HomeDemoSEO vs GEOCustomersPricingCompanyContact

Privacy Policy

AI Optimiser is a product of Oxira LLC.

This privacy policy applies to the AI Optimiser platform and all related services provided by Oxira LLC.

Your privacy is important to us. This policy explains how we collect, use, and protect your information.

Privacy Policy — AI Optimiser (by Oxira LLC)

Last updated: January 18, 2026
Contact (privacy): mail@oxira.onePrivacy Policy explains in detail how AI Optimiser, operated by Oxira LLC ("Oxira", "we", "us", "our") collects, uses, discloses, stores, and protects personal data in connection with our AI visibility platform and services, including: (i) AI entity modeling and identity building, (ii) knowledge space creation and structuring, (iii) source anchoring and placement, (iv) AI perception monitoring and analytics, and (v) related consulting and support services (collectively, the "Services"). It also explains your privacy rights and how to exercise them.

privacy.policyIntro

This Policy is intended to meet the requirements of the EU/EEA GDPR, UK GDPR, Swiss law, US state privacy laws (e.g., CCPA/CPRA), Brazil LGPD, Canada PIPEDA, and other applicable laws. Where jurisdictions differ, we apply the higher standard where commercially reasonable. If anything here conflicts with mandatory local law, local law prevails.

1) Controller, Representatives, and DPO

Data Controller: Oxira LLC (operating as AI Optimiser)
General contact: mail@oxira.one
Privacy/DPO contact: mail@oxira.one. When we provide Services on behalf of business clients (e.g., building AI entity profiles and knowledge spaces), we typically act as a processor/service provider and the client is the controller/business (see Section 7).

privacy.s1.processor

2) Scope and Audience

This Policy applies when you:

  • Visit AI Optimiser websites, landing pages, or in-product experiences that link to this Policy;
  • Use our AI visibility platform including entity modeling, knowledge structuring, and monitoring Services;
  • Interact with us via email or in-product communication for onboarding, support, or service delivery;
  • Receive reports, dashboards, newsletters, or other communications from us;
  • Apply for a job with Oxira LLC, or engage with us as a vendor or partner.

This Policy does not cover third-party sites, platforms, or services we do not control. Their privacy policies govern their processing.

3) Definitions (plain-language)

  • Personal data: any information that identifies or can reasonably be linked to a natural person.
  • Processing: any operation on personal data (collecting, storing, using, disclosing, deleting, etc.).
  • Controller: decides purposes and means of processing.
  • Processor/Service provider: processes data on behalf of a controller/business.
  • Profiling: automated processing to evaluate personal aspects (e.g., interests, engagement).
  • Sensitive data: categories needing extra protection (varies by law).

4) What we collect

We may collect the following categories of personal data:

A. Identity & Contact

Name, job title/role, employer, email, phone, company website, postal address (if provided).

B. Account & Preference

Login credentials (hashed), MFA settings, language/time zone, notification settings, dashboard preferences.

C. Company Information

Company details provided for AI entity modeling: brand information, products/services, differentiators, target markets, and competitive positioning.

D. Knowledge Space Data

Structured company knowledge including definitions, FAQs, use cases, problem solutions, and other content provided for the knowledge API.

E. AI Perception & Analytics

AI visibility scores, mention tracking data, perception analysis results, competitor comparisons, and aggregated analytics from AI system monitoring.

F. Technical & Usage

IP address, device/browser, OS, referrer, session IDs, cookie IDs, pages viewed, time on page, crash/error logs; mobile identifiers where lawful.

G. Billing (if applicable)

Billing contact, company details, VAT/Tax ID, payment metadata (we use PCI-compliant processors; we do not store full card numbers).

H. Recruiting (if you apply)

CV/resume, cover letters, portfolios, interview notes, references, and scheduling data.

We do not intend to collect special category data (e.g., health, religion) unless you voluntarily provide it and it is necessary (e.g., interview accommodation).

5) Where data comes from

  • Directly from you (forms, onboarding, email/chat, approvals, support).
  • Automatically (cookies, pixels, SDKs, server logs, analytics).
  • From clients (as processor): contact lists, product feeds, creative assets, audience IDs.
  • From platforms you connect (LinkedIn, Google Ads/Analytics, TikTok, Instagram/Meta) according to the permissions you grant.
  • From service partners (e.g., CRM or analytics tools you authorize).

6) Why we process data (purposes) and legal bases (when we are Controller)

A. Service delivery

Generate, schedule, approve, and publish content; manage ad campaigns; provide reports; operate support.

