Legal
Privacy policy
How Hawklify processes the personal data of people who visit the site, register and use the service.
Last updated: 2 October 2026
This notice, given under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), explains which personal data Hawklify processes, why, for how long, and what your rights are.
1. Who the controller is
The controller is Marcello Gallo (sole trader), trading as Hawklify, registered office Via Roma 148, Sant’Antimo (NA), Italia, VAT number IT10786761212. For any privacy question write to info@hawklify.com.
We are the controller of the data needed to handle access requests, accounts and the security of the service. For the data the assistant reads or changes in your organisation's Odoo we act instead as a processor on behalf of the organisation, which remains its controller: that processing is governed by the data processing agreement.
2. What data we process
- Registration: name, work e-mail, company, registration date and original trial end. Odoo URL, database and transport are collected during setup. Legacy access requests also include expected users and an optional message.
- Free trials: to grant one trial per mailbox and per Odoo database we also keep, with the account, a normalised form of the e-mail (without dots and “+” tags where the provider ignores them), the number of new registrations per day (no personal data) and, when a trial is deleted, a non-reversible fingerprint (HMAC with a secret key) of its e-mail and of its Odoo address and database.
- Account: e-mail, name if you give one, organisation, role and permissions set by your administrator, creation and last sign-in dates. The password is kept only as a hash (argon2id); the second-step secret is encrypted. If you sign in with Google or GitHub we keep only that account's identifier and the verified e-mail address it reported, never its password.
- Credentials: your Odoo user's API key, which you enter yourself on a protected page and which we store encrypted and, for administrators, the organisation's GitHub tokens and repositories. They are encrypted in our database and never shown or sent to the assistant.
- Connected applications: name and addresses of the application you authorise (for example Claude or ChatGPT), date of last use and the access tokens, kept only as hashes.
- Technical data: IP address, date and requested page in the server logs; the IP address is also used, in memory only, to limit sign-in attempts.
- Contact form: the name, e-mail, company (if given), topic and message you write in the contact form of the website. The website sends them by e-mail to us and does not store them.
- Website visits: the website is hosted by Cloudflare, which processes the technical data of each request (such as IP address and requested page) to deliver and protect the site. We use no analytics.
- Change log: for every write to Odoo made through the service, who made it, when, on which model and which records. It does not contain the values written.
3. The data in your Odoo
When you ask the assistant something, the service reads the data it needs from Odoo as your Odoo user and passes it to the assistant. We make no lasting copy of it: only the search index you build with the indexing tool (deleted after an hour without use), the results of long-running operations (one hour) and the changes you have validated but not yet confirmed (ten minutes) stay briefly, in memory and encrypted in our database so that every server of the service can use them. Changes to Odoo happen only after a preview and your confirmation.
4. The AI assistants you connect
You, or your organisation, choose the assistant (Claude, ChatGPT, Cursor, VS Code or another MCP client). The data read from Odoo reaches the assistant because you asked for it, and from then on the assistant's provider processes it under the contract and privacy policy it has with you or your organisation. We are not part of that relationship and send the assistant nothing else.
5. Why we process it and on what basis
- Answering your access request: pre-contractual steps (Art. 6(1)(b) GDPR).
- Providing the service, managing the account, sending you invitations and password reset links: performance of the contract with your organisation (Art. 6(1)(b)).
- Protecting the service, preventing abuse and tracing the changes made to Odoo: our legitimate interest and your organisation's (Art. 6(1)(f)).
- Answering the message you send through the contact form: pre-contractual steps and our legitimate interest in replying (Art. 6(1)(b) and (f)).
- Complying with legal obligations, such as tax rules: Art. 6(1)(c).
We do not use your data for advertising, we do not sell it and we make no automated decisions about you.
6. Cookies
The website uses no cookies; it keeps only your choice of language and light or dark theme in your browser's local storage, and does not send it to us. The service's pages use technical cookies only: the session after sign-in (12 hours), form protection (one hour) and the chosen language (one year). We use no profiling cookies and no analytics. The anti-spam check on the contact form and, when enabled, on the access request form is provided by Cloudflare Turnstile.
7. Who we share it with
The providers we need to run the service, appointed as processors: the hosting provider (Fly.io, Frankfurt (Germany)), the e-mail delivery provider (Resend (Plus Five Five, Inc., United States)) and Cloudflare (hosting of the website and anti-spam check). The contact form messages are delivered to us by Resend. Our authorised staff, bound by confidentiality. Authorities, only when the law requires it.
8. Transfers outside the European Union
The service and its database are hosted by Fly.io, Frankfurt (Germany). When a provider processes data outside the European Economic Area, it does so under an adequacy decision (such as the EU-U.S. Data Privacy Framework) or the European Commission's standard contractual clauses. In particular, service e-mails (invitations, activation, password reset) are sent through Resend, which processes data in the United States under the EU-U.S. Data Privacy Framework and the standard contractual clauses. The same applies to messages sent through the contact form, and to Cloudflare, which hosts the website and runs the anti-spam check.
9. How long we keep it
- Messages sent through the contact form: in our mailbox for as long as needed to answer you and follow up, then deleted.
- Access requests: until the decision, then 180 days.
- Registrations never activated (no password chosen): 7 days, or less if your organisation invites you with the same e-mail meanwhile.
- Expired trial organisations not converted to a paid plan: 30 days after the last day of the trial, with an e-mail notice to their administrators 7 days before; then we delete them with their accounts, credentials and settings.
- Fingerprints of deleted trials (e-mail and Odoo, non-reversible): 365 days from the deletion.
- Account, credentials and connected applications: as long as the account exists. Your organisation's administrator can delete it at any time, and someone on a trial can delete their own trial from Security; at the end of the contract we delete them as the data processing agreement provides.
- Application tokens: one hour for access tokens, 30 days for refresh tokens; invitation links 7 days, password reset links 30 minutes.
- Change log: 365 days.
- Number of requests to the assistant per user per day (for the daily limit): 90 days.
- Odoo data kept briefly (search index, results of long-running operations, changes awaiting confirmation): one hour at most; encrypted, it can remain in database backups until they expire.
- Server logs: they rotate and are overwritten, usually within a few days.
- Database backups: 14 days.
10. How we protect it
Connections always encrypted (HTTPS); keys and secrets encrypted in the database with a key kept elsewhere; passwords and tokens kept only as hashes; second step mandatory for our administrators; the assistant works as your Odoo user with the permissions Odoo gives you, plus the limits set by your administrator.
11. Your rights
You can ask us at any time for access to your data, rectification, erasure, restriction of processing and portability, and you can object to processing based on legitimate interest, by writing to info@hawklify.com. For the data we process on behalf of your organisation you can also contact your administrator; requests we receive are forwarded to them. You also have the right to lodge a complaint with a supervisory authority, in Italy the Garante per la protezione dei dati personali (garanteprivacy.it).
12. Changes
If we change this notice we update the date at the top; if the change is significant, we tell the organisations' administrators by e-mail.