Privacy policy
Last updated: 8 October 2026
This is a courtesy translation. The German version is legally binding.
This privacy policy explains how personal data is processed when you visit the website teamox.app (section A) and when you use the Teamox application at app.teamox.app and inside Microsoft Teams (section B).
1. Controller
Teamox – Philipp ten Eicken, Zur Hoppecke 22–26, 34508 Willingen (Upland), Germany
Email: datenschutz@teamox.app, phone: [Telefonnummer]
No data protection officer has been appointed because the legal requirements for a mandatory appointment are not met. Please direct privacy questions to the email address above.
A. Website teamox.app
2. Hosting and server logs
The website is delivered as a static site via Microsoft Azure Static Web Apps (Microsoft Ireland Operations Ltd., One Microsoft Place, Dublin 18, Ireland) through a global content delivery network operated by Microsoft. When you access it, Microsoft processes technically necessary connection data: IP address, time, page requested, data volume, browser and operating system. This data serves delivery, attack prevention and error analysis. We do not store server logs with IP addresses ourselves.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in secure and fast operation). A data processing agreement exists with Microsoft; the EU standard contractual clauses apply to any access from third countries.
3. No cookies, analytics without personal data
This website sets no cookies and uses no comparable technologies for recognition. To measure reach we use Plausible Analytics (Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia), hosted in the EU. Plausible processes page views without cookies and without storing IP addresses; a daily changing, non-reversible hash is derived from IP address and browser signature. No data is merged with other data and no cross-site tracking takes place.
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in usage analysis). Consent is not required because no information is stored on or read from your device (§ 25 TDDDG).
4. “Request a demo” and “Waitlist” forms
If you request a demo or join the waitlist, we process your details (name, company, work email address, team size, optional message) to handle your request, arrange an appointment and notify you about the launch of Teamox. The data is not used for other purposes and not shared with third parties.
Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures at your request). Retention: until your request is settled, at most twelve months; if a contract is concluded, the periods in section B apply.
5. Contact by email
If you email us, we process your details to reply. Emails are processed in Microsoft 365 (Exchange Online, EU data centres). Legal basis: Art. 6 (1) (b) or (f) GDPR. Deletion once the request is settled and no statutory retention obligations apply.
6. Fonts and external content
Fonts are served from our own server. No third-party content (fonts, maps, videos, social media plugins) is embedded. Links to external websites are recognisable as such.
B. The Teamox application
7. Roles
For the data your organisation processes in Teamox (emails, messages, notes, customer data) your organisation is the controller under the GDPR; we act as processor under Art. 28 GDPR on the basis of the data processing agreement. For the customer account data described in this section (registration, billing, user management, logs) we are the controller ourselves.
8. Registration and sign-in with Microsoft
Registering an organisation and signing in users happens through Microsoft Entra ID (your organisation’s Microsoft account). We receive: display name, email address, the user’s object ID, tenant ID and the organisation’s name. We store this data to set up your account, to attribute assignments and notes to people and for sign-in. Passwords are not transmitted to us. Inside Microsoft Teams sign-in happens via single sign-on without further input.
Legal basis: Art. 6 (1) (b) GDPR (performance of contract). Retention: for the duration of the contract, deletion 30 days after it ends.
9. Mailbox access via Microsoft Graph
Teamox accesses the mailboxes your administrator has released through the Microsoft Graph API. Access is technically restricted to those mailboxes by an Application Access Policy in Exchange Online. Emails are retrieved on demand, displayed and briefly held in the server’s memory for speed; they are not stored permanently in our database. Replies are sent via Microsoft Graph from the respective mailbox. We permanently store only collaboration metadata: conversation ID, assignment, status, internal notes, history, labels, snoozes and templates.
Internal notes are stored exclusively in our database and are never transmitted to Exchange, customers or third parties.
Legal basis: Art. 28 GDPR in conjunction with the data processing agreement; responsibility for the lawfulness of the communication data lies with your organisation.
