Legal Documents

Terms & Legal

Complete legal bundle governing your use of the Oprel desktop automation service.

Effective: 14 June 2026 Jurisdiction: Denmark / EU Contact: legal@getoprel.com
Contents
  1. Terms of Service
  2. Privacy Policy
  3. Cookie Policy
  4. EU AI Act Transparency Notice
  5. Data Processing Agreement
01

Terms of Service

These Terms of Service ("Terms") govern your access to and use of the Oprel desktop automation software and related services (collectively, the "Service") provided by Oprel ("we", "us", or "our"). By creating an account or using the Service, you agree to be bound by these Terms.

Oprel operates as a Danish sole proprietorship (enkeltmandsvirksomhed) registered in Denmark. These Terms are governed by Danish law and applicable European Union regulations.

1. Eligibility

You must be at least 18 years of age to use the Service. By agreeing to these Terms, you represent and warrant that you are at least 18 years old and have the legal capacity to enter into a binding agreement.

2. Description of the Service

Oprel is an AI-powered desktop automation application that uses artificial intelligence to control your computer's keyboard and mouse in order to complete tasks you specify ("Tasks"). The Service is currently offered as a beta/pre-release product. The Service includes:

  • A three-layer automation system: a native screen capture sidecar (30fps, local diff detection), a Gemini 2.5 Pro batch planner that produces 3–7 actions per planning cycle, and a native input executor that delivers keyboard and mouse actions directly to the OS
  • A Privacy Sieve that locally redacts personally identifiable information (PII) before any screenshot data is transmitted externally
  • A three-layer safety system comprising a Governor (command blacklist), Safety Guard (risk classification), and Hard Blocks (permanently prohibited actions)
  • A Human-in-the-Loop system that pauses execution when user input is detected

3. Beta Disclaimer

THE SERVICE IS PROVIDED AS A BETA / PRE-RELEASE PRODUCT. It may contain bugs, errors, and incomplete features. It is not suitable for mission-critical, professional, or production use. Oprel makes no warranty that the Service will meet your requirements or operate without interruption. You use the Service at your own risk.

4. Account Registration

To use the Service, you must register for an account. You agree to provide accurate and complete information during registration and to keep your account credentials confidential. You are responsible for all activity that occurs under your account. You must notify us immediately at legal@getoprel.com if you suspect unauthorised access.

5. Subscription, Fees, and Billing

The Service is offered under the following subscription tiers:

PlanMonthly HoursPrice
Free2 hours$0
Starter50 hours$29 / month
Pro120 hours$119 / month
Max500 hours$499 / month

Billing is handled by Stripe, Inc. By subscribing, you authorise Oprel to charge your payment method on a recurring monthly basis. All fees are exclusive of VAT. Danish and EU VAT rules apply where applicable.

You may cancel your subscription at any time. Cancellation takes effect at the end of the current billing period. No refunds are issued for partial months, except where required by applicable law (including the EU Consumer Rights Directive 14-day withdrawal right — see Section 13).

6. AI Disclaimer and Limitation of AI Liability

The Service uses artificial intelligence to execute Tasks on your behalf. You acknowledge and agree that:

  • AI systems are inherently imperfect and may produce incorrect, incomplete, or unintended results.
  • All Tasks are initiated at your explicit direction. You bear primary responsibility for the Tasks you instruct the Service to perform.
  • Oprel's safety systems reduce the risk of harmful actions but do not eliminate it. They do not constitute a warranty of error-free operation.
  • You should monitor the Service during execution and use the Human-in-the-Loop controls to pause or stop execution at any time.
  • Oprel is not responsible for any actions taken by the AI agent that were within the scope of the Task you specified, even if those actions had unintended consequences.

