Privacy Policy
Version 2.0 · Effective 17 September 2026
This policy explains how OXI ELECTRONIC INSTRUMENTS S.L. ("OXI", "we") processes personal data when you visit oxiinstruments.com and checkout.oxiinstruments.com, buy from us, use a customer account, contact support, subscribe to our newsletter or take part in our creator programme. It is written to meet Articles 13 and 14 of the General Data Protection Regulation (GDPR), the Spanish Organic Law 3/2018 on Data Protection and Digital Rights (LOPDGDD) and Law 34/2002 on Information Society Services (LSSI). We have tried to keep it readable. Where the law needs a precise term, we use it and explain it.
Cookies and similar technologies are covered in a separate Cookie Policy. The two documents should be read together.
1. Controller and contact
OXI ELECTRONIC INSTRUMENTS S.L. Rúa dos Pazos 4, Portal 2, Oficina 10, 36360 Nigrán (Pontevedra), Spain Registered in the Mercantile Registry of Pontevedra Email: support@oxiinstruments.com
We are the controller of the personal data described in this policy. We are not required to appoint a data protection officer under Article 37 GDPR or Article 34 LOPDGDD and have not done so. Any question or request about your data can be sent to the email address above; requests are handled by the people responsible for data protection at OXI.
2. Summary
If you only read one section, read this one.
We collect the data needed to run the website, sell and deliver instruments, support you, pay our creators and, only if you agree, to measure the site and advertise. We do not sell personal data. We use well-known providers (Shopify, Webflow, Google, Meta, TikTok, Klaviyo, Littledata, carriers and payment providers) under contracts that bind them to our instructions. Some of them are in the USA or the UK, and we use the legal transfer mechanisms described in section 7. You can access, correct, delete and export your data, object to processing, withdraw consent and complain to the Spanish Data Protection Agency. Details follow.
3. Data we process
Each purpose below states the data involved, the legal basis under Article 6 GDPR, whether you are obliged to provide the data, and how long we keep it.
3.1 Visiting the website
Data: the technical data your browser sends with every request — IP address, date and time, requested page, referring page, browser type and version, operating system, screen size, language.
Purpose: delivering the pages you request, keeping the site available and secure, detecting and blocking attacks and abuse, diagnosing errors.
Legal basis: our legitimate interest in operating a working, secure website (Art. 6(1)(f)). Our interest is limited to what is technically necessary; we do not use this data to build profiles.
Obligation to provide: none, but the site cannot be delivered without it.
Retention: server and security logs are kept by our hosting provider for a short rolling period and then deleted. IP addresses are not retained beyond that period except where needed to investigate a specific security incident.
3.2 Cookies, analytics and advertising
Data: identifiers set in your browser, pages and products viewed, cart contents, order value and a pseudonymous customer identifier at checkout, device and browser information, approximate location derived from IP.
Purpose: understanding how the site and shop are used (analytics); showing our instruments to people who have visited the site or are likely to be interested in them, and measuring whether those adverts led to a purchase (advertising and attribution).
Legal basis: your consent (Art. 6(1)(a) GDPR; Art. 22.2 LSSI). Analytics and advertising technologies are not activated until you choose "Accept" or enable the relevant category in "Preferences". Choosing "Reject" has no effect on your ability to use the site or shop. You can change or withdraw your choice at any time via "Cookie preferences" in the footer; withdrawal takes effect immediately for the future and the related cookies are deleted from your browser.
When you have consented, purchase data is also sent from our server to the same providers (Google Analytics 4 via Measurement Protocol, Meta Conversions API, TikTok Events API) through Littledata, so that a purchase can be linked to the visit that led to it even if your browser blocked the client-side request. This server-side transmission follows the same consent as the client-side one: if you did not consent to analytics, no analytics identifier is attached to the order; if you did not consent to marketing, no advertising identifier is attached.
Advertising providers use the data to show and measure adverts, including on their own platforms. To the extent they combine it with data they hold about you as their user, they act as independent controllers and their own privacy policies apply.
