Legal
Data Security
Last updated: 11 July 2026
1. Our approach
Security is built into how we deliver Odoo, not added on afterwards. This page describes the measures and the architecture we work with to protect client data and systems. We describe what the architecture supports and how we configure it; we do not claim ISO, SOC, or other formal certifications, and we do not claim to have completed external security audits we do not hold.
2. Hosting
Odoo systems we deliver run on Odoo.sh — Odoo's official managed cloud platform — or on infrastructure the client controls. Each client runs their own Odoo instance. Client data is not pooled across clients. The Odoo.sh subscription is contracted by the client directly with Odoo, and the platform's own infrastructure security applies.
3. Access control
We configure Odoo for least-privilege access: users get only the permissions their role requires. We use individual accounts rather than shared logins, and role-based permissions within Odoo so that each user sees and can change only what they should. Administrative access is limited to those who need it.
4. Data in transit
Access to Odoo systems we deliver is over encrypted connections using HTTPS/TLS, so data moving between users' browsers and the server is protected in transit.
5. Backups and recovery
On Odoo.sh, the platform provides managed backups of the production database on a regular schedule, which supports recovery if data is lost or corrupted. As part of delivery, we help establish recovery procedures so a system can be restored to a recent point when needed. Where a client hosts on their own infrastructure, backup and recovery are configured to that environment.
6. Staff confidentiality
Our team is bound by confidentiality obligations. We access client systems only as needed to deliver and support the work — for configuration, development, troubleshooting, and support — and not for any other purpose.
7. Vendor screening capability
For NGO and compliance-sensitive clients, Odoo can be configured to support vendor and counterparty screening — for example, checking suppliers against sanctions or OFAC lists as part of the procurement workflow. This is a capability we can configure where a client's compliance needs call for it; the screening decisions and obligations remain with the client.
8. Responsible disclosure
If you believe you have found a security vulnerability or a data-handling concern relating to our website or a system we deliver, please report it to [email protected]. Give us enough detail to reproduce and assess the issue, and allow us reasonable time to investigate and respond before disclosing it publicly. We appreciate reports made in good faith.
9. Your responsibilities
Security is a shared responsibility. On the client side, we ask that you maintain good password hygiene, keep user accounts and permissions up to date, remove access when staff leave, and follow the access practices we set up together. Strong day-to-day habits by your team are an essential part of keeping the system secure.
10. Related
For how we handle personal data collected through this website, see our Privacy Policy.
11. Contact
Questions about data security? Contact us at [email protected] or +968 90669347.