Privacy Policy of Oxolo GmbH
v3.1
At Oxolo, we take the protection of personal data seriously. This Privacy Policy informs you about how Oxolo GmbH processes personal data when you use our website oxolo.com, the Oxolo web application, the Oxolo iOS app, the Oxolo Android app, our support, communication and contract processes, and the B2B services we offer.
Oxolo is aimed exclusively at business customers and their authorised users. This Privacy Policy is therefore designed for the use of Oxolo in a B2B context within the EU.
Insofar as we process personal data on behalf of a customer, the respective customer is generally the controller within the meaning of the General Data Protection Regulation. Oxolo then acts as a processor in accordance with the data processing agreement concluded with the customer. In addition, Oxolo processes certain data as its own controller, in particular for website operation, registration, account administration, billing, security, support, communication, legal obligations, legal updates, marketing and its own product-operation data.
1. Controller and Data Protection Contact
The controller for the processing operations described in this Privacy Policy, insofar as Oxolo itself decides on the purposes and means, is:
Oxolo GmbH
Bohnenstraße 2
20457 Hamburg
Germany
Email for general communication: team@oxolo.com
Email for data-protection requests and data subject rights: gdpr@oxolo.com
The Data Protection Officer of Oxolo GmbH can be reached at gdpr@oxolo.com.
The competent supervisory authority is:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Straße 22
20459 Hamburg
Email: mailbox@datenschutz.hamburg.de
2. Terms and Roles
Personal data are all information relating to an identified or identifiable natural person. Processing means any handling of such data, for example collection, storage, transmission, retrieval, structuring, use, deletion or restriction.
In the product context, a distinction must be drawn:
Customer data / Customer Content: content that customers or users enter, upload, record, share or have generated in Oxolo, for example audio recordings, recordings of external online meetings, transcripts, project data, photos, videos, signatures, reports, tasks, variation orders, delays, chat/WhatsApp content and other project documentation.
Account, contract and operational data: data that Oxolo processes for its own account administration, billing, security, support, communication, legal enforcement and product provision.
Website, marketing and analytics data: data processed when visiting oxolo.com, when consenting to cookies/tracking, for the newsletter, for social-media presences and for marketing campaigns.
For Customer Content, the customer is regularly the controller. Oxolo processes these data, in principle, on the customer's instructions as a processor. For account, contract, security, support, website, marketing, communication and legal data, Oxolo is regularly its own controller.
3. Scope of Application
This Privacy Policy applies to:
the oxolo.com website and its subpages;
the Oxolo web application;
the Oxolo iOS app and Android app;
registration, login, user account, organisations, teams and subscriptions;
B2B contract initiation, contract performance, customer communication and legal updates;
support via email and comparable support channels;
the WhatsApp Cloud API, insofar as this function is activated or used by a customer;
the recording and transcription of external online meetings (e.g. Zoom, Microsoft Teams, Google Meet) by a Meeting Bot, insofar as this function is activated or used by a customer;
push notifications in the Oxolo iOS and Android apps;
referral and recommendation programmes (referral), insofar as offered and used;
the newsletter;
Oxolo's social-media presences on LinkedIn, Facebook, Instagram and YouTube or comparable portals;
analytics, marketing and attribution technologies, insofar as these are used and legally permissible.
This Privacy Policy does not apply to third-party websites, services or content to which we merely link or which are provided independently by third parties. The data-protection notices of the respective providers apply to such services.
4. Website Access and Technical Server Data
When you visit oxolo.com, we process technically necessary data that your browser or device transmits. This may include, in particular, IP address, date and time of access, time zone, requested page or file, HTTP status, volume of data transferred, referrer URL, browser type, browser version, operating system, device type and similar technical information.
The purposes of this processing are the provision of the website, system security, abuse detection, error analysis, technical administration and improvement of the website. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and user-friendly operation of the website. Insofar as the access is necessary for carrying out pre-contractual measures, Art. 6(1)(b) GDPR may additionally be applicable.
Technically necessary server data are stored only for as long as this is necessary for the stated purposes, subject to statutory retention obligations, security purposes and legal enforcement.
5. Cookies, Consent Management and Tracking on oxolo.com
On oxolo.com we use a consent management system from OneTrust. Non-necessary cookies, pixels, tags, SDKs and comparable technologies are only set or read out if you have consented beforehand. You can withdraw or change a consent given at any time via the cookie settings.
The legal basis for technically non-necessary cookies, pixels, tags, SDKs and comparable technologies is your consent, Art. 6(1)(a) GDPR, as well as, insofar as information is accessed on your terminal equipment or information is stored there, the applicable consent rule for terminal equipment under the Telecommunications Digital Services Data Protection Act (TDDDG). Technically necessary cookies and comparable technologies are used on the basis of Art. 6(1)(f) GDPR and the applicable exception for strictly necessary storage or access operations.