Legal bases: Contract (Art. 6(1)(b) GDPR), Legitimate interests (service operation, Art. 6(1)(f)), Consent where required (e.g., cookies/marketing).

B. Personalization & Profiling

Build Style Profiles and audience segments to tailor drafts and improve performance.

Legal bases: Consent where required; otherwise Legitimate interests balanced against your rights.

C. Analytics & Improvement

Quality, debugging, usage analytics, feature development, service optimization.

Legal bases: Legitimate interests; sometimes Consent for analytics cookies.

D. Security & Abuse Prevention

Fraud detection, spam prevention, account integrity, rate-limit handling, incident response.

Legal bases: Legitimate interests; Legal obligation where applicable.

E. Marketing Communications

Product updates, newsletters, offers (B2B expectations considered).

Legal bases: Consent (opt-in) or Legitimate interests where permitted; opt-out anytime.

F. Legal & Compliance

Tax and accounting, lawful requests, enforcement of agreements, dispute handling.

Legal bases: Legal obligation; Legitimate interests.

7) When we are Processor/Service Provider

For many Services (e.g., building AI entities and knowledge spaces for clients), AI Optimiser processes personal data on behalf of a client. In that role, we:

  • Process data only on the client's documented instructions;
  • Maintain appropriate security;
  • Assist controllers with data subject requests and impact assessments;
  • Limit sub-processing and cross-border transfers per contract (DPA/SCCs);
  • Delete or return data at end of engagement.

If you are an end user whose data we process for a client, please contact that client (controller) to exercise your rights. If you contact us, we will route your request to the controller.

8) Cookies, pixels, SDKs, and similar technologies

We use:

  • Strictly necessary cookies (security, session, load balancing);
  • Functional cookies (remembering preferences);
  • Analytics cookies/SDKs (e.g., Google Analytics 4; server-side analytics) to measure usage;
  • Marketing/retargeting tags (e.g., LinkedIn Insight Tag, Google Ads, TikTok Pixel, Meta Pixel) to attribute conversions and optimize campaigns.

Consent: We display a granular cookie banner (accept all / reject all / customize). You can change choices any time via Cookie Settings. Analytics/marketing cookies generally expire within up to 13 months. Blocking some cookies may limit functionality.

A live Cookie List is available in the banner/settings and should reflect actual tools deployed.

9) WhatsApp Business & Telegram approvals

If you opt into chat-based approvals:

  • We process your phone number or chat ID, the content of drafts we send, and your actions (Approve/Adjust/STOP) and comments.
  • We comply with platform rules: template-based proactive messages where required; otherwise reply within the 24-hour window.
  • We store minimal chat metadata needed to evidence approvals (audit logs).
  • You can switch to email-only approvals at any time by contacting us.

10) Platform integrations (LinkedIn, Google, TikTok, Instagram/Meta)

With your authorization (OAuth), we may:

  • Post to LinkedIn personal executive profiles (where permitted by LinkedIn policies), retrieve post insights, manage schedules;
  • Manage Google Ads campaigns and connect Google Analytics for attribution;
  • Create/post TikTok creatives and fetch performance;
  • Schedule Instagram photos/carousels and retrieve metrics via Meta interfaces.

Access tokens are encrypted, rotated, and revoked upon request. Each platform processes data under its own privacy policy; you may withdraw permissions at any time in the platform settings and/or through us.

11) Disclosures to third parties and sub-processors

We disclose personal data only as needed to:

  • Hosting & Infrastructure (e.g., EU-region cloud, CDN)
  • Email & Communications (transactional email, WhatsApp Business Cloud API, Telegram Bot API)
  • Analytics & Monitoring (e.g., GA4, error monitoring)
  • Ad/Marketing Platforms (LinkedIn, Google, TikTok, Meta)
  • AI/Content Tools (e.g., OpenAI for text/image generation; image templating)
  • Payments (PCI-compliant processors)
  • Support/CRM (e.g., ticketing or CRM platforms)

We maintain Data Processing Agreements and, where applicable, Standard Contractual Clauses with sub-processors. A current list is maintained in Annex B.

We may also disclose data to comply with law, court orders, or to protect rights and safety, after assessing the legality and scope of the request.

We do not sell personal data. Under CPRA, we also do not "share" personal data for cross-context behavioral advertising. If our practices change, we will provide required notices and opt-outs.

12) International transfers

If personal data is transferred outside your jurisdiction (e.g., EEA/UK/CH → US or other countries), we use one or more of the following safeguards:

  • Adequacy decisions (e.g., EU–US Data Privacy Framework);
  • EU Standard Contractual Clauses (SCCs) and UK IDTA/Addendum;
  • Transfer Impact Assessments and supplementary safeguards (encryption, access controls).