Obligation to provide: none.
Retention: the storage period of each cookie and identifier is listed in the Cookie Policy. Analytics data in Google Analytics is retained for 14 months. Consent records (what you chose and when) are kept for the life of the consent plus the limitation period for claims, so that we can demonstrate consent under Article 7(1) GDPR.
3.3 Buying from the shop
Data: name, email address, shipping address, billing address, telephone number, items ordered, prices, discount or referral code used, payment method chosen and payment confirmation, delivery status, order and invoice history, and any note you add to the order. For business customers in the EU requesting VAT-exempt (reverse-charge) treatment: company name and VAT identification number, which we verify against the European Commission's VIES system.
Purpose: taking and fulfilling your order, delivering it, issuing invoices, handling returns, warranty and repairs, preventing payment fraud, complying with tax and accounting law.
Legal basis: performance of the contract of sale and steps prior to it (Art. 6(1)(b)); compliance with legal obligations in tax, accounting and consumer law (Art. 6(1)(c)); our legitimate interest in preventing fraud and defending claims (Art. 6(1)(f)).
Obligation to provide: name, addresses, email and payment are required to conclude the contract. Telephone number is required by most carriers. Without them we cannot accept the order.
Payment: card and wallet details are entered on the checkout page directly with the payment provider you choose (for example Shopify Payments, PayPal). We never receive full card numbers; we receive a confirmation, a transaction reference and the last four digits for support purposes. Payment providers perform fraud screening on the transaction. Shopify additionally provides an automated fraud analysis for each order; we review flagged orders manually and no order is refused solely on the basis of an automated decision.
Shop Pay: if you choose to use Shop Pay or accelerated checkout, Shopify processes your data as an independent controller under its own privacy policy, in addition to acting as our processor for the order itself.
Retention: order and invoice records are kept for six years from the end of the financial year in which the transaction took place (Art. 30 Spanish Commercial Code), and for the limitation period of tax obligations (four years, Art. 66 General Tax Law) where longer. Warranty-related records are kept for the duration of the legal warranty (three years from delivery for consumers in Spain) plus the limitation period for claims.
3.4 Customer account
Data: name, email address, password (stored only as a hash), saved addresses, order history, preferences you set. Creators additionally see their code, commission statements and payout history.
Purpose: letting you see and manage your orders and details, and providing the creator dashboard.
Legal basis: performance of the contract (Art. 6(1)(b)).
Obligation to provide: an account is optional; you can buy as a guest.
Retention: until you delete the account or after a prolonged period of inactivity, whichever is first. Order and invoice records that we must keep by law are retained as described in 3.3 even after the account is deleted.
3.5 Support, warranty and repairs
Data: your name, email address, the content of your message, order number, instrument serial number, firmware version and diagnostic information you send us, and, for physical returns, a postal address and shipping details.
Purpose: answering your question, diagnosing and repairing instruments, handling returns and warranty claims, improving our products based on reported issues.
Legal basis: performance of the contract or steps taken at your request before entering into one (Art. 6(1)(b)); our legitimate interest in providing support and improving products (Art. 6(1)(f)); legal obligations under consumer warranty law (Art. 6(1)(c)).
Obligation to provide: none, but we cannot help without the information needed to understand the issue.
Retention: for the life of the support case and, where the case relates to a product under warranty, for the warranty period plus the limitation period for claims. General correspondence is deleted after two years of inactivity.
3.6 Newsletter and marketing emails
Data: email address, first name if you give it, date and time of subscription and confirmation, IP address at confirmation, which emails you open and which links you click.
Purpose: sending you news about our instruments, firmware, events and offers; measuring whether the emails are read.
Legal basis: your consent (Art. 6(1)(a) GDPR; Art. 21.1 LSSI). We use double opt-in: you are only subscribed after clicking the link in the confirmation email. Open and click measurement is part of the newsletter service; if you do not want it, use a mail client that blocks remote images or unsubscribe.
