Legal
Data processing agreement
The Art. 28 GDPR agreement between Hawklify and customer organisations for the data processed in their Odoo.
Last updated: 2 October 2026
This agreement supplements the terms of service and governs, under Art. 28 GDPR, the personal data that Marcello Gallo (sole trader), trading as Hawklify (the provider, processor) processes on behalf of the customer organisation (the customer, controller) in providing Hawklify. Where it conflicts with the terms of service, this agreement prevails on data protection.
1. Subject matter and duration
The provider processes the customer's personal data only to provide the service described in the terms, for the whole relationship and until the deletion set out in section 10.
2. Nature and purpose
The service reads and, only after a user's confirmation, changes data in the customer's Odoo at the request of users authorised by the customer, through the AI assistant the customer chose; it keeps the accounts, the encrypted API keys and the change log.
3. Data and data subjects
- Types of data: whatever the customer's users have the assistant read or write in Odoo (for example records of customers, suppliers and employees, contacts, sales and accounting documents, messages), the customer's users' account data and their API keys.
- Data subjects: the customer's users and the people whose data is in the customer's Odoo (customers, suppliers, employees, contacts).
- The service is not designed for special categories of data (Art. 9 GDPR): if Odoo holds any, the customer restricts access with the service's roles and hidden fields or with Odoo's permissions.
4. The customer's instructions
The provider processes the data only on the customer's documented instructions. Instructions are the terms of service, the customer's settings in the service (users, roles, allowed models and methods, hidden fields) and the requests the customer's users make through the assistant. The provider tells the customer if it believes an instruction infringes data protection law.
5. Confidentiality
The people the provider authorises to process the data are bound by confidentiality and access the data only when needed to provide or protect the service.
6. Security measures
- Encrypted connections (TLS) between users, assistants, the service and Odoo.
- API keys, GitHub tokens, client secrets and second-step secrets encrypted in the database (Fernet: AES-128 with HMAC-SHA256), with a key kept outside the database.
- Passwords kept as argon2id hashes; OAuth tokens as SHA-256 hashes; access tokens valid for one hour.
- Every user acts as their own Odoo user, hence under Odoo's access rules; on top of them, the roles, allowed models and methods and hidden fields set by the customer.
- Changes only after preview, validation and confirmation; change log.
- Isolation between organisations; second step mandatory for the provider's administrators; the service runs without system administrator privileges.
- Daily database backups, kept 14 days.
7. Sub-processors
The customer authorises the provider to engage the following sub-processors, bound by obligations equivalent to those of this agreement: Fly.io, Frankfurt (Germany) (hosting of the service and database) and Resend (Plus Five Five, Inc., United States) (delivery of service e-mails). The provider notifies the customer's administrator by e-mail at least 30 days before adding or replacing one; if the customer objects on reasonable grounds it may terminate without penalty.
The providers of AI assistants are not the provider's sub-processors: the customer chooses and connects them and governs that relationship.
8. Assistance to the customer
The provider helps the customer, as far as reasonable, to answer data subjects' requests and to carry out impact assessments and prior consultations, and informs it of a personal data breach without undue delay and in any case within 48 hours of becoming aware of it, with the information available.
9. Transfers
Data is processed in the European Economic Area, except as stated for the sub-processors. Any transfer outside the EEA takes place only with the safeguards of Chapter V GDPR, such as an adequacy decision or the standard contractual clauses. The delivery of service e-mails by Resend takes place in the United States, under the EU-U.S. Data Privacy Framework and the standard contractual clauses.
10. Deletion at the end of the relationship
When the organisation is closed, the provider deletes within 30 days the customer's accounts, API keys and other settings, unless the law requires otherwise. Backups run out within 14 days and the change log within 365 days. Odoo data is not copied by the service and stays in the customer's Odoo.
11. Audits
The provider makes available the information needed to demonstrate compliance with this agreement. The customer may carry out an audit, at its own expense, with 30 days' notice, at most once a year unless there has been a breach, also through an auditor bound by confidentiality.