Privacy
Privacy notice
How Odinma Limited handles personal information submitted through odinma.com and used in the Odinma Client Workspace.
1. Who we are
Odinma Limited (company number 06836067), registered in England and Wales and trading as Odinma, is a software consultancy and product studio based in Leeds, United Kingdom.
For the personal information described in this notice, Odinma Limited is normally the data controller. This means we decide why and how that information is used.
Contact us about privacy or your informationEmail: privacy@odinma.com
Website: Contact Odinma
Registered office: 24 Well House Road, Leeds, England, LS8 4BS
View Odinma Limited at Companies House
Where a client places personal information about other people into a service that Odinma operates solely on that client's documented instructions, the client may be the controller and Odinma may act as its processor. In that situation, the client's privacy notice and the applicable service agreement or data-processing agreement also apply.
2. What this notice covers
This notice explains how Odinma handles personal information when you:
- visit odinma.com or submit an enquiry;
- communicate with us about consultancy, products or support;
- receive or accept a Client Workspace invitation;
- use an Odinma account or Client Workspace;
- take part in a project, approval, support or service-delivery workflow; or
- ask to receive marketing updates.
Separate customer agreements or notices may apply to independently hosted Odinma product applications.
3. Information we collect
Depending on how you interact with us, we may collect:
- your name, business email address, telephone number, organisation and role;
- the service you are interested in and the content of your enquiry or correspondence;
- bounded email-migration details such as domain or provider information, mailbox counts, approximate data size, preferred timing and whether DNS access is available;
- optional marketing preferences and the version of the privacy notice shown when you submitted a form;
- limited source or campaign information included in the current request;
- account details such as name, email address, account status and organisation membership;
- security information such as password hashes, login attempts, lock status, multi-factor authentication records, recovery-code hashes and audit events;
- project, milestone, message, document, approval, support and product-subscription information used to deliver services;
- document metadata and document bytes that authorised users upload; and
- a pseudonymous, HMAC-derived rate-limit fingerprint and a server-side session identifier used to protect forms and accounts. Odinma does not retain the raw network address or browser user-agent in its application database for this purpose.
Please do not submit patient information, health information, payment-card data, passwords, confidential third-party information or production credentials through the public enquiry form. Odinma does not intend to collect special-category or criminal-offence information through the website.
4. How we obtain information
We normally obtain personal information directly from you, from an organisation that authorises or invites you to use a service, or from an authorised colleague participating in the same project or workspace. We may also receive limited technical and delivery information from the service providers supporting the website and business email.
5. How and why we use information
| Purpose | Usual lawful basis |
|---|---|
| Responding to enquiries and taking requested steps before a contract | Contract or legitimate interests |
| Providing contracted consultancy, products, support and Client Workspace services | Contract |
| Managing accounts, organisations, projects, messages, documents and approvals | Contract or legitimate interests |
| Operating security controls, preventing misuse, maintaining audit records and protecting legal rights | Legitimate interests or legal obligation |
| Maintaining financial, company and regulatory records | Legal obligation |
| Sending optional marketing updates | Consent or another lawful route permitted for the communication |
Where we rely on legitimate interests, those interests include operating and improving our business services, responding to requested contact, maintaining service records, protecting systems and users, preventing misuse and handling legal claims. We consider whether those interests are necessary and balanced against the rights and reasonable expectations of the people concerned.
You do not have to provide information through the public enquiry form, but we may be unable to respond or provide the requested service without the required contact and enquiry details. Information required for an account or contracted service is identified in the relevant form or agreement.
6. Marketing
Odinma sends optional marketing email only where it has an appropriate permission or another lawful route that applies to the recipient and communication. The website's marketing option is unticked by default.
You can withdraw consent or object to direct marketing at any time by replying to the message or emailing privacy@odinma.com. We may retain a minimal suppression record so that we continue to respect your choice.
9. International transfers
The main website application, database and private document storage are hosted in OVHcloud's London region. Some providers, particularly global email or support providers and their subprocessors, may store or access personal information outside the United Kingdom.
Where a transfer is restricted under UK data-protection law, Odinma will rely on an applicable UK adequacy regulation or put in place an approved safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required data-protection assessment. You may ask privacy@odinma.com for further information about the safeguard relevant to your information.
10. How long we keep information
Odinma keeps personal information only for as long as it is reasonably needed for the purpose for which it was collected, including service, security, accounting and legal requirements. Our standard periods are:
| Record | Standard period |
|---|---|
| Enquiries that do not become a client relationship | Up to nine months and 15 days after the enquiry is closed |
| Marketing permission | Until consent is withdrawn or the contact has been inactive for two years; a minimal suppression record may be kept afterwards |
| Client accounts, memberships, project records, messages, approvals, support records and relevant documents | For the service relationship and normally up to six years after it ends or the relevant project closes, unless a shorter client instruction or a longer legal requirement applies |
| Expired or revoked invitations and account-security records not required for a continuing relationship | Reviewed for deletion after two years, unless linked to a retained contractual, security or audit record |
| Security and audit records | Normally up to two years, or longer where needed to investigate an incident, protect legal rights or support a retained contractual record |
| Application backups | Up to 35 days on a rolling basis; OVHcloud's standard VPS backup is retained for approximately 24 hours. A short-lived change snapshot may be retained only while the related rollback risk remains |
When information reaches the end of its period, we will delete or anonymise it unless there is a documented reason to retain it. Backup copies are protected from routine access and may remain until the applicable backup cycle expires. Legal holds, active disputes, fraud or security investigations may require limited information to be kept longer.
Client-controlled content may be subject to a different documented retention instruction in the applicable agreement.
11. Security
Odinma uses measures intended to protect personal information against unauthorised access, alteration, disclosure or loss. These include encrypted HTTPS connections, restricted administrator access, multi-factor authentication for website administrators, server-side sessions, access checks for organisation data, private document storage, database transport encryption, audit records and tested backups.
No internet service can guarantee absolute security. Please contact privacy@odinma.com if you believe information has been exposed or an account has been misused.
12. Your rights
Depending on the circumstances, UK data-protection law may give you the right to:
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information;
- ask us to restrict how information is used;
- object to processing based on legitimate interests or to direct marketing;
- receive certain information in a portable format; and
- withdraw consent where consent is the lawful basis.
These rights are not absolute and may be limited by legal, contractual, security or record-keeping requirements. To make a request, email privacy@odinma.com. We may need to verify your identity and clarify the information involved before acting.
13. Complaints
Please contact privacy@odinma.com first so that we can try to resolve your concern.
You may also complain to the UK Information Commissioner's Office. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113.
14. Automated decisions
Odinma does not use the personal information covered by this notice to make solely automated decisions that produce legal or similarly significant effects.
15. Children
The website and Client Workspace are intended for business users and are not directed at children. Please do not submit information about a child unless this has been expressly agreed for a lawful service purpose.
16. Changes to this notice
We may update this notice when our services, providers or legal obligations change. The version and effective date at the top of the page identify the notice currently in force. Material changes will be communicated through an appropriate channel where required.