OXTA PRIVACY POLICY

Version 1.0 · Effective 18 September 2026

Convenience translation. The Ukrainian version prevails.

1. What this document covers

1.1. This Policy explains how ТОВ «Окста» (Oxta, we) processes personal data of account owners on the Oxta platform and visitors to oxta.io. For this data we are the controller under Regulation (EU) 2016/679 (GDPR) and the "володілець" under the Law of Ukraine "On Personal Data Protection".

1.2. This Policy does not cover data flowing through your flows, files, datasets, sites and connections — your customers' data, orders, correspondence and so on. For that data you are the controller and we are the processor acting on your configuration, governed by the Data Processing Agreement (DPA). If you are a customer of one of our users and have a question about your data, contact that user (Section 9.5).

1.3. GDPR applies to us under Article 3(2) because we offer services to persons in the EU/EEA. We have not appointed an EU representative under Article 27 GDPR; for any data questions contact us directly. We have not appointed a DPO; contact privacy@oxta.io for data matters.

2. What we process and why

DataSourcePurposeLegal basis (Art. 6 GDPR)Retention
E-mailYouSign-in, account identification, legally significant notices (changes, payments, incidents)Contract — Art. 6(1)(b)Account lifetime
Password hash (scrypt, salted; the password itself is not stored)YouAuthenticationArt. 6(1)(b)Account lifetime
First and last nameYouAddressing you, invoicesArt. 6(1)(b)Account lifetime
Time zoneYouFiring schedules in local timeArt. 6(1)(b)Account lifetime
Plan, usage counters (runs, AI operations)GeneratedLimit accounting, billingArt. 6(1)(b)Account lifetime; daily statistics 730 days
Account timestamps, session versionGeneratedSecurity, session revocationArt. 6(1)(b); legitimate interest in security — Art. 6(1)(f)Account lifetime
Session token (JWT)GeneratedKeeping you signed inArt. 6(1)(b)24 hours
IP address at sign-in/registrationGeneratedRate limiting, brute-force protectionArt. 6(1)(f)As a transient attempt counter only: 15 minutes for sign-in, 60 minutes for registration. The IP address is not written to our databases
Infrastructure logs (IP, request headers, time)CloudflareSecurity, attack mitigation, incident investigationArt. 6(1)(f)We have configured no log export of our own (Logpush is off) and keep no copies. Cloudflare keeps platform-level logs under its own policy; we do not control them
Payment records: amount, currency, exchange rate, status, masked card number (first 6 / last 4 digits), invoice IDYou; payment providerBilling, refunds, accounting and taxArt. 6(1)(b); legal obligation — Art. 6(1)(c)3 years after the end of the payment year
Consent records: which documents and versions, when, where accepted or withdrawnYou (action)Demonstrating acceptance/consent — Art. 7(1)Art. 6(1)(c), (f)Account lifetime + 3 years
Support correspondenceYouRespondingArt. 6(1)(b), (f)3 years
Editor assistant and help-search queriesYouGenerating the answerArt. 6(1)(b)Not stored separately from the session

We never receive or store the full card number — the payment provider processes it and returns only a masked number.

Usage metrics (Cloudflare Analytics Engine) contain the account ID, flow and step IDs, statuses, durations and counts. No data content.

We do not collect: data from other websites, advertising profiles, precise geolocation.

3. Cookies and local storage

We store in your browser only: the session token (sign-in, 24 hours), interface language and theme. All are strictly necessary for the platform (Article 5(3) of Directive 2002/58/EC exemption). No advertising, analytics or tracking cookies, so no consent banner is shown. If we introduce non-essential cookies we will ask for consent first.

Sites our users publish on *.sites.oxta.io are their sites; they are responsible for cookies there.

4. Recipients

RecipientRoleDataCountryTransfer basis
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USAProcessor: hosting, databases, storage, compute, AI models, securityAll platform dataUSA; global networkCloudflare Data Processing Addendum with EU Standard Contractual Clauses; Cloudflare's EU-U.S. Data Privacy Framework certification
Universal Bank JSC (Monobank), UkraineIndependent controller for payment data; payment service providerAmount, currency, invoice ID; card data goes directly from you to the bankUkraineContract performance
Public authorities, courtsOn lawful requestLegal obligation

We do not sell personal data or share it for third-party marketing. Services you connect to flows (Telegram, Slack, Google, your SMTP, your database, your AI provider) receive data on your instruction and are not our recipients — see the DPA.

5. Transfers outside the EEA and Ukraine

5.1. For persons in the EU/EEA. We are located in Ukraine, for which there is no European Commission adequacy decision. Transfer of your data to us is based on necessity for the performance of the contract with you (Article 49(1)(b) GDPR) — the service cannot be provided without us processing your data. Onward processing at Cloudflare relies on the SCCs in our contract with Cloudflare. We apply the safeguards in Section 7 regardless of processing location.

5.2. For persons in Ukraine. Transfer to Cloudflare (USA) is made under Article 29 of the Law of Ukraine "On Personal Data Protection" on the basis of contractual data-protection guarantees provided by Cloudflare.

5.3. Cloudflare is a global network; data may be processed in data centres in various countries. We have not configured any regional restriction on processing.

6. Automated decision-making

We make no decisions about you based solely on automated processing that have legal or similarly significant effects (Article 22 GDPR). IP-based sign-in rate limiting is a technical security measure, not such a decision.

7. How we protect data

Passwords are stored only as salted scrypt hashes. External-service credentials are encrypted with AES-GCM under a dedicated key with a random IV per record. Secrets are automatically redacted from run history. Every request checks that the data belongs to the account. HTTPS only. Sign-in rate limiting. One-click revocation of all sessions. Data at rest is protected by Cloudflare's infrastructure encryption.

Candidly, what we do not have: two-factor authentication; separate encryption of run content under our own key; a log of staff access to production data; ISO 27001 / SOC 2 certification. We will update this Section when that changes.

8. Retention and deletion

Periods are in the Section 2 table. Account deletion is available in settings; it removes all your data and Customer Data, except payment and consent records retained for the stated periods on the basis of legal obligation and defence against claims. Final destruction in infrastructure backups — within 30 days.

9. Your rights

9.1. You have the right of access and to a copy; rectification; erasure; restriction; portability in a machine-readable format; objection to processing based on legitimate interest; and to withdraw consent where processing relies on it, without affecting prior processing (Articles 15–21 GDPR; Article 8 of the Ukrainian Law).

9.2. Most data can be viewed and changed in settings; account deletion is there too. For other requests write to privacy@oxta.io from the account e-mail. We respond within one month; for complex requests this may be extended by two further months with reasons (Article 12(3) GDPR). We may ask you to confirm access to the account e-mail to verify identity.

9.3. Requests are free unless manifestly unfounded or excessive.

9.4. Complaints. You may lodge a complaint with a supervisory authority: in Ukraine — the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua); in the EU — the authority of your habitual residence, place of work or place of the alleged infringement (list: edpb.europa.eu). We would appreciate the chance to resolve matters directly first.

9.5. If you are a customer of our user (a store's shopper, the recipient of a message sent via Oxta), that user is the controller. Contact them. If a request reaches us we forward it to the user within 5 business days if identifiable and inform you; we cannot resolve it ourselves without the controller's instruction.

10. Children

The platform is not directed at persons under 18. If we learn of such an account we will delete it.

11. Changes

Material changes are notified by e-mail at least 30 days ahead; on your next sign-in the platform will ask you to accept the new version. Version archive: oxta.io/legal/archive.

12. Language

Made in Ukrainian; the English version is a convenience translation.

Contacts: ТОВ «Окста» · privacy@oxta.io