Legal

Data Processing Agreement

The Article 28 GDPR terms on which Ohmix processes your organisation's documents, cases and vehicle data on your instructions. This agreement forms part of the terms of service; accepting those accepts this.

Version 1 · Last updated 13 Aug 2026 · privacy@ohmix.eu

Two things must be completed before this is offered to a customer.

1. Roles

You are the controller of the data your organisation puts into its workspace. We are your processor. In this agreement "we", "us" and "Ohmix" mean registered company name, registered office registered office address, Italy, REA REA number, VAT VAT number.

Separately, we are the controller of the account and billing data of the people who use the Service; that is covered by our privacy notice, not by this agreement.

If the words in this agreement and the words in the terms of service conflict on a data-protection question, this agreement wins.

2. Processing on your instructions

We process your data only on your documented instructions. Your instructions are: this agreement, the terms of service, and the actions your members take in the Service — uploading a manual, opening a case, asking a question, generating a lesson, exporting, deleting.

We will tell you if we believe an instruction breaches the GDPR or other EU or member-state data protection law, and we may suspend that instruction until it is resolved. If we are required by law to process your data otherwise than on your instructions, we will tell you first, unless that law forbids it on important grounds of public interest.

We do not process your data for our own purposes. In particular, we do not use it to train artificial-intelligence models, our own or anyone else's, and we do not use one organisation's data to answer another organisation's question.

3. Confidentiality of personnel

Access is limited to personnel who need it to provide or support the Service. They are bound by confidentiality obligations that survive the end of their engagement, and their access is logged in the same append-only audit trail your own members' actions are logged in.

4. Security

We implement the technical and organisational measures set out in Annex II, which are appropriate to the risk. We may change them as technology and threats change, provided the level of protection is not reduced.

5. Sub-processors

You give us general authorisation to engage the sub-processors listed in Annex III. Each is bound by data protection obligations no less protective than these, and we remain fully liable to you for their performance.

We will give you at least 30 days' notice by email to your organisation's administrators before a new sub-processor starts processing your data. You may object on reasonable data-protection grounds within that period. If we cannot offer you a workable alternative, you may terminate the affected modules without penalty and receive a refund of any fee paid for the period after termination.

6. Data subject requests

If someone contacts us directly about data inside your workspace, we will not respond substantively; we will pass the request to you without undue delay, because you are the controller.

We help you meet your own obligations. In practice most of it you can do yourself: your workspace lets you find, export, correct and delete case and document records directly. Where a request needs something the interface does not offer, ask us and we will assist, taking account of the nature of the processing and the information available to us.

7. Personal data breach

We notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data. The notification describes what we know: the nature of the breach, the categories and approximate number of records concerned, the likely consequences, and the measures taken or proposed. Where we do not yet have the full picture we say so and follow up rather than delaying the first notification.

We assist you with your own notifications to a supervisory authority or to affected individuals.

8. Assistance with impact assessments

We provide reasonable assistance with data protection impact assessments and prior consultations, taking into account the nature of the processing and what is available to us. Annex II is written to be usable directly in one.

9. Information and audit

We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits by you or an auditor you mandate.

Audits are on reasonable notice, no more than once a year unless a breach or a supervisory authority requires otherwise, during business hours, without disrupting the Service, and subject to confidentiality. We will first offer documentation and written answers; an on-site or technical audit follows where those do not answer the question. We hold no ISO 27001 or SOC 2 certification and do not claim one — see the Trust centre.

10. Return and deletion

You can export your data at any time while your workspace is open, and you can delete documents yourself. Deletion removes the stored files as well as the database records; it is refused only while a document is still cited by a report that has not been withdrawn, so that a published report cannot silently lose its evidence.

After the Service ends, we delete your data on request, with no waiting period, and confirm when it is done. If you make no request we keep it available, so that a cancellation made in error does not cost you your library. Two categories survive, and we say so plainly because a deletion commitment that quietly has exceptions is worse than one that names them:

Backups are overwritten on their normal cycle; data deleted from the live system is not restored from a backup other than as part of a whole-system recovery.

11. International transfers

The database, file storage and the application's server-side functions run in the European Union — Ireland (AWS eu-west-1). Your documents are stored in the EU and are not moved out of it for storage.

Some processing sub-processors are established outside the EEA. Where a transfer takes place it is made under the European Commission's Standard Contractual Clauses (Decision 2021/914) with a transfer impact assessment, or under an adequacy decision where one covers the recipient. Annex III states the position for each.

Transfers are of the material needed for the request being processed — the passages retrieved to answer a question, the page being transcribed, the case text being reasoned over — not of your library as a whole, and not on a standing basis.

12. Liability and term

The limitations of liability in the terms of service apply to this agreement. This agreement runs for as long as we process your data and, for the obligations that by their nature must, beyond it.

Annex I — the processing

ItemDetail
Subject matterProvision of the Ohmix diagnostic, documentation-search and training service
DurationFor the term of the subscription, plus the period in section 10
Nature and purposeStorage; indexing and text extraction; retrieval; AI processing to produce cited answers, diagnostic reports and training lessons; transactional email; payment processing
Categories of data subjectYour personnel — technicians, service managers, trainers, administrators. Indirectly, vehicle owners and keepers, where a case identifies a vehicle or repeats what a customer said.
Categories of personal data Identification and contact data of your personnel (name, work email, role).
Case content: vehicle identification number, model, mileage, market, the customer complaint as recorded, fault codes, measurements, technician notes.
Case evidence: photographs, scan-tool reports, audio and video recordings, which may incidentally contain images or voices of identifiable people, registration plates or other identifiers.
Uploaded documentation, which is technical material rather than personal data by design, but may contain author or approver names.
Special categoriesNone is requested, and the Service has no field for one. Do not put health, biometric or other Article 9 data into a case.
FrequencyContinuous, for the duration of the subscription

On vehicle identification numbers. We treat a VIN as personal data. On its own it identifies a vehicle, but a dealer can link it to an owner through its own records, so it is identifiable in your hands and is handled as such throughout — stored inside your workspace, subject to your deletion instructions, and included in an export.

