Privacy policy
Draft · Updated: 17 September 2026
Draft · Updated: 17 September 2026. This policy describes what personal data Oktava collects, why, who processes it and what rights you have. Oktava provides software with background music for business venues, by subscription. The Service is addressed to businesses; the personal data we process belongs mostly to the people who represent them: owners, managers and staff who use the account. This English text is the reference version; translations on other language pages are provided for information only.
1. Who we are
Draft: company registration in Georgia is not yet complete. Operator: [TO COMPLETE: legal name]. Registration number: [TO COMPLETE: registration number]. Address: [TO COMPLETE: registered address]. These details have not been confirmed.
Questions and requests about personal data: admin@oktava.app. Requests are handled by the Oktava team; we have not appointed a data protection officer because our processing is limited in scale and does not involve sensitive data or systematic monitoring of individuals.
Our representative in the European Union under Article 27 GDPR, and where required in the United Kingdom, will be named on this page before the Service opens to customers there.
2. What we collect
Account data. The e-mail address and the sign-in identifier we receive from our authentication provider when you create an account or sign in, and the country of your account. We do not store passwords; sign-in is handled by the authentication provider.
Business data you enter. The name and address of each venue, its playback points, and the devices you activate. The venue name and address appear on the documents we generate for that venue.
Service data created by using Oktava. The playback log (which tracks played at which point and when), the activation and revocation history of devices, subscription status received from our payment provider, and product events (for example that an account was created, a device activated or a document downloaded). The playback log is part of the product: it documents what was playing at your venue.
Technical data. IP address, browser and device information, timestamps and error reports generated when you use the website, the account area or the player. Server and delivery logs are kept by our hosting providers.
Support correspondence. Messages you send us and our replies.
Referrals. If you invite another business with your referral link, we record the link between the inviting and the invited account.
Analytics. On the website we count visits without cookies and without identifying visitors. In the account area we may ask for your consent to record your sessions to improve the product; see Section 9.
Payment data. We do not receive or store card numbers or bank details. Payments are processed by our merchant of record, the seller of record named at checkout, which handles payment data as an independent controller under its own privacy policy. We receive the transaction identifier, payment status, plan, country and tax status.
We do not ask for and do not knowingly process special categories of personal data.
3. Why we use it and on what legal basis
Account data: to create the account, sign you in and provide the Service. Basis: performance of a contract, Art. 6(1)(b) GDPR.
Business data: to link subscriptions to venues, generate documents for each venue and apply the country rules. Basis: performance of a contract, Art. 6(1)(b).
Playback log and device history: to provide the evidence the documents refer to, investigate disputes and protect the catalogue. Basis: performance of a contract and legitimate interest, Art. 6(1)(b) and 6(1)(f).
Product events: to understand how the Service is used and fix onboarding problems. Basis: legitimate interest, Art. 6(1)(f).
Technical data and error reports: security, abuse prevention and diagnosing failures. Basis: legitimate interest, Art. 6(1)(f).
Support correspondence: to answer your requests. Basis: performance of a contract and legitimate interest.
Payment status from the merchant of record: to grant and withdraw access and for accounting. Basis: performance of a contract and legal obligation, Art. 6(1)(b) and 6(1)(c).
Referral records: to operate the referral programme. Basis: performance of a contract, Art. 6(1)(b).
Session recordings in the account area: to improve the product. Basis: consent, Art. 6(1)(a), withdrawable at any time.
Product news not related to the Service: to inform you about the product. Basis: consent, Art. 6(1)(a), withdrawable at any time.
We do not sell personal data, do not use it for third-party advertising, do not profile individuals for advertising, and do not make decisions with legal effects on people by automated means only.
4. Who processes it
We use service providers (processors) that act on our instructions under data-processing agreements. By category: authentication (sign-in and account security); merchant of record (payments, taxes, invoices; an independent controller for payment data); transactional e-mail delivery; hosting, content delivery and streaming of the catalogue; managed database; product analytics, session recordings and error monitoring; professional advisers (lawyers, accountants, auditors), bound by confidentiality.
The current list of providers, with the role and the processing region of each, is published on the Service providers page and is part of this policy. We update the list when a provider changes.
We also disclose data where the law or a lawful request of a competent authority requires it, and in the event of a merger, acquisition or sale of the business, on the conditions of this policy.
