1.Who we are
Oxelis, [legal form, address and company number to be filled in], is the controller for the data we process about you as a user. You can reach us at support@oxelis.be.
For the prospect data you enter or gather in Oxelis you are the controller and we are the processor; see the section Role in prospect data.
2.Which data we process
We process the following categories of data:
- Account data: name, email address, password (as a hash only) or Google login, preferences, time of sign-up and last login.
- Organization data: the name of your organization, members and their roles, invitations, plan and subscription status, settings, API keys (as a hash only) and webhooks.
- LinkedIn profile data: when connecting through LinkedIn OAuth we receive your name, profile picture, member ID and an access token to publish posts. With an outreach connection we also process your connections, invitations and messages, so the AI envoy can work on your behalf.
- Content: your ideas, drafts, posts, the sources you connect yourself (such as RSS, GitHub or Notion) and the statistics of your publications.
- Prospect data: name, job title, company, LinkedIn profile and notes of the people you approach, entered by you, imported or found through the prospect search.
- Conversations: the messages the AI envoy sends and receives on your behalf, and the qualification that follows from them.
- Usage data and logs: IP address, browser, timestamps, error messages, an audit log of important actions (logging in, members, keys, plan changes) and the AI usage per organization.
- Payment data: your billing details, VAT number and payment history at Stripe. Card numbers never reach us; Stripe processes them directly.
3.Purposes and legal bases
We process your data for these purposes, each with its legal basis under the GDPR:
- Delivering the Service: making your account, organization, content studio, AI envoy and connections work. Legal basis: performance of the contract.
- Billing and accounting: processing payments and keeping invoices. Legal basis: contract and legal obligation.
- Security and abuse prevention: rate limiting, audit log and debugging. Legal basis: legitimate interest.
- Communication about the Service: confirmation emails, reminders about your trial, warnings when a connection drops out and changes to the terms. Legal basis: contract and legitimate interest.
- Improving the Service: aggregated usage statistics, without profiling individual users. Legal basis: legitimate interest.
- We only send marketing emails with your consent; you can unsubscribe at any time through the link in the email.
4.AI processing
Oxelis uses language models from Anthropic (United States) for the weekly briefing, writing help, brainstorming, prospect qualification and the messages of the AI envoy. For that we send the relevant text to Anthropic's API: your voice profile, your sources, the conversation with a prospect and the settings of your agent.
Anthropic is contractually barred from using that data to train models and keeps it only briefly for abuse detection, under its commercial terms. The transfer to the US relies on the European Commission's standard contractual clauses and, where applicable, on the EU-US Data Privacy Framework.
What the AI proposes, you check yourself. Messages from the AI envoy only go out within the rules you set; you can always take over a conversation or pause the agent.
5.Subprocessors
We work with the following subprocessors. With each of them we have a data processing agreement; outside the EU we rely on standard contractual clauses or the EU-US Data Privacy Framework. If we add a subprocessor that processes your data, we tell the owner of your organization beforehand.
| Party | What for | Where |
|---|---|---|
| Supabase | Database, authentication and file storage | EU (Frankfurt) |
| Vercel | Hosting and application logic | US and EU (edge network) |
| Anthropic | AI processing of text; not for training | US |
| Stripe | Payments, invoices and VAT | EU and US |
| Resend | Transactional email | US and EU |
| Unipile | LinkedIn connection for outreach (invitations, messages) | EU |
6.Retention periods
We do not keep data longer than needed:
- Account and organization data, content, prospect data and conversations: for as long as your subscription runs and up to 90 days after it ends; after that we delete it.
- Technical logs (access, errors, rate limiting): 30 days.
- Audit log of important actions: 365 days.
- Invoices and accounting records: the statutory retention period for accounting documents.
- LinkedIn access tokens: until you break the connection or delete your account; then we erase them right away.
- If you delete a post, prospect or conversation yourself, it is gone from the Service; backups are overwritten within 30 days.
7.Security
We secure your data with technical and organizational measures that match the risk. If we discover a data breach that affects your rights, we notify you and, where needed, the supervisory authority within 72 hours. Specifically:
- Encryption in transit (TLS) and at rest; access tokens and integration keys are additionally encrypted with AES-256-GCM.
- Row-level security in the database: every query is limited to your own organization.
- We store passwords and API keys as a hash only; passwords are checked against lists of leaked passwords.
- Rate limiting on logging in, the API and incoming connections.
- Audit log of security-relevant actions, kept for 365 days.
- Need-to-know access: only people doing support or maintenance can reach data, and only when that is necessary.
8.Your rights
Under the GDPR you have these rights over your data:
- Access and export: through Settings → Account you download all your data as JSON.
- Correction: you adjust your account and organization data yourself in the app; what you cannot adjust yourself, we change on request.
- Deletion: the owner can delete the organization through Settings; a member can leave the organization. We then delete all data, except what we have to keep by law.
- Objection and restriction: you can object to processing based on legitimate interest; we then stop, unless we have compelling grounds.
- Portability: the JSON export is meant for taking your data with you.
- Complaint: if you are not happy with how we handle your data, you can lodge a complaint with the Belgian Data Protection Authority (GBA/APD), Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be. We would like to hear it from you first at support@oxelis.be.
10.Role in prospect data
For the prospect data and conversations you process through Oxelis you are the controller: you decide who you approach and why. We are the processor and process that data only on your instructions and according to your settings. On request at support@oxelis.be we enter into a data processing agreement with you.
You take care of a valid legal basis to approach prospects, usually legitimate interest for business contacts, and of respecting their rights. If a prospect asks for deletion, you do that in the app; requests that reach us we forward to you.
Prospects can also come to us directly; we then help them reach the right customer.
11.Changes
We adjust this policy when our processing, our subprocessors or the law change. We report far-reaching changes by email to the owner of your organization. The date at the top shows the latest version.
12.Contact
Questions about your data or this policy? Email support@oxelis.be. We answer within a month, as the GDPR requires.
Oxelis, [legal form, address and company number to be filled in].