Back to olmira.io

Privacy Policy

Last updated 22 July 2026

1. Two roles — read this first

  • Platform data (we are the controller): the account and billing data of tenants and their team members, operator logs, support conversations, and platform analytics.
  • Tenant-site data (we are the processor): personal data that visitors and customers submit to a tenant’s site (orders, form submissions, storefront accounts). The tenant is the controller; we process on the tenant’s behalf under the Terms and a data-processing addendum. Requests about a tenant’s store should go to that tenant; we forward misdirected requests where we can.

2. Who is responsible

For platform data, the data controller is the operator identified at the end of this policy — Individual Entrepreneur Mario Atienza Sanchez, registered in Georgia.

3. Data we collect (as controller)

  • Account: name, email, password hash, optional phone, two-factor enrolment, language.
  • Billing: plan, invoices and payment metadata from our merchant of record, Paddle (we never receive or store full card numbers).
  • Usage and security: IP addresses, device and browser metadata, sign-in and audit events, device fingerprints used for abuse prevention, and error and performance telemetry.
  • Content you store in your workspace, processed to host and render it.
  • Communications: support tickets, emails and in-app messages.

4. Purposes and legal bases

  • Providing the service and hosting your sites — contract.
  • Billing and tax records — legal obligation / contract.
  • Security, fraud and abuse prevention (including name-policy screening) — legitimate interest.
  • Service emails (verification, security, changes) — contract.
  • Product analytics and improvement — legitimate interest.
  • Marketing emails — consent (opt-in, revocable).

5. Sharing and subprocessors

We do not sell personal data. We share it only with the service providers we rely on to run the platform, our merchant of record, AI-model providers when you invoke AI features (input text only, no resale), and — where the law requires — authorities. Processors are bound by data-processing agreements. Our current subprocessors are:

  • DigitalOcean — cloud hosting, compute and storage infrastructure.
  • Cloudflare — DNS, CDN, TLS and edge security.
  • Paddle (Paddle.com Market Ltd) — merchant of record for subscription billing and payments.
  • Anthropic — AI-model provider for AI features you invoke.
  • OpenAI — AI-model provider for AI features you invoke.
  • Proton — transactional and account email delivery.

Paddle acts as an independent controller for the billing and payment data it processes as merchant of record; we never receive your full card details.

6. Law enforcement and fraud prevention

We disclose account data, logs and content to law-enforcement agencies, courts, regulators, financial institutions and payment providers where disclosure is required by law or requested through legal process, clear evidence or a reasoned suspicion of fraud, impersonation or other crime (legal basis: legal obligation, or legitimate interest). Fraud we detect ourselves is handled through platform enforcement, with evidence preserved for competent authorities on lawful request. We may retain data subject to an investigation beyond normal periods, including blocked identifiers (IP addresses, device fingerprints) needed to enforce bans.

7. International transfers

Infrastructure may be located in the EU/EEA, Georgia or the US. Where data leaves the EEA, we rely on adequacy decisions or standard contractual clauses with the relevant provider.

8. Retention

Account data is kept for the life of the account and up to 90 days after deletion (backup cycles), except where tax or accounting law requires longer (invoices). Security logs are kept for around 12 months. Abuse-investigation evidence is kept for the duration of the investigation and any ensuing proceedings. Tenant-site data is kept per the tenant’s instructions and deleted or returned on contract end after the export window.

9. Your rights

Depending on your jurisdiction (for EU residents, under the GDPR): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, plus the right to complain to your supervisory authority.

We verify identity before acting and respond within one month.

10. Security

TLS everywhere (HSTS on olmira.app), password hashing, optional and — for privileged roles — mandatory two-factor authentication, per-tenant database isolation, envelope-encrypted secrets, and audited operator access. No method is 100% secure; we notify affected users and authorities of qualifying breaches as the law requires.

11. Cookies

See our Cookie Policy for the cookies the platform surfaces set. Tenant sites set their own cookies under the tenant’s responsibility.

12. Changes

Material changes are announced by email or in-app at least 30 days in advance where feasible. The "last updated" date above always reflects the current version.

Operator

Individual Entrepreneur Mario Atienza Sanchez

Registered in Georgia (Sakartvelo) · ID/registration No. 305768354

Georgia, Tbilisi, Vake district, Ateni str. N6-8, Space N4b

Trading as "Olmira"

Questions about this document? privacy@olmira.io