Legal

Privacy notice

What personal data Ohmix processes, why, on what legal basis, who receives it, how long we keep it, and what you can ask us to do about it. Written under Articles 13 and 14 of the EU GDPR, and written to be read.

Version 2 · Last updated 13 Aug 2026 · privacy@ohmix.eu

Not yet in force. The controller's registered name, registered office, company (REA) number and VAT number must be filled in before this notice is published as final. They are marked like this below. This draft has not been reviewed by a data protection lawyer.

Two roles, two documents. For the account and billing data of the people who use Ohmix, we are the controller and this notice applies. For the manuals, cases and vehicle data an organisation puts into its workspace, that organisation is the controller and we are its processor — that relationship is governed by the Data Processing Agreement, which also lists every sub-processor and where each one is located.

Who is responsible

The controller is registered company name, registered office registered office address, Italy, REA REA number, VAT VAT number.

Contact for anything in this notice: privacy@ohmix.eu. We have not appointed a Data Protection Officer; we are not a public authority, our core activity is not large-scale monitoring, and we do not process special categories of data at scale. If that changes, we will appoint one and name them here.

What we process, and why

DataWhere it comes fromWhyLegal basis
Account — work email, name, interface language, organisation role You, when you register or are invited To create and run your account and to apply your permissions Performance of a contract, Art. 6(1)(b)
Sign-in — email, password (stored hashed, never in clear), sign-in and recovery timestamps You To authenticate you and to send sign-in and password-recovery links Performance of a contract, Art. 6(1)(b)
Organisation — legal and trading name, address, VAT number, phone, website, primary and billing contact You, during onboarding To identify the contracting party and to invoice Contract, Art. 6(1)(b); legal obligation for invoicing, Art. 6(1)(c)
Enquiry — name, email, company, role, country, the brands and documentation you tell us about You, if you contact us or ask for a pilot To answer you and take pre-contract steps Contract / pre-contract steps, Art. 6(1)(b)
Usage — which member ran which job, when, and how much of an allowance it consumed Generated by the Service To enforce allowances, to bill correctly, and to show you what you have used Contract, Art. 6(1)(b)
Audit — who did what and when: uploads, approvals, document opens, role changes, deletions Generated by the Service Accountability, security, and the traceability a warranty-grade record needs Legitimate interests, Art. 6(1)(f)
Billing — subscription status, period, payment references Our payment provider To take payment and keep accounting records Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c)
Support — what you write to us You To help you Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f)

Where we rely on legitimate interests, the interest is running a secure and accountable service, and we have balanced it against your rights: the data is limited to what the purpose needs, it is not combined into profiles, and you can object at any time (see below).

Card details never reach us. Payment is taken by our payment provider on its own systems. We receive the fact of payment and a reference, not your card number.

What we do not do

Who receives it

Our staff, on a need-to-know basis, and the service providers who make the platform work — hosting, database and storage, transactional email, payment processing, and the AI services that produce answers from your documents.

Every one of them is named, with its role, its location and the basis for any transfer outside the EEA, in the sub-processor register. That register is the single place we keep this list, so it cannot drift out of step between two pages.

We may also disclose data where the law requires it, or to establish or defend a legal claim. Where we are lawfully able to tell you first, we will.

Where it is processed

The database, file storage and the application's server-side functions all run in the European Union — Ireland (AWS eu-west-1). Some of our providers are established outside the EEA, or use support staff outside it. Where that involves a transfer, it is covered by the European Commission's Standard Contractual Clauses together with the additional measures described in the Data Processing Agreement, or by an adequacy decision where one applies.

How long we keep it

DataKeptWhy that long
Account and organisation dataWhile the account exists. Deleted on request, with no waiting period.You should not have to wait to leave
Enquiries that do not become accounts12 monthsLong enough to pick up a conversation, not indefinite
Usage recordsWhile needed to bill and to show your history, then with the accounting records they supportThey are the basis of an invoice
Audit recordsRetained after account deletion, reduced to actor, action and timeAccountability and traceability, which lose their value if they can be erased
Invoices and accounting records10 yearsRequired of company accounting records under Italian law (art. 2220 of the Civil Code)
Security and infrastructure logsShort-lived, per our providers' standard retentionDetecting and investigating incidents

Your organisation's documents and case data follow a different rule, because your organisation controls them: see section 17 of the terms and the Data Processing Agreement. In short, they stay while you leave them with us and are deleted on request without a waiting period.

Your rights

You can ask us to: give you a copy of your data (access); correct it; delete it; restrict how we use it; give it to you or another provider in a portable form; or stop processing it where we rely on legitimate interests (objection). Where we rely on consent, you can withdraw it at any time without affecting what we did before.

Write to privacy@ohmix.eu. We answer within one month and will tell you if we need longer, which we may for a complex request. We do not charge for this unless a request is manifestly unfounded or excessive.

If you work for an organisation that uses Ohmix and your request concerns the manuals, cases or vehicle records inside its workspace, we will pass it to that organisation, because it is the controller for that data and we may not act on it without instruction.

You may complain to a supervisory authority. Ours is the Italian Garante per la protezione dei dati personali (garanteprivacy.it); you may also complain to the authority where you live or work.

Cookies and local storage

We use no advertising, analytics or tracking cookies, so there is no consent banner to click — there is nothing to consent to.

The application stores only what it needs to work: your sign-in session, your light/dark preference, and your chosen interface language. These are strictly necessary and are kept on your own device. Clearing your browser storage signs you out and resets those preferences.

Security

Encryption in transit (TLS, with HSTS), encryption at rest through our infrastructure providers, row-level isolation between organisations enforced in the database rather than only in the interface, private file storage reachable only through short-lived signed links, and an append-only audit trail. The Trust centre describes this in detail, including what we have not certified.

If a personal data breach occurs and it is likely to result in a risk to people's rights, we notify the supervisory authority within 72 hours of becoming aware, and affected individuals where the risk is high. If you are our customer, we tell you without undue delay so you can meet your own obligations.

Changes to this notice

We will update this notice when what we do changes. The version and date at the top always reflect the current text, and for a material change we notify account administrators by email rather than relying on you to notice.