Introduction
WEI,LIBO, doing business as youkit studio ("youkit studio", "we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy ("Policy") explains how we collect, use, store, disclose, and protect personal information when you use odms.io and related ODMS products, including ODMS Studio, ODMS Insight, ODMS Connect, hosted services, licensed software, demos, documentation, support, and related AI-powered or data-management features (collectively, the "Service").
Please read this Policy carefully before using the Service. By using the Service, you agree to this Policy. This Policy should be read together with our Terms of Service.
1. Data Controller
The data controller for the Service is:
- Legal Name: WEI,LIBO
- Business Name: youkit studio
- Website: https://odms.io
- Product: odms.io / ODMS
- Privacy Contact: [email protected]
- Data Protection Officer: Not appointed / not applicable
- Mailing Address: Available upon verified legal, billing, or privacy request by contacting [email protected]
For enterprise, private deployment, or customer-controlled environments, your organization may act as the data controller for personal information it stores, connects, imports, or processes through ODMS. In those cases, we act as a service provider or processor for that customer data where applicable.
2. Personal Information We Collect
2.1 Information You Provide Directly
- Account information: name, email address, password or authentication credentials, organization name, role, language preference, and account settings.
- Billing information: transaction amount, plan, license scope, invoice details, payment status, billing email, tax information, and payment processor references. Full payment card numbers are not stored on our servers.
- Communications: emails, support requests, demo requests, sales inquiries, feedback, bug reports, screenshots, logs, and attachments you send to us.
- Product configuration: workspace names, tenant or organization settings, user and role assignments, access settings, notification settings, deployment preferences, and integration settings.
- Data source configuration: OData endpoint URLs, relational database connection metadata, schema names, entity names, field metadata, sync settings, and related technical configuration. Secrets such as passwords, tokens, API keys, and client secrets are handled as sensitive data.
- User content: prompts, queries, saved queries, dataset metadata, workflow configuration, ontology or business object definitions, AI instructions, generated outputs, and files or records you choose to upload or process through the Service.
2.2 Information Collected Automatically
- Device and network information: IP address, device type, operating system, browser type, user agent, time zone, language, referring URL, and approximate region derived from network data.
- Usage information: pages visited, features used, buttons clicked, session duration, timestamps, query execution metadata, sync activity, deployment activity, and product navigation.
- Log and security information: request timestamps, authentication events, access logs, audit logs, error logs, diagnostic logs, performance metrics, failed login attempts, and abuse-prevention signals.
- Cookies and local storage: session tokens, language preferences, theme preferences, security state, and other information required to operate the Service.
2.3 Customer Data and Connected Systems
ODMS may connect to systems selected by you or your organization, including OData services, relational databases, ERP systems, internal APIs, files, and AI model providers. Depending on how you configure the Service, data processed from those systems may include personal information, business records, credentials, metadata, and operational logs.
You are responsible for ensuring that you have the necessary rights, permissions, notices, and lawful basis to connect, import, query, analyze, or otherwise process such data through the Service.
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide, operate, maintain, and secure the Service | Contract performance / legitimate interests |
| Create and manage accounts, tenants, licenses, and access controls | Contract performance |
| Process payments, invoices, renewals, cancellations, refunds, and billing disputes | Contract performance / legal obligation |
| Provide technical support, sales support, implementation assistance, and customer communications | Contract performance / legitimate interests |
| Send service notices about billing, security, product updates, policy changes, and operational issues | Legitimate interests / legal obligation |
| Monitor security, prevent fraud, detect abuse, protect accounts, and enforce Terms | Legitimate interests / legal obligation |
| Improve reliability, usability, performance, diagnostics, and product quality | Legitimate interests |
| Provide AI-assisted features requested by you or your organization | Contract performance / legitimate interests |
| Comply with legal, tax, accounting, payment, export control, and regulatory obligations | Legal obligation |
| Send marketing communications where permitted | Consent / legitimate interests, depending on applicable law |
We may aggregate or anonymize information for analytics, statistics, product planning, and security research. Aggregated or anonymized information does not identify you.
4. Cookies and Tracking Technologies
We use cookies, local storage, and similar technologies to operate and secure the Service.
| Type | Purpose | Disableable |
|---|---|---|
| Strictly necessary | Login sessions, authentication, security, payment flow, and core product functionality | No |
| Functional | Language, theme, preferences, saved UI state, and convenience features | Yes, through browser or product settings where available |
| Analytics | Product reliability, usage trends, performance, and error diagnostics | Yes, where such tools are enabled and controls are available |
| Marketing | Campaign measurement and product communication effectiveness | Yes, where such tools are enabled |
At the time of this Policy, odms.io primarily uses strictly necessary and functional technologies for site and product operation. If we enable third-party analytics or marketing tools, we will identify them in the product, site notice, or cookie notice as appropriate.
5. Sharing and Disclosure
We do not sell your personal information, including as defined under laws such as the CCPA/CPRA. We share personal information only in the following circumstances:
- Service providers: infrastructure, hosting, cloud, email, support, logging, security, analytics, payment, and operational vendors that help us provide the Service and are bound by confidentiality or data processing obligations.
- Payment processors: payment card data is processed by Waffo Pancake or another payment processor identified at checkout or on your invoice. Full card numbers are not stored on our servers.