Existing customers: if you have bought from us, we may send you emails about our own products similar to those you bought, on the basis of Art. 21.2 LSSI and our legitimate interest (Art. 6(1)(f)), unless you told us at checkout or afterwards that you do not want them. Every such email contains an unsubscribe link.
Abandoned checkout reminders: if you started a checkout, entered your email and either consented to marketing at checkout or are an existing customer, we may send one or two reminders about the items you left. You can opt out through the link in the email.
Obligation to provide: none.
Retention: until you unsubscribe. After unsubscribing we keep your email address on a suppression list so that we do not contact you again by mistake; this list is used for no other purpose.
3.7 Creator and affiliate programme
This section applies if you are a creator, artist or partner with a referral or discount code.
Data: name, email address, country, tax and invoicing details you provide, your code, the orders placed with your code (order number, date, net order value; not the customer's identity), commission calculations, payout requests, the invoices you upload and the payments we make to you.
Purpose: operating the programme, calculating and paying commissions, keeping the accounting records the law requires.
Legal basis: performance of the creator agreement (Art. 6(1)(b)); legal obligations in tax and accounting (Art. 6(1)(c)).
Where the data comes from: from you, and from our shop system when an order uses your code.
Retention: invoices and payout records for six years (Art. 30 Commercial Code); programme data for the duration of your participation and the limitation period for claims afterwards.
Customers: if you buy with a creator code, the creator sees that an order was placed with the code, its date and value, and the resulting commission. The creator does not receive your name, address or contact details.
3.8 Competitions, giveaways and surveys
When we run one, we tell you at the point of entry what we collect (typically name, email address and country) and why. Legal basis: your consent (Art. 6(1)(a)) or the terms of the competition (Art. 6(1)(b)). Data is deleted when the competition or survey closes and any prize has been delivered, except what we need to keep to show that the draw was fair.
3.9 Social media and embedded content
Our site links to our profiles on third-party platforms (such as Instagram, YouTube, Facebook and SoundCloud). Clicking a link takes you to that platform, which processes your data under its own policy. Where we embed content from these platforms (for example a video), it is only loaded after you consent to the relevant category in the Cookie Policy.
4. Legitimate interests
Where we rely on legitimate interest (Art. 6(1)(f)), we have assessed that our interest does not override your rights and freedoms. Our legitimate interests are: keeping the website and shop secure and available; preventing fraud and abuse; answering enquiries; sending existing customers information about similar products under Art. 21.2 LSSI; establishing, exercising or defending legal claims; and keeping records of how we handle your requests. You have the right to object to any processing based on legitimate interest (section 8).
5. Automated decisions
We do not make decisions based solely on automated processing that produce legal effects or similarly significant effects on you (Art. 22 GDPR). Payment providers and Shopify apply automated fraud screening to transactions; any order flagged by such screening is reviewed by a person before it is refused. Advertising platforms may build interest profiles from the data you have consented to share (section 3.2); you can withdraw that consent at any time.
6. Recipients
We share personal data with the following categories of recipients, each of which is bound by a data processing agreement under Article 28 GDPR unless stated otherwise:
Website hosting and content management: Webflow, Inc. (USA). Shop platform, checkout, customer accounts and payments: Shopify International Ltd. (Ireland), with Shopify Inc. (Canada) and its affiliates as sub-processors; Shopify acts as an independent controller for Shop Pay and for its own fraud prevention. Cart and storefront integration: Storesynk (Shopyflow). Server-side analytics and advertising attribution: Littledata Ltd. (UK). Analytics, tag management and advertising, subject to your consent: Google Ireland Ltd. (Google Analytics 4, Google Tag Manager, Google Ads); Meta Platforms Ireland Ltd. (Meta Pixel, Conversions API); TikTok Technology Ltd. (Ireland) (TikTok Pixel, Events API). These providers also act as independent controllers for their own purposes. Email marketing and transactional email: Klaviyo, Inc. (USA). ERP, invoicing and stock management: our business management system provider. Payment providers: the provider you select at checkout, acting as an independent controller for the payment. Carriers: DHL and other carriers we use for your destination, who receive your name, address, telephone number and email address for delivery and notifications. Professional advisers: accountants, lawyers and auditors, bound by professional secrecy. Authorities: tax authorities, courts and law enforcement where the law requires it or a valid request is made.