7. Acceptable Use

You agree not to use the Service to:

  • Automate any activity that is unlawful under applicable law
  • Circumvent, disable, or interfere with any of Oprel's safety features, including the Governor, Safety Guard, Hard Blocks, or Privacy Sieve
  • Attempt to reverse-engineer the AI models or proprietary algorithms
  • Transmit viruses, malware, or other harmful code
  • Use the Service for any purpose that could harm Oprel or third parties

8. Intellectual Property

All rights in and to the Service, including its software, design, algorithms, AI models, trademarks (including the Oprel name and hexagon logo), and documentation, are owned by Oprel. These Terms grant you a limited, non-exclusive, non-transferable licence to use the Service for personal, non-commercial purposes in accordance with these Terms.

9. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, OPREL SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF DATA, LOSS OF REVENUE, LOSS OF PROFITS, SYSTEM DOWNTIME, CORRUPTED FILES, OR UNINTENDED FILE DELETIONS, EVEN IF OPREL HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
OPREL'S TOTAL LIABILITY TO YOU FOR ANY CLAIMS ARISING UNDER THESE TERMS SHALL NOT EXCEED THE TOTAL FEES YOU PAID TO OPREL IN THE THREE (3) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

Nothing in these Terms limits Oprel's liability for death or personal injury caused by Oprel's gross negligence or wilful misconduct, or for fraud, or for any liability that cannot be excluded under applicable Danish or EU law.

10. Third-Party Services

The Service uses third-party AI providers (including Google Gemini) and infrastructure providers (including Supabase). Your use of the Service is also subject to those providers' terms. Oprel is not responsible for the availability, accuracy, or conduct of third-party services.

11. Privacy

Your use of the Service is subject to Oprel's Privacy Policy, which is incorporated into these Terms by reference. The Privacy Policy describes how we collect, use, and protect your personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law.

12. EU AI Act Transparency

The Service uses AI systems subject to the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). You are hereby informed that the Service uses AI to autonomously control your computer's input devices, that it has been designed with safety constraints and human oversight mechanisms, and that you have the right to stop AI-driven actions at any time.

13. Consumer Right of Withdrawal (EU / Denmark)

If you are a consumer resident in the EU or Denmark, you have the right to withdraw from your subscription within 14 days of entering into the contract without giving any reason. By commencing use of the Service before the end of the withdrawal period, you expressly request that the Service begin immediately and acknowledge that your right of withdrawal is lost once the Service has been fully performed.

To exercise the right of withdrawal, contact us at legal@getoprel.com. We will process any refund due within 14 days using your original payment method.

14. Modifications to the Service and Terms

Oprel reserves the right to modify or discontinue the Service at any time. We will provide at least 30 days' notice of material changes to these Terms via email or in-app notification. Continued use of the Service after the effective date constitutes acceptance.

15. Termination

Oprel may suspend or terminate your account immediately if you violate these Terms, or if required by law. You may terminate your account at any time by contacting legal@getoprel.com.

16. Governing Law and Dispute Resolution

These Terms are governed by the laws of Denmark. Any dispute shall be subject to the exclusive jurisdiction of the courts of Denmark. If you are a consumer in the EU, you also have the right to use the EU Online Dispute Resolution platform at ec.europa.eu/consumers/odr.

17. Contact

Oprel
Email: legal@getoprel.com
Website: getoprel.com
Country of establishment: Denmark


02

Privacy Policy

Oprel is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Oprel desktop automation service ("Service"). It also describes your rights under the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the Danish Data Protection Act (Databeskyttelsesloven).

1. What Personal Data We Collect

Account Data

When you register for an account, we collect: your name, email address, password (hashed), and subscription details.

Usage and Task Data

When you use the Service, we process: the Tasks you specify (task instructions in text form), task execution logs, error logs, and session metadata.

Screenshot Data and the Privacy Sieve

The Service captures screenshots of your desktop during task execution. All screenshot processing occurs locally on your device. Before any screenshot data is transmitted externally, it passes through the Privacy Sieve — a local redaction engine that detects and masks PII including names, email addresses, phone numbers, and financial data using regex patterns and OCR. Only redacted screenshot data is transmitted to third-party AI providers. Oprel does not store raw screenshots on its servers.

