Privacy Policy

    How Oxira collects, processes, stores and protects personal data — full, transparent and GDPR-aligned.

    Last updated: April 29, 2026 · Contact: mail@oxira.one

    1. Introduction & Scope

    This Privacy Policy provides comprehensive information about how Oxira GmbH (DACH region) and Oxira LLC (US and international markets) — together referred to as "Oxira", "we", "us" or "our" — collect, process, store and protect personal data when you visit our websites at oxira.one, www.oxira.one, oxira.tech and any associated subdomains, and when you use our software products, web applications and communication channels (email, contact forms, meeting booking and idea-submission flows).

    We process your personal data exclusively on the basis of applicable data-protection laws, in particular the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications and Telemedia Data Protection Act (TTDSG) and — for users from the United States — the California Consumer Privacy Act (CCPA / CPRA) and comparable state-level laws.

    If you do not agree with parts of this policy, we kindly ask you to refrain from using our websites and services. This policy may be updated from time to time — the current version is always available at this URL.

    2. Data Controller & Privacy Contact

    The data controller within the meaning of the GDPR and other national data-protection laws is:

    Oxira GmbH (for users from the EU / DACH region)
    Oxira LLC (for users from the US and internationally)
    Email: mail@oxira.one

    Due to our company size we have not currently appointed an external Data Protection Officer. Please direct any data-protection inquiries, access, deletion or objection requests to the email address above with the subject line "Privacy Request". We respond within 30 days, and significantly faster for urgent matters.

    3. Our Privacy Principles

    Privacy is not a compliance check-box for us — it is a core part of our product philosophy. We follow four principles:

    • Data minimisation: we only collect data we actually need for the specific purpose — never "just in case".
    • Purpose limitation: data is only used for the purposes for which it was collected, unless a separate legal basis applies.
    • Transparency: this policy explains in plain language what data we collect, why, for how long and with whom we share it.
    • Privacy by design & by default: our internal AI systems Nova and Orbit are designed so that privacy-friendly defaults are the norm and sensitive data does not need to be centrally processed wherever possible.

    4. Categories of Processed Data

    We process the following categories of personal data:

    • Master & contact data: name, company, role, email address, phone number, business address — provided you actively share these via a form or by email.
    • Communication data: content of your messages, attachments (e.g. pitch decks, idea submissions, max. 10 MB), meeting notes.
    • Contract & project data: data created in the course of a partnership (equity or revenue share) — e.g. roadmaps, requirement documents, access credentials for test systems.
    • Usage data: pages visited, time on page, click paths, anonymised / pseudonymised device information.
    • Technical / log data: IP address (shortened or pseudonymised), browser type and version, operating system, referrer URL, date and time of the request, volume of data transferred.
    • Cookie & tracking IDs: only if you have given your consent — see section 8.

    5. Purposes and Legal Bases

    We process your data for the following purposes on the legal bases listed:

    • Provision of the website (technically necessary logs, security) — Art. 6 (1) (f) GDPR (legitimate interest in stable, secure operation).
    • Responding to inquiries via contact form, email or idea-submission — Art. 6 (1) (b) GDPR (pre-contractual steps) or (f).
    • Contract performance within a partnership — Art. 6 (1) (b) GDPR.
    • Sending confirmation & transactional emails (e.g. submission acknowledgement, meeting confirmation) — (b) or (f).
    • Reach measurement & product improvement — Art. 6 (1) (a) GDPR (consent) or (f) where privacy-friendly (e.g. anonymised counts).
    • Compliance with statutory retention and accountability obligations — Art. 6 (1) (c) GDPR in conjunction with HGB / AO.

    6. Hosting, Log Files & Technical Operation

    Our websites and web applications are operated in certified data centres in the EU (Frankfurt, Berlin). Individual components (e.g. global edge caching, optional US hosting for US customers) may run in data centres outside the EU — see section 11 on international data transfers.

    Each time a page is requested, technically necessary data is stored in so-called server log files: IP address (truncated after a maximum of 7 days), date and time, requested URL, status code, volume of data transferred, browser, operating system and referrer. This data is used solely to operate the service, detect attacks and analyse errors. It is not merged with other data sources; logs are automatically deleted or fully anonymised after no more than 30 days.

    Legal basis: Art. 6 (1) (f) GDPR (legitimate interest).

    7. Contact Form, Idea Submission & Meeting Booking

    When you contact us via the contact form, idea submission (incl. file upload up to 10 MB) or meeting booking, the data you enter (in particular name, email, message, optional attachments) is processed for the purpose of handling your request. Attachments are stored in an access-restricted storage bucket within our backend and are only accessible to authorised internal staff.

    Confirmation and reply emails are sent through our processor Resend (Resend Inc., USA — DPA concluded under Art. 28 GDPR including EU Standard Contractual Clauses).

    Meeting booking is provided through an embedded application at oxira-hub.lovable.app/book/oxira. Name, email and the desired time slot are processed to organise the meeting.

    Retention: inquiries are stored for as long as needed to handle them and any follow-up questions. After 24 months without further contact we delete the data, unless statutory retention obligations apply.

    8. Cookies, Local Storage & Comparable Technologies

    We use cookies and comparable technologies (LocalStorage, SessionStorage) only to the extent that they are necessary for operating the website or for which you have given explicit consent. The legal basis for storing non-essential cookies is § 25 (1) TTDSG in conjunction with Art. 6 (1) (a) GDPR.

