Privacy Policy
This Privacy Policy explains how Reality-Craft Private Limited, the company behind TimeOpera (“TimeOpera,” “we,” “us,” or “our”), collects, uses, stores, and protects information when you visit our website, request a demo, complete onboarding, use TimeOpera, or interact with TimeOpera Assistant.
TimeOpera is a Microsoft 365-aligned project time operations platform for timesheets, approvals, reporting, invoice preparation, guided onboarding, and read-only role-aware AI assistance.
1. Scope of this Privacy Policy
This Privacy Policy applies to:
- The TimeOpera website, including https://www.timeopera.app
- Demo, pricing, onboarding, training, and support requests
- TimeOpera onboarding experiences
- TimeOpera application services
- TimeOpera Assistant enablement and support experiences
- Related email, support, and service communications
This Privacy Policy does not replace any separate agreement, data processing agreement, order form, or enterprise contract between TimeOpera and a customer organization.
2. Company information
TimeOpera is a product of:
Reality-Craft Private Limited
917, Satyamev Eminence,
Science City Road,
Ahmedabad, Gujarat 380060, India
Support and privacy contact: support@timeopera.app
3. Who controls TimeOpera data
For most customer use of TimeOpera, the customer organization controls its Microsoft 365 tenant, SharePoint site collection, users, roles, permissions, business records, and access decisions.
TimeOpera acts as a service provider or processor for customer-managed TimeOpera data, except where we process information for our own business purposes such as website operation, demo requests, onboarding support, billing administration, licensing, security, support, service improvement, and legal compliance.
Customer administrators are responsible for configuring TimeOpera access, user roles, Microsoft 365 permissions, onboarding steps, and Assistant availability for their organization.
4. Information we collect
We may collect the following categories of information.
Website and contact information
When you visit the website, request a demo, contact support, request pricing, or request training, we may collect:
- Name
- Work email address
- Company name
- Job title or role
- Phone number, if provided
- Message content
- Demo, pricing, support, or training request details
- Website usage information such as pages viewed, browser type, device type, referral source, and approximate region
Onboarding information
During onboarding, we may collect information needed to register and configure a customer environment, such as:
- Company or tenant display name
- Admin name and email address
- Microsoft 365 primary domain
- Configured SharePoint workspace site URL
- Notification sender mailbox
- Microsoft tenant identifier
- Onboarding status
- Consent and setup status
- Site access validation status
- App package and API approval status
- Provisioning status
- Optional Teams setup status
- Optional TimeOpera Assistant setup status
- Support and setup notes
User and role information
To operate TimeOpera, we may process information such as:
- User name
- Work email address
- Microsoft Entra user object ID
- TimeOpera role
- Project assignment information
- Approval responsibility information
- Licensed user assignment status
- Support or onboarding state associated with the user or tenant
TimeOpera business records
Depending on customer configuration and user activity, TimeOpera business records may include:
- Customers
- Projects
- Sections
- Tasks
- Categories
- Timesheet entries
- Worklog notes
- Approval status and comments
- Invoice-preparation records
- Reports and summaries
- Configuration and settings records
5. Where TimeOpera business records are stored
TimeOpera is designed so that real customer business records are stored in the configured TimeOpera SharePoint site collection in the customer’s Microsoft 365 tenant.
Your real TimeOpera business records - including timesheets, projects, tasks, categories, worklog notes, approvals, invoices, invoice-preparation data, and related reports - are stored in the configured TimeOpera SharePoint workspace site in your Microsoft 365 tenant.
TimeOpera does not maintain a separate external application database containing your real timesheet, project, task, category, note, approval, invoice, or invoice-preparation records.
TimeOpera-managed services may store operational metadata such as tenant registration, onboarding status, setup status, licensing status, configuration references, support state, service operation metadata, and diagnostic information. This operational metadata helps us operate, secure, support, and maintain the service.
TimeOpera uses diagnostic logging and telemetry to monitor service health, reliability, performance, and operational issues. These logs are designed for support and diagnostics and are not intended to store customer business records, raw business content, secrets, or request/response payloads.
This statement is about persistent storage of real business records. TimeOpera services may process information transiently to provide the service, perform onboarding, validate Microsoft 365 setup, call Microsoft Graph, send notifications, support TimeOpera Assistant, or respond to user requests.
6. TimeOpera Assistant and AI-related processing
TimeOpera Assistant is designed as a read-only, role-aware AI assistant for TimeOpera data. It helps users ask questions about timesheets, worklogs, projects, approvals, reports, utilization, invoice readiness, and access guidance.
TimeOpera Assistant:
- Provides read-only answers
- Follows TimeOpera role and project assignment visibility
- Does not submit timesheets
- Does not approve or reject timesheets
- Does not create, update, send, export, or delete records
- Does not bypass TimeOpera access controls
TimeOpera Assistant answers questions from TimeOpera data stored in the configured Microsoft 365 SharePoint site collection. TimeOpera does not store a separate external copy of real timesheet, project, task, category, note, approval, invoice, or invoice-preparation records for Assistant use.
