Privacy Policy
How Ottili ONE collects, uses and protects your data.
Data controller
Ottili Electronics Willi Ott Tannenberg 1 96132 Schluesselfeld Germany
What data we collect
- Account and identity data
Information you provide to create an account, such as your email address and company name.
- Email address
- Company name
- Display name
- Authentication and security data
Credentials and security metadata used to protect your account, including your password (hashed with Argon2id) and API keys (stored as HMAC-SHA256 hashes).
- Hashed password
- API key hashes
- Login and session metadata
- Company and team data
Company profile details and information about team members you invite to your Ottili ONE workspace.
- Company profile
- Team member details
- Workspace roles
- Usage and telemetry data
Information about how you use Ottili ONE, such as workflow runs, module activity, and API usage, processed to operate and improve the platform.
- Workflow runs
- Module activity
- API usage
- Content and AI data
Prompts, documents, and generated outputs you create, plus the context you configure for Ottili AI. AI processing stays inside your configured context.
- Prompts and documents
- Generated outputs
- Configured AI context
- Integration and third-party data
Data from services you connect (such as Shopify, eBay, or Gmail) that flows through your workspace under your control. You can disconnect integrations at any time.
- Connected store data
- Linked email data
- Integration settings
- Billing and payment data
Billing details, subscription information, and invoice data processed to calculate charges and handle payments for your Ottili ONE subscription.
- Billing details
- Subscription information
- Invoice data
- Communication data
Support requests, contact messages, and notification preferences you send through Ottili ONE.
- Support requests
- Contact messages
- Notification preferences
- Audit and compliance data
Audit logs retained for compliance, debugging, and security, including records of access to your workspace through authenticated API endpoints.
- Audit logs
- Access records
- Security events
How we use your data
- Operating your Ottili ONE workspace
We use your account and company details to create and operate your Ottili ONE workspace, authenticate you, and keep your workspace available to you and your team.
- Providing Ottili AI assistance
When you use Ottili AI features, the context you configure is processed to generate responses and run AI actions within your workspace. AI processing stays inside your configured context.
- Processing billing and payments
Billing details are processed to calculate charges, issue invoices, and process payments for your Ottili ONE subscription.
- Sending platform notifications
We send service and security notifications about your account, subscription, and workspace activity so you stay informed about the operation of your workspace.
- Operating and improving the platform
Usage data such as workflow runs, module activity, and API usage is processed to operate, secure, and improve Ottili ONE. This data is never sold to third parties.
Contact and inquiry forms
When you use a public form on this website — the contact form, the sales enquiry form, the demo-request form, or a call-to-action form — we collect the details you enter. This typically includes your name, email address, company (required for sales enquiries), the topic of your request, and your message. Demo and call-to-action forms may also collect your team size, current tools, and use case, plus technical context such as the page you came from (referrer) and campaign parameters. Submissions are sent from the site to our Unified API and delivered to our support inbox at support@ottili.one. They are not stored in a database on this website. We use an anti-spam honeypot field and, where available, a minimum-time check. Delivery is recorded with a privacy-safe, content-free log (a one-way hash and length of your message — never your name, email, or message text).
Authentication and your account
This website does not authenticate you itself. Sign-in, account creation, and account management take place on our dashboard at dashboard.ottili.one, which is operated by Ottili Auth. When you choose to sign in from a marketing page you are redirected to that surface; a non-personal session cookie (ottili_session) is used only to remember that you are signed in and never contains readable personal data. The actual authentication, single sign-on, and identity checks are performed by the separate Ottili Auth service.
Analytics and cookies
We use a consent-based cookie and tracking approach. Strictly necessary cookies are required for the site and your session to work. Analytics and marketing technologies — for example Google Analytics 4 and Plausible for analytics, and Meta Pixel, Google Ads, and LinkedIn Insight Tag for marketing — are loaded only after you give consent and only where they are enabled in the deployed environment. You can review every category and vendor and change your choice at any time from the footer (Cookie Settings). The full, current list of cookies and vendors is published on our Cookie Policy.
Integrations and third-party services
Where you connect a third-party integration inside your Ottili ONE workspace (for example Shopify, eBay, or Gmail), data from that service flows through your workspace under your control and you can disconnect it at any time from your workspace settings. Beyond the integrations you configure, we use a limited set of sub-processors to run the platform — for example Stripe for payments and Anthropic, OpenAI, and Google for AI features. The current, complete list of sub-processors and their roles is published on our Sub-processors page.
