Privacy

Privacy notice

How Odinma Limited handles personal information submitted through odinma.com and used in the Odinma Client Workspace.

Effective date
Version
2026-08-12

1. Who we are

Odinma Limited (company number 06836067), registered in England and Wales and trading as Odinma, is a software consultancy and product studio based in Leeds, United Kingdom.

For the personal information described in this notice, Odinma Limited is normally the data controller. This means we decide why and how that information is used.

Contact us about privacy or your information
Email: privacy@odinma.com
Website: Contact Odinma
Registered office: 24 Well House Road, Leeds, England, LS8 4BS
View Odinma Limited at Companies House

Where a client places personal information about other people into a service that Odinma operates solely on that client's documented instructions, the client may be the controller and Odinma may act as its processor. In that situation, the client's privacy notice and the applicable service agreement or data-processing agreement also apply.

2. What this notice covers

This notice explains how Odinma handles personal information when you:

  • visit odinma.com or submit an enquiry;
  • communicate with us about consultancy, products or support;
  • receive or accept a Client Workspace invitation;
  • use an Odinma account or Client Workspace;
  • take part in a project, approval, support or service-delivery workflow; or
  • ask to receive marketing updates.

Separate customer agreements or notices may apply to independently hosted Odinma product applications.

3. Information we collect

Depending on how you interact with us, we may collect:

  • your name, business email address, telephone number, organisation and role;
  • the service you are interested in and the content of your enquiry or correspondence;
  • bounded email-migration details such as domain or provider information, mailbox counts, approximate data size, preferred timing and whether DNS access is available;
  • optional marketing preferences and the version of the privacy notice shown when you submitted a form;
  • limited source or campaign information included in the current request;
  • account details such as name, email address, account status and organisation membership;
  • security information such as password hashes, login attempts, lock status, multi-factor authentication records, recovery-code hashes and audit events;
  • project, milestone, message, document, approval, support and product-subscription information used to deliver services;
  • document metadata and document bytes that authorised users upload; and
  • a pseudonymous, HMAC-derived rate-limit fingerprint and a server-side session identifier used to protect forms and accounts. Odinma does not retain the raw network address or browser user-agent in its application database for this purpose.

Please do not submit patient information, health information, payment-card data, passwords, confidential third-party information or production credentials through the public enquiry form. Odinma does not intend to collect special-category or criminal-offence information through the website.

4. How we obtain information

We normally obtain personal information directly from you, from an organisation that authorises or invites you to use a service, or from an authorised colleague participating in the same project or workspace. We may also receive limited technical and delivery information from the service providers supporting the website and business email.

5. How and why we use information

Purposes and usual lawful bases
PurposeUsual lawful basis
Responding to enquiries and taking requested steps before a contractContract or legitimate interests
Providing contracted consultancy, products, support and Client Workspace servicesContract
Managing accounts, organisations, projects, messages, documents and approvalsContract or legitimate interests
Operating security controls, preventing misuse, maintaining audit records and protecting legal rightsLegitimate interests or legal obligation
Maintaining financial, company and regulatory recordsLegal obligation
Sending optional marketing updatesConsent or another lawful route permitted for the communication

Where we rely on legitimate interests, those interests include operating and improving our business services, responding to requested contact, maintaining service records, protecting systems and users, preventing misuse and handling legal claims. We consider whether those interests are necessary and balanced against the rights and reasonable expectations of the people concerned.

You do not have to provide information through the public enquiry form, but we may be unable to respond or provide the requested service without the required contact and enquiry details. Information required for an account or contracted service is identified in the relevant form or agreement.

6. Marketing

Odinma sends optional marketing email only where it has an appropriate permission or another lawful route that applies to the recipient and communication. The website's marketing option is unticked by default.

You can withdraw consent or object to direct marketing at any time by replying to the message or emailing privacy@odinma.com. We may retain a minimal suppression record so that we continue to respect your choice.

7. Cookies and browser storage

The website uses one strictly necessary session cookie named ODINMASESSION. It supports server-side sessions, sign-in and protection against forged form submissions. It is a browser-session cookie, is HttpOnly, uses SameSite=Lax, and is Secure in production. The server ends an inactive session after 30 minutes.

