OdooConsole
Pricing Blog MCP reference Open console
Legal

Privacy Policy

Last updated 11 August 2026

OdooConsole is operated by Cybergarden Software (“we”, “us”). This policy explains what we collect, why, who we share it with, and the choices you have. It covers the marketing site, the console, and the hosted Odoo instances and MCP endpoints we run for you (the “Service”).

1. Who is responsible for your data

For your account and billing data, we are the data controller. For the business records you put inside your Odoo instance, you are the controller and we are your processor — we host and safeguard that data and act on your instructions, but it is yours.

2. What we collect

CategoryExamplesWhy
AccountEmail, name, a securely hashed password (or a Google sign-in identifier), your company nameTo create and secure your account and name your instances
BillingPlan, subscription status, and a Stripe customer reference. We never see or store full card numbers.To take payment and enforce plan limits
Instance dataThe ERP records, files, and users inside the Odoo instances you createTo provide the hosted instance you asked for
Connection grantsWhich AI connectors you have authorised, and their scopesSo you can see and revoke access
TechnicalServer and access logs, IP address, timestamps, minimal audit records of MCP tool callsSecurity, abuse prevention, and debugging

We do not run third-party advertising or analytics trackers on the console, and we do not sell your data to anyone.

3. Payments

Payments are processed by Stripe. When you subscribe, your card details are entered on Stripe’s secure checkout and are held by Stripe, not by us. We receive only a customer reference and your subscription status.

4. How we use it

  • To provide, maintain, and secure the Service.
  • To take recurring payment for paid plans and enforce plan limits.
  • To respond to support requests and send essential service notices (for example, a failed payment or a security matter).
  • To detect, prevent, and investigate abuse, fraud, and security incidents.
  • To meet legal and accounting obligations.

5. Who we share it with (subprocessors)

We use a small set of providers to run the Service. They act on our instructions and only receive what they need:

ProviderPurposeWhere
Oracle Cloud InfrastructureHosting and storage of instances and databasesSydney, Australia
StripePayment processing and subscription managementGlobal
GoogleOptional “Sign in with Google” only, if you choose itGlobal

We may also disclose data if required by law, or to protect the rights, safety, and security of our users and the Service.

6. Where your data is stored

Your instances and databases are hosted in Oracle Cloud’s Sydney, Australia region. Some subprocessors (Stripe, Google) may process limited data in other countries; where they do, they provide their own safeguards for international transfers.

7. How long we keep it

We keep your account and instance data for as long as your account is active. When you delete an instance, its database and files are removed. When you close your account, we delete your instances and personal data within 30 days, except records we must retain for legal, tax, or fraud-prevention reasons (for example, invoices).

8. Security

Passwords are hashed with a strong, salted algorithm. Each instance runs in its own isolated network with a database role scoped to that instance alone. Traffic is encrypted in transit (TLS). AI connectors reach your data only through an authorised, scoped OAuth grant that you can revoke at any time. No system is perfectly secure, but we design for isolation and least privilege by default.

9. Your rights

You can access, correct, export, or delete your data. Because instances are standard Odoo, you can ask us for a PostgreSQL dump and your filestore at any time — no export fee, no notice period. Depending on where you live, you may have additional rights under the Australian Privacy Act, the GDPR, or other laws, including the right to complain to your data protection authority. To exercise any of these, email us.

10. Children

The Service is not directed to anyone under 16, and we do not knowingly collect their data.

11. Changes

We may update this policy. If we make a material change, we will update the date above and, where appropriate, notify you by email.

12. Contact

Questions or requests: almaz@cybergarden.au.

This policy is provided in good faith to describe how the Service handles data. It is not legal advice; if you rely on OdooConsole for regulated or high-risk data, review your own obligations with a qualified professional.
© 2026 OdooConsole
Pricing · Blog · MCP reference · Privacy · Terms · Contact