Privacy Policy

This Privacy Policy outlines how Oxaar TECHNOLOGIES LTD ("we," "our," or "us"), a company incorporated in England and Wales under Company Registration Number 17268084, collects, uses, stores, and protects personal data under the statutory frameworks of the UK GDPR and the Data Protection Act 2018. Our registered office is located at 66 Paul Street, London, Greater London, England, EC2A 4NA.

We operate as an enterprise Business-to-Business (B2B) Software-as-a-Service (SaaS) provider. We treat data privacy with the highest institutional discipline, aligning all operations under the statutory framework of the UK GDPR and the Data Protection Act 2018.

Structural Scope: Data Controller Vs. Data Processor

  • Oxaar as a Data Controller: We act as a Data Controller for the personal data of our direct corporate clients, platform administrators, prospects, and website visitors (e.g., corporate contact names, business email addresses, billing data, and telemetry logs on oxaar.com).
  • Oxaar as a Data Processor: We act strictly as a Data Processor regarding any customer, end-user, or relational financial data uploaded, managed, or stored by our clients inside our proprietary software modules (such as The Ultimate CRM, Client Portal, or Support Ticketing). Our corporate clients remain the absolute Data Controllers for their respective databases and hold independent liability for establishing their own consumer data permissions.

Categories Of Information We Collect

  • Corporate Account Data: Company legal name, corporate registration numbers, financial license details, primary authorized administrative names, work emails, and corporate telephone connections.
  • Financial & Billing Data: Corporate banking details, corporate credit indicators, transaction logs, and commercial invoice matching fields.
  • Technical & Telemetry Data: Anonymized IP addresses, browser configurations, login timestamps, operating system metadata, and functional platform activity logs.

Legal Bases For Data Processing

  • Contractual Necessity: To provision cloud architectures, establish instances, and validate licenses as requested under commercial service contracts.
  • Legal Obligation: To maintain proper corporate tax files, verify corporate entities against statutory registers, and prevent software infrastructure misuse under UK corporate law.
  • Legitimate Interests: To optimize application infrastructure performance, secure network perimeters against unauthorized penetration, and coordinate standard B2B client service management workflows.

Data Storage, Retention, And Server Locations

All core infrastructure data, database systems, and enterprise assets are hosted on secure, isolated cloud servers located within premium, high-security data centers inside the United Kingdom and the European Economic Area (EEA). We retain corporate account history data only for as long as necessary to satisfy explicit statutory UK accounting rules (typically up to six [6] fiscal years following the formal termination of an agreement).

Information Security Controls

We employ rigorous electronic, physical, and administrative protection systems engineered to prevent data leaks, unauthorized access, or loss. These layers include mandatory Advanced Encryption Standards (AES-256) for data at rest and transport-layer protection (TLS/SSL) for all browser connections to the CRM and Portal interfaces.

Statutory Rights Under UK GDPR

Authorized corporate representatives holding active profiles within our systems possess the right to request transparent disclosure regarding what personal account parameters we hold, the right to demand instant rectification of erroneous registry items, the right to request data erasure where tracking is no longer contractually required, and the right to lodge an inquiry or formal concern directly with the Information Commissioner's Office (ICO), the primary supervisory authority for data protection in the United Kingdom.