Legal
Privacy Policy
Last updated: 10 August 2026
This policy explains what Prime Softworks collects when you use Odeer, why we collect it, who we share it with, how long we keep it, and how you get it deleted. It covers the Odeer product and this website. Odeer is a shared customer-messaging inbox: businesses connect their own WhatsApp Business, Instagram and Facebook Page accounts, answer customer messages from one place, and track those conversations as leads in their own Odeer sales pipeline.
1. Who we are
Odeer is operated by Prime Softworks (full registered entity name available on request), trading as Prime Softworks, established in the Arab Republic of Egypt.
| Registered address | Available on request from the privacy contact below |
| Registration number | Available on request from the privacy contact below |
| Privacy contact | The privacy team at the address below — our privacy address (publication pending) — reach us at primesoftworks.com |
| Support | our support address (publication pending) — reach us at primesoftworks.com |
2. Scope and our two roles
We handle two different kinds of data, and our responsibility is different for each.
- Client account data. Information about the business that subscribes to Odeer and the people who log in. For this we are the controller: we decide why and how it is processed.
- End-customer message data (Platform Data). The conversations our client’s customers have with that client on WhatsApp, Instagram and Messenger. For this we are a processor: we act only on our client’s documented instructions. The client is the controller and remains the owner of the data and of the connected accounts.
If you messaged a business that uses Odeer and want your data removed, contact that business first. See Your rights for what we do if they do not respond.
3. Client account data we collect
- Name and business name.
- Work email address and phone number.
- Billing details: billing entity, address, tax identifier and payment status.
- Authentication metadata: password hashes or federated sign-in identifiers, session tokens, IP address, browser and device information, and sign-in timestamps.
- Access tokens and account identifiers for the systems the client chooses to connect, held encrypted.
- Support correspondence, including email and messages sent to our team.
- Product usage and diagnostic logs, such as which features were used and when.
4. Meta Platform Data we process
When a client connects a WhatsApp Business account, an Instagram professional account or a Facebook Page through Meta Embedded Signup, we receive and process the following on that client’s behalf:
- Message content, including text, and attachments such as images, audio and documents.
- The sender’s phone number and WhatsApp profile name.
- Instagram handles and Facebook user names, and the scoped IDs Meta issues for them.
- Page identifiers, Instagram account identifiers, WhatsApp Business Account (WABA) and phone-number identifiers.
- Message timestamps, direction, and delivery, read and failure status.
- Conversation metadata: conversation category, the state of the customer service window, message-template names and their approval status.
- Contact records the client builds from these conversations: name, phone number, handle, assigned owner and notes.
We do not request Meta permissions beyond those needed for the messaging inbox and the sales pipeline described in this policy.
5. How and why we use it
| Purpose | Data used | Lawful basis |
|---|---|---|
| Rendering the client’s shared inbox | Platform Data | Processing on the client’s instructions; performance of our contract with the client |
| Routing and assigning conversations to the right salesperson | Platform Data, client account data | Processing on the client’s instructions |
| Maintaining the client’s own sales pipeline (contacts, lead stage, won/lost, timeline) | Platform Data, client account data | Processing on the client’s instructions |
| Delivery diagnostics and support | Message status, error codes, logs | Performance of contract; our legitimate interest in a working service |
| Billing, invoicing and collections | Client account data, usage counts | Performance of contract; legal obligation |
| Security, fraud and abuse prevention | Authentication metadata, logs | Our legitimate interest in protecting the service and its users |
| Marketing this website and measuring its campaigns | Website visitor data only — never Platform Data | Consent, where required |
| Meeting legal, tax and accounting obligations | Client account data, invoices | Legal obligation |
6. Restrictions on Meta Platform Data
Data obtained from the WhatsApp Business Platform, Instagram Messaging and Messenger is used solely to provide the Odeer service to the client from whose connected account it originated.
Specifically, that data is:
- never sold, licensed or rented to anyone;
- never shared with any third party for advertising, ad targeting, retargeting, audience building or measurement;
- never combined across clients — each client’s data is isolated, and no client can see another client’s conversations, contacts or metrics;
- never used to train machine-learning or artificial-intelligence models, ours or anyone else’s;
- never used to build profiles for any purpose other than serving that same client.
Where AI features are used to draft or summarise a reply, the request is made on the client’s instruction to the provider named in Sub-processors under terms that prohibit training on the content submitted, and the output is returned only to that client’s workspace.
Prime Softworks acts as a Tech Provider and complies with the Meta Platform Terms, the Meta Developer Policies and the WhatsApp Business Messaging Policy. Each client owns its own WhatsApp Business Account, Facebook Page and Instagram account; our access is delegated by that client and can be revoked by that client at any time.
7. Sub-processors
We use the providers below to run the service. Each is bound by a written agreement that limits them to processing data on our documented instructions and holds them to confidentiality and security obligations no weaker than ours.
| Provider | Purpose | Processing region |
|---|---|---|
| Vercel Inc. | Website and application hosting, edge delivery | United States / global edge |
| Supabase Inc. | Managed PostgreSQL database and storage | Confirmed on request |
| Named on request | Transactional and notification email | Confirmed on request |
| Named on request | AI assistance for reply drafting and summarisation, on the client's instruction | United States |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. | WhatsApp Business Platform, Instagram Messaging and Messenger APIs | Ireland / United States |
We keep this list current and notify clients before a material change, so they have the chance to object.