According to the current status, we use the following tools:
Tool / Provider | Purpose | Retention | Third-country transfer | Legal basis |
OneTrust | Obtaining, storing and documenting the consent decision as well as the banner status | up to 1 year | USA possible; DPF certification OneTrust, insofar as applicable | Art. 6(1)(f) GDPR; technically necessary for consent management |
Google Tag Manager | Tag management and delivery of website tags | n/a (loads further tags after consent) | USA possible; DPF certification Google LLC | Consent (Art. 6(1)(a) GDPR in conjunction with § 25 TDDDG), insofar as non-necessary tags are delivered |
Google Ads (conversion tracking and remarketing) | Measurement of ad performance, conversion tracking and remarketing | typically up to 90 days | USA possible; DPF certification Google LLC | Consent |
Meta Pixel (Facebook/Instagram) - currently exclusively on the Oxolo landing page | Measurement and optimisation of campaigns on Meta platforms, remarketing | up to 2 months | USA possible; DPF certification Meta group | Consent |
PostHog (EU instance, eu.i.posthog.com) | Product and web analytics, usage evaluation, feature analysis, funnel and error analysis | up to 1 year | EU processing; supplementary EU SCC vis-à-vis US parent company | Consent for non-necessary analytics |
AppsFlyer (mobile SDK in iOS/Android app) | Mobile attribution, campaign measurement, install and conversion attribution in the mobile apps | usually up to 24 months | Processing in Germany (AppsFlyer Germany GmbH); group nexus Israel (adequacy decision) | Consent or app/device-based agreement pursuant to ATT (iOS) or Google UMP (Android) |
Framer | Hosting and provision of the oxolo.com landing page, delivery of website scripts and hosted assets, as well as provision and processing of lead/contact forms | essentially session-based | EU/Netherlands (Framer B.V.); supplementary EU SCC, insofar as necessary | Art. 6(1)(f) GDPR for the technically necessary provision of the website; consent, insofar as non-necessary tags/cookies are set |
Google Fonts | Display of fonts on the website or in product interfaces | n/a | USA possible in the case of external retrieval; DPF certification Google LLC | In the case of external retrieval: consent; in the case of local integration: technically necessary |
6. Registration, User Account and Login
A user account is required to use Oxolo. In a B2B context, users can be invited by a customer, administrator or authorised team lead. In addition, business self-registration may be possible.
Upon registration and login, we process in particular:
name, business email address, telephone number, company, role, team/organisation affiliation and permissions;
one-time passwords (OTP), login links sent by email (magic link), session and access tokens, and other authentication information;
verification status, time of registration, login and security events (in particular the request and verification of one-time passwords, logins, set-up and change of the telephone number, in each case with result, time, telephone number, IP address and device/browser identifier), IP address, device and browser information;
device tokens for push notifications as well as the platform designation (iOS/Android);
profile details, user preferences, settings, language, organisation and project assignments;
invitations, roles, permissions, project memberships and administrative actions.
The purposes are registration, identity verification, login, provision of the user account, administration of organisations and teams, rights and role concept, security, abuse prevention, support and contract performance. The legal bases are Art. 6(1)(b) GDPR for contract performance and pre-contractual measures, as well as Art. 6(1)(f) GDPR for security, abuse prevention, verifiability and stable product provision. The provision of these data is necessary for the set-up and use of a user account; without them, the user account cannot be set up and Oxolo cannot be used. There is no statutory obligation to provide them.
Login currently takes place via the telephone number by means of a one-time password (OTP) sent by SMS, and possibly via a login link (magic link) sent to the business email address. A password chosen by the users themselves is not used for login and is not stored. After successful login, Oxolo issues a signed access token; the associated signing key is held in a key-management service of Amazon Web Services in the Ireland region (eu-west-1) and does not leave it. Authentication and account data are, in principle, processed for as long as the user account or the contractual relationship exists and beyond that, insofar as this is necessary for security, legal obligations, legal enforcement or evidentiary purposes.
For the dispatch of one-time passwords by SMS and for the verification of telephone numbers, we use Twilio as a processor. The telephone number, the one-time code and technical delivery and status information are transmitted in this process. Insofar as personal data are transmitted to the USA in this process, we rely on suitable safeguards pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses, supplemented, insofar as the recipient is certified, by the EU-US Data Privacy Framework. The precise processing region is set out in Annex 3 of the Data Processing Agreement.
7. Contact after Registration, Contract Communication, Contract Initiation and Legal Updates
If a user registers, provides a telephone number or email address, creates an account, requests a demo, trial, product information or a quote, or makes any other recognisable business contact with Oxolo, we may use these contact details in order to contact them by telephone or email in the course of contract initiation. This includes, in particular, follow-up questions about the registration, qualification of the business need, explanation of the Oxolo functions, product demonstrations, onboarding, references to suitable paid plans, licences, modules or offers, as well as the preparation of a contract conclusion.
After a registration, we may contact registered users, customer administrators, account owners, relevant billing contacts and invited users by email or telephone, insofar as this is necessary in order to discuss an existing or potential contract, a subscription, a trial, an order, onboarding, product use, support, product advice, contract initiation, contract extension or contract performance.
Insofar as we do not collect business contact details directly from the data subject but obtain them from specialised providers for the acquisition of business contacts (lead providers) or from publicly accessible business sources such as company websites, industry directories or professional networks, we regularly process the following categories: first and last name, business function or position, company, business email address, business telephone number, as well as information about the company such as industry, size and location. The purpose is the approach of potential business customers in a B2B context. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in the direct approach of business contacts for a product used exclusively for business purposes. We disclose the specific origin of the respective data at the latest upon first contact, and otherwise on request at gdpr@oxolo.com. You can object to the processing at any time pursuant to Section 27; we then cease the approach and delete the data processed for this purpose.
