiries
We may use information to respond when someone contacts Opynex, requests information, submits a form or requests a consultation.
Develop business relationships
We may process professional contact information to identify organizations that may benefit from Opynex services and to communicate relevant business propositions to appropriate decision-makers.
Where we rely on legitimate interests for such processing, we consider the nature of the information, reasonable expectations of the individuals involved and the interests of Opynex in developing relevant business relationships.
Individuals may object to direct marketing at any time.
Deliver services
We process information as necessary to scope, configure, implement, support, monitor and administer contracted services.
Manage customer relationships
We may use personal data to manage contracts, projects, meetings, support, billing, account administration, service reviews and customer communications.
Improve our services
We may analyse feedback, service performance and aggregated usage information to improve our processes, services and customer experience.
Maintain security and prevent misuse
We may process information to investigate suspicious activity, protect our infrastructure, prevent fraud, manage access and respond to security incidents.
Meet legal and regulatory requirements
We may process and retain information where necessary to comply with applicable legal, regulatory, tax, accounting or other obligations.
Establish, exercise or defend legal claims
Information may be processed where necessary in connection with contractual disputes, legal proceedings, investigations or protection of our legal rights.
6. Lawful Bases
Where the UK GDPR or EU GDPR applies, the lawful basis used depends on the processing activity.
We may rely on:
Contract
Where processing is necessary to enter into or perform a contract with you.
Legitimate interests
Where processing is necessary for legitimate business purposes and those interests are not overridden by applicable individual rights and interests.
These interests may include:
- operating and improving Opynex;
- protecting our systems;
- managing business relationships;
- relevant B2B business development;
- preventing fraud;
- maintaining records; and
- protecting legal rights.
Legal obligation
Where processing is necessary for compliance with an applicable legal requirement.
Consent
Where consent is required or otherwise appropriate, including for certain cookies or communications.
Consent can be withdrawn where applicable without affecting the lawfulness of processing carried out before withdrawal.
Other lawful bases may apply where permitted by applicable law.
7. B2B Outreach
Opynex may conduct targeted business-to-business outreach to professionals whose roles are reasonably relevant to the operational problems and services we address.
This may include executives and professionals responsible for operations, technology, transformation, finance, customer operations and related business functions.
We may use professional information obtained from public or appropriately sourced business information to:
- identify relevant organizations;
- understand organizational responsibilities;
- conduct company research;
- identify potential operational challenges;
- prepare relevant business proposals; and
- contact appropriate representatives.
We do not intend this activity to justify indiscriminate mass collection or irrelevant communications.
Where applicable, recipients can object to direct marketing or request that we stop contacting them.
8. Cookies and Similar Technologies
Opynex may use cookies and similar technologies necessary to operate and secure the website.
We may also use analytics, preference or marketing technologies where configured and legally permitted.
Where applicable law requires consent before non-essential technologies are placed or accessed, we will seek the required consent.
A separate Cookie Notice should identify the cookies and technologies actually deployed on opynex.com, including their provider, purpose and duration.
9. Sharing Personal Data
We may disclose personal data where reasonably necessary to:
-
service providers;
-
cloud and infrastructure providers;
-
professional advisers;
-
payment providers;
-
communication providers;
-
analytics providers;
-
contractors supporting our operations;
-
regulators or public authorities where legally required;
-
prospective purchasers, investors or advisers in connection with a corporate transaction; and
-
other parties where you instruct or authorize us to do so.
Service providers should receive only the access appropriate to the service being performed and be subject to applicable contractual requirements.
10. Customer Processing and Data Processing Agreements
Where Opynex processes personal data on behalf of a customer, the relationship may be governed by a Data Processing Agreement.
Depending on the processing activity and applicable law, such arrangements may address:
- processing subject matter and duration;
- processing nature and purpose;
- categories of personal data;
- categories of data subjects;
- documented customer instructions;
- confidentiality;
- security measures;
- sub-processors;
- assistance with individual rights;
- security incident assistance;
- data protection impact assessment assistance where applicable;
- deletion or return of data;
- audit and information rights; and
- international transfers.
The customer remains responsible for determining whether its processing activities are lawful and for providing Opynex with lawful instructions where the customer acts as controller.
11. Sub processors
Certain Opynex services may depend on third-party providers.
Where Opynex acts as a processor and engages another processor to process customer personal data, the applicable customer agreement and Data Processing Agreement govern the use of such sub-processors.
