Privacy Policy
Last updated: 14 February 2026
This privacy policy explains how OLOXA ("we", "us", "our") collects, uses, and protects your personal data when you use our website and services, including the SOP Builder tool at sopbuilder.oloxa.ai.
We take your privacy seriously and process your data in accordance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and the German Telecommunications-Digital Services Data Protection Act (TDDDG).
1. Controller
The data controller responsible for processing your personal data is:
OLOXA Sway Clarke Berlin, Germany Email: hello@oloxa.ai Website: oloxa.ai
2. What Data We Collect
2.1 SOP Builder Submissions
When you use the SOP Builder, we collect the data you provide in the form:
Name and email address - to send you your SOP analysis
Goal, department, improvement type, end user - to generate a relevant analysis
Process steps (text or audio) - the content you submit for analysis
2.2 Audio Uploads
If you upload an audio recording, the file is temporarily stored in Google Drive for transcription via OpenAI Whisper. Once transcribed, the audio file is retained for processing purposes only.
2.3 Server Logs
Our servers automatically collect standard access logs (IP address, browser type, timestamp, requested URL). These logs are used for security and troubleshooting and are deleted after 30 days.
3. How We Use Your Data
PurposeData UsedLegal BasisGenerate your SOP analysis and send it to you by emailName, email, process content, form selectionsConsent (Art. 6(1)(a) GDPR)Transcribe audio uploadsAudio fileConsent (Art. 6(1)(a) GDPR)Store your submission for guided resubmission (score improvement)Name, email, SOP analysis, scoresConsent (Art. 6(1)(a) GDPR)Lead management (CRM)Name, email, department, score, timestampsLegitimate interest (Art. 6(1)(f) GDPR)Server security and troubleshootingIP address, browser info, timestampsLegitimate interest (Art. 6(1)(f) GDPR)
For lead management, our legitimate interest is maintaining contact with people who have used our free tools, so we can inform them about relevant services. You can object to this processing at any time (see Section 7).
4. Third-Party Processors
We use the following third-party services to process your data. All processors have been selected for GDPR compliance and are bound by data processing agreements:
ServicePurposeLocationOpenAI (OpenAI, LLC)AI analysis of your SOP content (GPT-4o-mini) and audio transcription (Whisper)USA*Google Workspace (Google Ireland Ltd)Sending analysis emails (Gmail) and temporary audio storage (Google Drive)EU / USA*Airtable (Formagrid Inc)Storing submission records and lead dataUSA*DigitalOcean (DigitalOcean, LLC)Hosting our workflow automation serverEU (Frankfurt)
*Transfers to the USA: Where data is transferred to the United States, these transfers are protected by the EU-U.S. Data Privacy Framework (adequacy decision adopted by the European Commission on 10 July 2023) and/or Standard Contractual Clauses (SCCs) as appropriate. You can request a copy of the relevant safeguards by contacting us.
5. Data Retention
SOP submissions and analysis data: Retained for 12 months from your last submission, then deleted.
Lead/CRM data (name, email, score): Retained until you request deletion or 24 months of inactivity, whichever is sooner.
Audio uploads: Retained for 30 days after transcription, then deleted.
Server logs: Deleted after 30 days.
6. Cookies and Tracking
The SOP Builder does not use cookies, tracking pixels, or analytics tools. We do not track your behaviour across pages or sessions. No data is shared with advertising networks.
7. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
Right of access (Art. 15) - Request a copy of your personal data we hold.
Right to rectification (Art. 16) - Correct inaccurate or incomplete data.
Right to erasure (Art. 17) - Request deletion of your data ("right to be forgotten").
Right to restriction (Art. 18) - Restrict how we process your data.
Right to data portability (Art. 20) - Receive your data in a structured, machine-readable format.
Right to object (Art. 21) - Object to processing based on legitimate interest, including for direct marketing.
Right to withdraw consent (Art. 7(3)) - Withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, email us at hello@oloxa.ai. We will respond within 30 days.
8. Right to Lodge a Complaint
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The relevant authority for Berlin is:
Berliner Beauftragte fur Datenschutz und Informationsfreiheit Friedrichstr. 219 10969 Berlin, Germany Phone: +49 30 13889-0 Website: datenschutz-berlin.de
9. Automated Decision-Making
The SOP Builder uses AI (OpenAI GPT-4o-mini) to analyse and score your submitted process. This produces an automated score and improvement suggestions. This analysis is provided as a helpful tool only and does not produce legal or similarly significant effects. You are free to disregard the results. No decisions with legal consequences are made solely on the basis of automated processing.
10. Children's Data
Our services are not directed at children under the age of 16. We do not knowingly collect data from children. If you believe a child has submitted data through our tool, please contact us and we will delete it promptly.
11. Changes to This Policy
We may update this privacy policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. We encourage you to review this page periodically.
12. Contact
For any questions about this privacy policy or your personal data, contact:
Sway Clarke OLOXA Email: hello@oloxa.ai