You may request details of relevant transfer mechanisms via mail@oxira.one.

13) Security measures

We implement technical and organizational measures including:

  • Encryption in transit (TLS 1.2+) and at rest (e.g., AES-256 where applicable);
  • Strict key management and secrets vault;
  • Role-based access/least privilege, SSO/2FA for admins;
  • Network segmentation, WAF, DDoS protections, rate-limiting;
  • Secure SDLC, code reviews, dependency scans, patch cadence;
  • Logging/monitoring, anomaly detection, and audit trails (e.g., approvals);
  • Daily backups, disaster recovery, and business continuity planning;
  • Vendor security due diligence and contractual controls.

No system can be 100% secure. If a personal-data breach occurs, we will notify affected parties and regulators where required (e.g., within 72 hours under GDPR).

14) Retention

Unless longer retention is required by law or contract, we generally retain:

  • Account & contract data: contract term + 90 days;
  • Drafts/approvals & audit logs: 12 months (unless a different period is agreed);
  • Campaign performance data: 24 months for benchmarking and trend analysis;
  • Cookie identifiers: up to 13 months (region-specific);
  • Support tickets: 12–24 months depending on complexity;
  • Backups: rolling 30–90 days;
  • Recruiting data: 6–12 months (or longer with consent).

At end of retention, we anonymize or securely delete the data. See Annex C for a detailed schedule.

15) Automated decision-making and profiling

We use profiling to:

  • Build and refine Style Profiles for executives (tone, structure, preferred topics);
  • Segment audiences and optimize posting times and ad budgets;
  • Suggest hooks, CTAs, and content formats (photo vs. carousel).

We do not conduct solely automated decisions that produce legal or similarly significant effects (GDPR Art. 22). You may object to profiling for direct marketing at any time (see Section 16).

16) Your rights and how to exercise them

Depending on your location, you may have the right to:

  • Access your personal data;
  • Rectify inaccurate or incomplete data;
  • Erase data ("right to be forgotten");
  • Restrict processing;
  • Object to processing (including direct marketing and certain profiling);
  • Data portability (machine-readable copy);
  • Withdraw consent at any time (without affecting prior processing).

How to submit a request:

Email mail@oxira.one with the subject "Privacy Request" and include:

  • Your name and contact details;
  • The right(s) you wish to exercise;
  • The email/phone you used with AI Optimiser;
  • Any context (e.g., client name, if we process on their behalf).

We may verify your identity (and, if we are a processor, we will route your request to the relevant controller). We aim to respond within 30 days (extendable as permitted).

17) Children's data

Our Services target professionals and businesses. We do not knowingly collect data from children under 16 (or higher local age). If you believe a child provided data, contact mail@oxira.one and we will delete it promptly.

18) Do Not Track and global privacy control

Some browsers offer Do Not Track (DNT) or Global Privacy Control (GPC) signals. Where legally required and technically feasible, we endeavor to honor valid signals for opt-out preferences related to tracking and targeted advertising. You can also manage cookies via our banner/settings.

19) Third-party links and embedded content

Our websites, emails, or reports may link to third-party sites or embed third-party content (e.g., maps, social posts). Those providers process data under their own privacy policies. Review their policies before interacting.

20) Changes to this Policy

We may update this Policy to reflect changes in law or our practices. The "Last updated" date will change accordingly. For material changes, we will provide a prominent notice (e.g., in-product, website banner, or direct message where appropriate).

21) Contact

AI Optimiser (by Oxira LLC) — Privacy
Email: mail@oxira.one

For EU/EEA, UK, or Swiss residents, you may also contact your local supervisory authority.

For the complete privacy policy with all sections and annexes, please contact us at mail@oxira.one

Annex A — Cookie & Tracker Details (Illustrative)

Category: Strictly Necessary

Examples: session_id, csrf_token, load balancer cookie

Purpose: login/session security, request routing

Typical duration: session to 12 months

Control: essential; cannot be disabled without breaking core features

Category: Functional

Examples: locale, timezone, cookie_consent_status

Purpose: remember preferences and improve UX

Typical duration: 6–12 months

Control: via Cookie Settings or browser settings

Category: Analytics

Examples: Google Analytics 4 (truncated IP, events); server-side analytics

Purpose: measure usage, performance, errors; A/B testing

Typical duration: up to 13 months

Control: Cookie Settings; GA opt-out mechanisms

Category: Marketing/Retargeting

Examples: LinkedIn Insight Tag, Google Ads, TikTok Pixel, Meta Pixel

Purpose: attribute conversions, optimize campaigns, build audiences

Typical duration: 6–13 months

Control: Cookie Settings; platform-level ad settings

Your live cookie banner should list the exact cookies/SDKs and durations actually in use.

