This policy explains what personal data ProjoMania ("we", "us") collects when you use the OBM website (obm.projomania.com), the OBM Pro application (app-obm.projomania.com), or the self-hosted OBM Community Edition, and what we do with it. We keep it in plain language on purpose.
1. The two kinds of data — and our two roles
- Your data as our customer (account details, billing, support emails, usage): here we are the controller, and this policy applies.
- The contents of your backups: your Odoo databases may contain personal data about your customers, employees and users. That data is yours. We store and process it only on your instructions, as a processor, under our Data Processing Addendum. We do not open, read, mine or analyze the contents of your backup archives; automated integrity verification (checksums, archive structure checks) is the only processing that touches them.
2. What we collect
Account & profile
- Name, email address, password (stored as a salted hash — we cannot read it).
- Team membership and role, notification preferences (e.g. a Telegram chat ID you connect).
Billing
- Payments are handled by Paddle, our merchant of record. Paddle collects your payment details and billing address directly; we never see full card numbers. Paddle shares with us your subscription status, plan, and the country used for tax purposes. Paddle acts as an independent controller for its checkout — see Paddle's privacy policy.
Instance configuration
- The Odoo instance URLs and database names you register, and each instance's master password, which is encrypted at rest and used exclusively to call that instance's own backup/restore API. Master passwords are never logged and never displayed back in plain text.
Backup archives
- The backup files themselves (customer content, processed under the DPA), plus technical metadata we generate about them: size, SHA-256 checksum, verification result, timestamps.
Logs & telemetry
- Standard server logs (IP address, user agent, requested URL, timestamp), kept for up to 90 days for security and debugging.
- Application activity records (who ran which backup/restore/download and when) — these are a feature: they are your audit trail.
- CE update check: once a day, a self-hosted OBM CE installation contacts
obm.projomania.com sending only its edition and version string, to learn whether a newer
release exists. Our web server sees the request's IP address in its logs like any HTTP
request. It can be disabled with
VERSION_CHECK=false, and no other telemetry is sent by CE.
Support
- Emails you send us, and — only if you attach it — diagnostic data you choose to share.
This website
- The marketing site sets no cookies and runs no third-party analytics or ad trackers. The app sets a session cookie strictly required to keep you signed in.
-
We do measure how the marketing site is used, with our own analytics software
(Umami) running on our own servers. It is served from this domain, so your browser never
contacts another company, and no data about your visit leaves our infrastructure. It records
the page you viewed, the referring site, and coarse details derived from your browser — device
type, browser, operating system and country. It sets no cookies, assigns you
no identifier, and cannot follow you across sites or sessions. Your IP address is used only to
look up the country and is not stored by the analytics software (our web server logs it like
any HTTP request, as described above). We honour
Do Not Track, and if you block the script with a content blocker, nothing on the site breaks.
3. What we use it for
- Providing the service: running backups, verification, retention, restores, alerts.
- Operating accounts, plans and (via Paddle) billing.
- Security: intrusion detection, abuse prevention, audit trails.
- Support and service announcements (e.g. incident or deprecation notices).
- Product emails about OBM itself. We do not sell personal data, and we do not share it with advertisers — there is nothing on this list resembling "marketing partners".
Where GDPR applies, our legal bases are: performance of contract (running the service), legitimate interests (security, service communications, defending claims), and consent where we ask for it (e.g. optional Telegram notifications).
4. Sub-processors and recipients
We use a deliberately short list of infrastructure providers:
- Backblaze, Inc. — object storage for backup archives, EU region, encrypted at rest.
- Cloudflare, Inc. — DNS, TLS and network security in front of our services.
- Paddle — merchant of record: payments, tax, invoicing (independent controller for checkout).
- GitHub, Inc. — code hosting and the public issue tracker for OBM CE (anything you post in an issue is public).
The current list, and how we announce changes to it, is maintained in the DPA. Beyond these, we disclose data only if required by law — and if a demand for customer backup data ever arrives, we will notify you unless legally barred from doing so.
5. Where your data lives
- Backup archives are stored in the EU (Backblaze B2, EU region), encrypted at rest.
- The control plane (application servers and the metadata database: accounts, schedules, checksums, activity logs) runs on infrastructure outside the EU, behind Cloudflare. We are honest about this distinction: OBM stores backup data in the EU, but it is not an "EU-hosted service" end to end.
- We are an Egypt-based company and have not appointed an EU representative under GDPR Article 27. Where transfers of EU personal data occur, we rely on standard contractual clauses and equivalent safeguards as described in the DPA.
6. How long we keep it
- Backup archives: exactly as long as your retention rules say — that is the product.
- After cancellation: read-only access — no new backups run, and stored archives stay downloadable. Deletion happens on your instruction, within 30 days of the request; we give notice before any deletion we initiate.
- Account data: for the life of the account, then deleted or anonymized within 90 days.
- Server logs: up to 90 days.
- Billing records: kept as long as tax and accounting law requires (by us and by Paddle).
7. Security
- TLS for all traffic — between you and OBM, between OBM and your Odoo, and to storage.
- Backup archives encrypted at rest; master passwords additionally encrypted at the application layer.
- Password hashing (bcrypt-class), role-based access, audit logging.
- Access to production systems is limited to the small number of people who operate the service, on a need-to-use basis.
If a breach affects your personal data, we will notify you without undue delay, with what we know and what we are doing about it.
8. Your rights
Depending on your jurisdiction (GDPR and similar laws), you can ask us to access, correct, export or delete your personal data, restrict or object to processing, and you may lodge a complaint with your supervisory authority. For data inside your backup archives, ask the organization that backs up that Odoo (they control it; we will help them respond). To exercise any right, email [email protected] — we answer within one business day and resolve requests within 30 days.
9. Children
OBM is a business tool and is not directed at children under 16. We do not knowingly collect their data.
10. Changes to this policy
If we change this policy in a way that matters, we will email account holders and note the change here at least 14 days before it takes effect. The "Last updated" date above always reflects the current version.
11. Contact
Privacy questions and requests: [email protected] (ProjoMania, Cairo, Egypt).