This contact does not serve general advertising without a legal basis, but the initiation, performance, extension or servicing of a specific B2B contract or usage relationship. The legal basis is Art. 6(1)(b) GDPR, insofar as the communication is necessary for contract performance or for carrying out pre-contractual measures. Insofar as we contact legitimate B2B contacts, Art. 6(1)(f) GDPR may additionally be applicable. Our legitimate interest lies in efficient B2B contract initiation, customer servicing, product advice, licence marketing and product provision.
Insofar as the contact, beyond immediate contract performance or specific contract initiation, also has an advertising character, in particular in the case of active approaches regarding paid plans, additional licences, modules, upgrades or similar products, this takes place in a B2B context only in accordance with the applicable advertising-law requirements, in particular § 7 UWG (German Act Against Unfair Competition). Telephone approaches to other market participants require at least presumed consent; email marketing generally requires consent or a legally permissible existing-customer situation. You can object to advertising contact at any time with effect for the future.
We may inform customer administrators, account owners, billing contacts and, where necessary, affected users by email of legal, contractual or security-related changes, in particular of changes to the GTC, the Data Processing Agreement, this Privacy Policy, security information, price/subscription information or product-related mandatory information. The legal bases are Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR. For general communication, team@oxolo.com may be used; for data-protection requests, please contact gdpr@oxolo.com.
Referral programme. Insofar as we offer a referral programme, registered users and partners can share a personalised referral link. In this process, the identifier of the referring user, the identifier of the referral link, the time and channel of access, the attribution of a resulting registration or order, and the details necessary for granting or paying out a reward are processed. For the technical handling, we use Cello (PowerPlay GmbH, Munich) as a processor. The legal basis is Art. 6(1)(b) GDPR for the performance of the participation conditions vis-à-vis the referring user, as well as Art. 6(1)(f) GDPR for the attribution of the referral and abuse prevention. Referred persons receive the above information on the origin of their contact details upon first contact.
8. Subscriptions, Payment Processing and Invoice Data
When a customer, administrator, account owner or user orders, manages or pays for paid Oxolo services, we process the contract, billing and payment data necessary for this. This may include, in particular: name, business contact details, company, invoice address, VAT or tax information, order and subscription data, plan, term, seats, prices, invoice status, payment status, transaction identifiers, IP address and technical payment metadata.
Depending on the chosen payment method, processing takes place via invoice, Stripe, the Apple App Store or Google Play or another payment channel supported by Oxolo.
For payments via Stripe, we use Stripe Payments Europe, Limited, Ireland. Stripe may process payment data both as a processor and, for its own legal, regulatory, security and fraud-prevention purposes, as an independent controller. Oxolo generally does not receive full credit-card data, but payment and transaction information necessary for subscription administration, invoicing, accounting, abuse prevention and contract performance.
When a subscription is concluded via the Apple App Store or Google Play, payment processing is carried out by Apple or Google under their own controllership. Oxolo generally receives from Apple and Google only information necessary for the verification and management of the subscription, for example transaction identifiers, product/plan information, term, status and technical confirmation information.
The legal bases are Art. 6(1)(b) GDPR for contract performance and billing, Art. 6(1)(c) GDPR for tax, commercial and accounting obligations, as well as Art. 6(1)(f) GDPR for receivables management, fraud prevention and evidentiary purposes.
9. Use of the Oxolo Product and Customer Content
Oxolo is a B2B software for digital project, deployment, construction-site and field documentation. Depending on the booked or activated range of functions, customers and users can enter, upload, record, structure, analyse, share data and have it transferred into reports or other outputs.
In this process, the following categories of personal data may, in particular, be processed:
audio recordings, voice data, transcripts, speaker assignments and, insofar as activated or used, voice profiles or voiceprints;
recordings of external online meetings including audio and video data, voices, displayed names and participant identifiers of all participants, insofar as the Meeting Bot function is activated or used;
photos, videos, evidence files, image/video metadata, project images, avatar images and other uploads;
project, construction-site, organisation, customer, team and role information;
tasks, variation orders, delays, reports, logs, signatures, sharing links, download and export information;
AI-generated content such as summaries, titles, tasks, tags, descriptions, translations, report proposals or other structured outputs;
authentication and login events, device tokens for push notifications, as well as consent and agreement records, for example for speaker recognition and for communication via WhatsApp;
usage, security, audit and activity data, insofar as they are necessary for operation, security, rights management, support, traceability or compliance.
Insofar as it concerns Customer Content, the processing takes place, in principle, on behalf of the respective customer and on their instruction. The purposes are, in particular, the provision of the Oxolo functions, project and construction-site documentation, transcription, speaker assignment, report creation, task and variation-order management, collaboration, sharing, export, support, security and contract performance. The legal basis on the part of Oxolo as a processor is the contract with the customer including the data processing agreement. Insofar as Oxolo processes its own account, security, support or operational data, the legal bases stated in this Privacy Policy apply.
Customers and users are responsible for holding the necessary rights, notices, legal bases and, where necessary, consents for personal data that they upload, record or otherwise have processed in Oxolo. This applies in particular to persons whose voice, image, location, signature or other personal data are contained in construction-site, project or communication content.
