Skip to content
Keyboard shortcuts: alt + m toggle mobile navigation menu, alt + n focus main navigation, alt + c jump to main content, alt + s open site search, alt + ? open this shortcuts help.

Legal

Privacy policy

Information under Art. 13 GDPR about how OXORY processes personal data and how you can exercise your rights.

1. Controller

OXORY AS.DS GmbH
Koblenzer Str. 89
50968 Cologne, Germany
Managing Director: Cahit Temizkan
Phone: +49 221 500 598 12
Email: info@oxory.net

Further company information is available in our Legal Notice.

2. Processing activities

a) Website delivery and server logs

Data categories: IP address, browser information, requested page and timestamp.

Purpose: Secure and reliable website delivery, operation and troubleshooting.

Legal basis: Art. 6(1)(f) GDPR (our legitimate interests in secure website operation).

Retention: Rolling retention by the hosting provider.

Recipients: Lovable and Cloudflare.

b) Contact, enquiry and booking forms

Forms covered: General enquiries, PIPO migration enquiries, SAP connection enquiries and slot-booking forms.

Data categories: Name, email address, optional company and message.

Purpose: Handling your enquiry, preparing or performing requested pre-contractual steps and related follow-up.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(f) GDPR (efficient enquiry handling and follow-up).

Retention: Deleted when no longer needed for the enquiry and related follow-up, unless statutory retention obligations apply.

Recipients: Enquiries are stored as support tickets in our database and emailed to info@oxory.net; recipients are Supabase and Google (Gmail / Google Workspace).

d) Performance and conversion measurement

Data categories: Core Web Vitals and first-party conversion events, including CTA clicks, form start, submit, success and error events, element views and deep-link events, together with the page path and campaign UTM parameters from the landing URL. No names, email addresses or message text are collected for this purpose.

Purpose: Measuring website performance and understanding whether site journeys and forms work as intended.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG; processing occurs only with analytics consent.

Retention: UTM parameters are stored in session storage for the current visit. No fixed retention period is stated here for server-side measurement data.

Recipients: Processed on our own servers; no third-party analytics tool is used.

You can withdraw consent at any time with effect for the future using .

e) Marketing category

Data categories: Data set by a marketing cookie or pixel, if such a service is activated after consent.

Purpose: Marketing measurement for a service disclosed in the consent settings.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG.

Retention: Determined by the activated service and disclosed before use; marketing cookies or pixels do not load before consent.

Recipients: Only the provider of an activated marketing service disclosed in the consent settings.

f) Outlook Bookings calendar (Microsoft)

Data categories: When loaded: IP address and browser data; when booking: the booking details you provide.

Purpose: Displaying the external calendar and arranging a requested meeting.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG for loading the calendar; Art. 6(1)(b) GDPR for booking data.

Retention: Microsoft determines retention within Outlook Bookings / Microsoft 365; OXORY retains booking information only as needed for arranging and following up the meeting, subject to statutory retention obligations.

Recipients: Microsoft; processing may involve a transfer to the USA.

The calendar loads only after you click “Load booking calendar” or opt in to always load external calendars. The direct link opens Microsoft in a new tab without loading the calendar on this site.

g) AI chat assistant

Data categories: For the required user account: name, company, email and password hash. For chat use: messages, replies, start page, browser language, hashed IP, device type and country.

Purpose: Providing the account and chat, responding to questions, internal follow-up and misuse detection.

Legal basis: Art. 6(1)(b) GDPR (account and use) and Art. 6(1)(f) GDPR (misuse detection).

Retention: The full conversation is deleted automatically 90 days after the last message. An anonymised statistic consisting of date, device type and country is retained for up to 12 months.

Recipients: Supabase for user accounts and storage; Anthropic (Claude), USA, as AI processor; transcripts are also emailed to info@oxory.net through Google.

You are chatting with an AI assistant. Answers may be inaccurate. Please do not enter sensitive personal data. There is no automated decision-making within the meaning of Art. 22 GDPR.

h) Newsletter

Data categories: Email address, consent and double opt-in confirmation.

Purpose: Sending the newsletter requested by you and documenting consent.

Legal basis: Art. 6(1)(a) GDPR.

Retention: Stored until you unsubscribe; consent proof is kept as long as needed to demonstrate consent.

Recipients: Supabase and Google (Gmail / Google Workspace).

You can unsubscribe at any time through the link in every email.

i) Gated downloads

Data categories: Email address, optional company, consent text and timestamp.

Purpose: Sending the requested whitepaper or case study and related follow-up.

Legal basis: Art. 6(1)(a) GDPR.

Retention: Until consent is withdrawn or the data is no longer needed for the stated purpose, unless statutory retention obligations apply.

Recipients: Supabase and Google (Gmail / Google Workspace).

Withdraw consent at any time by emailing info@oxory.net.

j) WhatsApp link

Data categories: No data is sent by this website before you click. After clicking, WhatsApp may process connection and communication data.

Purpose: Opening a conversation requested by you.

Legal basis: Your voluntary action in opening the external service; subsequent processing is governed by WhatsApp's own privacy policy.

Retention: OXORY does not set retention for data processed by WhatsApp / Meta.

Recipients: WhatsApp / Meta only after you click the “Chat per WhatsApp” link to wa.me.

k) Self-hosted fonts

Data categories: No personal data is transmitted to a font provider.

Purpose: Consistent display of this website.

Legal basis: Art. 6(1)(f) GDPR (consistent and privacy-friendly website presentation).

Retention: Only normal browser caching applies.

Recipients: No Google Fonts connection and no external font recipient.

3. Recipients and processors

We do not sell personal data. Depending on the service you use, the following recipients or processors may receive data:

ProviderRole
LovableWebsite platform and hosting
CloudflareContent delivery and security
SupabaseDatabase and user accounts
AnthropicAI chat processing
GoogleGmail / Google Workspace email sending
MicrosoftOutlook Bookings / Microsoft 365

4. Third-country transfers

Some providers process data in the USA. Transfers are based on the EU–US Data Privacy Framework where the provider is certified; otherwise, they are based on EU Standard Contractual Clauses under Art. 46(2)(c) GDPR.

5. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and withdrawal of consent with effect for the future (Art. 7(3)). Contact info@oxory.net to exercise your rights.

Right to object (Art. 21 GDPR)

You may object at any time to processing based on Art. 6(1)(f) GDPR. Contact info@oxory.net.

You can also withdraw cookie consent at any time using .

6. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Kavalleriestr. 2–4, 40213 Düsseldorf, Germany.

7. Obligation to provide data

Providing personal data is voluntary. Without the required fields, however, we cannot answer an enquiry or create a chat account.

8. Automated decision-making and profiling

We do not use automated decision-making or profiling within the meaning of Art. 22 GDPR.

9. Data security

We protect personal data through TLS encryption, security headers and access restrictions.

10. Changes to this policy

We may update this policy when our services, processing activities or legal requirements change. The current version is always available on this page.

Last updated: October 2026.

Chat with OXORY

Ask our assistant about SAP and IT staffing, consulting or AMS — or continue on WhatsApp.

Chat per WhatsApp?