8. International transfers
Our application and database run in a region confirmed on request, so data is processed outside Egypt — typically in the European Union and the United States. Where data leaves Egypt or the EEA, we rely on Standard Contractual Clauses and equivalent contractual safeguards with each provider, together with encryption in transit and at rest. A copy of the relevant transfer terms is available on request.
9. Retention
| Data | Kept for |
|---|---|
| Message content, attachments and contact records | The life of the client’s subscription, then deleted within 30 days of the subscription ending |
| Data for a disconnected WhatsApp, Instagram or Facebook account | Purged within 30 days of disconnection |
| Data covered by a verified deletion request | Deleted within 30 days of verification |
| Encrypted backups | Deleted records age out of backups within 35 days; backups are never restored to reinstate deleted data |
| Security and access logs | 12 months, then deleted |
| Invoices and accounting records | 5 years, because Egyptian tax and commercial law requires it |
| A minimal record of each deletion request | Kept as long as the account record itself, so we can prove the request was honoured |
10. Security
These are the practices we actually operate. They are practices, not certifications.
- All traffic is encrypted in transit with TLS; stored data is encrypted at rest.
- Tenant isolation: every record carries the workspace that owns it, and access rules are enforced at the database layer so one client’s query cannot reach another’s data.
- Role-based access inside a client workspace, and least-privilege access for our own staff.
- API credentials and access tokens are stored encrypted, never written to logs and never shipped to the browser.
- Access to production is limited to named staff, authenticated, and logged.
- Application and access logging with monitoring for anomalous activity.
- Incident response: if a breach affects your data we notify affected clients without undue delay and, where required, within 72 hours of becoming aware, together with what we know and what we are doing about it.
We do not claim SOC 2, ISO 27001, HIPAA or GDPR certification. If we obtain one we will say so here and name the auditor.
11. Your rights
Subject to applicable law, you can ask us to:
- confirm what personal data we hold about you and give you access to it;
- correct data that is wrong or incomplete;
- delete your data — see Data deletion;
- export your data in a portable, machine-readable format;
- restrict or object to a particular use;
- withdraw a consent you previously gave, without affecting what was done before.
Send requests to our privacy address (publication pending) — reach us at primesoftworks.com. We respond within 30 days. We verify identity before acting on a request, and we may ask for information that lets us match the request to an account.
If you are an end customer who messaged a business that uses Odeer, that business controls the data — contact them first. Tell us anyway and we will forward the request to them and help them action it. If they do not respond within 30 days, contact us again and we will act on the request ourselves to the extent we are able.
You also have the right to complain to a supervisory authority — in Egypt, the Egyptian Personal Data Protection Center established under Law No. 151 of 2020, or the data-protection authority where you live.
12. Deleting your data
Deletion has its own page, with the in-app path, what disconnecting an account removes, a request form and the exact information to include: https://odeer-ai.vercel.app/data-deletion. Verified requests are completed within 30 days.
13. Cookies and analytics
This marketing website loads two third-party measurement pixels, and only if the corresponding ID is configured by us:
- Meta Pixel (connect.facebook.net). Fires a page view on load, a custom BookCallClick event when a “Book a call” button is clicked, and Lead plus CompleteRegistration when the call-booking form is submitted. It collects the page URL, referrer, browser and device information, IP address and Meta’s own cookies.
- TikTok Pixel (analytics.tiktok.com). Fires the equivalent page, ClickButton, SubmitForm and CompleteRegistration events, collecting the same categories of website data.
The site also uses browser local storage to remember your language and light/dark theme choice. That never leaves your device.
These pixels measure this marketing website only. They are never present in the Odeer application, and no message content, contact or other Platform Data is ever passed to them. To opt out, block third-party scripts or cookies in your browser, use a content blocker, or adjust your ad settings with Meta and TikTok.
Booking a call writes the name, phone number, email and country you enter into our customer database so we can call you back. That is the only form on the marketing site.
14. Children
Odeer is a business tool sold to businesses. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, write to our privacy address (publication pending) — reach us at primesoftworks.com and we will delete it.
15. Changes to this policy
We update this policy when the service changes. The effective date at the top of the page always reflects the current version. For a material change we notify clients by email, and in the application, at least 14 days before it takes effect. Continuing to use Odeer after that date means the updated policy applies.
This version is effective from 10 August 2026.
16. Contact us
| Privacy and data-protection | our privacy address (publication pending) — reach us at primesoftworks.com |
| Support | our support address (publication pending) — reach us at primesoftworks.com |
| Deletion requests | our deletion address (publication pending) — reach us at primesoftworks.com · /data-deletion |
| Postal | Registered address available on request, Arab Republic of Egypt |
This page is published in English. An Arabic copy is available on request from our support address (publication pending) — reach us at primesoftworks.com.