- AI model providers: when you use AI-powered features, prompts, selected context, metadata, files, or outputs may be sent to third-party AI providers or user-configured model endpoints only as needed to provide the requested feature.
- Customer administrators: if your account belongs to an organization, workspace, tenant, or private deployment, administrators may access account, usage, audit, configuration, and customer data according to their permissions.
- Legal requirements: where required by law, subpoena, court order, regulatory request, export control, sanctions compliance, or to protect rights, safety, and security.
- Business transactions: in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, subject to reasonable confidentiality and notice where required.
- With your consent: for any other purpose with your explicit consent or instruction.
6. AI Features and Model Providers
Some ODMS features may generate summaries, suggestions, queries, mappings, business object definitions, analysis, reports, or automation logic using AI. To provide these features, we may process prompts, metadata, user-selected records, schema information, configuration, and outputs.
We do not use your confidential customer data to train third-party AI models without your explicit consent. If your organization configures its own AI model provider, gateway, or API key, that provider's terms and privacy practices may apply to the processing performed through that configuration.
7. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information, including:
- TLS / HTTPS encryption in transit.
- Encryption, hashing, or secure handling for passwords, secrets, and sensitive configuration where appropriate.
- Access controls based on least privilege.
- Authentication, authorization, audit logging, and operational monitoring.
- Separation of production, test, and demo environments where applicable.
- Security review and remediation of reported issues.
- Backup, recovery, and incident response processes appropriate to the Service.
No method of transmission or storage is perfectly secure. You are responsible for securing your accounts, credentials, database permissions, deployment environment, API keys, model provider keys, network access, and user permissions.
If a security incident affects your rights or personal information, we will notify affected users and relevant authorities within 72 hours of discovery where required by applicable law.
8. Data Retention and Storage
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
| Data Type | Retention Period | Upon Expiry |
|---|---|---|
| Account information | While active; up to 90 days after cancellation or deletion request unless longer retention is required | Delete or anonymize |
| Billing and transaction records | Up to 7 years, or longer if required for tax, accounting, legal, or dispute purposes | Archive, delete, or anonymize |
| Support and sales communications | Up to 3 years after the last interaction unless needed for legal, security, or customer relationship purposes | Delete or archive |
| Security, audit, and access logs | Up to 24 months, or longer if needed for security investigations, compliance, or disputes | Delete or anonymize |
| Product usage and diagnostic logs | Up to 24 months | Delete or anonymize |
| Customer data in hosted environments | While active; up to 90 days after termination unless otherwise agreed | Delete, export, or anonymize according to product capability and agreement |
| Demo and trial data | Up to 90 days after trial or demo expiry | Delete or reset |
| Aggregated or anonymized data | May be retained indefinitely | No personal identification |
Private deployment customers may control retention inside their own infrastructure. We do not control retention of data stored solely in a customer-managed environment unless we are given access for support or managed services.
9. Your Data Rights
Depending on your location and applicable law, you may have rights to know what data we collect, access a copy of your personal information, correct inaccurate or incomplete information, request deletion under certain conditions, restrict processing, receive data in a structured and machine-readable format, object to processing based on legitimate interests or marketing, withdraw consent, and opt out of sale or certain sharing where applicable.
To exercise these rights, contact [email protected]. We will respond within 30 calendar days where required by law. We may need to verify your identity before fulfilling a request. If your account is controlled by an organization, we may direct you to that organization or coordinate with its administrator.
You may also lodge a complaint with your local data protection authority.
10. Marketing and Opt-Out
We may send product updates, launch notices, educational content, or commercial communications where permitted by law. You can opt out at any time by using an unsubscribe link where available or by contacting [email protected].
Opting out of marketing does not affect essential service communications, such as billing notices, security alerts, account notices, support replies, policy updates, and transactional messages.
11. International Data Transfers
We and our service providers may process information in Japan, the United States, the European Economic Area, Singapore, or other regions where we or our vendors operate. For private deployments, data may be processed in the infrastructure region selected or operated by the customer.
Where required by applicable data protection law, we use appropriate safeguards for cross-border transfers, such as data processing agreements, Standard Contractual Clauses, adequacy mechanisms, contractual confidentiality commitments, and transfer risk assessments.
12. Children's Privacy
The Service is intended for users aged 18 and above. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, contact [email protected] and we will take appropriate steps to delete it.
13. Third-Party Links and Services
The Service may include links to or integrations with third-party services, such as payment processors, AI model providers, cloud providers, OData services, database systems, ERP systems, documentation sites, community platforms, or support tools. This Policy applies only to information we directly collect or process. We are not responsible for third-party privacy practices, and you should review their policies before using them.
14. Policy Changes
We may update this Policy from time to time. For material changes, we will provide at least 15 days' advance notice by website notice, email, in-product notice, or another reasonable method where practical or required by law. The "Last Updated" date at the top of this Policy indicates the latest revision. Continued use after the effective date constitutes acceptance of the updated Policy.
15. Contact Us
For privacy, support, billing, security, sales, or general questions, contact us at:
- Privacy and Support Email: [email protected]
- General Email: [email protected]
- Sales Email: [email protected]
- Website: https://odms.io
- Legal Name: WEI,LIBO
- Business Name: youkit studio
- Product: odms.io / ODMS
- Mailing Address: Available upon verified legal, billing, or privacy request by contacting [email protected]
WEI,LIBO / youkit studio - https://odms.io