Privacy Policy
Last updated: April 8, 2026
1. Data Controller
The data controller for personal data collected through this website is Odoniq, based in Palma de Mallorca, Balearic Islands, Spain.
Contact email: privacy@odoniq.com
2. Data We Collect
- Account data: name, email, and clinic name provided during registration.
- Browsing data: IP address, browser type, pages visited, and time spent, collected through cookies and analytics tools.
- Application usage data: if you are a registered user, clinical data you enter into the platform (managed under a separate data processing agreement).
3. Purpose of Processing
- Provide and manage the Odoniq service.
- Send commercial communications (only with prior consent).
- Improve our services through web analytics.
- Comply with legal obligations.
4. Legal Basis
- Consent: for commercial communications and non-essential cookies.
- Contract performance: for service provision to registered clinics.
- Legitimate interest: for service improvement and fraud prevention.
- Legal obligation: for tax and commercial compliance.
5. Data Recipients
- Infrastructure providers: Microsoft Azure (EU-based servers).
- AI providers: Anthropic (clinical image processing, with contractual privacy guarantees).
- Analytics tools: Google Analytics and Meta (with IP anonymization).
6. International Transfers
Some providers may be located outside the European Economic Area. We ensure appropriate safeguards under Article 46 of the GDPR, including Standard Contractual Clauses approved by the European Commission.
7. Retention Period
- Account data: until 2 years after the last interaction or until you exercise your right to erasure.
- Contractual data: during the contract term plus legally required retention periods.
- Browsing data: maximum 13 months (analytics cookies).
8. Your Rights
You have the right to: access, rectification, erasure, restriction, portability, and objection.
To exercise these rights, email privacy@odoniq.com.
You may also file a complaint with the Spanish Data Protection Agency (AEPD).
9. Security
We implement appropriate technical and organizational measures including TLS encryption in transit, AES-256 encryption at rest, role-based access control, and periodic security audits.