    Categories:

    • Strictly necessary cookies / storage entries: language preference (German / English via LanguageContext), session identifier, CSRF protection, storage of your cookie preferences. These cannot be disabled as the website would not function meaningfully without them.
    • Functional cookies: e.g. remembering preferred views or recently visited content. Set only with your consent.
    • Statistics / reach measurement: aggregated, anonymised page-view analysis — only with your consent.
    • Marketing / third party: we currently do not use marketing or advertising tracking cookies. If this changes, we will obtain your consent via a consent banner beforehand.

    Storage duration: session cookies are deleted when the browser is closed; persistent cookies have a maximum lifetime of 12 months and consent is then requested again.

    Withdrawing consent: you can withdraw your consent at any time with effect for the future — either via your browser's cookie settings (delete / block cookies) or by a short message to mail@oxira.one.

    9. Processing by Our AI Systems (Nova & Orbit)

    Within our partnership projects we use our internal AI systems Nova (Auto Dev Engine) and Orbit (AI Agent). These systems exclusively process project and development data of our partners — never personal data of end users of our websites.

    If a partner project explicitly requires the processing of personal data (e.g. a customer chatbot based on Orbit), we conclude a separate Data Processing Agreement (DPA) with the partner pursuant to Art. 28 GDPR. The DPA specifies exactly what data is processed, for what purpose, in which region (EU / US / on-premise of the customer) and with which sub-processors.

    We do not use personal data of our website visitors to train our AI models.

    10. Processors & Recipients

    We use carefully selected service providers that help us provide, operate and improve our services. We have Art. 28 GDPR agreements with all processors; for transfers to third countries we additionally rely on EU Standard Contractual Clauses (SCCs) as well as supplementary technical and organisational measures where appropriate.

    • Backend & database: SOC 2 Type II certified and HIPAA-compliant backend provider (hosted in EU regions).
    • Hosting / CDN: ISO 27001 / SOC 2 certified data centres in the EU plus global edge nodes.
    • Transactional emails: Resend Inc. (USA) — SCCs + technical safeguards.
    • Meeting booking: embedded service at oxira-hub.lovable.app.
    • Tax & legal advisors, auditors: only to the extent legally required.

    We do not share your data with third parties for advertising purposes.

    11. International Data Transfers

    Where personal data is transferred to recipients in countries outside the European Economic Area (EEA) — in particular to the USA — this is done exclusively on the basis of appropriate safeguards under Art. 44 et seq. GDPR. These include in particular:

    • EU Standard Contractual Clauses (SCCs) in their current version,
    • for US recipients, where applicable, certification under the EU-US Data Privacy Framework (DPF),
    • supplementary technical safeguards such as encryption in transit and at rest, pseudonymisation and strict access controls.

    You may request a copy of the agreed safeguards at any time: mail@oxira.one.

    12. Retention Periods & Deletion Concept

    We store personal data only as long as necessary for the respective purposes or as required by law. Specifically:

    • Server log files: max. 30 days, IPs truncated after 7 days.
    • Contact and inquiry data: up to 24 months after last contact.
    • Contract data: for the duration of the contract plus 10 years (commercial and tax retention obligations under § 257 HGB, § 147 AO).
    • Cookie consents: 12 months, after which consent is requested again.
    • Applicant or idea-submission data without follow-up contract: 6 months.

    13. Your Rights as a Data Subject

    You have the following rights regarding the personal data concerning you at any time:

    • Access (Art. 15 GDPR) — which data we process about you,
    • Rectification (Art. 16 GDPR) of incorrect or incomplete data,
    • Erasure ("right to be forgotten", Art. 17 GDPR),
    • Restriction of processing (Art. 18 GDPR),
    • Data portability (Art. 20 GDPR) in a structured, commonly used, machine-readable format,
    • Objection to processing based on Art. 6 (1) (f) GDPR (Art. 21 GDPR),
    • Withdrawal of consent with effect for the future (Art. 7 (3) GDPR),
    • Complaint to a supervisory authority (Art. 77 GDPR) — e.g. the competent data-protection authority at your place of residence.

    An informal email to mail@oxira.one is sufficient to exercise these rights. We will process your request within the statutory one-month deadline.

    14. Additional Rights for US Users (CCPA / CPRA)

    Residents of California additionally have rights under the California Consumer Privacy Act (CCPA) as amended by the CPRA: right to know which categories of personal information are collected, right to deletion, right to correction, right to opt out of "sale" or "sharing" (we do not sell or share your data within the meaning of the CCPA), and the right not to be discriminated against for exercising these rights. Send requests to mail@oxira.one with the subject line "CCPA Request".

    15. Data Security

    We use state-of-the-art technical and organisational measures (TOMs) to protect your data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access — in particular:

    • TLS encryption (HTTPS) for data transmission between your browser and our servers,
    • encryption of sensitive data at rest in the database,
    • strict role-based access control (least privilege) for our backend systems,
    • regular security updates, automated vulnerability scanning via Nova,
    • two-factor authentication for all internal staff accounts,
    • backups stored in geographically separated data centres.

    16. Minors

    Our offerings are aimed exclusively at business users (B2B) and adults. We do not knowingly collect data from individuals under the age of 16. If we become aware that data of a minor has been provided to us without appropriate consent, we will delete it without undue delay.

    17. External Links

    Our website contains links to third-party websites (e.g. AI Optimiser, MySafe Pro, IndieCATR, tmv.is, Oxira.one). We have no influence over their content or privacy practices; please consult the respective privacy policies on those sites.

    18. Changes to This Privacy Policy

    We update this Privacy Policy whenever legal or factual changes occur — e.g. when new features are introduced or new processors are engaged. The current version, with the "Last updated" date, is always available at this URL. Where appropriate, we will actively communicate material changes to you in addition.