Cloud Policy
Effective - 12th May, 2025

Data Protection

Your data, your control. Oddr provides the safeguards law firms need to protect sensitive client and financial information.

Client confidentiality and regulatory compliance are core to every law firm’s business. Oddr was designed from the ground up with data protection at the center giving firms control over where their data resides, how it is isolated, and what happens to it throughout its lifecycle.

Data Sovereignty

Law firms often have specific requirements about where their data is physically stored, driven by internal policy, client expectations, or regulatory mandates. Oddr addresses this by leveraging Microsoft Azure’s global data center footprint and letting firms choose the geographic region where their data resides.

This means an Australian firm can keep data in the APAC region, a Canadian firm can keep data within Canadian borders, a European or UK firm can keep data in EU data centers (Netherlands and Ireland), and a US firm can keep data within US borders — all on the same platform.

Once a region is selected during onboarding, all of the firm’s data and platform resources are provisioned within that region.

Per-Tenant Data Isolation

Oddr uses a multitenant SaaS architecture, but tenant data is strictly isolated at the platform level. Each tenant's data resides in a separate database and storage container, and is never commingled with another tenant’s data for any purpose — not for analytics, not for training, and not for operational convenience.

This isolation is enforced through per-tenant separation at both the application and database layers, and it is part of Oddr's control environment, which is covered by the SOC 2 Type II audit and ISO 27001 certification.

Data Ownership & Control

Your firm retains full ownership of its data at all times. Oddr’s service agreements make this explicit: neither Oddr nor any of its sub-processors will use your data for purposes outside the scope of contracted services.

Oddr provides real-time visibility into your data through the platform, and access is governed by role-based permissions that your firm’s administrators control.

Encryption

In Transit

All communication between the Oddr Secure Cloud and users' devices is encrypted in transit using TLS 1.2 or higher. The only publicly accessible endpoint is a WAF-enabled Azure Application Gateway.

At Rest

Data at rest is encrypted with AES-256 using Microsoft managed keys. This covers the PostgreSQL databases, Blob Storage, and backups.

Data Retention & Disposal

Oddr has established a formal Data Retention and Disposal Policy that defines procedures for the appropriate retention, disclosure, and disposal of sensitive, confidential, and personal information.

When a firm’s contract with Oddr ends, customer data is securely deleted in accordance with the agreed contractual terms. Media disposal follows secure procedures proportional to the sensitivity of the information stored.

Sub-Processors

Oddr maintains a limited set of sub-processors and is transparent about who they are and what role they play. The sub-processors below are current as of publication.

The authoritative, up-to-date list is maintained at https://www.oddr.com/legal/sub-processors.

Customers may subscribe to sub-processor change notifications by emailing dpa@oddr.com

Microsoft Azure

Cloud infrastructure hosting, platform services, data storage, and compute resources.

Postmark

Transactional email delivery only — invoice notifications, statements, and payment reminders. Postmark is not the system of record for billing, invoices, payments, or any application data; those records remain in the Oddr Secure Cloud in your selected region. Emails carry a secure link for clients to view invoices in the portal rather than attaching financial documents.

Postmark processes email-delivery data (recipient address, delivery status, and message metadata) in the United States, regardless of the customer's selected region. For firms outside the US, this is a cross-border transfer covered by Postmark's Data Processing Agreement — addressing GDPR, UK GDPR, and CCPA — with Standard Contractual Clauses, TLS encryption in transit, and documented technical and organizational measures and US government-access safeguards. Core application data is unaffected and stays within your Azure region.

References: postmarkapp.com/eu-privacy, postmarkapp.com/dpa, postmarkapp.com/support/article/1218-gdpr-faq.

Oddr Personnel & Contractors

Support, maintenance, professional services, and DevOps. Locations: United States, India. Access is governed by Oddr's Tenant Access Policy (least-privilege, MFA, audit-logged).

Oddr’s service agreements detail the role of each sub-processor. Oddr does not share customer data with sub-processors for purposes outside the contracted scope of services.

Privacy & Regulatory Alignment

Oddr’s data handling practices are designed to align with the privacy and regulatory expectations of law firms operating across multiple jurisdictions. Key elements include:

GDPR Alignment

For firms subject to the EU General Data Protection Regulation, Oddr’s European data residency option (West Europe / North Europe), combined with its data processing practices, supports compliance with GDPR data localization and protection requirements. Oddr’s service agreements include data processing terms that address GDPR obligations.

No Secondary Use of Data

Oddr does not use customer data for advertising, profiling, resale, or any purpose beyond delivering the contracted platform services. This commitment extends to all sub-processors.

AI Features & Data Handling

Oddr offers optional AI features (like account summarization and contextual assistance) that are enabled per firm through a feature flag and can be turned off at any time. These features run on Microsoft Azure OpenAI within your selected Azure region. Processing is stateless — your data is not retained by the model. Your firm's data is never used to train Oddr's or any third party's AI models, and AI output is subject to human review. When the feature is disabled, no data is processed by Azure OpenAI.

Data Minimization

Oddr collects and processes only the data necessary to operate the platform and deliver services. The scope of data ingested from your FMS is defined collaboratively during implementation and limited to what is needed for invoicing, collections, and revenue intelligence.

Right to Deletion

Customers may request the deletion of their data at any time. Upon contract termination, data is securely deleted in accordance with the agreed contractual terms (standard 90-day post-termination window) and Oddr's Data Retention and Disposal Policy.

FAQ

1. Does Oddr use my firm’s data for AI training or analytics?
A: No. Your firm’s data is used solely to deliver the contracted Oddr platform services. It is not used for cross-tenant analytics, machine learning model training, or any other purpose outside the scope of your agreement.
2. Does Oddr use AI?
A: Yes, optionally. AI features are off unless your firm enables them, run on Azure OpenAI in your region, are stateless, and are never used to train models.
3. Can my firm choose where its data is stored?
A: Yes. During onboarding, your firm selects the Azure region where data will reside. Regions currently available include US (East/West), Canada (Central/East), Europe including UK (West/North), and APAC (Australia East/Southeast). Additional regions may be available upon request.
4. How is tenant data separated?
A: Tenant data resides in a separate database and a separate storage container. Although the platform uses a multitenant architecture, data is never commingled across tenants. These controls are part of Oddr's SOC 2 Type II-audited control environment.
5. What happens to my firm’s data if we stop using Oddr?
A: Upon contract termination, Oddr securely deletes your firm’s data in accordance with the agreed contractual terms and Oddr’s Data Retention and Disposal Policy.
6. Who are Oddr’s sub-processors?
A: Oddr’s primary sub-processors are Microsoft Azure (cloud hosting and platform services) and Postmark (transactional email delivery). The full list is available at https://www.oddr.com/legal/sub-processors.
7. Where does Postmark process email data?
A: In the United States, regardless of your firm's selected region. Postmark handles only email-delivery data — recipient address, delivery status, and message metadata — not your billing, invoice, payment, or application records, which stay in your selected Azure region. For firms outside the US, this transfer is covered by Postmark's DPA (GDPR, UK GDPR, CCPA) with Standard Contractual Clauses and TLS in transit.