OXTA PRIVACY POLICY
Version 1.0 · Effective 18 September 2026
Convenience translation. The Ukrainian version prevails.
1. What this document covers
1.1. This Policy explains how ТОВ «Окста» (Oxta, we) processes personal data of account owners on the Oxta platform and visitors to oxta.io. For this data we are the controller under Regulation (EU) 2016/679 (GDPR) and the "володілець" under the Law of Ukraine "On Personal Data Protection".
1.2. This Policy does not cover data flowing through your flows, files, datasets, sites and connections — your customers' data, orders, correspondence and so on. For that data you are the controller and we are the processor acting on your configuration, governed by the Data Processing Agreement (DPA). If you are a customer of one of our users and have a question about your data, contact that user (Section 9.5).
1.3. GDPR applies to us under Article 3(2) because we offer services to persons in the EU/EEA. We have not appointed an EU representative under Article 27 GDPR; for any data questions contact us directly. We have not appointed a DPO; contact privacy@oxta.io for data matters.
2. What we process and why
| Data | Source | Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|---|---|
| You | Sign-in, account identification, legally significant notices (changes, payments, incidents) | Contract — Art. 6(1)(b) | Account lifetime | |
| Password hash (scrypt, salted; the password itself is not stored) | You | Authentication | Art. 6(1)(b) | Account lifetime |
| First and last name | You | Addressing you, invoices | Art. 6(1)(b) | Account lifetime |
| Time zone | You | Firing schedules in local time | Art. 6(1)(b) | Account lifetime |
| Plan, usage counters (runs, AI operations) | Generated | Limit accounting, billing | Art. 6(1)(b) | Account lifetime; daily statistics 730 days |
| Account timestamps, session version | Generated | Security, session revocation | Art. 6(1)(b); legitimate interest in security — Art. 6(1)(f) | Account lifetime |
| Session token (JWT) | Generated | Keeping you signed in | Art. 6(1)(b) | 24 hours |
| IP address at sign-in/registration | Generated | Rate limiting, brute-force protection | Art. 6(1)(f) | As a transient attempt counter only: 15 minutes for sign-in, 60 minutes for registration. The IP address is not written to our databases |
| Infrastructure logs (IP, request headers, time) | Cloudflare | Security, attack mitigation, incident investigation | Art. 6(1)(f) | We have configured no log export of our own (Logpush is off) and keep no copies. Cloudflare keeps platform-level logs under its own policy; we do not control them |
| Payment records: amount, currency, exchange rate, status, masked card number (first 6 / last 4 digits), invoice ID | You; payment provider | Billing, refunds, accounting and tax | Art. 6(1)(b); legal obligation — Art. 6(1)(c) | 3 years after the end of the payment year |
| Consent records: which documents and versions, when, where accepted or withdrawn | You (action) | Demonstrating acceptance/consent — Art. 7(1) | Art. 6(1)(c), (f) | Account lifetime + 3 years |
| Support correspondence | You | Responding | Art. 6(1)(b), (f) | 3 years |
| Editor assistant and help-search queries | You | Generating the answer | Art. 6(1)(b) | Not stored separately from the session |
We never receive or store the full card number — the payment provider processes it and returns only a masked number.
Usage metrics (Cloudflare Analytics Engine) contain the account ID, flow and step IDs, statuses, durations and counts. No data content.
We do not collect: data from other websites, advertising profiles, precise geolocation.
3. Cookies and local storage
We store in your browser only: the session token (sign-in, 24 hours), interface language and theme. All are strictly necessary for the platform (Article 5(3) of Directive 2002/58/EC exemption). No advertising, analytics or tracking cookies, so no consent banner is shown. If we introduce non-essential cookies we will ask for consent first.
Sites our users publish on *.sites.oxta.io are their sites; they are responsible for cookies there.