Technical and Device Data

We collect: IP address (for security and fraud prevention), operating system type, application version, crash reports, and performance metrics.

Payment Data

Payment processing is handled by Stripe, Inc. Oprel does not store your full payment card details.

2. How We Use Your Personal Data

  • Contract performance (Article 6(1)(b) GDPR): To provide the Service, execute Tasks, manage your account, and handle billing.
  • Legitimate interests (Article 6(1)(f) GDPR): To improve the Service, detect fraud, and maintain system stability.
  • Legal obligation (Article 6(1)(c) GDPR): To comply with Danish and EU legal requirements, including Bogføringsloven.
  • Consent (Article 6(1)(a) GDPR): Where we ask for your explicit consent, e.g. for optional analytics.

3. Data Processors and Third Parties

  • Google LLC (Gemini AI): Processes redacted screenshot data and task instructions. Governed by Google's Data Processing Terms and Standard Contractual Clauses.
  • Supabase, Inc.: Stores account data and task logs. GDPR-compliant with EU Standard Contractual Clauses.
  • Stripe, Inc.: Processes payment information per Stripe's Privacy Policy.

We do not sell your personal data to third parties. We do not use your data to train AI models without your explicit consent.

4. International Data Transfers

Where personal data is transferred outside the EEA, we ensure adequate safeguards are in place, including EU Standard Contractual Clauses pursuant to Article 46 GDPR.

5. Data Retention

Data TypeRetention Period
Account dataDuration of account + 5 years after termination
Task logs12 months, then deleted or anonymised
Payment records5 years (Bogføringsloven)

6. Your Rights Under GDPR

  • Right of access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate data.
  • Right to erasure (Article 17): Request deletion of your data, subject to legal retention obligations.
  • Right to restriction (Article 18): Request that we restrict processing in certain circumstances.
  • Right to data portability (Article 20): Receive your data in a structured, machine-readable format.
  • Right to object (Article 21): Object to processing based on legitimate interests.

To exercise any of these rights, contact us at legal@getoprel.com. We will respond within 30 days. You also have the right to lodge a complaint with the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk.

7. Security

We implement appropriate technical and organisational measures to protect your personal data, including: local PII redaction via Privacy Sieve, encrypted transmission (TLS), hashed password storage, and access controls. In the event of a data breach, we will notify the relevant supervisory authority within 72 hours as required by GDPR.

8. Children

The Service is not directed at children under the age of 18. We do not knowingly collect personal data from minors.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification at least 30 days before changes take effect.

10. Contact and Data Controller Details

Oprel — Data Controller
Email: legal@getoprel.com
Website: getoprel.com
Supervisory Authority: Datatilsynet, datatilsynet.dk


03

Cookie Policy

This Cookie Policy explains how Oprel uses cookies and similar tracking technologies on our website (getoprel.com) and in our desktop application.

1. What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences, understand how you use the site, and deliver relevant content.

2. Cookies We Use

Strictly Necessary Cookies

These cookies are essential for the website and Service to function and cannot be disabled. Examples include session authentication cookies, security tokens (CSRF protection), and load balancing cookies.

Functional Cookies

These cookies enable enhanced functionality and personalisation, such as remembering your preferences and subscription tier.

Analytics Cookies

With your consent, we use analytics tools to understand how users interact with our website. Analytics data is aggregated and anonymised where possible. We do not use third-party advertising cookies.

3. Your Choices

  • Browser settings: Most browsers allow you to block or delete cookies.
  • Consent manager: Our website presents a cookie consent banner where you can accept or decline non-essential cookies.
  • Opt-out of analytics: You can opt out at any time through your account settings.

4. Third-Party Cookies

Our website may load content from third-party services that set their own cookies. We do not control these cookies.

5. Contact

For any questions about this Cookie Policy, contact us at legal@getoprel.com.


04

EU AI Act Transparency Notice

This notice is provided by Oprel pursuant to the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, "AI Act"). It describes how the Oprel desktop automation service uses AI systems and your rights as a user.