We do not sell personal data and do not share it with data brokers.
7. International transfers
Some recipients are located outside the European Economic Area.
United Kingdom (Littledata): covered by the European Commission's adequacy decision for the UK. United States (Webflow, Klaviyo, and the US entities of Google, Meta, TikTok and Shopify where data is transferred there): we rely on the EU-US Data Privacy Framework for providers certified under it, and otherwise on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), supplemented by a transfer impact assessment and additional measures where needed. Canada (Shopify Inc.): covered by the European Commission's adequacy decision for Canada (PIPEDA).
You can request a copy of the relevant safeguards by writing to support@oxiinstruments.com.
8. Your rights
You have the following rights under Articles 15 to 22 GDPR and Articles 12 to 18 LOPDGDD:
Access: to know whether we process your data and to receive a copy, together with the information in this policy as it applies to you. Rectification: to have inaccurate data corrected and incomplete data completed. Erasure: to have your data deleted where it is no longer needed, where you withdraw consent, where you object and there is no overriding ground, or where processing was unlawful. Data we must keep by law (section 3.3) is retained but blocked from other use. Restriction: to have processing limited while a dispute about accuracy or lawfulness is resolved, or where you need the data for a legal claim. Portability: to receive the data you provided to us under a contract or consent in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible. Objection: to object at any time, on grounds relating to your particular situation, to processing based on legitimate interest, in which case we stop unless we can show compelling legitimate grounds. Where the processing is for direct marketing, including any related profiling, you can object at any time and we will stop without exception. Withdrawal of consent: to withdraw consent at any time, with effect for the future and without affecting the lawfulness of processing before withdrawal. For cookies use "Cookie preferences" in the footer; for the newsletter use the unsubscribe link; for anything else, email us. Not to be subject to automated decisions: see section 5.
How to exercise them: email support@oxiinstruments.com from the address we hold for you, or state which address or order we should look up. We may ask for information to verify your identity, and no more than is needed for that purpose. We respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you why. Exercising your rights is free of charge unless requests are manifestly unfounded or excessive.
Complaint: you have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live, work or where the alleged infringement occurred. In Spain this is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es. We would appreciate the chance to resolve any concern first, but you are not required to contact us before complaining.
9. Security
We apply technical and organisational measures appropriate to the risk (Art. 32 GDPR), including: TLS encryption across the website, shop and checkout; access to personal data limited to staff and providers who need it for the purposes above, under confidentiality obligations; passwords stored as salted hashes by the shop platform; creator invoices and payout files stored outside the publicly accessible web space with restricted access; providers selected for recognised security certifications; and logging of administrative access. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay and notify the AEPD within 72 hours as required by Articles 33 and 34 GDPR.
10. Children
Our products and website are intended for adults. In accordance with Article 7 LOPDGDD, we do not knowingly process the personal data of anyone under 14, and we do not knowingly sell to minors. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Other sources
Most of the data we hold comes from you. We also receive: delivery status updates from carriers; payment confirmations and fraud indicators from payment providers and Shopify; order data associated with a creator code from our shop system (for creators); and, where you have consented, aggregated campaign metrics from advertising platforms. We do not purchase personal data or enrich your profile from external sources.
12. Changes to this policy
We review this policy whenever our services, providers or the law change, and at least once a year. The version number and effective date at the top identify the current text. Material changes are announced on the website before they take effect; if you hold an account or are subscribed to the newsletter, we may also inform you by email. Previous versions are available on request.
