Privacy Policy
How OakHive handles personal data it decides about itself — website visitors, enquiries, and customer contacts.
- Applies to
- Visitors and customer contacts
- Last updated
- 1 September 2026
- Questions
- legal@oakhive.ai
This policy covers the personal data OakHive decides about for itself: people who visit this website, people who ask us for a demonstration, and the individuals we deal with at a customer organisation.
If you have been asked to take part in an OakHive interview, this is the wrong document. Your employer decides that the interview happens and what is done with it — we run it on their instructions. The document written for you is the Interview Privacy Notice.
1What this policy covers — and what it does not
OakHive plays two different roles with personal data, and confusing them is the single most common way a policy like this misleads people. So, plainly:
| Situation | Our role | Where it is described |
|---|---|---|
| You visit this website or ask for a demo | Controller — we decide what happens | This document |
| You are a customer contact, administrator or billing contact | Controller | This document |
| You take part in an interview run by your employer | Processor — your employer decides | Interview Privacy Notice and the DPA |
| You use the OakHive portal because your employer subscribes | Processor for interview content; controller only for security logs | DPA, and section 3 below |
2Who is responsible
The controller is Nambra, MB, registered in Lithuania under company code 307624165, at Pajautos g. 3-48, LT-06203 Vilnius, Lithuania. OakHive is the name of its product.
Privacy enquiries: privacy@oakhive.ai.
No data protection officer is appointed. That is a considered position rather than an oversight: Article 37 GDPR makes appointment mandatory only where the core activity is large-scale systematic monitoring or large-scale processing of special categories, and neither describes what we do. The address above reaches the people who can actually answer. Our UK representative under Article 27 UK GDPR is [ TO BE COMPLETED: UK Article 27 representative — name and address ].
3What we collect and why
Visiting this website
The site sets no cookies, runs no analytics, embeds no third-party scripts, and carries no advertising or tracking pixels. Nothing here builds a profile of you or follows you elsewhere. The full detail is in the Cookies and Local Storage page, which is short for the same reason.
Serving a web page inevitably involves your IP address and basic request information reaching our infrastructure provider. That is technically unavoidable and is used to deliver and protect the site, not to identify you.
If you switch the site between light and dark, that choice is stored in your own browser. It never reaches us.
Asking for a demonstration
| What | Why | Legal basis |
|---|---|---|
| Name, work email, company, team size, and what you are trying to solve | To reply to you and prepare for the conversation you asked for. | Steps taken at your request before entering a contract (Article 6(1)(b)), and our legitimate interest in responding to a business enquiry (Article 6(1)(f)). |
| Our correspondence with you afterwards | To carry on the conversation and keep a record of what was discussed. | Legitimate interest in managing a sales conversation (Article 6(1)(f)). |
We ask for a work address because it tells us which company we are meeting. Free webmail addresses are rejected by the form for that reason, not to collect anything extra.
Being a customer contact
| What | Why | Legal basis |
|---|---|---|
| Name, work email, role, phone where you give it | Managing the contract, support, invoicing and service notices. | Performance of a contract (Article 6(1)(b)), or legitimate interest where the contract is with your employer rather than you (Article 6(1)(f)). |
| Billing records and invoices | Accounting and tax. | Legal obligation (Article 6(1)(c)). |
| Security and audit logs of administrative actions | Detecting misuse, investigating incidents, and proving what happened. | Legitimate interest in securing the service (Article 6(1)(f)), and legal obligation under Article 32 GDPR. |
| Occasional product and service email | Telling you about changes that affect you. | Legitimate interest for service messages; consent for anything promotional, withdrawable at any time. |
Where we rely on legitimate interest, we have weighed it against your interests and rights. You can ask us for that assessment, and you can object — see section 8.
4What we deliberately do not do
These are commitments, not aspirations. Each is checkable against the site itself.
- We do not sell personal data, and never have.
- We do not share personal data for cross-context behavioural advertising, and run no advertising technology at all.
- We do not buy contact lists or enrich your record from data brokers.
- We do not track you across other websites.
- We do not use personal data to train machine learning models. Customer interview content is likewise never used for training — see the AI Transparency Statement.
- We make no automated decisions that produce legal or similarly significant effects.
6Where it goes
We are established in the European Union and our systems run in the European Economic Area. Some providers listed above operate outside it.
