OportunlyBack to Oportunly

Privacy Notice

Version 2026-09-09. This notice explains what we collect, why we are allowed to, who else touches it, and how to make us delete it.

1. Who we are

Oportunly is the service described on this site, run by the team behind oportunly.com. We are the data controller for everything described here, which means we decide what is collected and why, and we are the ones you hold responsible for it.

The data controller is Solaia Technologies, LLC, a limited liability company formed in Delaware, United States, with its business address at 6007 North Dakota Avenue Northwest, Washington, DC 20011, United States.

Questions, requests or complaints: privacy@oportunly.com. We answer within one month, which is the deadline the GDPR gives us.

2. What we collect

When you join the waitlist or ask for a demo spot

  • First and last name, email address, university.
  • Your LinkedIn profile address, and the public information on that profile: your name, headline, photo, location and education. We read it so you do not have to type it.
  • Your WhatsApp number, which we use for one thing: telling you when your access is ready. We do not use it for marketing.
  • Whether you accepted this notice and the Terms, when, from which IP address, and whether you opted in to product news.
  • Technical detail that arrives with any web request: browser, referring page, and campaign parameters if you came from a link that carried them.

When you use the product

  • Your CV, if you upload one, and the information we read from it: education, experience, skills, languages.
  • What you tell us about your search: roles, cities, industries, target companies, and the short answers you write about yourself.
  • The lists we build for you, the drafts we write, and what you did with them.

When you browse our website and product

We measure page categories, referral categories, device type and an estimate of time spent on visible pages. Public website visits use a temporary identifier held only in the open page, without analytics cookies or browser storage. These visits are not linked to your account. Inside the product, usage is associated with your signed in account so we can understand adoption, troubleshoot issues and monitor service costs. We do not collect form contents, private page addresses or full referring URLs in this analytics record. We respect Do Not Track and Global Privacy Control signals for this measurement.

Optional product analytics and session recordings

If you allow optional analytics, we use PostHog to understand journeys between our website and app, page visits, active time, completed actions and technical errors. We also store a limited copy of consented page views, navigation, product steps, request timings and error categories in our own admin analytics. This copy contains no form values, message text or session recordings. An analytics cookie connects visits across Oportunly subdomains. After sign in, we associate this activity with your internal account ID, without sending your name or email address as analytics properties. We mark team accounts separately.

Where session recording is enabled, it shows interactions and page structure with all page text, form inputs and element attributes masked. Images, embedded content, CV previews and media are blocked. We do not record request bodies, headers or console logs. Page addresses use templates without query strings, access codes or campaign IDs. The admin panel and sign in pages are excluded.

This optional measurement starts only after you choose Allow analytics. Choose Privacy settings, then Decline analytics, to stop future collection and remove the analytics identifier. Your choice lasts six months and is shared across Oportunly subdomains. We respect Do Not Track and Global Privacy Control. To request deletion of data already collected, contact privacy@oportunly.com.

When you sign in with Google

  • Your name, email address and profile picture, to sign you in and label your account. Nothing else.

When you connect Gmail, Outlook or LinkedIn

You connect your mailbox or your LinkedIn on a hosted page run by our sending provider, Unipile, using Google’s, Microsoft’s or LinkedIn’s own sign in. Oportunly never sees or stores your password. That connection lets Oportunly do two things:

  • Send messages from your address, in your name, as part of a campaign you started.
  • Receive the messages that arrive in reply, which is how we notice a reply, a bounce, or someone asking you to stop, and halt the follow-ups for that person.

We do not read, index or store your inbox. We keep only the messages that belong to a conversation you started through Oportunly: your message and their reply. Anything else that arrives is discarded on receipt.

What goes out without you pressing a button each time. When you start a campaign you approve its messages as a batch: the first message for each person, written from your CV, which you can read, edit or delete before starting, and the follow-ups, which are templates you chose. From that moment the engine sends them for you, inside the hours and the daily limit you set, and stops for anyone who replies. Pause the campaign and nothing more goes out.

Our use of information received from Google APIs, directly or through our provider, follows the Google API Services User Data Policy, including its Limited Use requirements. We never use Google or Microsoft user data for advertising, never sell it, never use it to train AI models, and no human at Oportunly reads it except with your explicit permission for support, for security, or where the law requires it. You can revoke access at any time from your Google account permissions, your Microsoft account permissions, or by disconnecting the channel inside Oportunly; either way, sending stops immediately and the provider deletes the connection.

3. Why we are allowed to

WhatLegal basis
Running your account and building your lists and draftsPerforming the contract you asked for (Art. 6(1)(b) GDPR)
Telling you your access is ready, sending your invite code, account and security emailsPerforming the contract. These are not marketing and you cannot opt out of them while you have an account
Product news and tipsYour consent (Art. 6(1)(a)), given by ticking an optional box. You can withdraw it at any time
Keeping the service safe, preventing abuse, keeping records of consentOur legitimate interest (Art. 6(1)(f)) in running a service that works and in being able to prove what was agreed
Contact details of the people you write toLegitimate interest, explained in the next section

4. People you write to

This is the part most privacy notices skip, so we will be plain about it. To do its job, Oportunly processes the professional contact details of people who never signed up with us: their name, job title, employer, professional profile, and a work email address.

