Information notice on the processing of personal data pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).
Last updated: 1 May 2026
The data controller is Odin Health Srl (company being incorporated), with operating offices in Lecce, Italy.
For any request regarding personal data — exercising your rights, clarifications, reports — you can write to hello@odinhealth.it.
No Data Protection Officer (DPO) has been appointed under Article 37 of the GDPR, as the processing does not currently fall within the cases that make such appointment mandatory. The appointment will be reconsidered when the clinical platform goes operational.
Through this site we collect the following personal data, provided voluntarily by the data subject:
For security and anonymous-statistics purposes we collect: IP address, browser user agent, country of origin (detected by the CDN). This data is associated with the individual sign-up/request and retained with it.
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Managing the waitlist sign-up and contact at product launch | Consent (art. 6.1.a) — expressed by submitting the form |
| Managing professional demo requests (doctors, pharmacists) | Performance of pre-contractual measures (art. 6.1.b) |
| Managing applications for open positions in the team | Performance of pre-contractual measures (art. 6.1.b) |
| IT security, abuse prevention, aggregate statistics | Legitimate interest (art. 6.1.f) |
Processing is carried out mainly by automated means, using electronic tools and with appropriate security measures (encryption in transit via HTTPS, restricted database access, automatic backups, encrypted secrets).
There is no automated decision-making that produces legal effects on the data subject. No profiling operations are carried out.
Data is processed by the controller and by the following providers, appointed as data processors under Article 28 of the GDPR:
| Provider | Purpose | Location / data region |
|---|---|---|
| Cloudflare, Inc. | Site hosting (Pages), database (D1), CDN, security | USA — DPA with EU standard contractual clauses; data centres mainly in the EU |
| Brevo (Sendinblue SAS) | Sending confirmation and notification emails | France (EU) — servers in the European Union |
| Web3Forms | Forwarding applications with attached PDF CV (to be replaced soon) | USA — DPA with EU standard contractual clauses |
Data is not transferred, sold or made available to third parties other than the processors listed above. No transfers are made for commercial or advertising purposes.
Cloudflare and Web3Forms are based in the United States. Transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical measures (encryption, pseudonymisation where possible). Brevo operates entirely within the European Union.
In accordance with Articles 15 to 22 of the GDPR, you have the right to:
To exercise any of these rights, write to hello@odinhealth.it. We will respond within 30 days of receiving the request.
You also have the right to lodge a complaint with the Italian Data Protection Authority (Garante) (www.garanteprivacy.it) if you believe that the processing of your data infringes the GDPR.
This site uses only technical cookies necessary for the hosting platform (Cloudflare) to function. No profiling, analytics or third-party advertising cookies are used. For full details, see our Cookie Policy.
This notice may be updated as the project, the providers involved or the processing purposes evolve. Any material changes will be communicated by email to subscribers and flagged on the site. The date of the last update is shown at the top.
We're opening Odin carefully, from Lecce. Leave your email to receive early access and follow the journey closely.