Introduction

This Privacy Policy describes how personal data is handled in connection with the Octo+ SaaS platform. Octo+ is primarily designed to manage operational logistics data such as goods flows, RFID identifiers and inventory-related information. Personal data processing is limited and incidental to platform operation.

Roles and responsibilities

In relation to customer data processed within the Octo+ platform, we generally act as a Data Processor on behalf of our customers, who act as Data Controllers. We may act as an independent Data Controller only for limited operational purposes such as security monitoring, service administration, contractual management and legal compliance.

Types of personal data processed

The Octo+ platform processes minimal personal data. This typically includes professional user contact details (e.g. email addresses), authentication data and limited support communications. No sensitive personal data or consumer profiling data is intentionally processed.

Purpose of processing

Personal data is processed solely to provide and maintain access to the Octo+ platform, ensure platform security and reliability, deliver customer support and meet contractual and legal obligations.

Data hosting and transfers

Customer data is hosted within the European Economic Area, typically via infrastructure providers located in Germany or other EU regions. No routine transfer of personal data outside the EEA is planned.

Security measures

Technical and organisational measures include controlled privileged access via bast ion infrastructure, access logging, security monitoring, incident response processes and regular infrastructure maintenance.

Data retention

Personal data is retained only as long as necessary to provide the service or meet contractual obligations. User account data is removed when accounts are closed. Backup retention follows defined operational cycles.

Data subject rights

Where applicable, data subjects may exercise rights such as access, rectification or erasure through the relevant customer acting as Data Controller. We support customers in responding to such requests.

Third party service providers

Infrastructure hosting providers such as European cloud providers may be used strictly for hosting purposes under contractual data protection obligations.

Incident management

We maintain incident detection and response procedures. In the unlikely event of a personal data breach affecting customer data, customers will be notified without undue delay.

Contact

For privacy-related questions, please contact your usual Octo+ representative or support contact.