10. Audio Recordings, Transcription and Speaker Recognition
When users create or upload audio recordings, Oxolo processes the audio data in order to create transcripts, summaries, speaker assignments, tasks, reports and further project-relevant outputs. Audio data may be captured and processed via mobile apps, the web application or connected communication channels.
For transcription and speech processing, Oxolo may use specialised service providers, in particular AssemblyAI for transcription and Pyannote.ai for speaker diarisation, speaker identification and, insofar as activated or used, voiceprint functions. The transcription and speaker diarisation by AssemblyAI take place exclusively in batch mode via the EU endpoint of AssemblyAI. Live or streaming transcription is not offered; audio data are not transmitted to AssemblyAI in the USA. Information on the processing region of Pyannote.ai is contained in Annex 3 of the Data Processing Agreement; insofar as personal data are processed outside the European Economic Area in this process, we rely on suitable safeguards pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses. Further details are contained in the Data Processing Agreement.
Audio recordings and transcripts are processed as Customer Content, in principle, for the term of the contract or on the customer's instruction, unless a deletion, anonymisation, statutory obligation, security requirement or deviating contractual arrangement applies.
The user who starts or uploads a recording is responsible for duly informing data subjects and, where necessary, for ensuring their consent or another suitable legal basis. This applies in particular where voices of employees, subcontractors, customers, visitors or other third parties are recorded.
11. Recording of External Online Meetings (Meeting Bot)
Insofar as a customer activates or uses the Meeting Bot function, an automated participant ("bot") may, at the instigation of an authorised user, participate in and record external online meetings in services such as Zoom, Microsoft Teams or Google Meet.
In this process, the following are processed, in particular: audio and video data of the meeting, voices and speech contributions of all participants, displayed names and participant identifiers, meeting metadata such as title, time, duration and platform, as well as the transcripts, speaker assignments, summaries, tasks and reports generated therefrom.
The recordings are transferred into the same processing chain as the other audio recordings; Sections 10, 12 and 15 therefore additionally apply. If the voiceprint function is used, biometric data within the meaning of Art. 9(1) GDPR of external meeting participants may also be processed in this process.
For the provision of the Meeting Bot, we use Recall.ai (Hyperdoc Inc., USA) as a processor. The processing is configured to the eu-central-1 region. Insofar as personal data are transmitted to the USA, we rely on suitable safeguards pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses, supplemented, insofar as the recipient is certified, by the EU-US Data Privacy Framework.
The legal basis in relation to Customer Content is processing on the customer's instruction. The customer or the user who adds the bot to a meeting is responsible for informing all participants, before the recording begins, about the recording, its purpose, the AI processing used and the responsible party, as well as for obtaining and documenting the required legal bases and — in particular in the case of biometric speaker recognition — the required explicit consents pursuant to Art. 9(2)(a) GDPR. It should be noted that the recording of the non-publicly spoken word without the consent of all participants may be a criminal offence under § 201 StGB (German Criminal Code).
For deletion, Sections 12.3 and 25 apply accordingly.
12. Voiceprints and Biometric Speaker Recognition, Insofar as Activated or Used
Insofar as voiceprint-based speaker recognition is activated or used, Oxolo may process voice profiles in order to re-recognise speakers in later recordings. Voiceprints are biometric data for the unique identification of a natural person and thus special categories of personal data within the meaning of Art. 9(1) GDPR, insofar as they are used or can be used for unique identification.
12.1 An identity is the assignment of a speaker name to one or more voiceprints. A voiceprint is a technical or numerical representation of a voice sample. If a user re-registers their voice, a new voiceprint can be added to the existing identity; this does not necessarily replace the previous voiceprint. In speaker recognition, the voiceprint with the highest match may be decisive.
The biometric representation of the voice is technically held in two separate databases: in the database of the transcription service and — for historical reasons — additionally in the application database. Information on the respective processing regions is contained in Annex 3 of the Data Processing Agreement. A deletion pursuant to Section 12.3 covers both storage locations as well as the associated source audio.
Voiceprints are isolated on an organisation-specific basis and are not used across organisations for speaker recognition. Automatic speaker recognition (auto-enrollment) is activated by default at the organisation level (opt-out model). For as long as a customer administrator has not deactivated this function, speakers in a recording whose voice is not already assigned to a registered identity are automatically created as a new identity with an anonymised placeholder label (e.g. "Speaker b74bj73") and a voiceprint is generated for them. An authorised user of the customer can later name or delete this identity.
Within an organisation, the roles of owner, administrator (admin) and user are available. The owner and users with an administrator role can deactivate auto-enrollment in the organisation settings at any time; they can also name, merge and delete voiceprint identities and have access to the content of their organisation. A deactivation of auto-enrollment takes effect for the future; voiceprints already generated continue to exist until their deletion pursuant to Section 12.3.
12.2 The registration of one's own voice takes place through a separate, express action by the user in the app: the user speaks a predefined phrase after having been informed beforehand that a voice profile is generated from it. The controller for this processing is the customer in whose organisation the user is active; Oxolo provides the consent function on behalf of the customer and processes the data as a processor. The customer regularly bases the processing on the explicit consent of the data subject pursuant to Art. 9(2)(a) GDPR in conjunction with Art. 6(1)(a) GDPR; the review of whether the consent declaration used in the Product is sufficient for its deployment context is incumbent on the customer. The consent is versioned and logged; the version of the consent capture, the time, the platform and the assignment to the recording concerned are stored. Users can withdraw the consent at any time with effect for the future and can delete their own voiceprint at any time via the app. The withdrawal does not affect the lawfulness of the processing carried out up to the withdrawal.
