Last updated: 2 September 2026
The controller within the meaning of Art. 4(7) GDPR is itcv GmbH, Solmsstraße 71, 60486 Frankfurt am Main, Germany; e-mail: info@itcv-software.com, telephone: +49.69.24742919-0.
itcv GmbH markets and operates ocatis for customers inside the European Union. The software is developed technically by ORDIS Co., Ltd. in Bangkok; for data processing on this website and towards EU customers, itcv GmbH is solely responsible.
We answer requests under Arts. 15 to 22 GDPR within the period stated in clause 16.
This notice uses the terms of Art. 4 GDPR. “Personal data” means any information relating to an identified or identifiable natural person; “processing” covers any operation such as collection, organisation, storage, retrieval, disclosure, restriction, erasure or destruction; “restriction of processing” means the marking of stored data with the aim of limiting its future processing. We also use “controller”, “processor” and “third country” as defined in Art. 4 GDPR.
We process personal data only in accordance with the principles of Art. 5 GDPR: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, integrity and confidentiality, and storage limitation.
This website does not collect special categories of personal data under Art. 9 GDPR. Please do not send us such information through the contact, demo or trial forms.
Conversations within an ocatis instance may contain special categories, depending on what members of your organisation enter. For that content the customer is the controller and must determine and document its own legal basis under Art. 6 and Art. 9 GDPR.
This website and the managed ocatis instances we operate are hosted in the European data centres of Hetzner Online GmbH, in particular in Germany and Finland.
Self-hosted installations run entirely inside the customer’s own infrastructure; data generated there leaves it only if and to the extent the customer enables providers or services.
Each request to this website automatically records: a truncated IP address, date and time of access, the resource requested, referrer URL, browser type and version, and operating system.
The purposes are delivering the website, protecting the infrastructure (abuse and disruption detection) and statistical optimisation. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in secure, uninterrupted operation.
Server log files are deleted shortly after storage, unless they are temporarily needed to investigate a detected security incident.
This website sets no marketing, advertising or tracking cookies and loads no scripts, fonts or measurement points from third parties; every resource is served from our own domain.
The only cookie this website uses is “NEXT_LOCALE”. It contains the language you chose (“en” or “de”) and is a session cookie: it carries no expiry and is deleted when you close your browser. It has path “/” and SameSite “Lax” and is not flagged HttpOnly; these attributes serve only the language mechanism and contain no identifier that follows you across websites.
The cookie is set or refreshed when a page is requested in a language different from the one previously stored — including on a first visit, when the requested language differs from the preference reported by your browser. If stored preference and requested language match, no cookie is set. When you switch languages through the language selector, your browser writes the same value directly.
In addition, this website stores two entries in your browser’s local storage: “ocatis-theme” (the light or dark design you picked) and “ocatis-market-seen” (a flag recording that the notice about the other market was already displayed). The language itself is not kept in local storage; it is carried by the URL path.
Cookie and local storage entries are technically necessary: the cookie keeps your language choice across pages, the theme entry prevents a flash of the wrong design, and the banner flag avoids repeating the market notice. They serve the provision of the telemedia service at your request within the meaning of § 25(2) TDDDG, which is why no consent is required and no consent-management tool is used; the accompanying processing of these preference values rests on Art. 6(1)(f) GDPR. You can delete stored entries at any time through your browser settings.
We do not currently use analytics or tracking tools on this website. If a self-hosted, cookie-free reach measurement is activated, we will update this privacy notice beforehand.
If you write to us through the contact or demo form, we process the information you provide — name, e-mail address, company, topic and message, plus optionally role, organisation size and preferred date for a demo request — in order to handle and answer your enquiry.
The legal basis is Art. 6(1)(b) GDPR where the enquiry serves the conclusion or performance of a contract with you or your company, otherwise Art. 6(1)(f) GDPR (interest in responding to enquiries).
Documentation arising from an enquiry is kept until the enquiry is concluded and no statutory retention duties (in particular the commercial and tax retention periods under § 257 HGB and § 147 AO, up to ten years) apply.
We send no marketing e-mails without your separate consent; the forms contain no pre-settled option to give it. Consent you have given can be withdrawn at any time with effect for the future (Art. 7(3) GDPR).
For the 14-day Business trial we process first name, last name, business e-mail address, company name and the password you set (stored solely as an Argon2id hash, never in plain text). These data are required to create the tenant, provide you with access and administer the trial.
Activation happens through a single-use link in an e-mail. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures at your request).
The trial lasts 14 days from activation. Without conversion to a paid subscription, the tenant becomes read-only on day 14 and is deactivated on day 44; data is preserved for 30 days after the end of the trial and deleted thereafter unless statutory retention duties apply. One self-service owner trial per global identity and per market is provided for.
For in-app Business conversion we collect a billing profile (invoice address, contact data, VAT identification number, billing period, currency and seat count). It is stored and processed in our own billing portal, which itcv GmbH operates on its own infrastructure in our European data centres; checkout, payment methods, invoices, receipts and cancellation run through that portal using separate portal credentials, distinct from your ocatis credentials.
For card payments and direct debit we use Stripe as payment processor (Stripe Payments Europe Ltd., Dublin). Stripe processes payment data only to the extent required for handling the payment. Where Stripe transfers data to its US parent Stripe, Inc., that transfer rests on the adequacy decision for companies certified under the EU-US Data Privacy Framework.
