Privacy notice
What personal data Ohmix processes, why, on what legal basis, who receives it, how long we keep it, and what you can ask us to do about it. Written under Articles 13 and 14 of the EU GDPR, and written to be read.
Version 2 · Last updated 13 Aug 2026 · privacy@ohmix.eu
Not yet in force. The controller's registered name, registered office, company (REA) number and VAT number must be filled in before this notice is published as final. They are marked like this below. This draft has not been reviewed by a data protection lawyer.
Two roles, two documents. For the account and billing data of the people who use Ohmix, we are the controller and this notice applies. For the manuals, cases and vehicle data an organisation puts into its workspace, that organisation is the controller and we are its processor — that relationship is governed by the Data Processing Agreement, which also lists every sub-processor and where each one is located.
Who is responsible
The controller is registered company name, registered office registered office address, Italy, REA REA number, VAT VAT number.
Contact for anything in this notice: privacy@ohmix.eu. We have not appointed a Data Protection Officer; we are not a public authority, our core activity is not large-scale monitoring, and we do not process special categories of data at scale. If that changes, we will appoint one and name them here.
What we process, and why
| Data | Where it comes from | Why | Legal basis |
|---|---|---|---|
| Account — work email, name, interface language, organisation role | You, when you register or are invited | To create and run your account and to apply your permissions | Performance of a contract, Art. 6(1)(b) |
| Sign-in — email, password (stored hashed, never in clear), sign-in and recovery timestamps | You | To authenticate you and to send sign-in and password-recovery links | Performance of a contract, Art. 6(1)(b) |
| Organisation — legal and trading name, address, VAT number, phone, website, primary and billing contact | You, during onboarding | To identify the contracting party and to invoice | Contract, Art. 6(1)(b); legal obligation for invoicing, Art. 6(1)(c) |
| Enquiry — name, email, company, role, country, the brands and documentation you tell us about | You, if you contact us or ask for a pilot | To answer you and take pre-contract steps | Contract / pre-contract steps, Art. 6(1)(b) |
| Usage — which member ran which job, when, and how much of an allowance it consumed | Generated by the Service | To enforce allowances, to bill correctly, and to show you what you have used | Contract, Art. 6(1)(b) |
| Audit — who did what and when: uploads, approvals, document opens, role changes, deletions | Generated by the Service | Accountability, security, and the traceability a warranty-grade record needs | Legitimate interests, Art. 6(1)(f) |
| Billing — subscription status, period, payment references | Our payment provider | To take payment and keep accounting records | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Support — what you write to us | You | To help you | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) |
Where we rely on legitimate interests, the interest is running a secure and accountable service, and we have balanced it against your rights: the data is limited to what the purpose needs, it is not combined into profiles, and you can object at any time (see below).
Card details never reach us. Payment is taken by our payment provider on its own systems. We receive the fact of payment and a reference, not your card number.
What we do not do
- We do not sell personal data, and we do not share it for advertising.
- We run no advertising or analytics trackers on this website. The site's Content Security Policy permits scripts only from ohmix.eu itself, so a third-party tracker could not load even if one were added by mistake.
- Our own application code does not record your IP address. Our hosting and database providers keep short-lived infrastructure logs, which is normal and necessary to run and secure a service.
- We make no decision about you by automated means that produces a legal or similarly significant effect. The AI in Ohmix analyses vehicles and documents, not people.
- We do not use your data, or your organisation's documents and cases, to train artificial-intelligence models.
Who receives it
Our staff, on a need-to-know basis, and the service providers who make the platform work — hosting, database and storage, transactional email, payment processing, and the AI services that produce answers from your documents.
Every one of them is named, with its role, its location and the basis for any transfer outside the EEA, in the sub-processor register. That register is the single place we keep this list, so it cannot drift out of step between two pages.
We may also disclose data where the law requires it, or to establish or defend a legal claim. Where we are lawfully able to tell you first, we will.
Where it is processed
The database, file storage and the application's server-side functions all run in the European Union — Ireland (AWS eu-west-1). Some of our providers are established outside the EEA, or use support staff outside it. Where that involves a transfer, it is covered by the European Commission's Standard Contractual Clauses together with the additional measures described in the Data Processing Agreement, or by an adequacy decision where one applies.
How long we keep it
| Data | Kept | Why that long |
|---|---|---|
| Account and organisation data | While the account exists. Deleted on request, with no waiting period. | You should not have to wait to leave |
| Enquiries that do not become accounts | 12 months | Long enough to pick up a conversation, not indefinite |
| Usage records | While needed to bill and to show your history, then with the accounting records they support | They are the basis of an invoice |
| Audit records | Retained after account deletion, reduced to actor, action and time | Accountability and traceability, which lose their value if they can be erased |
| Invoices and accounting records | 10 years | Required of company accounting records under Italian law (art. 2220 of the Civil Code) |
| Security and infrastructure logs | Short-lived, per our providers' standard retention | Detecting and investigating incidents |
Your organisation's documents and case data follow a different rule, because your organisation controls them: see section 17 of the terms and the Data Processing Agreement. In short, they stay while you leave them with us and are deleted on request without a waiting period.
Your rights
You can ask us to: give you a copy of your data (access); correct it; delete it; restrict how we use it; give it to you or another provider in a portable form; or stop processing it where we rely on legitimate interests (objection). Where we rely on consent, you can withdraw it at any time without affecting what we did before.
Write to privacy@ohmix.eu. We answer within one month and will tell you if we need longer, which we may for a complex request. We do not charge for this unless a request is manifestly unfounded or excessive.
If you work for an organisation that uses Ohmix and your request concerns the manuals, cases or vehicle records inside its workspace, we will pass it to that organisation, because it is the controller for that data and we may not act on it without instruction.
You may complain to a supervisory authority. Ours is the Italian Garante per la protezione dei dati personali (garanteprivacy.it); you may also complain to the authority where you live or work.
Cookies and local storage
We use no advertising, analytics or tracking cookies, so there is no consent banner to click — there is nothing to consent to.
The application stores only what it needs to work: your sign-in session, your light/dark preference, and your chosen interface language. These are strictly necessary and are kept on your own device. Clearing your browser storage signs you out and resets those preferences.
Security
Encryption in transit (TLS, with HSTS), encryption at rest through our infrastructure providers, row-level isolation between organisations enforced in the database rather than only in the interface, private file storage reachable only through short-lived signed links, and an append-only audit trail. The Trust centre describes this in detail, including what we have not certified.
If a personal data breach occurs and it is likely to result in a risk to people's rights, we notify the supervisory authority within 72 hours of becoming aware, and affected individuals where the risk is high. If you are our customer, we tell you without undue delay so you can meet your own obligations.
Changes to this notice
We will update this notice when what we do changes. The version and date at the top always reflect the current text, and for a material change we notify account administrators by email rather than relying on you to notice.