Back to olmira.io

Privacy Policy

Last updated 18 August 2026

1. Three roles — read this first

  • Platform data (we are the controller): the account and billing data of tenants and their team members, operator logs, support conversations, and platform analytics.
  • Tenant-site data (we are the processor): personal data that visitors and customers submit to a tenant’s site (orders, form submissions, storefront accounts). The tenant is the controller; we process on the tenant’s behalf under the Terms and a separate data-processing addendum (DPA), available on request from info@olmira.app. Requests about a tenant’s store should go to that tenant; we forward misdirected requests where we can.
  • Purchase data (our merchant of record is an independent controller): the personal data Dodo Payments collects to sell you an Olmira subscription — the billing identity you give it, your payment method, your invoice and the tax data behind it. Dodo Payments decides for itself why and how it processes that data, under its own privacy notice; it does not process it on Olmira’s instructions. Section 5 explains what that means for you.

2. Who is responsible

For platform data, the data controller is Olmira — the operator identified in full at the end of this policy: Individual Entrepreneur Mario Atienza Sanchez, registered in Georgia under registration and taxpayer number 305768354, at Ateni str. N6-8, Space N4b, Vake district, Tbilisi, Georgia.

We process platform data under the data-protection law of the operator’s jurisdiction (Georgia) and, for individuals in the EU/EEA, in line with the GDPR where it applies.

3. Data we collect (as controller)

  • Account: name, email, password hash, optional phone, two-factor enrolment, language.
  • Billing: your plan, your invoices, and the payment metadata our merchant of record reports back to us — the status of a charge, the brand and last digits of the payment method used, and the country used to determine tax. We never receive or store full card numbers.
  • Usage and security: IP addresses, device and browser metadata, sign-in and audit events, device fingerprints used for abuse prevention, and error and performance telemetry.
  • AI usage metering: counts of the AI tokens and AI generations consumed under your plan, recorded per account.
  • Content you store in your workspace, processed to host and render it.
  • Communications: support tickets, emails and in-app messages.

4. Purposes and legal bases

  • Providing the service and hosting your sites — contract.
  • Billing and tax records — legal obligation / contract.
  • Metering AI usage to enforce plan allowances — contract.
  • Security, fraud and abuse prevention (including name-policy screening) — legitimate interest.
  • Service emails (verification, security, changes) — contract.
  • Product analytics and improvement — legitimate interest.
  • Marketing emails — consent (opt-in, revocable).

5. Sharing and subprocessors

We do not sell personal data. We share it only with the service providers we rely on to run the platform, our merchant of record for subscription purchases, AI-model providers when you invoke AI features (input text only, no resale), and — where the law requires — authorities. Our service providers are processors bound by data-processing agreements; our merchant of record is not one of them, and the paragraph below sets out what it is instead. Our current subprocessors and service providers are:

  • DigitalOcean — cloud hosting, compute and storage infrastructure.
  • Cloudflare — DNS, CDN, TLS and edge security.
  • Dodo Payments — merchant of record for Olmira subscription purchases, and an independent controller of the personal data of those purchases.
  • Anthropic — AI-model provider for AI features you invoke.
  • OpenAI — AI-model provider for AI features you invoke.
  • Proton — transactional and account email delivery.

Dodo Payments is not our processor. As merchant of record it sells the subscription in its own name, so it determines for itself the purposes and the means of the processing that sale requires: identifying you as its buyer, taking and securing the payment, preventing fraud, issuing your invoice, and meeting its own tax, accounting and anti-money-laundering duties. For that processing it is an independent controller, not a processor acting on our instructions, and its own privacy notice governs it: https://dodopayments.com/privacy-policy. Data-subject requests to Dodo Payments go through the support channels it publishes: its contact page at https://dodopayments.com/contact and, for deletion of your data, support@dodopayments.com under its data-deletion policy (https://dodopayments.com/legal/data-deletion). Where we and Dodo Payments exchange data — the order we pass to it, the payment and tax metadata it reports back — each of us is a controller of what it holds, and neither acts on the other’s instructions. We never receive your full card details. None of this concerns a Stripe or PayPal account a tenant connects to their own site to charge their own customers — that account belongs to the tenant and is governed by the tenant’s own agreement with that provider.

6. Law enforcement and fraud prevention

We disclose account data, logs and content to law-enforcement agencies, courts, regulators, financial institutions and payment providers where disclosure is required by law or requested through legal process, clear evidence or a reasoned suspicion of fraud, impersonation or other crime (legal basis: legal obligation, or legitimate interest). Fraud we detect ourselves is handled through platform enforcement, with evidence preserved for competent authorities on lawful request. We may retain data subject to an investigation beyond normal periods, including blocked identifiers (IP addresses, device fingerprints) needed to enforce bans.

7. International transfers

Infrastructure may be located in the EU/EEA, the US, or the operator’s home jurisdiction (Georgia). Where personal data of EEA residents is transferred outside the EU/EEA to a country without an EU adequacy decision, we rely on standard contractual clauses (SCCs) or another valid transfer mechanism with the relevant provider, and we comply with any cross-border transfer rules of the operator’s jurisdiction. Our merchant of record transfers the purchase data it controls under its own privacy notice and its own transfer mechanisms.

8. Retention

Account data is kept for the life of the account and up to 90 days after deletion (backup cycles), except where tax or accounting law requires longer (invoices). Security logs are kept for around 12 months. Abuse-investigation evidence is kept for the duration of the investigation and any ensuing proceedings. Tenant-site data is kept per the tenant’s instructions while the contract runs; when a workspace is suspended — after a cancellation takes effect, a pause converts to cancellation, or a trial expires — workspace and site data is retained for 90 days and then permanently deleted, with prior warning, except where legal retention duties or evidence preservation require longer.

9. Your rights

Depending on your jurisdiction, under the data-protection law of the operator’s jurisdiction (Georgia) and (where applicable) the GDPR: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.

You may lodge a complaint with the data-protection supervisory authority of the operator’s jurisdiction (Georgia) or, for EU/EEA residents, with your local supervisory authority.

Rights over the purchase data our merchant of record holds are exercised with it, because it is the controller of that data and not our processor — write to us and we will point you to the right contact. Rights over your Olmira account, your sites and your content are exercised with us.

We verify identity before acting and respond within one month.

10. Security

TLS everywhere (HSTS on olmira.app), password hashing, optional and — for privileged roles — mandatory two-factor authentication, per-tenant database isolation, envelope-encrypted secrets, and audited operator access. No method is 100% secure; we notify affected users and the competent supervisory authority of qualifying personal-data breaches without undue delay — where a deadline applies, within 72 hours of becoming aware — as the applicable law requires.

11. Cookies

See our Cookie Policy for the cookies the platform surfaces set. Tenant sites set their own cookies under the tenant’s responsibility.

12. Changes

Material changes are announced by email or in-app at least 30 days in advance where feasible. The "last updated" date above always reflects the current version.

Operator

Individual Entrepreneur Mario Atienza Sanchez

Registered in Georgia · Registration / taxpayer ID (Georgia): 305768354

Ateni str. N6-8, Space N4b, Vake district, Tbilisi, Georgia

Trading as "Olmira"

Subscription payments are processed by Dodo Payments as merchant of record.

Questions about this document? info@olmira.app