1. AI System Description

The Oprel Service uses a three-layer automation architecture to execute Tasks on your desktop:

  • Screen Capture Sidecar: A native process that captures your screen at up to 30fps with local change detection, ensuring only meaningful frames are processed.
  • Batch Planner: Powered by Gemini 2.5 Pro, this component analyses the current screen state and your task goal to generate batches of 3–7 discrete actions per planning cycle.
  • Native Input Executor: Delivers keyboard and mouse actions directly to the operating system using native APIs (CGEvent on macOS, Win32 on Windows), without simulated or injected input layers.

2. AI Risk Classification

Oprel has assessed the automation system under the EU AI Act risk framework. The system is classified as a general-purpose AI application used for personal productivity automation. It does not fall within the high-risk AI system categories listed in Annex III of the AI Act. Oprel maintains documentation of this risk assessment as required.

3. Transparency Obligations

In accordance with Article 52 of the AI Act, Oprel discloses that:

  • You are interacting with an AI system when using the Oprel Service.
  • The AI system controls your computer's keyboard and mouse. You retain full control and may stop execution at any time.
  • AI-generated actions are based on your explicit task instructions and the AI's interpretation of your screen content.
  • The AI system is not a human and does not possess human judgement, consciousness, or accountability.

4. Human Oversight

  • Human-in-the-Loop: Execution pauses automatically when user input is detected.
  • Planning Mode: Before executing complex tasks, the AI presents a plan for your review and confirmation.
  • Stuck Chat: If the AI cannot proceed, it notifies you and requests guidance rather than acting autonomously.
  • Hard Blocks: Certain actions (formatting drives, deleting system files, disabling security software) are permanently prohibited and cannot be overridden.
  • Safety Guard: Every planned action is risk-classified before execution. Actions classified as risky or blocked are escalated or halted.

5. Your Rights

  • Stop AI execution at any time using the application controls.
  • Request human review of any AI-generated outcome.
  • Lodge a complaint with Datatilsynet or your local supervisory authority.
  • Contact Oprel with any concerns at legal@getoprel.com.

6. Contact

Oprel — legal@getoprel.comgetoprel.com


05

Data Processing Agreement

This Data Processing Agreement ("DPA") supplements the Terms of Service between Oprel ("Data Processor" or "Oprel") and you, the user ("Data Controller"), to the extent that you process personal data of third parties using the Oprel Service. This DPA is entered into pursuant to Article 28 of the GDPR. If you use Oprel solely for personal tasks and do not process third-party personal data, this DPA may not apply to your use.

1. Definitions

  • "Controller" means the entity that determines the purposes and means of processing personal data (you, where applicable).
  • "Processor" means Oprel, which processes personal data on behalf of the Controller.
  • "Sub-processor" means a third party engaged by Oprel to assist in processing personal data.

2. Oprel's Obligations as Processor

Oprel agrees to:

  • Process personal data only on your documented instructions and in accordance with applicable law.
  • Ensure persons authorised to process data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures pursuant to Article 32 GDPR, including the Privacy Sieve PII redaction system.
  • Notify you without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach.
  • Upon termination, delete or return all personal data processed on your behalf, unless retention is required by law.

3. Sub-Processors

You hereby grant general authorisation for Oprel to engage the following sub-processors:

Sub-processorRoleSafeguards
Google LLC (Gemini AI)AI model inference (redacted data only)Google Data Processing Terms + SCCs
Supabase, Inc.Cloud database storageGDPR-compliant + SCCs
Stripe, Inc.Payment processingDoes not receive task or screenshot data

Oprel will notify you of any intended changes to sub-processors at least 30 days in advance.

4. Security Measures

  • Local PII redaction (Privacy Sieve) before any data is transmitted externally
  • Encrypted transmission using TLS
  • Access controls and authentication
  • Incident response procedures

5. Governing Law

This DPA is governed by Danish law and the laws of the European Union. Any disputes shall be subject to the jurisdiction of the courts of Denmark.

6. Contact

Oprellegal@getoprel.com