The website does not currently use analytics cookies, advertising pixels, browser local storage, embedded advertising or other non-essential tracking. Because only essential storage is used, Odinma does not display a consent banner. If this changes, we will update this notice and introduce any consent controls required before non-essential technologies operate.

8. Who we share information with

We may share personal information only where necessary with:

  • OVHcloud, which provides the UK-hosted virtual server and backup infrastructure;
  • Google Workspace, which provides business email delivery and storage;
  • 123 Reg, which provides domain registration and DNS services;
  • network and security service providers supporting the website;
  • professional advisers, insurers, auditors or contractors who need the information for an authorised business purpose and are subject to appropriate duties;
  • regulators, courts, law-enforcement bodies or other authorities where disclosure is required or permitted by law; and
  • authorised users within your organisation where this is necessary to provide a shared workspace or service.

Odinma does not sell personal information. Service providers may use subprocessors only under their applicable contractual terms and data-protection obligations.

9. International transfers

The main website application, database and private document storage are hosted in OVHcloud's London region. Some providers, particularly global email or support providers and their subprocessors, may store or access personal information outside the United Kingdom.

Where a transfer is restricted under UK data-protection law, Odinma will rely on an applicable UK adequacy regulation or put in place an approved safeguard, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any required data-protection assessment. You may ask privacy@odinma.com for further information about the safeguard relevant to your information.

10. How long we keep information

Odinma keeps personal information only for as long as it is reasonably needed for the purpose for which it was collected, including service, security, accounting and legal requirements. Our standard periods are:

Standard retention periods
RecordStandard period
Enquiries that do not become a client relationshipUp to nine months and 15 days after the enquiry is closed
Marketing permissionUntil consent is withdrawn or the contact has been inactive for two years; a minimal suppression record may be kept afterwards
Client accounts, memberships, project records, messages, approvals, support records and relevant documentsFor the service relationship and normally up to six years after it ends or the relevant project closes, unless a shorter client instruction or a longer legal requirement applies
Expired or revoked invitations and account-security records not required for a continuing relationshipReviewed for deletion after two years, unless linked to a retained contractual, security or audit record
Security and audit recordsNormally up to two years, or longer where needed to investigate an incident, protect legal rights or support a retained contractual record
Application backupsUp to 35 days on a rolling basis; OVHcloud's standard VPS backup is retained for approximately 24 hours. A short-lived change snapshot may be retained only while the related rollback risk remains

When information reaches the end of its period, we will delete or anonymise it unless there is a documented reason to retain it. Backup copies are protected from routine access and may remain until the applicable backup cycle expires. Legal holds, active disputes, fraud or security investigations may require limited information to be kept longer.

Client-controlled content may be subject to a different documented retention instruction in the applicable agreement.

11. Security

Odinma uses measures intended to protect personal information against unauthorised access, alteration, disclosure or loss. These include encrypted HTTPS connections, restricted administrator access, multi-factor authentication for website administrators, server-side sessions, access checks for organisation data, private document storage, database transport encryption, audit records and tested backups.

No internet service can guarantee absolute security. Please contact privacy@odinma.com if you believe information has been exposed or an account has been misused.

12. Your rights

Depending on the circumstances, UK data-protection law may give you the right to:

  • ask for access to your personal information;
  • ask us to correct inaccurate or incomplete information;
  • ask us to erase information;
  • ask us to restrict how information is used;
  • object to processing based on legitimate interests or to direct marketing;
  • receive certain information in a portable format; and
  • withdraw consent where consent is the lawful basis.

These rights are not absolute and may be limited by legal, contractual, security or record-keeping requirements. To make a request, email privacy@odinma.com. We may need to verify your identity and clarify the information involved before acting.

13. Complaints

Please contact privacy@odinma.com first so that we can try to resolve your concern.

You may also complain to the UK Information Commissioner's Office. Visit ico.org.uk/make-a-complaint or telephone 0303 123 1113.

14. Automated decisions

Odinma does not use the personal information covered by this notice to make solely automated decisions that produce legal or similarly significant effects.

15. Children

The website and Client Workspace are intended for business users and are not directed at children. Please do not submit information about a child unless this has been expressly agreed for a lawful service purpose.

16. Changes to this notice

We may update this notice when our services, providers or legal obligations change. The version and effective date at the top of the page identify the notice currently in force. Material changes will be communicated through an appropriate channel where required.