Version 2026-08-03
This agreement governs how we process personal data on your behalf when you use our service. It forms part of the contract between us and applies for as long as you hold an account.
You are the controller. You decide what personal data goes into your Odoo instance — your customers, your contacts, your staff — and why. You remain responsible for having a lawful basis for it, and for informing the people concerned.
We are the processor. RAG Solutions (<SIREN / VAT / registration no.>), <street, postcode, city, country>, hosts and operates that instance for you. We process the data it contains only to provide the service, and only as described here.
For your own account data — your name, email address and subscription — we are the controller, not your processor. That processing is described in our privacy policy.
| Subject matter | Hosting and operation of an Odoo Community instance and its backups on your behalf. |
|---|---|
| Duration | For as long as your account exists, and for the limited period after termination described in section 9. |
| Nature and purpose | Storage, hosting, backup and restoration; provisioning and configuration of your instance; technical support you request; and any read or write operation you or a tool you have connected instruct us to perform. |
| Types of personal data | Whatever you choose to enter. Typically: contact details of your customers and prospects, commercial correspondence and notes, project and task assignments, and the names and accounts of your own staff who use the instance. |
| Categories of data subjects | Your customers, prospects, suppliers, employees and any other person whose data you enter. |
We do not decide what you store. If you enter special categories of data (health, biometrics, and the other categories in Article 9 GDPR) you remain responsible for the additional obligations that attach to them.
We process personal data in your instance only on your documented instructions. Your instructions are: this agreement, the settings you choose in the application, and the actions you perform or request — including actions performed through an AI assistant you have connected yourself.
We will process it otherwise only where EU or member-state law requires us to, in which case we will tell you before doing so unless that law forbids it. We do not use your instance data for our own purposes, we do not sell it, and we do not use it to train any model.
You may connect an AI assistant of your choosing to your account. If you do, the parts of your instance data that the assistant reads or changes are sent to the AI provider you selected, under your instruction. That provider is your processor, not our sub-processor: we do not choose it, we have no contract with it on your behalf, and its own terms govern what it does with the data. We never send your data to an AI provider on our own initiative. Revoking the credential ends that access immediately.
Access to your data is limited to the people who need it to operate the service. They are bound by an obligation of confidentiality that survives the end of their engagement with us.
We implement appropriate technical and organisational measures under Article 32 GDPR. They are listed in Annex 2. We may change them as the service evolves, provided the level of protection is not reduced.
You give us general authorisation to engage the sub-processors listed in Annex 3. We impose on each of them data protection obligations equivalent to those in this agreement, and we remain fully liable to you for their performance.
We will tell account holders by email before adding or replacing a sub-processor. If you object on reasonable data protection grounds you may terminate your subscription, and section 9 applies.
If we become aware of a personal data breach affecting your data, we will notify you without undue delay, and in any event within 48 hours of becoming aware of it. The notification will describe, as far as we know it at the time: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take. Where we cannot provide all of it at once, we will provide it in phases without undue further delay.
Notifying the supervisory authority under Article 33, and the data subjects under Article 34, remains your decision as controller. We will give you the information you need to make it.
You can export your full database yourself at any time, at no cost, from your dashboard — the export is a standard Odoo archive that another provider can restore. We do not charge for exporting or for leaving.
When your account is terminated, your data remains available for you to export for 30 days. After that, or earlier if you ask us in writing, we delete your instance database and your account data. Copies held in operational backups are deleted or overwritten within a further 90 days. We will confirm the deletion in writing on request. We keep nothing beyond that except where EU or member-state law requires us to.
We will make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits. In practice: send us your questions or your security questionnaire and we will answer them. An on-site or in-depth audit may be carried out once per calendar year, by you or an auditor you mandate who is not our competitor, on 30 days' written notice, during business hours, and without disrupting the service or the confidentiality of our other customers.
Your instance, its backups and your account data are stored in the European Union. We do not transfer them outside the European Economic Area.
One exception is under your own control: if you connect an AI assistant (section 3), that provider may be established outside the EEA. You choose the provider and instruct that transfer, so it is for you to ensure it has an appropriate transfer mechanism.
If this agreement changes materially we will publish a new version and ask you to accept it the next time you use the service. The version in force is shown at the top of this page. You can always read the current text here before accepting it.
This agreement is part of, and subject to, the contract between us. Where it conflicts with any other document on the subject of data protection, this one prevails.
Questions about this agreement, requests for assistance, breach notifications and deletion confirmations: mohamed@innova-advancedtech.com.
These are the measures in place today.
| Sub-processor | Purpose | Location |
|---|---|---|
| <your VPS provider's legal name> | Hosting of the platform, of your Odoo database and of its backups | <country where the VPS sits, e.g. Germany (EU)> |
| Google Ireland Limited | Sign-in only, for customers who choose "Continue with Google" — name, email address and Google account identifier. No instance data. | European Union |
Your own AI provider, if you connect an assistant, is not in this list — see section 3 for why.