Opynex intends to maintain a current sub-processor register identifying applicable providers used for relevant customer processing.
A current sub-processor register may be made available where applicable and should identify only providers actually used in production.
The register should contain only providers actually used in production.
12. International Data Transfers
Our operations, service providers or customer-selected technologies may result in personal data being processed in countries other than the country in which it was originally collected.
Where applicable data-protection law restricts international transfers, we seek to use an appropriate transfer mechanism where required.
Depending on the circumstances, this may include:
- an adequacy decision;
- approved contractual safeguards;
- applicable Standard Contractual Clauses;
- the relevant UK transfer mechanism; or
- another legally recognized transfer mechanism.
The appropriate mechanism depends on the parties, jurisdictions and processing involved.
13. Data Security
We seek to apply security measures appropriate to the nature of the systems and information involved.
Depending on the relevant environment, measures may include:
- access controls;
- least-privilege principles;
- authentication controls;
- scoped credentials;
- environment separation;
- encryption where supported and appropriate;
- logging;
- monitoring;
- backup and recovery processes;
- vulnerability and dependency management;
- incident handling;
- confidentiality obligations; and
- supplier controls.
Specific controls vary according to the service and deployment architecture.
No internet-connected system can be guaranteed to be completely secure. Accordingly, we do not represent that security incidents are impossible.
14. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for applicable legal, accounting, security, contractual or dispute-resolution requirements.
Retention periods depend on the category and context of the information.
Our considerations may include:
- duration of the customer relationship;
- applicable limitation periods;
- accounting and tax obligations;
- contractual requirements;
- security requirements;
- outstanding disputes; and
- whether continued retention remains necessary.
15. Automated Decision-Making and AI
Opynex may use automation and AI-assisted tools within its internal operations or customer solutions.
Where Opynex determines the purposes and means of processing, we assess the role of such systems according to the relevant use case.
Where AI is used within customer-controlled processing, responsibilities are determined by the relevant contractual arrangement and architecture.
Opynex does not claim that all AI-supported processes are appropriate for fully autonomous execution.
Depending on the use case, systems may incorporate:
- human review;
- confidence thresholds;
- restricted actions;
- deterministic validation;
- escalation mechanisms; and
- other safeguards.
Where applicable law provides specific rights concerning solely automated decisions producing legal or similarly significant effects, those requirements will be considered in the relevant processing context.
16. Your Data Protection Rights
Depending on your jurisdiction and circumstances, you may have rights including:
- The right to receive information about processing;
- The right to access personal data;
- The right to correct inaccurate information;
- The right to request erasure in applicable circumstances;
- The right to restrict processing in applicable circumstances;
- The right to data portability where applicable;
- The right to object to certain processing;
- The right to object to direct marketing;
- Rights concerning certain automated decision-making; and
- The right to withdraw consent where processing is based on consent.
These rights are not absolute and may be subject to legal conditions or exemptions.
To exercise an applicable right, contact:
We may request information reasonably necessary to verify identity before acting on a request.
17. Marketing Preferences
You may ask us to stop sending direct marketing communications at any time.
Where an unsubscribe mechanism is provided, you may use it directly.
You may also contact:
We may retain limited suppression information after an opt-out where necessary to ensure we respect the request.
18. Complaints
We encourage you to contact us first if you have concerns about our handling of personal data.
You may also have the right to complain to the competent data-protection supervisory authority.
For UK matters, this may include the Information Commissioner's Office.
For individuals in the EEA, you may be entitled to contact the supervisory authority applicable to your circumstances.
19. Third-Party Websites and Services
Our website or services may contain links to, integrate with or depend upon third-party websites and services.
Those organizations operate under their own privacy practices.
This Privacy Policy does not control independent processing undertaken by third parties acting as separate controllers.
20. Children's Privacy
Opynex is a business-to-business service and is not directed at children.
We do not intentionally design our services to collect personal data from children through the ordinary use of our corporate website or business-development activities.
21. Changes to This Policy
We may update this Privacy Policy as our services, technology, legal obligations or processing activities change.
The latest version will be made available on the Opynex website with an updated revision date.
Where a material change affects how we process personal data, we will take appropriate steps to communicate the change where required.
22. Contact
For privacy questions, requests, or concerns:
Opynex is a trading brand of Himox Limited.
Email: info@opynex.com
Website: opynex.com
Your operations. Running without you. Your control. Staying with you.