odoma.app · dashboard.odoma.app

Privacy Policy

Effective date: 4 September 2026 · ODOMA SERVICES OSAÜHING · Tallinn, Estonia · GDPR, notice under Articles 13 and 14
In short. The Odoma dashboard is a company's tool. Data on trips, receipts, sites and invoices belongs to the company that uses it, and we process it on the company's instructions. The mobile apps themselves are published by the non-profit association Odoma Digipädevuse Selts, which has its own policy. Only work trips from a phone that the person has connected themselves reach the dashboard; personal trips stay on the phone.
1. Who we are
2. Two roles: the company and us
3. What we store
4. What we do not store
5. Where the data is and who else sees it
6. How long we keep it
7. Legal bases
8. Your rights
9. Security
10. Cookies and browser storage
11. Children
12. Changes

1. Who we are

This policy applies to the website odoma.app and the web dashboard dashboard.odoma.app (the “dashboard”). Their operator is ODOMA SERVICES OSAÜHING, registry code 17589729, VAT number EE103025241, Tallinn, Harju maakond, Estonia (“we”).

The mobile apps Odoma Tracker and Odoma Checkit are published by the non-profit association Odoma Digipädevuse Selts (reg. no. 80659718). Everything the app does on the phone is described in the apps' privacy policy. This policy begins where data from the phone, by the person's decision, reaches their employer's dashboard.

For questions about data write to privacy@odoma.ee. We respond within 30 days.

2. Two roles: the company and us

The company is the controller. The company that opens an account in the dashboard decides which employees are connected, which trips, receipts, customers and invoices are kept in it, and which of its people get access. Within the meaning of the GDPR the company is the controller of this data and we are the processor acting on its instructions (Article 28). Using the dashboard for its intended purpose counts as the instruction; the processing terms are part of the terms of use. An employee whose data the company keeps turns first to the company for access, rectification or erasure; we help the company fulfil such a request.

We are the controller for the data needed for the account and the agreement to exist: the email address and name of the account owner, company details, plan invoices and their payment, support requests, technical logs of the service.

3. What we store

3.1 Account and company (we are the controller)

3.2 Company data in the dashboard (the company is the controller, we are the processor)

3.3 Phone diagnostic logs

The phone sends us diagnostic logs only in developer mode, which the person enables themselves in the app settings. Such logs may contain coordinates and details of the tracker's operation and are needed to investigate errors. In normal operation they are not sent to the server.

4. What we do not store

5. Where the data is and who else sees it

WhoWhyWhere
Google Cloud / Firebasedatabase, files (receipt photos, PDFs, logs), server, account sign-indatabase — region europe-west2 (London, United Kingdom; transfer on the basis of the European Commission's adequacy decision, valid until 27.12.2031); files and server — europe-west3 (Frankfurt, EU)
Brevo (Sendinblue)sending email: invoices to the company's customers, plan emails, address confirmations; receiving email to odoma.app addressesEU
Google Cloud Translationtranslating support requests into Russian for the operatorEU / under Google Cloud rules
Telegrama copy of support requests goes to the operator in Telegram so that we can reply quicklyTelegram servers
Apple, Googleaccount sign-in via the “Sign in with…” buttonunder the sign-in provider's rules
Montonioonline payment of invoices by the company's customers — only if the company has connected itEU
Estonian Business Registersuggesting the company name and code from open dataopen data, not personal

Database backups are made automatically: daily backups are kept for 7 days, weekly for 98 days; once a week a copy is exported to a separate storage in the EU with a 30-day deletion lock, and old copies are deleted no later than 12 months.

6. How long we keep it

8. Your rights

The account owner can at any time in the dashboard: export all company data as a single archive (Settings → Data → Export: records, receipt photos, invoice PDFs), correct company details and records, delete the company with a 30-day cancellation window. An employee of a company turns to their company; if the company does not respond, write to us and we will help.

Access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21) — by email to privacy@odoma.ee. A complaint can be lodged with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).

9. Security

10. Cookies and browser storage

The website odoma.app sets no cookies and uses no counters. The dashboard stores sign-in data (Firebase Authentication) and your screen settings in the browser's localStorage; there are no third-party cookies.

11. Children

The dashboard is intended for companies and their employees. We do not open accounts for persons under 16.

12. Changes

We announce material changes by email to the account address and update the date at the top of the page.

This policy is drawn up in Estonian, Russian and English; in the event of a discrepancy between the versions, the Estonian version prevails.

Change log