Draft — must be reviewed before publication
This text is a template. It has not been reviewed by a lawyer and is not in force. Placeholders in square brackets have to be filled in.
Privacy Policy
What personal data Odinex Cloud processes, why, and your rights.
Last updated: [Date]
1. Controller
The controller for the processing described here is [Operator name], a sole proprietor, [Address], [Country]. Contact for privacy matters: [Privacy contact email].
[Review: name a data protection officer if one is required, or remove this note.]
2. This website
The website odinex.cloud (including the documentation) does not use cookies, analytics or advertising trackers.
- Server logs. When you visit the website, our web servers process your IP address, the requested page, date and time, and your browser's user agent to deliver the pages and to keep them secure. [Review: retention period, e.g. [N] days.] Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
- Theme preference. If you choose a light or dark theme, the choice is stored in your browser's local storage. It never leaves your device.
- Pricing and status pages load current prices and the platform status from our API. These requests contain no personal data beyond what is listed under server logs.
3. Your account and the services
When you use the console and the services we process:
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address, password hash, two-factor settings | Your account and login | Contract (Art. 6(1)(b)) |
| Login sessions: IP address, browser, time | Security of your account; you can see and end your sessions | Contract; legitimate interest in security (Art. 6(1)(f)) |
| Organizations, projects, resources and their settings, audit log | Providing the services | Contract |
| Balance, payments, usage and statements | Billing | Contract; legal obligations (Art. 6(1)(c)) |
| Support tickets and abuse reports | Support and handling abuse | Contract; legitimate interest |
Cookies in the console. The console uses a session cookie (odx_session) to keep you logged in and a security
cookie (odx_csrf) to protect against cross-site request forgery. Both are strictly necessary.
Data on your servers. We do not access the content of your servers or volumes, except where you ask us to (for example in a support case) or where required by law. For personal data you store on the services, you are the controller and we process it on your behalf. [Review: provide a data processing agreement (Art. 28 GDPR).]
4. Recipients
- Payments: Stripe [Stripe entity and address]. Card details are entered directly with Stripe; we never see the full card number.
- Email delivery: [Email provider, entity and address].
- Infrastructure: our servers are located in Frankfurt, Germany. [Review: list hosting and data centre providers.]
- Sign-in with Google or GitHub, if you choose to use it: Google [entity] or GitHub [entity] receive the request to sign you in.
[Review: transfers outside the EU/EEA and the safeguards used.]
5. Retention
We keep account data while your account exists. Billing records are kept for [N] years as required by [law]. Server logs are kept for [N] days. [Review all periods.]
6. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, and to data portability. You can export your account data and delete your account in the console. To exercise any other right, contact [Privacy contact email]. You also have the right to lodge a complaint with a supervisory authority, for example [competent authority].
7. Changes
We will update this policy when our processing changes and show the date of the last update at the top.