4. Recipients
| Recipient | Role | Data | Country | Transfer basis |
|---|---|---|---|---|
| Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA | Processor: hosting, databases, storage, compute, AI models, security | All platform data | USA; global network | Cloudflare Data Processing Addendum with EU Standard Contractual Clauses; Cloudflare's EU-U.S. Data Privacy Framework certification |
| Universal Bank JSC (Monobank), Ukraine | Independent controller for payment data; payment service provider | Amount, currency, invoice ID; card data goes directly from you to the bank | Ukraine | Contract performance |
| Public authorities, courts | — | On lawful request | — | Legal obligation |
We do not sell personal data or share it for third-party marketing. Services you connect to flows (Telegram, Slack, Google, your SMTP, your database, your AI provider) receive data on your instruction and are not our recipients — see the DPA.
5. Transfers outside the EEA and Ukraine
5.1. For persons in the EU/EEA. We are located in Ukraine, for which there is no European Commission adequacy decision. Transfer of your data to us is based on necessity for the performance of the contract with you (Article 49(1)(b) GDPR) — the service cannot be provided without us processing your data. Onward processing at Cloudflare relies on the SCCs in our contract with Cloudflare. We apply the safeguards in Section 7 regardless of processing location.
5.2. For persons in Ukraine. Transfer to Cloudflare (USA) is made under Article 29 of the Law of Ukraine "On Personal Data Protection" on the basis of contractual data-protection guarantees provided by Cloudflare.
5.3. Cloudflare is a global network; data may be processed in data centres in various countries. We have not configured any regional restriction on processing.
6. Automated decision-making
We make no decisions about you based solely on automated processing that have legal or similarly significant effects (Article 22 GDPR). IP-based sign-in rate limiting is a technical security measure, not such a decision.
7. How we protect data
Passwords are stored only as salted scrypt hashes. External-service credentials are encrypted with AES-GCM under a dedicated key with a random IV per record. Secrets are automatically redacted from run history. Every request checks that the data belongs to the account. HTTPS only. Sign-in rate limiting. One-click revocation of all sessions. Data at rest is protected by Cloudflare's infrastructure encryption.
Candidly, what we do not have: two-factor authentication; separate encryption of run content under our own key; a log of staff access to production data; ISO 27001 / SOC 2 certification. We will update this Section when that changes.
8. Retention and deletion
Periods are in the Section 2 table. Account deletion is available in settings; it removes all your data and Customer Data, except payment and consent records retained for the stated periods on the basis of legal obligation and defence against claims. Final destruction in infrastructure backups — within 30 days.
9. Your rights
9.1. You have the right of access and to a copy; rectification; erasure; restriction; portability in a machine-readable format; objection to processing based on legitimate interest; and to withdraw consent where processing relies on it, without affecting prior processing (Articles 15–21 GDPR; Article 8 of the Ukrainian Law).
9.2. Most data can be viewed and changed in settings; account deletion is there too. For other requests write to privacy@oxta.io from the account e-mail. We respond within one month; for complex requests this may be extended by two further months with reasons (Article 12(3) GDPR). We may ask you to confirm access to the account e-mail to verify identity.
9.3. Requests are free unless manifestly unfounded or excessive.
9.4. Complaints. You may lodge a complaint with a supervisory authority: in Ukraine — the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua); in the EU — the authority of your habitual residence, place of work or place of the alleged infringement (list: edpb.europa.eu). We would appreciate the chance to resolve matters directly first.
9.5. If you are a customer of our user (a store's shopper, the recipient of a message sent via Oxta), that user is the controller. Contact them. If a request reaches us we forward it to the user within 5 business days if identifiable and inform you; we cannot resolve it ourselves without the controller's instruction.
10. Children
The platform is not directed at persons under 18. If we learn of such an account we will delete it.
11. Changes
Material changes are notified by e-mail at least 30 days ahead; on your next sign-in the platform will ask you to accept the new version. Version archive: oxta.io/legal/archive.
12. Language
Made in Ukrainian; the English version is a convenience translation.
Contacts: ТОВ «Окста» · privacy@oxta.io