§1

Who is responsible

The controller for the processing described here, within the meaning of Art. 4(7) GDPR, is:

ONWYN_CONTROLLER_NAME
ONWYN_CONTROLLER_ADDRESS
Email: privacy@onwyn.io

Onwyn is operated by a natural person and is not yet incorporated. When the operating company is registered, this section and the Impressum will name it, and the change will appear in §12.

Data protection officer

None is appointed, and none is required. Art. 37(1) GDPR does not apply — there is no public-body processing, no large-scale regular and systematic monitoring, and no large-scale processing of Art. 9 or Art. 10 data. §38(1) BDSG requires an appointment only where at least twenty people are constantly engaged in automated processing, which is not the case. If either threshold is reached, a data protection officer will be appointed and named here. Until then, privacy enquiries go to the address above and are answered by the controller personally.

§2

The short version

  • This website sets no cookies. No analytics, no advertising, no tag manager, no consent banner — there is no consent to collect because nothing is being collected in your browser.
  • No third-party requests. Fonts, stylesheets, scripts and images are all served from onwyn.io. Nothing is loaded from Google Fonts, a CDN, or anyone else's server, so no third party learns that you visited.
  • The web server keeps an access log. It records your IP address along with each request. This is the one thing this site collects that you cannot see, and §3 describes it precisely.
  • The contact form does what it looks like. What you type reaches us and is used to answer you. Your IP address is not stored with it.
  • Everything is hosted in the EU. No personal data is transferred to a third country today.
  • AI features are switched off. Not "we don't misuse them" — they are disabled in production and no document leaves our server to be processed by any AI provider. §5 explains the interlock.
  • Documents your company uploads belong to your company. For those we are a processor, not the controller — see §6.
§3

This website (onwyn.io)

Cookies
None. The site sets no cookie of any kind, first- or third-party.
Browser storage
None. No localStorage, no sessionStorage, no IndexedDB. Nothing about you persists in your browser between visits.
Third-party requests
None. The typeface (Plus Jakarta Sans) is self-hosted. No fonts.googleapis.com or fonts.gstatic.com request is made. The site's Content-Security-Policy restricts scripts to this origin, and a build check fails the release if that is ever loosened.
Analytics
None, on the site or in the portal. There is no tracking pixel, no fingerprinting, no advertising identifier and no third-party embed. If privacy-respecting analytics are ever added, this notice will be updated before they are switched on.
Server access log
The reverse proxy that serves this site records, for each request: your IP address, the requested URL, the timestamp, the HTTP status, the referrer and your browser's user-agent string. This is ordinary web-server logging and is needed to deliver pages and to detect abuse. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in operating a working, secure website. The log is not used to build a profile, is not combined with any other data, and is not shared. Retention: the log rotates by size — five rotations of 20 MB — so how long a given entry survives depends on traffic volume rather than a fixed period. It is not copied off the server.
Automated blocking
Addresses that repeatedly fail authentication against the portal are blocked automatically for one hour, increasing on repetition to a maximum of 48 hours, after which the block record is discarded. Legal basis: Art. 6(1)(f) GDPR, and Art. 32 GDPR obliges us to defend the service.
§4

The contact form

The quote form on the contact page submits to our portal. We receive exactly the fields you filled in:

  • your name;
  • your work email address;
  • your company, if you entered one;
  • the service you selected from the dropdown;
  • your message, if you wrote one.

Legal basis: Art. 6(1)(b) GDPR — steps taken at your request prior to entering into a contract; and Art. 6(1)(f) GDPR for our legitimate interest in keeping the form free of spam.

Your IP address is not stored with your enquiry. The form is rate-limited to five submissions per hour per address, and it carries a hidden honeypot field that silently discards automated submissions. The rate limiter holds addresses in memory only, for one hour, and writes nothing to the database. There is no CAPTCHA and no third-party bot-protection service, so no outside provider sees your submission.

Retention: enquiries are kept for up to 18 months after our last contact with you, then deleted. If a contract follows, the record moves under that contract's terms and statutory commercial and tax retention periods may apply to the resulting documents. You can ask us to delete an enquiry sooner — see §11.

§5

The Onwyn Portal (portal.onwyn.io)

This section applies once you have an account. Where your employer is our client, some of what follows is governed by their contract with us rather than by this notice — §6 draws the line.

Artificial intelligence — currently switched off

The portal contains AI-assisted drafting and gap-analysis features. They are disabled in production and no client document is sent to any AI provider. This is not a policy promise; it is an interlock in the software. The AI layer refuses to start unless an attestation flag is set, and that flag is deliberately unset. The flag can only honestly be set once we have the provider's written terms, a decided and evidenced transfer basis, and an executed amendment to our data processing agreement — with advance notice to every client and a period in which they may object.

If and when those features are switched on, the provider will be named on our sub-processor register first, clients will be notified in advance, and this notice will be updated before any processing begins.

