Privacy and cookies
LAST UPDATED: 2 OCTOBER 2026
This page explains how NEOXIS Corp. ("we", "us") collects, uses and protects personal data when you visit neoxis.ai or correspond with us, in line with the EU General Data Protection Regulation 2016/679 ("GDPR") and Bulgarian data protection law.
1. Data controller
UIC 208772721 · VAT BG208772721
6400 Dimitrovgrad, Bulgaria
2. What we collect
This site is intentionally minimal. We do not run advertising pixels or social media trackers. The only third-party script is Google Analytics, and it loads only if you accept it in the cookie banner. Fonts are served from our own server, so your browser does not contact font providers when you visit.
- Server access logs: IP address, user agent, referrer and timestamp. Kept for 30 days for security and abuse prevention. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Website analytics, only with your consent: if you click "Accept" in the cookie banner, we use Google Analytics 4 to measure visits: the pages you view, the website or search engine that sent you, your approximate location (country and city, derived from your IP address, which Google Analytics does not store), your device, browser and screen size, and interactions such as scrolling, clicks on our email address, phone number or WhatsApp link and use of the quote form. From the quote form we send only the workload and term you select, never your name, company or notes. Google Ireland Limited processes this data on our behalf. Legal basis: consent (Art. 6(1)(a) GDPR). Event-level data is kept for 14 months. Google signals and advertising features are switched off.
- Quote requests: the quote form on our homepage does not send anything to our servers. It only prepares an email in your own mail app. We receive what you choose to send.
- Correspondence: if you email, call or message us on WhatsApp, we keep that correspondence for as long as needed to respond and for any business relationship that follows. WhatsApp messages are delivered by WhatsApp Ireland Limited under its own terms and privacy policy. Legal basis: steps prior to a contract, contract performance or legitimate interest.
3. Cookies and local storage
This site sets no cookies unless you accept analytics. Your choice in the cookie banner is saved in your browser's local storage under the key "neoxis-consent", so the banner does not appear on every page. This is strictly necessary and contains no personal data.
If you accept analytics, Google Analytics sets two first-party cookies: _ga, which distinguishes visitors, and _ga_E43KMEWQDQ, which keeps the state of your visit. Both expire after up to 2 years. You can change your choice at any time with "Cookie settings" at the bottom of every page. If you withdraw consent, we delete these cookies from your browser.
Our hosting provider (Hostinger) and our CDN (Cloudflare) may set minimal security cookies that are needed to deliver the site over HTTPS and to protect it from abuse. These are outside our control and strictly necessary for the site to work.
4. How we use the data
- To deliver the website to your browser.
- To respond to enquiries and prepare quotes and agreements.
- To confirm that business correspondence we send has reached the intended recipient (see section 7).
- To investigate abuse, security incidents and technical errors.
- To understand which pages are useful and how visitors find the site, so we can improve it. This happens only if you accept analytics.
We do not sell, rent or transfer your data to third parties for marketing purposes, and we do not profile you. We do not transfer data outside the EU/EEA except where strictly necessary to deliver the site, for example through CDN edge nodes operated by Cloudflare under EU Standard Contractual Clauses. If you accept analytics, Google may also process the data in the United States; Google LLC is certified under the EU-US Data Privacy Framework.
5. Your rights under the GDPR
Where we hold personal data about you, you have the right to:
- access your personal data (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict or object to processing (Art. 18 and 21);
- receive your data in a portable format (Art. 20);
- withdraw consent at any time, where processing is based on consent;
- lodge a complaint with the Bulgarian Commission for Personal Data Protection (cpdp.bg).
To exercise any of these rights, write to [email protected]. We will respond within 30 days.
6. Security
The site is served over HTTPS only. Access to the server is restricted and protected by our hosting provider's standard controls. We do not collect any data in your browser beyond what is described above.
7. Email open tracking
Business emails sent from @neoxis.ai addresses may include a small, transparent 1×1 pixel image hosted at neoxis.ai/track/pixel.php. When your email client downloads remote images, that request is logged on our server. We use this signal only to confirm that proposals, quotes and other business correspondence have reached you, and to time follow-ups appropriately.
What we record
- The time of each pixel load.
- The IP address that requested the pixel (often a proxy address from Apple, Google or Microsoft rather than your own).
- The user agent of the email client.
- An opaque tracking ID that links the event to the specific message we sent. It reveals nothing about you that we did not already have.
What we do not do
- We do not track clicks, scrolling or any reading behaviour beyond "the email was displayed at least once".
- We do not match IP addresses against third-party identity databases.
- We do not share this data or use it for advertising or profiling.
- We do not send newsletters or bulk email. The pixel is used in direct business correspondence only.
Legal basis and retention
Processing is based on our legitimate interest (Art. 6(1)(f) GDPR) in managing business correspondence efficiently and avoiding unnecessary follow-ups. We have weighed this against your rights and consider the impact minimal: the data is technical and small in volume, and we never publish or transfer it. Events are kept for 12 months and then deleted.
How to opt out
- Block remote images in your email client. The pixel will not load and nothing is recorded.
- With Apple Mail Privacy Protection, images are preloaded through Apple's proxy, so we see neither your IP address nor when you read the message.
- Email us at [email protected] with the subject "No tracking" and we will send you plain correspondence without the pixel.
8. Changes to this policy
We may update this policy to reflect operational, legal or regulatory changes. The date at the top of the page shows the latest revision.
Questions about this policy? Write to [email protected].