In the case of voices of persons who are not themselves users or who do not themselves register a voice profile in the Product — including speakers captured automatically within the framework of the function described above — the customer or the recording user is responsible for obtaining and documenting the required notices, legal bases and, where necessary, explicit consents outside the Product. Oxolo processes such data, in relation to the customer, in principle as a processor.
12.3 When a voiceprint is deleted, the voiceprint and the associated source audio are removed. Deletion takes place, in particular, in the following cases:
the user deletes their own voiceprint via the app;
the user is removed from an organisation; in this case, the user's own voiceprints in that organisation are deleted;
the account is deleted or archived;
the organisation owner or a user with an administrator role deletes an identity via the settings;
a speaker is marked as "noise".
Transcripts, original recordings and audit-trail data, however, are retained as Customer Content or compliance data, insofar as they are not separately deleted or a deviating instruction, statutory obligation or contractual arrangement applies. Old transcripts may therefore continue to contain the name displayed at the time; new recordings may display anonymised speaker labels after deletion.
13. Photos, Videos, Uploads, EXIF/GPS Metadata and Signatures
Depending on the activated function, users can capture or upload photos, videos, evidence files, project images, avatar images, signatures and other files in Oxolo. These data are processed in order to create project and construction-site documentation, manage evidence, generate reports, share content and provide product-related workflows.
Uploaded images or videos may contain metadata, for example date, time, device information, camera settings, location data or other EXIF/GPS metadata. This metadata is not removed server-side. Users and customers should therefore check which files they upload and whether metadata must be removed before the upload.
The legal basis in relation to customer content is, in principle, processing on the customer's instruction. Insofar as Oxolo pursues its own operational or security purposes, Art. 6(1)(b) and (f) GDPR may apply.
14. Location Data and Mobile Permissions
The Oxolo iOS and Android apps may request certain device permissions. Permissions are, in principle, only requested where they are necessary for a specific function or are required by the operating system.
Permission / Data category | Purpose | Note |
Microphone / Audio | Recording of audio documentation, transcription and report creation. | Core function for recordings. Without authorisation, the recording function cannot be used. |
Camera and Photos / Media Library | Capture and upload of photos, videos and evidence files. | Optional per function. Uploads may contain EXIF/GPS metadata. |
Location Data | Tagging of recordings or evidence with construction-site/project location and support with project assignment. | Optional and only upon activation of a relevant function. Location data may include GPS coordinates and derived place names. |
Storage / Files | Export or storage of reports, images or other files on the device. | Optional per operating system and function. |
Biometric device lock such as Face ID / fingerprint | Local unlocking of the app, if activated by the user. | Oxolo generally does not receive any biometric raw data of the device; the check is carried out via the operating system. |
Speech recognition / local system services | Possible local speech-recognition or operation functions, insofar as provided by the device. | The primary transcription takes place via cloud service providers. |
Push Notifications | Delivery of notices on projects, tasks, reports and security-relevant events to the device. | Optional. Upon activation, the device generates a push token that is transmitted to and stored by Oxolo. Delivery takes place via the push service of Expo and the push infrastructure of Apple or Google. Can be deactivated in the system settings. See Section 18. |
Tracking and advertising identifiers (App Tracking Transparency on iOS, advertising ID on Android) | Measurement of campaigns as well as install and conversion attribution in the mobile apps. | Only upon agreement via the ATT dialogue (iOS) or the corresponding consent request (Android). See Section 21. |
The legal bases are, depending on the function, Art. 6(1)(b) GDPR for the provision of the desired product function, Art. 6(1)(a) GDPR in the case of consent-requiring device or tracking functions, as well as Art. 6(1)(f) GDPR for security and operational purposes. App permissions can be managed in the settings of the operating system.
15. AI Processing and Automatically Generated Content
Oxolo uses AI functions in order to generate from Customer Content, for example, transcripts, summaries, tasks, variation orders, delays, report proposals, translations, tags, image descriptions, project context or other outputs. AI-generated content may be incomplete, erroneous or misleading and must be reviewed by the user.
For AI-supported text and image processing, LLM models are used. A current overview of the AI service providers used is contained in Section 23. Oxolo does not use Customer Content to train its own AI models. Oxolo also does not process Customer Content to train the large language models provided by third-party providers, insofar as this is excluded under the relevant product and contract terms of these third-party providers. Any use of Customer Content for product improvement by Oxolo takes place only if the customer has expressly activated the corresponding system setting, and only within the framework of the contractual agreements and applicable data-protection requirements.
Insofar as Oxolo provides AI systems with which users interact directly, we point this out. The project assistant in the application is designated as an AI assistant and points out at the beginning of each session that the answers originate from an AI system. In the WhatsApp channel, users receive the same notice with the assistant's first response.