We rely on legitimate interest for this, which the GDPR allows for business contact in a professional context, and we keep it narrow on purpose:

  • Only professional data, in a professional context. No personal addresses, no private numbers, no special categories.
  • Only people whose role plausibly relates to hiring or to the team a student is writing about.
  • The message is sent by the student, from the student’s own mailbox, and identifies them.
  • Every message says how to stop receiving them, and one request is enough.

If you are a recipient and you want out, you have two ways. Reply to the student and say so: that student stops writing to you the same day, in every campaign. Or write to privacy@oportunly.com and we delete your details from every list where they appear and mark your address so nobody using Oportunly contacts you again. You do not have to explain why, and we do not ask you to create an account to do it.

Where do your details come from? Public professional sources: your public LinkedIn profile, your employer’s website, and, when a work address cannot be confirmed from those, business contact databases that sell professional addresses. Each address is checked before a student can write to it. We keep name, role, employer, profile address and work email, nothing else, while you are on a student’s list.

5. Emails and WhatsApp

There are two different things here and mixing them up is what gets companies in trouble, so we keep them apart.

  • Messages about your access. That your spot is ready, your invite code, password resets. You asked for the service, so we send these. If you gave us a WhatsApp number we may use it for the same purpose, because that is what you gave it for.
  • Product news. Optional, off unless you tick the box, and never a condition of getting in. Every one of them carries a one-click unsubscribe, and saying no changes nothing about your place on the list.

6. Who else touches it

We do not sell anything to anybody. These are the companies that process data on our behalf, and what each of them sees:

WhoWhat forWhere
SupabaseDatabase and sign in. Your account, profile, lists and drafts live hereEU (Paris)
VercelHosting and serving the site, plus cookieless traffic analyticsUnited States, with edge servers worldwide
PostHogOptional product analytics and masked session recordings, only with your consentEU Cloud (Germany)
ResendSending our emails to youUnited States
ApifyReading public LinkedIn profiles and company pagesEU and United States
AnthropicReading your CV and drafting your messagesUnited States. Your data is not used to train their models
UnipileConnects your mailbox and LinkedIn and carries every message you send and receive through Oportunly. Holds the connection tokensFrance, EU
MillionVerifierChecks whether a work address exists before we let you write to it. Sees only the addressEU
Business contact databases, through ApifySupply a work address for a person when it cannot be confirmed from public pages. See only the name and employer we ask aboutUnited States and EU
Meta (WhatsApp Business)Delivers the WhatsApp messages about your access. Sees your number and the messageUnited States
StripePayments, invoices and tax, once plans exist. Sees your name, email, country and card, which we never seeUnited States and EU

If we add another one we will list it here before it starts processing anything.

7. Data leaving the EU

Some of the companies above are in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses, and where the provider is certified, on the EU-US Data Privacy Framework.

8. How long we keep it

  • Waitlist: until you unsubscribe or ask us to delete it, and in any case no longer than two years after we open, if you never became a user.
  • Account and product data: while your account is open, and 30 days after you close it, so an accidental deletion can be undone.
  • Recipient contact details: while they are on one of your lists, and deleted when you delete the list or your account.
  • Mailbox and LinkedIn connections: held by our sending provider while the connection is active, and deleted the moment you disconnect or revoke it.
  • Messages sent and received through Oportunly: while your account is open, so you can see every conversation, and deleted with the account.
  • Consent records: kept as long as we might have to prove them, and no longer.
  • Suppression list: kept indefinitely on purpose. It only holds what is needed to make sure we never write to that address again.

9. Your rights

You can ask us for a copy of your data, to correct it, to delete it, to limit what we do with it, to hand it to you in a portable format, and to object to processing we base on legitimate interest. If you gave consent for product news, you can withdraw it whenever you like without affecting what came before.

Write to privacy@oportunly.com. If you think we handled it badly you can complain to your national data protection authority; in Spain that is the Agencia Española de Protección de Datos.

10. Security

Traffic is encrypted in transit and data is encrypted at rest. Access to the database is restricted by row-level rules so one account cannot read another’s data, and the internal panel is invitation only and lives on a separate origin from the public site. Nobody is perfect: if a breach ever affects your rights, we will tell you and the authority within the deadlines the law sets.

11. Age

Oportunly is for university students and is not intended for anyone under 16. If we find out we are holding data on someone younger, we delete it.

12. Changes

When this notice changes we update the version at the top. If a change actually affects you, we tell you by email rather than expecting you to notice.