Annex B — Sub-Processor Register (Illustrative)

  • Cloud/Hosting/CDN: EU-region cloud provider; CDN (e.g., Cloudflare/Fastly)
  • Email/Transactional: transactional email provider (EU or with SCCs)
  • Analytics/Monitoring: Google Analytics 4; error monitoring (e.g., Sentry/Datadog)
  • Databases/Backups: managed DB in EU region; encrypted backups
  • Communications: WhatsApp Business Cloud API (Meta); Telegram Bot API
  • Ad/Marketing Platforms: LinkedIn, Google, TikTok, Meta (per authorization)
  • AI/Content Generation: OpenAI (text/images), image templating/editing services
  • Payments (if applicable): PCI-DSS compliant processor (e.g., Stripe/Adyen)
  • Support/CRM: ticketing or CRM platform (e.g., Intercom/Zendesk/HubSpot)

We review vendors for security and privacy posture and execute appropriate DPAs/SCCs. This register may evolve; where legally required, we will notify customers of material changes.

Annex C — Retention Schedule (Detailed)

Data CategoryExamplesDefault RetentionRationale
Account & Contractprofile, company, planContract term + 90 daysService continuity, billing, disputes
OAuth Tokensplatform access tokensActive term; deleted within 30 days of disconnectSecurity, revocation hygiene
Drafts & Approvalsposts, comments, actions, timestamps12 monthsAudit/compliance, reproducibility
Campaign Performanceimpressions, clicks, conversions, costs24 monthsBenchmarking, seasonal trends, ROI
Chat LogsWhatsApp/Telegram approval metadata12 monthsEvidence of consent/approvals
Analyticsaggregated usage metricsup to 13 monthsProduct improvement, capacity planning
Support Ticketsmessages, attachments12–24 monthsTroubleshooting history
Backupsdatabase snapshotsrolling 30–90 daysDisaster recovery
RecruitingCVs, interviews6–12 months (or longer with consent)Talent pipeline management

Retention may be extended for legal holds, disputes, or regulatory obligations.

Annex D — Data Subject Request (DSR) Procedure

  1. Submission: Email mail@oxira.one with subject "Privacy Request".
  2. Include: full name; contact details; rights you want to exercise; identifiers used with AI Optimiser (email/phone); whether your data is processed as part of a client engagement.
  3. Verification: we may request reasonable information to confirm identity/authority (and controller identity if we are a processor).
  4. Timeline: we aim to respond within 30 days (GDPR/UK/CH) or 45 days (CPRA), extendable as permitted.
  5. Denials/Limitations: we may deny or limit requests where law allows (e.g., protecting others' rights, trade secrets).
  6. Appeals: where applicable (e.g., certain US laws), you may appeal a denial by replying to our response with "Appeal".
  7. Controller Routing: if we process on behalf of a client, we will forward your request to that controller.

Annex E — Legal Bases & Legitimate Interests Balancing (Summary)

  • Contract (Art. 6(1)(b) GDPR): service setup, content generation, scheduling, posting, reporting.
  • Consent (Art. 6(1)(a)): analytics/marketing cookies, marketing emails, certain profiling.
  • Legitimate Interests (Art. 6(1)(f)): service analytics, security/abuse prevention, improvement.
  • Balancing tests: minimal data; pseudonymization where feasible; opt-out mechanisms; strong security; no disproportionate impact; direct marketing opt-out honored immediately.
  • Legal obligation (Art. 6(1)(c)): taxes, accounting, lawful requests.

Annex F — Platform & Chat Integration Notes

  • LinkedIn: We use approved APIs and your granted scopes. Personal executive posting is subject to LinkedIn platform rules and your permissions.
  • Google Ads/Analytics: We connect accounts you authorize, and ingest only required metrics for reporting/optimization.
  • TikTok & Instagram/Meta: We generate creatives and retrieve insights per your granted scopes, honoring platform policies.
  • WhatsApp Business & Telegram: Proactive messages use approved templates where required; 24-hour window applies for customer care.
  • AI/Content Generation: When we use AI services (e.g., OpenAI) to generate drafts, we transmit the minimum necessary prompt/context. We contractually limit vendor use of your data for model training where available and appropriate.

Questions?

Email mail@oxira.one and we'll help.