AI-generated outputs are, where they are presented as a self-contained result, identified as such in the application; this concerns in particular the summaries of recordings and the automatically populated fields in report templates. In addition, the content generated or altered by Oxolo is labelled in machine-readable form as AI-generated; this includes in particular transcripts, tasks automatically generated from recordings and the body text of generated reports. The labelling may not be removed, altered or rendered unrecognisable. These notices are provided in implementation of the transparency obligations under Art. 50(1) and (2) of Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744.
16. WhatsApp Cloud API
Insofar as a customer activates or uses the WhatsApp function, users or end users can interact with Oxolo workflows via WhatsApp. In this process, the following may in particular be processed: telephone numbers, WhatsApp profile information, message content, media, attachments, timestamps, technical delivery information, template variables and assignments to customer, workspace, project or workflow contexts.
The purposes are the provision of the respective WhatsApp workflow, import of messages and media into Oxolo, assignment to projects or customer contexts, processing of user requests, notifications, documentation and support. The legal basis in relation to Customer Content is regularly processing on the customer's instruction. Insofar as Oxolo pursues its own operational, security or support purposes, Art. 6(1)(b) and (f) GDPR may apply.
Insofar as users use communication via WhatsApp, we document the underlying agreement. The telephone number in E.164 format, the wording and the version of the underlying agreement text, the platform (web or mobile app) and the time of granting are stored. These records are continuously supplemented and not subsequently altered; they are deleted when the associated user account is completely deleted.
Messages that serve the performance of the contract or usage relationship — for example status notifications regarding recordings, reports or tasks — we send on the basis of Art. 6(1)(b) GDPR. Messages of an advertising character, in particular references to new functions, product recommendations or requests for renewed use, we send exclusively on the basis of a separate, explicit consent pursuant to Art. 6(1)(a) GDPR and § 7(2) UWG. This consent can be withdrawn at any time with effect for the future.
WhatsApp is provided by Meta. When WhatsApp is used, Meta processes personal data in accordance with its own terms and data-protection notices. Customers and users should inform data subjects about the use of this channel and check whether WhatsApp is suitable for the specific communication content. Further information on the use of WhatsApp is available at https://www.whatsapp.com/legal/privacy-policy-eea. For WhatsApp Business, the information can be found at https://www.whatsapp.com/legal/business-data-processing-terms.
17. Support, Live Chat and Other Communication
If you contact us or request support, we process the data you transmit to us. This may include, in particular, name, business email address, company, user account, message text, attachments, screenshots, technical information, product context, browser/device data, timestamps, communication history and support status.
The purposes are the handling of your request, error analysis, customer servicing, contract performance, internal documentation, quality assurance and security review. The legal bases are Art. 6(1)(b) GDPR, insofar as the communication is necessary for contract performance or pre-contractual communication, as well as Art. 6(1)(f) GDPR. Our legitimate interest lies in efficient B2B support, error correction and customer satisfaction.
18. Email Dispatch, Transactional Messages and Postmark
Oxolo may send emails that are necessary for registration, verification, account administration, security, invitation, billing, contract performance, support, product use or legal updates. For this purpose, Oxolo may use email service providers such as Postmark.
The following are processed in particular: email address, name, company, language, content of the message, technical dispatch information, delivery status, open/click information, insofar as technically necessary and legally permissible, as well as timestamps. The legal bases are Art. 6(1)(b) GDPR, Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR.
For the dispatch of SMS, in particular of one-time passwords for login and for the verification of telephone numbers, we use Twilio (see Section 6). The telephone number, message content, delivery status and technical dispatch information are processed.
For push notifications in the mobile apps, the device generates a push token, which we store together with the platform designation (iOS/Android) and assign to the delivery. Dispatch takes place via the push service of Expo (650 Industries, Inc., USA) and from there via the push infrastructure of Apple or Google. The legal basis is Art. 6(1)(b) GDPR for product-related transaction and mandatory notifications, as well as Art. 6(1)(a) GDPR insofar as the notification requires consent. Push notifications can be deactivated at any time in the settings of the operating system. Section 24 applies to transfers to the USA.
19. Newsletter
When you sign up for the newsletter, we process your email address, where applicable name, company, role, language, sign-up time, confirmation time, IP address, consent status and unsubscribe status.
Sign-up takes place via a double opt-in procedure. After signing up, you receive a confirmation email and are only added to the newsletter distribution list after confirmation. Every newsletter contains an unsubscribe option. The legal basis is your consent pursuant to Art. 6(1)(a) GDPR. You can withdraw the consent at any time with effect for the future.
Insofar as newsletter emails contain tracking pixels or click tracking, we use these only insofar as there is a valid legal basis for this and the function is transparently described.
20. Social-Media Presences
Oxolo maintains presences on
LinkedIn (https://www.linkedin.com/company/oxoloai/);
Facebook (https://www.facebook.com/oxoloAI);
Instagram (https://www.instagram.com/oxoloai/) and;
YouTube (https://www.youtube.com/@oxoloAI)
When you interact with our profiles, for example by following, commenting, liking, sharing, direct messages or accessing our content, we may process the profile data and communication content visible in this process.
The purposes are corporate communication, B2B marketing, relationship maintenance, processing of messages, evaluation of the reach of our content and public relations. The legal bases are Art. 6(1)(f) GDPR and, insofar as you send us a message or make a specific request, Art. 6(1)(b) GDPR. The platform providers additionally process data under their own responsibility in accordance with their respective data-protection notices.
