Privacy notice

What this platform collects, why it collects it, who else sees it, and what you can ask us to do about it — including your Odoo data, your Git credentials, and what happens when you use the AI features.

Last updated August 14, 2026

1. Who is responsible for your data

Two different situations, with different consequences, and it is worth knowing which one you are in.

If you signed up directly, we are the controller for your account, your team and your billing data: you deal with us and your rights are exercised against us.

If your environment was sold to you by an integrator using this platform, that integrator is the controller. We act as a processor on their instructions. Your requests go to them first, and we will tell you who they are if you ask.

2. What we collect

Grouped by why it exists rather than by where it is stored.

  • Account and identity: name, email address, preferred language, the teams you belong to and your role in each. Authentication is handled by Keycloak; we never see your password.
  • Billing: your team country and the currency that follows from it, invoices, wallet balance and credit history, and the references returned by the payment provider. Card numbers and mobile-money credentials are handled by the provider and never reach us.
  • Operational: the environments you create, their plan and size, deployment and build history, build logs, resource metrics and the application logs of your own environments.
  • Content you place on the platform: your Odoo database and its filestore, and the repositories you connect.
  • Support: the messages you send us and what is in them.
  • Site usage: session cookies and your language and theme preference. No advertising or cross-site tracking cookies.

3. Your Odoo data

The contents of your Odoo database are yours. We store them, back them up and restore them on your instruction. We do not read them in the ordinary course of running the service.

An engineer may access an environment when it is necessary to diagnose a fault, and only for that. This includes any personal data your own business holds in Odoo — customers, employees, invoices — for which you are the controller and we are the processor.

4. Repository access

Connecting a repository stores a credential for it. It is encrypted at rest and used for one purpose: reading the branch being built, and writing back only when you explicitly ask for a commit.

Revoking access on the provider side, or disconnecting the repository here, ends that access immediately.

5. AI features

This one deserves reading before you use them rather than after.

When you use the AI module developer or the AI workspace, what you submit is sent to a third-party language model provider to be processed. That includes your prompts and the repository files the agent reads while working — which it selects itself, so the set is wider than what you typed.

Which provider receives it is a configuration choice of whoever operates this platform; typically Anthropic or an OpenAI-compatible endpoint. Ask us which one is configured if it matters to you, and it should.

Consequently: do not point the AI features at a repository containing secrets or personal data you are not permitted to share with that provider. The AI features are optional and the rest of the platform works without them.

6. Why we process it, and on what basis

  • To provide what you signed up for — creating environments, running them, billing them. Basis: performance of a contract.
  • To keep the platform secure and to detect abuse and fraud. Basis: our legitimate interest, and yours.
  • To issue invoices and keep accounting records. Basis: a legal obligation.
  • To send service messages you cannot opt out of while you hold an account — an invoice, a suspension warning, a security notice. Basis: performance of a contract.
  • To send anything promotional. Basis: your consent, withdrawable at any time, in your notification preferences.

7. Who else is involved

We do not sell personal data and we do not share it for advertising. The service needs these categories of provider to work:

  • Infrastructure hosting the cluster your environments run on.
  • Object storage holding backups and uploaded artefacts.
  • Payment providers, including mobile money, which handle payment credentials directly.
  • Email delivery for notifications and invoices.
  • Language model providers, only when you use the AI features.

8. How long we keep it

  • Account and team data: while the account exists, then deleted or anonymised.
  • Invoices and payment records: for the period accounting and tax law requires, which is longer than your account and which we cannot shorten on request.
  • Environment data and backups: while the environment exists, plus its backup retention. Deleting an environment starts the deletion of its data.
  • Logs and metrics: a rolling window for operating and investigating incidents.
  • A suspended team keeps its data during the recovery period described in the terms. Final purge is a deliberate, irreversible administrative action, not an automatic one.

9. Your rights

You can ask for a copy of your personal data, ask us to correct it, ask us to delete it, ask for it in a portable form, and object to processing based on legitimate interest.

Write to the privacy address on the contact page. We may need to confirm your identity first — which is a protection for you, since the alternative is handing your data to whoever asks for it. We answer within one month.

If the answer does not satisfy you, you can complain to the data protection authority where you live.

10. Cookies

The site sets a session cookie so you stay signed in, and stores your language and theme so the interface does not reset on every visit. That is all.

There are no advertising cookies, no cross-site trackers and no third-party analytics embedded in the pages. Blocking cookies entirely will prevent you from signing in.

11. International transfers

Where your data physically sits depends on where this deployment runs; it is named in the legal information on the about page.

Some providers listed above operate outside that region. Where they do, transfers rely on the safeguards the law provides, such as standard contractual clauses.

12. Security

How environments are isolated, what is encrypted, who can access what, and how to report a vulnerability are described on the security page rather than summarised into a sentence here.

13. Changes to this notice

The date at the top moves whenever the substance changes. A change that affects how we process your data is notified to account holders before it takes effect, not after.