Privacy policy
Your data, handled with care.
Last updated: July 28, 2026
This policy explains what personal data we collect through theodin.ai, why we collect it, how long we keep it, who we share it with, and the rights you have over it — including your rights under the EU and UK General Data Protection Regulation (GDPR). We keep it in plain language on purpose.
01Who we are
Odin.AI (“Odin”, “we”, “us”) is an AI-first brand and growth agency operating the website theodin.ai. For the purposes of the GDPR, the data controller is:
TheOdin Infotech Pvt. Ltd.
Email: hello@theodin.ai
For any question about this policy or your personal data, email hello@theodin.ai with the subject line “Privacy”.
02What we collect
Information you give us
- Audit and contact requests. When you use our contact form we collect your name, work email address, your website URL (if you share it), the services you are interested in, and anything you write in the message field.
- Newsletter. If you subscribe to our letter, we collect your email address.
- Correspondence. If you email us directly, we keep the correspondence and the address you wrote from.
- Applications. If you apply to work with us, we collect the information you choose to send — typically your name, contact details, CV, and portfolio links.
Information collected automatically
- Technical logs. Like almost every website, our hosting infrastructure records standard server logs: IP address, browser type and version, device type, the pages you visit, and timestamps. We use these only to run, secure, and debug the site.
We do not ask for, and you should not send us, special-category data (such as health, religious, or biometric information). We do not collect payment details through this website.
03Why we use it, and our legal bases
Under the GDPR we need a legal basis for every use of your personal data. These are ours:
- Answering your enquiry and preparing your audit — we use your contact details, website URL, and message to respond, review your site, and prepare the call you asked for. Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)).
- Sending the newsletter — only if you subscribed. Every letter includes an unsubscribe link. Legal basis: consent (Art. 6(1)(a)).
- Running and protecting the site — technical logs, abuse prevention, and spam filtering (our contact form uses an invisible honeypot field rather than tracking-based anti-spam). Legal basis: legitimate interests (Art. 6(1)(f)).
- Considering your application — assessing candidates for roles at Odin. Legal basis: steps taken at your request prior to entering a contract (Art. 6(1)(b)).
- Complying with the law — keeping records we are legally required to keep and responding to lawful requests. Legal basis: legal obligation (Art. 6(1)(c)).
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell personal data.
06International transfers
Our service providers may store or process data outside your country, including outside the European Economic Area and the United Kingdom. Where they do, we rely on an adequacy decision or on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK equivalents), so that your data receives an essentially equivalent level of protection. You can ask us for details of the safeguards used at any time.
07How long we keep data
- Enquiries and audit requests — up to 24 months after our last contact, unless we start working together, in which case data is kept for the duration of the engagement and as required afterwards.
- Newsletter subscriptions — until you unsubscribe, after which we remove your address from the list.
- Applications — up to 12 months after the process ends, so we can contact you about future roles, unless you ask us to delete them sooner.
- Technical logs — short rolling periods, typically no more than 90 days.
- Legal and accounting records — as long as the law requires.
When data is no longer needed, we delete it or irreversibly anonymise it.
08Your rights
If you are in the EEA or the UK (and in many other places), you have the right to:
- Access — get a copy of the personal data we hold about you;
- Rectification — have inaccurate data corrected;
- Erasure — have your data deleted where there is no good reason for us to keep it;
- Restriction — limit how we use your data in certain situations;
- Portability — receive the data you gave us in a structured, machine-readable format;
- Objection — object to processing based on legitimate interests, and to any direct marketing at any time;
- Withdraw consent — where processing is based on consent (like the newsletter), withdraw it at any time without affecting the lawfulness of what came before.
To exercise any of these rights, email hello@theodin.ai. We respond within one month, and the exercise of these rights is free of charge. We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the chance to resolve your concern first, but you can contact them at any time.
09Visitors from other regions
If you are a California resident, the CCPA/CPRA gives you similar rights of access, deletion, and correction, and the right to non-discrimination for exercising them. We do not sell or “share” personal information as those terms are defined in the CCPA. Residents of other jurisdictions with privacy laws (such as Brazil’s LGPD or India’s DPDP Act) may exercise the equivalent rights available to them by writing to hello@theodin.ai.
10Security
We use appropriate technical and organisational measures to protect personal data: encrypted connections (HTTPS) across the site, access limited to the people who need it, and reputable infrastructure providers. No method of transmission or storage is completely secure, but if a breach ever affects your data in a way that puts your rights at risk, we will notify you and the relevant authority as the law requires.
11Children
Our site and services are aimed at businesses and are not directed at children under 16. We do not knowingly collect data from children; if you believe a child has given us personal data, contact us and we will delete it.
12Third-party links
Our site links to third-party websites — client sites, social networks, and articles. Their privacy practices are their own; this policy stops at our door, so review theirs when you visit.
13Changes to this policy
When we change this policy, we will update it on this page and revise the “Last updated” date above. If a change meaningfully affects how we use data you have already given us, we will take reasonable steps to bring it to your attention — for example, by emailing subscribers.
14Contact
Questions, requests, or concerns: hello@theodin.ai — subject line “Privacy”. Or start from the contact page.