In the case of page statistics or comparable insights functions, joint controllerships or independent controllerships of the platform providers may exist, depending on the platform. Further information can be found in the data-protection notices of the respective platform.
21. Product Analytics, Security, Error Analysis, Attribution and Logs
For the provision, security and improvement of Oxolo, we process usage, security, system, attribution and error data. This may include, in particular, user ID, organisation ID, project ID, timestamps, IP address, device and browser information, app version, feature use, event logs, error messages, performance data, crash reports, API use, campaign parameters, install data, audit events and similar technical information.
For this purpose, we use, among others:
PostHog (EU instance, eu.i.posthog.com) for product analytics, feature analysis, website/product usage events, funnel evaluation and feature flags;
Sentry (DE instance, ingest.de.sentry.io) for error, crash and performance analysis;
AppsFlyer for mobile attribution, campaign measurement, install and conversion attribution in the mobile apps.
The purposes are system security, error correction, abuse detection, product stability, product improvement, support, campaign measurement and verifiability. The legal basis is Art. 6(1)(f) GDPR, insofar as the processing is technically necessary or necessary for security/operational purposes. For non-necessary analytics, marketing, attribution or tracking functions, we obtain consent, insofar as this is legally required.
Audit and security logs may be stored for longer, insofar as this is necessary for the fulfilment of statutory obligations, for security, for abuse and fraud prevention, for verifiability or for the assertion, exercise or defence of legal claims.
22. Google Fonts
Oxolo may use Google Fonts or comparable fonts to display the website or product interfaces. When fonts are hosted locally, there is generally no transmission to Google when the page is accessed. When fonts are loaded externally from Google servers, your browser may transmit technical data such as IP address, browser information, requested font and time of retrieval to Google.
23. Recipients, Service Providers and Subprocessors
We only pass on personal data insofar as this is necessary for the stated purposes, a legal basis exists or we are obliged to do so. Recipients may, in particular, be:
hosting, cloud and infrastructure providers, in particular Amazon Web Services (AWS) for computing power, databases, object storage and key management in the Ireland region (eu-west-1), as well as Framer for the oxolo.com landing page including the website scripts, hosted assets and lead/contact forms integrated there;
transcription, speaker-recognition and AI service providers, in particular AssemblyAI, Pyannote.ai, Anthropic Ireland Ltd.;
providers for the recording of external online meetings, in particular Recall.ai, insofar as the Meeting Bot function is activated or used;
providers for telephony and SMS services, in particular Twilio for the dispatch of one-time passwords and SMS notifications;
providers for push notifications, in particular Expo as well as Apple and Google as operators of the respective push infrastructure;
email and support service providers, in particular Postmark for transactional emails and in-app support;
providers of referral and recommendation programmes, in particular Cello (PowerPlay GmbH, Munich), insofar as such a programme is offered and used;
payment and subscription service providers, in particular Stripe, the Apple App Store and Google Play;
analytics, error, attribution and tracking service providers, in particular PostHog, Sentry, AppsFlyer, Google (including Google Ads and Google Tag Manager), Meta (limited to the landing page);
Meta for the WhatsApp Cloud API, insofar as this function is activated or used;
Google Maps, insofar as location or map functions are activated or used;
service providers that Oxolo uses exclusively for its own purposes as a controller and that do not process customer content on behalf of a customer: Slack Technologies LLC for internal team communication, HubSpot Germany GmbH and HubSpot Inc. for CRM, lifecycle and marketing communication, as well as OneTrust, LLC for consent management on oxolo.com and the documentation of consent decisions;
tax advisors, legal advisors, auditors, authorities, courts and other bodies, insofar as this is legally required or necessary for legal enforcement.
Insofar as service providers process personal data on our behalf, we conclude suitable data-processing agreements. Insofar as providers act as independent controllers, their own data-protection information additionally applies.
24. International Data Transfers
The core operation, in particular essential compute, database, authentication, embedding and AI processing, is configured to be EU-resident. Computing power, databases, object storage and key management are operated at AWS in the Ireland region (eu-west-1); transcription takes place via the EU endpoint of AssemblyAI, product analytics via the EU instance of PostHog, and error analysis via the DE instance of Sentry. Nevertheless, depending on the function, provider and configuration, data may be processed outside the European Economic Area. This concerns in particular Twilio (SMS and one-time passwords), Expo as well as Apple and Google (push notifications), Recall.ai (Meeting Bot), Postmark (email dispatch), HubSpot (CRM), Meta (WhatsApp) as well as Apple and Google (app stores and map services). In the case of AppsFlyer, the processing takes place in Germany by AppsFlyer Germany GmbH with a group nexus to Israel, for which an adequacy decision of the EU Commission exists. Cello (PowerPlay GmbH) processes the data in Germany.
Insofar as personal data are transmitted to countries outside the European Economic Area for which no adequacy decision exists, we use suitable safeguards pursuant to Art. 46 GDPR, in particular EU Standard Contractual Clauses, supplementary measures, provider data-protection agreements or other permissible transfer mechanisms, insofar as necessary. For transfers to the USA, we additionally rely, insofar as the respective recipient is certified, on the EU-US Data Privacy Framework (adequacy decision of the EU Commission C(2023) 4745 final of 10 July 2023). We base third-country transfers primarily on EU Standard Contractual Clauses; the EU-US Data Privacy Framework is only used supplementarily. Should this adequacy decision be repealed or declared invalid, the Standard Contractual Clauses remain in place as an independent basis. We make a copy of the suitable safeguards used in each case available to you on request at gdpr@oxolo.com.