Email

We do not yet operate a transactional email service, so account notifications are currently produced and handled on our own server rather than sent through an outside provider. When an email provider is contracted it will be named on the sub-processor register and here.

§6

Controller or processor — who answers for what

Two different situations, and the difference decides who you should ask:

  • We are the controller when you browse this website, send us an enquiry, or where we run your portal account and its security — your login, our security logs, our audit trail. We decide how that processing works, so we answer for it, and this notice applies directly.
  • We are a processor for the content your company puts into the portal: uploaded evidence, policies, engagement records and any personal data inside them. Your employer is the controller of that material. We process it only on their documented instructions under a data processing agreement meeting Art. 28 GDPR.

If your question is about content your employer uploaded, the fastest route is your employer's privacy contact. If you come to us instead we will not ignore you — we forward the request to them without undue delay and assist them in answering it, which is what Art. 28(3)(e) requires of us.

§7

Who else sees data

We keep this list deliberately short, and everyone on it is bound by a contract meeting Art. 28(3) GDPR.

Hosting
ONWYN_HOSTING_PROVIDER — the website and the portal run on a virtual server in the EU. The provider operates the infrastructure and has no business reason to access application data.
Certification bodies
Where your company is being audited, its auditor sees your company's materials — but only under a scoped grant that your company's administrator approved, only for as long as that grant lasts, and every such access is written to the audit trail where your company can see it.
Everyone else
Nobody. We do not sell personal data, we do not share it for advertising, and there is no analytics provider, no CRM and no marketing platform in the path. We disclose personal data otherwise only where the law requires it of us.

Providers that are planned but not active — an email provider, off-site encrypted backup storage, any AI provider, and any delivery partner outside the EU — are listed on our sub-processor register before they process anything. Client companies receive advance notice and may object. The current register is available from privacy@onwyn.io.

§8

Transfers outside the EU

None today. Everything is hosted and processed within the EU, and nobody outside the EU/EEA has access to portal data.

If that ever changes — an AI provider, an off-site backup, a delivery partner — it happens only under Chapter V GDPR safeguards: Standard Contractual Clauses plus a documented transfer impact assessment, and only after the provider has appeared on the sub-processor register with the notice period described in §7. For client data this is a contractual commitment in our data processing agreement, not merely a statement of intent on a web page.

§9

Cookies

This website: no cookies at all. That is why you have not been shown a banner.

The portal: exactly one cookie, __Host-onwyn_sid. It holds a random session identifier and nothing else — no profile data, no tracking value. It is marked Secure, HttpOnly and SameSite=Lax, so it travels only over HTTPS, cannot be read by scripts, and is not sent on cross-site requests. It expires after a period of inactivity and in any case 12 hours after sign-in.

This cookie is strictly necessary to provide a service you have requested — signing in — so under §25(2) TDDDG it requires no consent. There are no other cookies to consent to.

§10

How long we keep things

The specific periods are in the table in §5 and the rows in §3 and §4. The principles behind them:

  • Enquiries: at most 18 months after last contact.
  • Account and security data: as long as needed to run and defend the service.
  • Sessions: hours, not days.
  • Web server logs: rotated by volume, never copied off the server.
  • Backups: a 14-day cycle, then overwritten.
  • Audit trails: kept, deliberately. A record of who did what is worthless if it can be quietly trimmed, and our clients rely on it as evidence.
  • Statutory retention duties under commercial and tax law override deletion for the specific records they cover. Where that applies, we restrict the data rather than continue to use it.
§11

Your rights

Under the GDPR you have the right to:

  • access your data and receive a copy (Art. 15);
  • rectify data that is wrong or incomplete (Art. 16);
  • erasure (Art. 17);
  • restrict processing (Art. 18);
  • portability — receive your data in a machine-readable form (Art. 20);
  • object to processing based on legitimate interest, including on grounds relating to your particular situation (Art. 21). Where we rely on Art. 6(1)(f) above, this right applies.

Write to privacy@onwyn.io. We answer within one month, as Art. 12(3) requires; if a request is complex we may extend by two further months and will tell you why within the first month. Exercising these rights is free.

Complaining to a supervisory authority

You may lodge a complaint with a data protection supervisory authority, and you do not have to come to us first. Under Art. 77(1) GDPR you may choose the authority of your habitual residence, of your place of work, or of the place where you believe the infringement occurred. The authority competent for us is the one for the controller's address given in §1.

§12

Changes to this notice

This is version 1.0, effective 6 August 2026. We will update it when what the software does changes — not on a schedule, and not to quietly widen what we are permitted to do. Three changes are already foreseeable and are flagged above rather than left to surprise you: naming the operating company once it is incorporated (§1), contracting an email provider (§5), and enabling the AI features (§5), each of which is gated on the steps described there.

Questions about anything on this page go to privacy@onwyn.io and are answered by a person, not a form.