Odzy
EN
← Back to home

Security & privacy

Last updated: April 2026

Odzy is a tool used by salespeople and sales teams to analyze their deals. We process potentially sensitive data: customer interactions, call notes, CRM content. This page documents precisely how we handle your data — where it is stored, who has access, and what commitments we make.

EU hosting GDPR compliant SOC 2 certified stack OAuth read-only

1. Where your data is stored

All your structured data (account, profile, analyzed deals, debriefs, playbook) is stored at Supabase, on their PostgreSQL instances hosted by Amazon Web Services in Ireland (eu-west-1). These servers are physically located in Dublin and subject to EU jurisdiction.

The Odzy web application is served by Vercel from their European servers. No structured data leaves the European Union for storage.

In short: your profile, analyses, debriefs and CRM tokens stay in Ireland. They are not replicated outside the EU.

2. What is stored exactly

Here is the complete and exhaustive list of what our database contains:

Data typeDetail
Account Email, first name, password (irreversibly hashed via Supabase Auth)
Sales profile Product sold, sector, ICP, average deal size, sales cycle, methodology
Analyzed deals Company, contact, amount, stage, and the AI analysis result (summary, closing rate, advice, detected objections)
Post-call debriefs Debrief notes you write yourself after your calls
CRM integration tokens HubSpot OAuth tokens (access + refresh), encrypted at rest by Supabase
Credits Remaining analysis credit balance

What is NOT stored

During an analysis, we read on demand the information of the contact concerned in your CRM, we use it immediately to build the AI prompt, and we do not retain it. We keep the result of the analysis, not the raw material that was used to produce it.

3. Who has access to your data

You, and only you
Your data is strictly isolated by your user identifier via Supabase Row Level Security policies. No other Odzy user can access your analyses.
The Odzy team (admin)
The Odzy administrator technically has access to the database for support and maintenance needs. Written commitment: no consultation without your explicit request.
Our technical sub-processors
Supabase, Vercel, Anthropic and HubSpot in their respective scopes, each governed by their own compliance (see section 4).
No one else
No data resale. No third-party tracking cookies for marketing. No analytics tool that sees the content of your deals.

4. Technical sub-processors and their certifications

Odzy relies exclusively on certified, GDPR-compliant cloud infrastructure. Here is the exhaustive list of our sub-processors:

Sub-processorRoleLocationCertifications
Supabase Database and authentication Ireland (EU) SOC 2 Type II, HIPAA, GDPR
Amazon Web Services Physical infrastructure for Supabase Ireland (eu-west-1) ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
Vercel Web app hosting Frankfurt (EU) SOC 2 Type II, GDPR
Anthropic AI inference (Claude model) United States SOC 2 Type II, GDPR via SCC
HubSpot Source CRM (OAuth read-only) EU / US (depending on your account) SOC 2 Type II, ISO 27001, GDPR

5. The exception: AI inference and transfer outside the EU

Let's be transparent about the only point that leaves the European Union. When you launch an analysis, the following content is sent to Anthropic (creator of the Claude model) on their servers in the United States:

This transfer is governed by the Standard Contractual Clauses (SCC) approved by the European Commission in 2021, which form the official legal framework for EU → US transfers since the Privacy Shield was invalidated. This is the same mechanism used by OpenAI, Notion, Slack, Linear, GitHub, and the vast majority of modern SaaS tools.

According to Anthropic's commercial API Terms of Use:

6. HubSpot integration security

When you connect your HubSpot account to Odzy, here is exactly what happens:

List of requested HubSpot scopes:

7. Your GDPR rights

Under the General Data Protection Regulation (EU 2016/679), you have the following rights over your personal data:

To exercise any of these rights, write to hello@revlineapp.io. We commit to responding within a maximum of 30 days.

8. Our approach to certifications

Odzy is currently in the early user testing phase. Like most SaaS tools at this stage (Lemlist, Resend, Cal.com and many others did this before us), we have not yet obtained our own formal certifications such as SOC 2 or ISO 27001. However, our technical stack is already composed exclusively of certified infrastructure, which guarantees a high level of de facto security.

For buyers needing a stronger contractual framework (NDA, bilateral DPA, security questionnaire), contact us at hello@revlineapp.io — we usually respond within 48h.

9. Reporting an incident or asking a question

For any question regarding security or privacy, or to report an incident or vulnerability, contact us directly at hello@revlineapp.io.

For B2B buyers needing a bilateral Data Processing Agreement (DPA), or to fill out a security questionnaire, write to us at the same address — we usually respond within 48h.

This page is updated with every significant change to our infrastructure or practices. For the formal privacy policy, see our Privacy Policy.