The legal basis is Art. 6(1)(b) GDPR for settling the contract and Art. 6(1)(c) GDPR for the retention of contract and invoice data required by tax and commercial law.
Recipients of your data are Hetzner Online GmbH as hosting provider (clause 4), our own billing portal — operated by us — and Stripe Payments Europe Ltd. as payment processor, plus tax advisers and auditors within statutory duties, and public authorities where a statutory or official obligation or a court order exists.
A current list of the processors we use is available on request. We do not sell personal data. We do not use automated decision-making within the meaning of Art. 22 GDPR.
We delete personal data once the purpose of processing ceases and no legal retention duty applies. Key periods: server log files deleted shortly after storage; enquiry and demo documentation until the exchange is concluded; contract and invoice data for the statutory retention periods of up to ten years (§ 257 HGB, § 147 AO); account-related data after termination of the contractual relationship, subject to retention duties; trial tenants 30 days after the trial ends without conversion.
Where you operate ocatis as a customer — self-hosted or managed by us — the customer is the controller for the content arising in its instance: conversation content, messages, file attachments, prompt records, usage and token statistics, and its organisation’s end-user accounts.
itcv GmbH does not process this content for its own purposes. In a managed deployment operated by us, we process it solely on the customer’s instructions as a processor under a contract pursuant to Art. 28 GDPR (DPA), including technical and organisational measures appropriate to the risk under Art. 32 GDPR.
For self-hosted installations no processing by itcv GmbH takes place, and there is no remote maintenance or diagnostic access to customer data without the customer’s explicit enablement.
ocatis is a bring-your-own-key platform: the customer contracts directly with the AI providers it uses and stores the corresponding API keys in its own instance. We provide the connection but do not assume the provider contracts.
Where tenant administrators select providers seated in the United States or another third country (for example OpenAI, Anthropic, Google), prompt content and context data are transmitted there. Responsibility for that transfer and for securing it under Chapter V GDPR lies with the customer as controller of its instance.
Transfer mechanisms may consist of an adequacy decision of the European Commission — including the EU-US Data Privacy Framework for certified companies — or the Commission’s standard contractual clauses; where standard contractual clauses are relied on, a transfer impact assessment must be documented.
If only local inference endpoints (Ollama, LM Studio) or providers with EU regions are used, the system performs no third-country transfer.
We do not use personal data to train language models.
Under the GDPR you have the following rights:
Art. 15 — right of access to the data stored about you and the circumstances of its processing.
Art. 16 — right to rectification of inaccurate data and completion of incomplete data.
Art. 17 — right to erasure (the “right to be forgotten”), except where processing is necessary for freedom of expression and information, for a legal obligation, for reasons of public interest, or for the establishment, exercise or defence of legal claims.
Art. 18 — right to restriction of processing.
Art. 20 — right to data portability in a structured, commonly used and machine-readable format.
Art. 21 — right to object on grounds relating to your particular situation; against direct marketing, objection requires no justification.
Art. 7(3) — right to withdraw given consent with effect for the future.
To exercise rights under Arts. 15 to 22 GDPR, contact info@itcv-software.com. We respond within one month of receipt; for complex requests the period may be extended by two further months, and we will inform you (Art. 12(3) GDPR).
The first copy of your data we provide in the course of an access request is free of charge; for further copies we may charge a reasonable fee based on administrative costs (Art. 12(5) GDPR).
For personal data in a customer instance, the request goes to the customer as controller; the customer administers access, rectification and erasure requests of its end users through the administration interface of its ocatis instance. We support the customer in answering such requests but are not the contact point for end users.
Without prejudice to any other remedy, you may lodge a complaint with a data protection supervisory authority about our processing of personal data (Art. 77 GDPR). For itcv GmbH the competent authority is The Commissioner for Data Protection and Freedom of Information for the state of Hesse, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.
We maintain technical and organisational measures under Art. 32 GDPR appropriate to the risk: TLS encryption in transit, AES-256-GCM encryption of stored secrets with a tenant-bound key hierarchy, Argon2id password hashing, role-based access control (RBAC), strict tenant isolation, and logging of administrative actions.
In the event of a personal data breach we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware pursuant to Art. 33 GDPR, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the risk is high we inform affected data subjects under Art. 34 GDPR. Customers of a managed deployment are informed without undue delay so they can meet their own obligations as controllers.
ocatis is an AI system within the meaning of Regulation (EU) 2024/1689 that integrates generative models. Where the transparency duties of Art. 50 of that Regulation apply — informing people of the AI nature of an interaction and labelling machine-generated content — we describe our documented approach on the data-protection page (link at the end of this notice); the current scope stated there governs.
Details of our classification and of your obligations as a deployer are also on that page.
This privacy notice governs processing by itcv GmbH under the GDPR and the German BDSG. It applies to the EU market under ocatis.com.
Customers of ORDIS Co., Ltd. under ocatis.ai are covered by a separate notice aligned with the Thailand Personal Data Protection Act B.E. 2562 (2019), which sets out different lawful bases, duties and rights: Privacy policy — Thailand (PDPA).
Detailed technical description of the processing: Data Protection.