Annex II — technical and organisational measures

These are what the Service actually does, not aspirations. Where something is not in place, it is listed as not in place.

MeasureHow it is implemented
Tenant isolationRow-level security in the database on every customer-data table and on file storage, so isolation is enforced by the database rather than by the interface. A negative isolation test suite runs against a staging replica before schema changes are promoted.
Encryption in transitTLS/HTTPS throughout, HSTS with preload, upgrade-insecure-requests
Encryption at restProvided by the database and object-storage layers of our infrastructure provider
Document accessPrivate storage bucket; documents are never publicly readable and are served only through signed links valid for 15 minutes, to signed-in members of the owning organisation
Access controlPer-person accounts with password or one-time email link sign-in; seven organisation roles; no member can raise their own role; platform staff roles are separate and cannot be self-granted
Restricted documentationUploads for restricted brands are refused server-side unless an authorisation grant is recorded for the organisation; each upload batch additionally requires a recorded, versioned authorisation confirmation from the uploader
AuditabilityAppend-only audit trail covering upload, approval, document open, role change, archive, withdrawal, deletion and grants
Browser hardeningContent Security Policy limiting scripts, styles and network connections to our own origin and our database; all third-party JavaScript is vendored rather than loaded from a CDN; framing denied; camera, microphone, geolocation and payment APIs disabled at the document level
Data minimisation to AI providersOnly the passages and evidence needed for the request are sent, per request; no library is transferred wholesale or held by a provider on a standing basis
Integrity of outputTechnical values are validated against the cited page before reaching a report; unsupported values are withheld; a part replacement is authorised only when a confirming technician measurement is recorded
ResilienceStateless server-side functions; job queues with bounded retries that fail visibly rather than silently; managed database with automated daily physical backups, verified by an operator check that reads the backup series and reports missing days rather than trusting that it ran
Backup and recovery The database is backed up daily and roughly a week of daily backups is retained. Point-in-time recovery is not enabled, so a database restore recovers to the last nightly backup and can lose up to 24 hours of work.
Your uploaded source documents are held in object storage, which is a separate subsystem and is not covered by those database backups. We state this because it is the part most easily assumed: enabling point-in-time recovery on the database would not extend to your documents. Keep your own copies of anything you could not obtain again.
Most of the database — the search index, page geometry and term index, together about 99% of its size — is derived from those source documents and would be rebuilt rather than restored. What cannot be reconstructed from anywhere else is the account, case, report and lesson layer, and the audit trail.
Not in placeNo ISO 27001 or SOC 2 certification. No independent penetration test yet. Point-in-time recovery is not enabled (see above). No contractual uptime or incident-response SLA. These are stated so that you can assess them rather than discover them.

Annex III — sub-processor register

Everyone we use to process your data, what each one does, and what it receives. This is the single authoritative list; other pages link here rather than repeating it.

Sub-processorFunctionData it receivesProcessing location
Supabase Database, authentication and file storage All workspace data and account data Ireland (EU). Corporate group outside the EEA; SCCs.
Netlify Website hosting and server-side functions Data in transit through the application; no customer data stored Functions run in Ireland (EU). Corporate group outside the EEA; SCCs.
OpenAI Document indexing (embeddings), page and diagram transcription, audio transcription, fact extraction, report translation Document passages and page images; case evidence including photographs and audio Outside the EEA; SCCs.
DeepSeek Reasoning that produces answers, diagnostic reports and training lessons Retrieved document passages and case text, which can include the vehicle identification number and the recorded complaint Outside the EEA, in a country without an adequacy decision; SCCs with a transfer impact assessment.
Google Image and video understanding of case evidence and diagrams Case photographs and video clips; diagram images Outside the EEA; SCCs.
Mistral AI Optical character recognition of scanned pages and case documents Page and document images France (EU). No transfer outside the EEA.
Cohere Reranking of search results before an answer is composed The question asked and candidate document passages Outside the EEA; adequacy decision or SCCs as applicable to the contracting entity.
Resend Transactional email — sign-in links, password recovery, team invitations Email address and the message itself Outside the EEA; SCCs.
Stripe Payment processing and subscription billing Billing contact and payment details, taken on Stripe's own systems Ireland (EU) for EEA customers, with onward transfer under SCCs.

Available in the software, not engaged

One further integration exists in our code and is switched off. We list it because an undisclosed capability is how a register goes out of date: the day someone supplies the credential it would begin processing, and you are entitled to know in advance rather than afterwards.

ProviderWhat it would doStatus
Anthropic An independent second-opinion review of a completed diagnostic report on escalated cases. It would receive the case text and the retrieved manual excerpts. Not engaged. No credential is configured, so the path returns "inactive" and no data leaves. Engaging it would be a new sub-processor and would require the 30 days' notice under section 5 first.

Every engaged provider above is under its own data-processing terms, on API tiers whose terms exclude training models with submitted data. The specific contracting entity and the version of each addendum are recorded internally and available on request under section 9 — see the note at the top of this page for the items still to be recorded.

Changes to this register are notified under section 5. The date at the top of this page changes whenever the register does.