5. International transfers
Your data is stored and processed on servers in the European Union. Oktava is established in Georgia, and our team accesses the systems from Georgia; this is a transfer to a country for which the European Commission has not adopted an adequacy decision. We base it on the standard contractual clauses approved by the European Commission, with a transfer risk assessment and technical measures (encryption in transit and at rest, minimised access). Where a provider processes data outside the EEA, we rely on an adequacy decision or on standard contractual clauses.
6. How long we keep it
Account and business data: while the account exists. When you delete the account, the e-mail address and sign-in identifier are erased and the account is anonymised.
Playback log and device history: kept after account deletion in anonymised form, linked to the venue and not to a person. The log is the evidence your documents refer to and may be needed for as long as a collecting society can raise a claim for past periods.
Product events: kept with the account and anonymised with it.
Technical logs and error reports: kept by our providers for a limited period set in their terms and then deleted.
Session recordings: kept for the short period stated when we ask for your consent, then deleted.
Support correspondence: as long as needed to handle the request and related follow-ups.
Accounting records and transaction data: for the period required by tax and accounting law.
7. Your rights
If you are in the EU or EEA you have the right to access your data and receive a copy, to correct it, to erase it, to restrict processing, to data portability, to object to processing based on legitimate interest (including direct marketing, which we then stop unconditionally), to withdraw consent at any time without affecting processing before the withdrawal, and to lodge a complaint with the supervisory authority of the country where you live or work.
How to exercise them: export your data and delete your account from the account area, or write to admin@oktava.app from the address linked to the account. We reply within one month; for complex requests we may extend by up to two further months and will tell you. We may ask you to confirm your identity. Requests are free unless manifestly unfounded or repetitive.
Some rights are limited by our obligations: accounting records cannot be erased before the statutory period ends, and the playback log of a venue is not erased on request, because it does not identify a person and serves as evidence under the contract.
8. Rights under other laws
We apply the same standard to all customers regardless of country. In addition:
United Kingdom. The rights in Section 7 apply under UK GDPR; complaints go to the Information Commissioner's Office.
United States. Where a state privacy law applies, you may request access, correction, deletion and a copy of your data. We do not sell personal data and do not share it for targeted advertising, so no opt-out mechanism is needed. We do not discriminate for exercising rights.
Canada. You may access and correct your data and complain to us and then to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.
Australia. You may request access and correction and complain to us and then to the Office of the Australian Information Commissioner.
Brazil. The rights under the LGPD (access, correction, anonymisation, deletion, portability, information about sharing, withdrawal of consent) can be exercised at admin@oktava.app; complaints go to the ANPD.
9. Cookies, local storage and analytics
The website and the account area use only the cookies and local storage needed to sign in, keep your session and remember your interface settings. No consent is required for them, and there is no cookie banner.
Website visits are counted without cookies and without identifiers stored in your browser.
In the account area we may ask you to allow recording of your sessions to improve the product. Nothing is recorded until you agree. Recordings mask typed text, e-mail addresses and postal addresses. You can withdraw consent in the account area or by writing to admin@oktava.app. Product usage in the account area is measured by account identifier, not by e-mail or name.
We do not use advertising trackers.
10. Security
We protect data with measures proportionate to the risk, including: encryption in transit; encryption at rest by our database provider; database access restricted to our servers; delivery of the catalogue only through signed short-lived links; an individual token for each player device, which you can revoke from the account area; two-factor authentication on administrative accounts; separation of test and production environments; regular backups. No system is completely secure, and we cannot guarantee absolute security.
11. Children
The Service is offered to businesses and is not directed at anyone under 18. We do not knowingly collect children's data; if you believe we have, write to admin@oktava.app and we will delete it.
12. Data breaches
If a personal-data breach is likely to result in a risk to individuals, we notify the competent supervisory authority within 72 hours of becoming aware of it and, where the risk is high, the affected individuals and customers without undue delay.
13. Changes to this policy
We may update this policy, for example when a provider changes or the Service opens in a new country. The current version, with its effective date, is always available on our website. We notify customers of material changes in advance by e-mail or in the account area.
The contract between you and Oktava is governed by the laws of Georgia; this does not affect your rights under the data-protection law of the country where you are, or your right to complain to your local supervisory authority.
This information is provided for general reference and is not legal advice.