Hosting and infrastructure
This website is delivered through Cloudflare's global edge network using OpenNext (Cloudflare Workers). Authenticated Ottili ONE workspace data is stored in PostgreSQL and isolated per company (company_id); access goes through authenticated API endpoints and there is no cross-company sharing through the platform. Cloudflare provides request-level observability for the site.
Logs and monitoring
We keep operational logs to run and secure the site. Cloudflare provides request observability at the edge. Our own inquiry-delivery logs are structured and deliberately free of personal content: they record a submission identifier, the kind of request, the delivery channel, and a one-way hash and length of your message — never your name, email address, or message text. The website does not load any third-party error-tracking or session-replay SDK.
Data isolation
Company workspace data is isolated per account. No cross-company data sharing occurs through the platform architecture. All data access goes through authenticated API endpoints.
Data retention
- Account and operational records
We keep account, company, and operational records only as long as required to provide the service, meet contractual duties, handle support, preserve security evidence, or satisfy legal retention obligations.
- Audit logs
Audit logs are retained for compliance, debugging, and security evidence.
- Workflow run history
Workflow run history is retained for a configurable period controlled by your workspace administrator.
- Support communications
Support requests and contact messages are retained only as long as needed to resolve your request and for quality and compliance purposes.
Your data protection rights
- Right of access
You can request confirmation of whether we process your personal data and obtain a copy of that data, including the purposes of processing and the categories of data involved (GDPR Art. 15).
- Right to rectification
You can have inaccurate personal data corrected and incomplete data completed (GDPR Art. 16).
- Right to erasure
You can request deletion of your personal data where one of the grounds in GDPR Art. 17 applies, such as when the data is no longer necessary for the purposes it was collected. You can request data export or deletion by contacting our privacy contact.
- Right to restriction of processing
You can request that we restrict processing of your personal data in the situations described in GDPR Art. 18, for example while the accuracy of the data is being verified.
- Right to data portability
You can receive the personal data you provided to us in a structured, commonly used and machine-readable format and request transmission to another controller where technically feasible (GDPR Art. 20).
- Right to object
You can object, on grounds relating to your particular situation, to processing based on legitimate interests, and you can object at any time to processing for direct marketing (GDPR Art. 21).
- Right to withdraw consent
Where processing is based on your consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal (GDPR Art. 7(3)).
- Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (GDPR Art. 77).
How to exercise your rights
You can exercise any of the rights listed above free of charge and without affecting the lawfulness of processing already carried out. Choose the channel that fits your request.
How to submit a request
- Sign in to your Ottili ONE workspace and use the in-product privacy and account settings where available — for example, to correct profile data, export your data, or withdraw consent.
- If you cannot use the in-product controls, or your request needs our help, email our privacy team using the contact address shown in the Contact section below. Include the email address of the affected account and state the right you wish to exercise (access, correction, deletion, portability, objection, or withdrawal of consent).
Sending documents safely
Do not send copies of identity documents (passport, ID card, driving licence), financial statements, passwords, or other sensitive documents by email. Unencrypted email is not a secure way to transmit personal data. We verify your identity through your authenticated Ottili ONE account and, where needed, through a secure verification step — never by asking you to email identification documents.
Verifying your identity
To protect your data, we confirm your identity before actioning a request. For account holders this is done through your authenticated session; we will never ask for your password or for identification documents by email.
Our response
We respond to verifiable requests within one month (GDPR Art. 12(3)). If a request is complex or numerous, we may extend by up to two further months and will tell you. Requests that are manifestly unfounded or excessive may be refused or charged a reasonable fee, in line with Art. 12(5).
Privacy inquiries
For general privacy questions, use the same contact address. To complain about our processing, you also have the right to lodge a complaint with your supervisory authority (see above).
Security
We protect personal data with transport encryption (TLS) in transit and strong, salted one-way hashing for passwords and secrets at rest. Access to production systems and customer data is restricted and audited. A detailed, current description of our technical and organisational measures is maintained on our Security page.
Contact
For privacy questions or data requests, please use the contact address below.
Email: datenschutz@ottili.one
Version 2026.05 • Effective: May 15, 2026
This legal document is published but pending final legal verification. Treat it as provisional until verified.
Governed under T-Q1-WEB-0199: added effective date, status and approval governance to the privacy policy.
