Privacy Notice
This notice explains how ODEARO LTD handles personal information through odearo.com, business inquiries, secure client intake, and delivery of ODEARO services.
1. Scope and our role
This Privacy Notice applies to personal information ODEARO LTD collects or receives through this website, business communications, secure client intake, and ODEARO RECOVER engagements. Depending on the activity, ODEARO may act as a data controller/business for its own business-contact and website information, or as a processor/service provider when handling client-provided customer data under a client agreement.
Client contracts, statements of work, data-processing terms, and written instructions may impose additional obligations. Where those documents conflict with this public notice for client-processed data, the applicable signed agreement governs to the extent permitted by law.
2. Information we may collect
Depending on how you interact with ODEARO, we may collect:
- Business contact information, such as name, company, company email address, business telephone number, role, and CRM/FSM information.
- Inquiry and communications information, including messages, inquiry numbers, status, responses, and correspondence.
- Client intake information, including engagement tier, agreed fees, data period, data-ownership confirmations, invitation status, and linkage to an approved RECOVER client.
- Client-provided operational data, such as approved CSV/XLSX exports containing estimates, opportunities, contact details, service information, suppression instructions, follow-up history, and outcome evidence needed for the agreed service.
- Security and technical information, such as IP-derived security hashes, timestamps, session information, file metadata, MIME type, file size, generated storage identifiers, and SHA-256 checksums.
ODEARO does not ask for consumer payment-card information through the secure data-upload workflow and does not intentionally request special-category/sensitive personal information unless it is specifically required, lawful, and covered by appropriate written terms.
3. Why we use personal information
We use information to respond to legitimate business inquiries; qualify prospective business clients; provide and administer contracted services; securely receive, validate, classify, and review approved client data; apply suppression and do-not-contact instructions; manage recovery actions; attribute and report outcomes; protect the website and systems; maintain audit records; comply with legal obligations; establish, exercise, or defend legal claims; and improve service quality and operational controls.
4. Legal bases for UK and EEA processing
Where the UK GDPR or EU GDPR applies, ODEARO relies on one or more lawful bases appropriate to the activity, including performance of a contract or steps requested before entering a contract, legitimate interests in operating and protecting a B2B service and responding to business communications, compliance with legal obligations, and consent where consent is legally required. Where ODEARO processes personal information solely on a client's documented instructions, the client is generally responsible for determining the applicable lawful basis for that underlying processing.
5. U.S. privacy disclosures
ODEARO is a B2B-focused service. U.S. privacy rights vary by state and may apply only when statutory thresholds and other conditions are met. Where applicable law grants rights, eligible individuals may request access/knowledge, correction, deletion, or a portable copy of covered personal information, and may have rights to opt out of certain sale, sharing, targeted advertising, or profiling activities.
Current ODEARO practice: ODEARO does not sell personal information for money and does not use personal information collected through this website or RECOVER secure intake for cross-context behavioral advertising or targeted advertising. ODEARO does not knowingly use sensitive personal information to infer characteristics about individuals.
California notice
For California residents, categories that may be collected can include identifiers/business contact information, internet or security activity, professional or employment-related business information, and commercial/operational records supplied in a business context. These categories are used for the business purposes described above. Where the CCPA/CPRA applies, eligible California residents may exercise applicable rights without unlawful discrimination. ODEARO does not offer financial incentives in exchange for personal information.
6. Business-email requirement
The public inquiry form is intended for business use. ODEARO requires a valid company/business email address and may reject commonly used consumer or free-email domains. This validation supports B2B qualification and abuse prevention; it is not a guarantee that any domain belongs to a particular employer or authorised representative.
7. Client data, suppression, and communication controls
Clients must be authorised to provide data to ODEARO and are responsible for the lawfulness of their collection and disclosure of that data. ODEARO requires clients to provide applicable suppression, opt-out, do-not-contact, dispute, and other control information relevant to the agreed work. ODEARO's recovery workflow is designed to preserve those controls and does not treat the existence of an estimate or opportunity as permission to disregard applicable privacy or communications rules.
8. Secure uploads and file handling
Approved client uploads are invitation-bound and are staged for validation before admission into RECOVER. ODEARO records the original filename as metadata, generates a separate storage filename, records file type and size, and generates a SHA-256 checksum to support integrity and auditability. A received file is not automatically classified as recoverable revenue or admitted into the RECOVER data truth. File acceptance does not itself confirm that the contents are lawful, accurate, complete, malware-free, or within scope.
9. Sharing and service providers
ODEARO may disclose information to hosting, email, security, professional-adviser, and technology providers where reasonably necessary to operate the service, subject to appropriate contractual and security controls where required. ODEARO may also disclose information when required by law, court order, legal process, or to protect legal rights, safety, systems, and users. We do not disclose client data to unrelated third parties for their own marketing.
10. International data transfers
ODEARO operates from the United Kingdom and serves U.S. and international businesses. Personal information may therefore be processed in more than one country. Where UK GDPR or EU GDPR transfer restrictions apply, ODEARO will use a legally recognised transfer mechanism as appropriate to the transfer, which may include an adequacy decision/regulation, the UK International Data Transfer Agreement or UK Addendum, EU Standard Contractual Clauses, or another lawful safeguard. The exact mechanism can depend on the parties, service providers, and destination country.
11. Retention
ODEARO retains personal information only for as long as reasonably necessary for the purpose collected, contractual and operational requirements, security, auditability, dispute resolution, and applicable legal or regulatory obligations. Retention periods may vary by record type and client agreement. Secure upload and client-delivery retention rules may be specified in the applicable engagement documentation. When information is no longer required, ODEARO will delete, anonymise, or securely dispose of it where reasonably practicable and legally permitted.
12. Security
ODEARO uses administrative, technical, and organisational safeguards appropriate to the nature of the information and the service. Current controls include restricted administrative access, secure-session settings, invitation tokens for client uploads, server-side file validation, private/staged file handling, generated storage filenames, integrity checksums, and audit records. No internet transmission or storage system can be guaranteed to be completely secure.
13. Cookies and similar technologies
The current public ODEARO website does not intentionally deploy third-party advertising pixels or behavioral advertising cookies. ODEARO's administrative and secure-upload functions may use strictly necessary session cookies to maintain authenticated or invitation-bound sessions and protect security. If ODEARO later introduces analytics, advertising, or other non-essential cookies, this notice and any required consent controls should be updated before those technologies are enabled.
14. Your rights and requests
Depending on your location and applicable law, you may have rights to obtain information about processing; access personal information; correct inaccurate information; request deletion; restrict or object to certain processing; receive portable information; withdraw consent where processing is based on consent; and complain to an applicable supervisory authority. Some rights are subject to exceptions, identity verification, legal thresholds, and the role ODEARO is performing.
To submit a privacy request, email tariq@odearo.com with enough information for us to understand and verify the request. If ODEARO processes the relevant information only on behalf of a client, we may direct the request to that client or assist the client in responding as required by contract and law.
15. Children
ODEARO is a business-to-business service and is not directed to children. We do not knowingly solicit personal information from children through this website. If you believe a child has provided information to ODEARO, contact us so we can assess and take appropriate action.
16. Changes to this notice
We may update this Privacy Notice as our services, technologies, providers, or legal obligations change. The updated version will be posted on this page with a revised date. Material changes may also be communicated through other reasonable means where appropriate.
17. Regulatory contacts
Where applicable, individuals in the United Kingdom may have the right to complain to the UK Information Commissioner's Office, and individuals in the EEA may complain to their competent data protection authority. U.S. residents may also have rights to contact relevant state regulators or attorneys general where state law provides.