← Back to the site

Privacy Policy

Information notice on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

Last updated: 1 May 2026

1. Data controller

The data controller is Odin Health Srl (company being incorporated), with operating offices in Lecce, Italy.

For any request regarding personal data — exercising your rights, clarifications, reports — you can write to hello@odinhealth.it.

No Data Protection Officer (DPO) has been appointed under Article 37 of the GDPR, as the processing does not currently fall within the cases that make such appointment mandatory. The appointment will be reconsidered when the clinical platform goes operational.

2. Types of data processed

Through this site we collect the following personal data, provided voluntarily by the data subject:

Waitlist sign-up

  • Name (for users, caregivers, doctors, other profiles)
  • Email address
  • Declared role (user, caregiver, doctor, pharmacist, other)
  • City (optional, required for doctors and pharmacists)
  • Medical specialty (doctors only)
  • Pharmacy name and role (pharmacists only)
  • Browsing language

Demo request (doctors and pharmacies)

  • Full name
  • Email, phone (optional)
  • Specialty (doctors) / pharmacy name and role (pharmacists)
  • City, optional free-text message

Application to join the team

  • Full name, email
  • Curriculum Vitae in PDF format
  • Optional cover letter

Data collected automatically

For security and anonymous-statistics purposes we collect: IP address, browser user agent, country of origin (detected by the CDN). This data is associated with the individual sign-up/request and retained with it.

3. Purposes and legal basis

PurposeLegal basis (GDPR art. 6)
Managing the waitlist sign-up and contact at product launchConsent (art. 6.1.a) — expressed by submitting the form
Managing professional demo requests (doctors, pharmacists)Performance of pre-contractual measures (art. 6.1.b)
Managing applications for open positions in the teamPerformance of pre-contractual measures (art. 6.1.b)
IT security, abuse prevention, aggregate statisticsLegitimate interest (art. 6.1.f)

4. How data is processed

Processing is carried out mainly by automated means, using electronic tools and with appropriate security measures (encryption in transit via HTTPS, restricted database access, automatic backups, encrypted secrets).

There is no automated decision-making that produces legal effects on the data subject. No profiling operations are carried out.

5. Retention period

  • Waitlist sign-ups: until the data subject withdraws consent, or in any case up to 24 months from the platform’s operational launch.
  • Demo requests: up to 24 months from the request date, or until the end of any relationship that begins.
  • Applications: 12 months from the submission date (if not hired), then deleted. CVs and attached data follow the same retention.
  • Technical data (IP, user agent): associated with the main record and deleted together with it.

6. Recipients and external data processors

Data is processed by the controller and by the following providers, appointed as data processors under Article 28 of the GDPR:

ProviderPurposeLocation / data region
Cloudflare, Inc.Site hosting (Pages), database (D1), CDN, securityUSA — DPA with EU standard contractual clauses; data centres mainly in the EU
Brevo (Sendinblue SAS)Sending confirmation and notification emailsFrance (EU) — servers in the European Union
Web3FormsForwarding applications with attached PDF CV (to be replaced soon)USA — DPA with EU standard contractual clauses

Data is not transferred, sold or made available to third parties other than the processors listed above. No transfers are made for commercial or advertising purposes.

7. Transfers outside the EU

Cloudflare and Web3Forms are based in the United States. Transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical measures (encryption, pseudonymisation where possible). Brevo operates entirely within the European Union.

8. Rights of the data subject

In accordance with Articles 15 to 22 of the GDPR, you have the right to:

  • Access your personal data (art. 15)
  • Request their rectification (art. 16)
  • Request their erasure (right to be forgotten, art. 17)
  • Request restriction of processing (art. 18)
  • Receive your data in a structured format and port it elsewhere (portability, art. 20)
  • Object to processing (art. 21)
  • Withdraw consent at any time, without affecting the lawfulness of prior processing (art. 7)

To exercise any of these rights, write to hello@odinhealth.it. We will respond within 30 days of receiving the request.

You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante) (www.garanteprivacy.it) if you believe that the processing of your data infringes the GDPR.

9. Cookies

This site uses only technical cookies necessary for the hosting platform (Cloudflare) to function. No profiling, analytics or third-party advertising cookies are used. For full details, see our Cookie Policy.

10. Changes to this notice

This notice may be updated as the project, the providers involved or the processing purposes evolve. Any material changes will be communicated by email to subscribers and flagged on the site. The date of the last update is shown at the top.

Odin Health · Lecce, Italy · hello@odinhealth.it
This notice is also available in Italian.