10. WhatsApp channels
If your organisation connects a WhatsApp Business number, we receive and send messages through the WhatsApp Business Cloud API of Meta Platforms Ireland Ltd. Message content, phone number and sender name are stored in your organisation’s database so the team can handle the history together. Meta’s terms additionally apply to the use of WhatsApp Business; your organisation is responsible for informing communication partners about the processing.
11. Notifications in Microsoft Teams
Teamox sends notifications to the Microsoft Teams activity feed (new email, mention, due snooze, overdue request) and, if the mentioning user has enabled it in their account, messages to the 1:1 chat between two users. Subject, an excerpt of the note and a link to the conversation are transmitted. This data remains in your organisation’s Microsoft 365.
12. AI features
The AI features (reply drafts, summaries, text improvement, rules with AI conditions) are inactive by default. They are only used once your administrator enters their own OpenAI API key. Then the thread of the respective conversation, your templates and your input are transmitted to OpenAI (OpenAI Ireland Ltd., processing also in the USA). The transfer takes place on the instruction and under the responsibility of your organisation; OpenAI’s terms and data processing terms apply between your organisation and OpenAI. The API key is stored encrypted and never delivered to users. Without a key, no email content leaves the Microsoft environment.
13. Add-ons: shop, phone system, trades, accounting
If your organisation activates an add-on, Teamox retrieves data about the respective customer from the connected system when a conversation is opened and shows it in the contact tab: orders from Shopware, contacts and calls from Placetel, projects from HERO Software, documents from Lexware Office. Retrieval uses credentials your administrator enters, which we store encrypted. The data is cached only briefly (up to six hours for phone system contacts, otherwise a few minutes) and not stored permanently. Responsibility for the lawfulness of processing in the connected systems lies with your organisation.
14. Payment processing
Billing is handled by Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland. Stripe processes the data required for invoicing and payment (organisation name, billing address, VAT ID, contact email address, payment details, number of users). Payment details such as card numbers or bank details are collected and stored exclusively by Stripe; we only receive a reference and the payment status. Legal basis: Art. 6 (1) (b) GDPR; invoice data is retained for ten years under § 147 AO and § 257 HGB.
15. Platform emails
We send emails required for the contract: registration confirmation, user invitations, notices about the end of the trial, invoices, security-related messages and announcements of changes to sub-processors. We send marketing emails only with your consent (Art. 6 (1) (a) GDPR), which you can withdraw at any time.
16. Logs and security
For the security of the service and for error analysis, the application logs technical events (time, user ID, action, affected conversation ID, error messages). These logs are deleted after 30 days. Within the application, users of your organisation see in a conversation’s “History” who assigned, replied or wrote a note and when; this serves the traceability of collaboration. Legal basis: Art. 6 (1) (f) GDPR.
17. Hosting of the application, backups, deletion
The application and databases run in Microsoft Azure, region Germany West Central (Frankfurt am Main). Connections are encrypted with TLS 1.2 or higher, stored data is encrypted (AES-256). Each organisation’s database is backed up daily; backups are retained for 30 days. After the contract ends we provide the data for export for 30 days and then delete it completely, backups after their retention period. Statutory retention obligations (in particular for invoices) remain unaffected.
18. Recipients and third-country transfers
Recipients of personal data are the sub-processors named in our data processing agreement (annex 2) and under Security and privacy: Microsoft (hosting, Microsoft 365), Stripe (payment) and optionally OpenAI (AI, only with your key) as well as the add-on providers you connect. Transfers to third countries take place only under the EU-US Data Privacy Framework or on the basis of standard contractual clauses.
C. Your rights
19. Data subject rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6 (1) (f) GDPR (Art. 21). You may withdraw consent at any time with effect for the future. Contact datenschutz@teamox.app. If your request concerns data an organisation processes in Teamox (for example as its customer), please contact that organisation; we support it in responding.
20. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, workplace or the place of the alleged infringement. The authority responsible for us: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Gustav-Stresemann-Ring 1, 65189 Wiesbaden.
21. No automated decision-making
No automated decision-making including profiling within the meaning of Art. 22 GDPR takes place. AI drafts are suggestions that a user reviews and sends.
22. Changes
We update this privacy policy when processing or the legal situation changes. The current version with date is available at teamox.app/en/privacy; we inform customers of material changes by email.