If optional AI-powered note refinement or similar AI features are enabled, note text may be processed transiently by the configured AI service to return a refined result. TimeOpera does not store a separate external copy of the original or refined note outside the customer’s Microsoft 365 tenant as application business data.
TimeOpera Assistant availability depends on tenant configuration, Microsoft 365 Copilot readiness, administrator enablement, and TimeOpera Assistant setup.
7. How we use information
We use information to:
- Provide, operate, and maintain TimeOpera
- Support onboarding and provisioning
- Authenticate users and enforce role-based access
- Validate customer tenant and configured SharePoint site collection context
- Provide timesheet, approval, reporting, and invoice-preparation functionality
- Support TimeOpera Assistant and related read-only responses
- Send service, onboarding, support, training, and administrative communications
- Send setup notifications, timesheet reminders, approval notifications, and workflow emails
- Respond to demo, pricing, support, and training requests
- Manage licensing, trials, and customer accounts
- Improve reliability, security, performance, and user experience
- Detect, prevent, investigate, or respond to misuse, security events, or technical issues
- Comply with legal, contractual, regulatory, and accounting obligations
8. Microsoft 365 and Microsoft Graph
TimeOpera integrates with Microsoft 365 services such as Microsoft Entra ID, SharePoint, Microsoft Graph, Teams, Outlook, and Microsoft 365 Copilot-enabled experiences where applicable.
TimeOpera uses Microsoft 365 authentication and permission models so administrators can review and approve required permissions. Some features require administrator consent, configured SharePoint site collection access, user sync, notification permissions, Teams setup, or Assistant enablement.
Customer administrators control the Microsoft 365 tenant, user access, and permission decisions for their organization.
9. Cookies and website analytics
The TimeOpera website may use cookies or similar technologies to:
- Operate the website
- Remember preferences
- Understand website usage
- Improve content and performance
- Support security and form submissions
If analytics or marketing tools are used, they should be configured in accordance with applicable law and customer-facing cookie notice requirements.
You can control cookies through your browser settings. Some website features may not work correctly if certain cookies are disabled.
10. When we share information
We may share information with:
- Microsoft services used to operate TimeOpera integrations
- Cloud hosting, infrastructure, security, monitoring, support, email, and analytics providers
- Professional advisors such as legal, accounting, and compliance advisors
- Authorized customer administrators or users according to their TimeOpera roles
- Law enforcement, regulators, courts, or other parties where required by law
- Successors in connection with a merger, acquisition, restructuring, financing, or sale of assets
We do not sell customer business records.
We do not use real customer timesheet, project, task, category, note, approval, invoice, or invoice-preparation records to build a separate external TimeOpera business database.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information processed by TimeOpera.
These safeguards may include:
- Microsoft Entra ID authentication
- Role-based access controls
- Project assignment-based visibility
- Configured SharePoint site collection boundaries
- Tenant-aware onboarding
- Backend authorization checks
- Logging and monitoring
- Secure configuration practices
- Limited access for operational personnel
- Protection of secrets and service credentials
No system is completely secure. Customers are responsible for managing their Microsoft 365 environment, user accounts, administrator access, device security, tenant policies, and internal governance.
12. Data retention
Customer business records stored in the configured SharePoint site collection are retained according to the customer’s Microsoft 365 configuration, retention policies, and administrative decisions.
TimeOpera operational metadata is retained for as long as needed to provide the service, support onboarding, manage licensing, maintain security, comply with legal obligations, resolve disputes, and enforce agreements.
Demo, support, pricing, and training request information may be retained for business communication, service improvement, legal, and recordkeeping purposes.
13. International processing
TimeOpera and its service providers may process operational information in locations where we or our providers operate. Customers should review their own Microsoft 365 data residency, compliance, and tenant configuration requirements.
Where required, appropriate contractual or legal safeguards should be used for international transfers.
14. Your rights and choices
Depending on your location and applicable law, you may have rights to:
- Access personal information
- Correct inaccurate information
- Request deletion
- Object to or restrict certain processing
- Request portability
- Withdraw consent where processing is based on consent
- File a complaint with a data protection authority
For TimeOpera data controlled by your employer or organization, please contact your organization’s administrator first. We may refer requests relating to customer-controlled data to the relevant customer administrator.
To contact us about privacy, email: support@timeopera.app
15. Customer administrator responsibilities
Customer administrators are responsible for:
- Deciding whether to use TimeOpera
- Completing Microsoft 365 consent and onboarding steps
- Selecting the configured SharePoint workspace site
- Managing users, roles, and project assignments
- Enabling or disabling features
- Reviewing Microsoft 365 permissions
- Managing internal policies, retention, and access controls
- Deciding whether to enable TimeOpera Assistant for eligible users
16. Children’s privacy
TimeOpera is intended for business and organizational use. It is not intended for children or personal consumer use. We do not knowingly collect personal information from children through the TimeOpera website or service.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised “Last updated” date.
Material changes may be communicated through the website, email, in-product notice, or other appropriate means.
18. Contact us
For privacy questions, support requests, or concerns, contact:
Reality-Craft Private Limited
917, Satyamev Eminence,
Science City Road,
Ahmedabad, Gujarat 380060, India
Email: support@timeopera.app