LEGAL
Privacy
Policy.
Odin is a powerful, AI-driven CMS built for modern media infrastructure. Here is how we handle your data.
This Privacy Policy explains how AST Consulting ("we", "us", "our") collects, uses, shares, and protects information when you use Odin CMS, our AI-powered content management platform (the "Service"), whether through our hosted product or an instance of the self-hosted community edition connected to our optional cloud services. It applies alongside our Terms of Service.
- 1. Information we collect
- 2. Legal basis for processing
- 3. How we use your information
- 4. How we share information
- 5. Cookies & tracking
- 6. Data retention
- 7. Data security
- 8. International transfers
- 9. Your rights & choices
- 10. Children's privacy
- 11. Third-party links
- 12. Changes to this policy
- 13. Contact us
1. Information We Collect
To provide our robust platform experience, we collect the following categories of data when you use our platform:
- Authentication data: We collect and securely store information necessary to authenticate users, such as names, email addresses, and OAuth tokens (e.g., from Google or other third-party providers) to ensure secure access to your newsroom and operations layer.
- API and integration data: When you connect Odin to third-party services (like analytics tools, distribution channels, and LLM providers such as Anthropic or OpenAI), we process and temporarily store API keys, endpoint data, and metadata necessary for these integrations to function seamlessly.
- Content and workspace data: Articles, drafts, media, infographics, templates, and metadata you create or upload, along with editorial and workflow state (assignments, review status, publish schedule).
- Usage information: We monitor how our APIs and services are accessed — device and browser type, IP address, pages viewed, and feature interactions — to ensure platform stability, prevent abuse, and continuously improve the editor, infographics generation, and distribution engine.
- Communications: Messages you send us, such as support requests or free-audit bookings, and the contact details you provide with them.
2. Legal Basis for Processing
Where applicable data protection law (such as India's Digital Personal Data Protection Act, 2023, or the EU/UK GDPR) requires it, we process your information on one or more of the following bases: performance of a contract with you (operating your account and workflows), your consent (e.g., optional analytics cookies), our legitimate interests (securing the Service, preventing abuse, and improving product quality), and compliance with legal obligations.
3. How We Use Your Information
We use the data collected strictly to operate, maintain, and enhance the Odin CMS ecosystem. Authentication data is used solely to verify your identity and authorize access to your distinct roles and modules. API data is used to execute the powerful automated tasks you trigger, such as AI-assisted drafting, automated tagging, infographic generation, and multi-channel content distribution. Usage information helps us diagnose issues, harden security, and prioritize what we build next. We do not use your editorial content to train third-party foundation models.
5. Cookies & Tracking Technologies
We use strictly necessary cookies to keep you signed in and to remember workspace preferences (such as light/dark theme). With your consent where required, we may also use analytics cookies to understand aggregate usage of the marketing site and product. You can control cookies through your browser settings; disabling strictly necessary cookies may prevent parts of the Service from working correctly.
6. Data Retention
We retain account and content data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within a commercially reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements. API keys are retained only for as long as an integration remains connected and are deleted upon disconnection.
7. Data Security
We apply industry-standard technical and organizational measures — including encryption in transit and at rest, access controls, and monitoring — to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you as required by applicable law.
8. International Transfers
Odin CMS and its infrastructure and sub-processors may operate in countries other than your own, including India, where AST Consulting is based. Where we transfer personal data across borders, we rely on appropriate safeguards recognized under applicable law, such as standard contractual clauses, to protect that data consistently with this Policy.
9. Your Rights & Choices
Depending on your location, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent where processing is based on consent. To exercise any of these rights, contact us at [email protected]; we will respond within the timeframe required by applicable law. You may also manage or revoke third-party API connections at any time from your workspace settings.
10. Children's Privacy
Odin CMS is intended for business and professional use and is not directed to individuals under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Third-Party Links
The Service may link to or integrate with third-party websites, distribution channels, and AI providers. This Policy does not cover those third parties' practices; we encourage you to review their own privacy policies before connecting them to Odin CMS.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will update the "Last updated" date above and, for material changes, provide additional notice such as an in-app message or email. Continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
13. Contact Us
If you have any questions, requests, or require data deletion, please contact us at [email protected].