25. Storage Period and Deletion
We store personal data only for as long as this is necessary for the respective purposes. The specific storage period depends on the nature of the data, contract and customer settings, the customer's instructions, product functions, statutory retention obligations, security requirements, evidentiary interests, backup cycles and the assertion, exercise or defence of legal claims.
Security, audit and authentication logs, including login events, IP address and device information, are currently retained, as they serve verifiability, abuse and fraud prevention, as well as the assertion, exercise or defence of legal claims. Upon deletion of a user account, the assignment of these logs to the user is anonymised. We regularly review the necessity of continued retention.
For Customer Content, the following generally applies: the processing takes place during the contract term and on the customer's instruction. Customers or authorised administrators can, depending on the function, delete or export data or end their processing. After the end of the contract, access to the export and download functions available in the Product remains in place for at least thirty (30) days; in addition, an export in text form to team@oxolo.com can be requested within this period, insofar as this is technically available and legally permissible. Thereafter, Customer Content may, in principle, be deleted or returned, insofar as no statutory retention obligations, legitimate evidentiary interests or deviating instructions conflict with this. In all other respects, the provisions of the Data Processing Agreement apply.
For voiceprints, the following applies: voiceprints are deletable on request or via a product function and are deleted upon account closure, account archiving, removal from an organisation, deletion of an identity by the organisation owner or a user with an administrator role, or marking as "noise". In this process, the biometric representation of the voice in all databases used for this purpose, as well as the associated source audio, are deleted. Transcripts, original recordings and audit-trail data may, however, continue to exist as Customer Content or compliance data, insofar as they are not separately deleted or a deletion is not permissible or not provided for. In particular, the speaker name displayed in already created transcripts is not deleted; it remains in the text of the respective transcript line until the customer deletes the transcript or the underlying recording itself.
Account, contract, billing, payment and legal data may be stored beyond the end of the contract, insofar as this is necessary for statutory obligations, accounting, tax, legal enforcement, receivables management, security or evidentiary purposes. Accounting and tax data are regularly retained for the statutorily prescribed period.
26. Data Subject Rights
Under the GDPR, you have, in particular, the following rights:
the right of access to the personal data concerning you;
the right to rectification of inaccurate or incomplete data;
the right to erasure of personal data;
the right to restriction of processing;
the right to data portability;
the right to object to processing based on Art. 6(1)(e) or (f) GDPR;
the right to withdraw a consent given, with effect for the future;
the right to lodge a complaint with a data-protection supervisory authority.
Please direct data-protection requests to gdpr@oxolo.com. If your request relates to Customer Content for which an Oxolo customer is the controller, we may forward the request to the respective customer or refer you to them. We support customers within the framework of the Data Processing Agreement in handling data subject requests.
An automated self-service interface for access or data-export requests is not currently available in the software. Requests are therefore handled manually via the data-protection process. The statutory deadlines remain unaffected.
Automated decision-making, including profiling within the meaning of Art. 22(1) and (4) GDPR, which produces legal effects concerning you or similarly significantly affects you, does not take place within the framework of the processing carried out by Oxolo on its own responsibility. AI-supported functions such as transcription, speaker identification, summarisation or report proposals are technical aids; decisions with legal effect are made exclusively by the customer or its users.
27. Right to Object
Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR, you can object to this processing at any time on grounds relating to your particular situation. We then no longer process the data, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or the processing serves the assertion, exercise or defence of legal claims.
Insofar as we process personal data for direct marketing, you can object to this processing at any time. Thereafter, we no longer process your data for this purpose.
An objection to direct marketing does not automatically end communications about legal, contractual or security-related updates that are necessary for contract performance, the fulfilment of statutory obligations or the safeguarding of legitimate interests.
28. Security
We use appropriate technical and organisational measures in order to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. Depending on the processing, these include in particular access controls, role-based permissions, encryption during transmission and storage, logging, tenant separation, security monitoring, confidentiality obligations and processes for handling security incidents.
No system is absolutely secure. Users and customers must, for their part, take appropriate security measures, in particular secure their devices as well as the telephone numbers and email mailboxes used for login, not pass on one-time passwords and login links to third parties, treat access credentials confidentially, manage permissions appropriately and inform Oxolo without undue delay of suspected compromises.
Insofar as Oxolo acts as a processor, the respective data processing agreement contains further details on technical and organisational measures.
29. Changes to This Privacy Policy
We may change this Privacy Policy where this is necessary due to changes to our services, our data processing, our providers, the legal situation or official or judicial requirements. We inform customer administrators, account owners, billing contacts and, where necessary, affected users of material changes in an appropriate manner, in particular by email, in the Product or on oxolo.com.
For legal updates, in particular changes to the GTC, the Data Processing Agreement, this Privacy Policy, security-related notices or comparable mandatory information, we may process and use the contact details necessary for this. The legal bases are Art. 6(1)(b), (c) and (f) GDPR.