Where personal data goes to a country without a European Commission adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where UK data is involved. You can ask us for a copy of the relevant clauses, with commercial terms redacted.
7How long we keep it
| What | How long | Then what |
|---|---|---|
| Demo enquiry and related correspondence | 24 months from our last exchange | Deleted |
| Customer contact records | For the contract, and six years afterwards | Deleted, except what tax law requires us to keep |
| Invoices and accounting records | As required by Lithuanian accounting and tax law | Deleted at the end of that period |
| Security and audit logs | As set out in the DPA | Deleted or aged out |
| Error records | 90 days, automatically | Expired by the platform |
8Your rights
Where the GDPR or UK GDPR applies to you, you have the right to:
- be told what we hold about you, and get a copy of it;
- have inaccurate data corrected, and incomplete data completed;
- have data erased, where the grounds in Article 17 apply;
- have processing restricted while a dispute about it is resolved;
- receive data you gave us in a portable format, and have it sent to another controller where that is technically feasible;
- object to processing based on legitimate interest, including profiling — and to object to direct marketing at any time, which we will always honour;
- withdraw consent where we relied on it, without affecting what came before.
Write to privacy@oakhive.ai. We respond within one month, and will tell you if we need longer because the request is complex. We do not charge for this, and we will not ask you for more identification than we need to be sure it is you.
If your request is about an interview, we are the processor and not the decision maker. We will pass your request to your employer and tell you we have done so. Your employer can action every one of these rights inside the product.
9If you are in the United States
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas or another US state with a comprehensive privacy law, the following applies in addition to the rest of this policy.
What we do with your information
In the twelve months before the date of this policy, we have collected identifiers (name, work email, employer) and commercial information (the substance of your enquiry) directly from you when you contacted us or became a customer contact. We collect it for the business purposes described in section 3 and keep it for the periods in section 7.
We do not sell or share it
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined by the California Consumer Privacy Act. We have not done so in the preceding twelve months, including for anyone under 16. Because we run no advertising technology at all, there is nothing for an opt-out preference signal such as Global Privacy Control to switch off — but if you send one, we honour it.
Sensitive personal information
We do not collect sensitive personal information for the purpose of inferring characteristics, and we use none of it beyond what is necessary to provide what you asked for.
Your rights
- to know what we collect, use, disclose and retain, and to get a copy;
- to have it deleted, subject to the exceptions the law allows;
- to have inaccurate information corrected;
- to opt out of sale or sharing — inapplicable here, because we do neither;
- to limit the use of sensitive personal information — likewise inapplicable;
- not to be discriminated against for exercising any of these rights;
- in some states, to appeal a refusal. If we refuse a request we will tell you how to appeal, and you may contact your state attorney general.
Exercise any of them at privacy@oakhive.ai. An authorised agent may act for you with written proof of authority. We respond within 45 days and may extend once where the law allows.
10Children
This website and the OakHive service are for business use by adults. They are not directed at children, and we do not knowingly collect personal data from anyone under 18. Nothing here is a child-directed service within the meaning of the US Children’s Online Privacy Protection Act, and no age-gated content is offered.
If you believe a child has given us personal data, tell us at privacy@oakhive.ai and we will delete it.
11How it is protected
Personal data is protected by the measures described in the Security Overview: encryption in transit and at rest, least-privilege access, audit logging, and a deployment check that keeps personal data out of operational logs.
If something goes wrong and your personal data is affected in a way that is likely to present a risk to you, we will tell you, and we will tell the supervisory authority within the time the law requires. Report a suspected problem to security@oakhive.ai.
12Changes to this policy
We update this policy when what we do changes. The date at the top of the page is the date of the current version. Where a change materially affects your rights, we will tell you directly rather than relying on you noticing.
13Contacting us, and complaining
Privacy questions and rights requests: privacy@oakhive.ai.
Security reports: security@oakhive.ai.
Everything else: hello@oakhive.ai.
Postal address: Nambra, MB, Pajautos g. 3-48, LT-06203 Vilnius, Lithuania.
If you are not satisfied with how we have handled your personal data, you can complain to a supervisory authority. Ours is the Valstybinė duomenų apsaugos inspekcija (State Data Protection Inspectorate) in Lithuania (vdai.lrv.lt). You may also complain to the authority where you live or work, or where the issue arose. We would rather you came to us first, but it is your right either way.