Skip to content
ODONEXOSmile Academy

Legal

Privacy

How Odonexo Academy collects, uses and protects your personal data.

What we collect

When you submit an application, contact form or member registration we collect the details you provide: name, email address, telephone number, country, profession, experience level and any message you write.

When you hold a member account we additionally store a one-way hash of your password, your enrolment records and any certificates issued to you.

What we do not collect

We do not store your password. Passwords are hashed with PBKDF2-SHA256 before they reach the database and cannot be reversed.

We do not store raw IP addresses. Where an IP is needed for security purposes it is hashed one-way before being written to the audit log.

We do not use advertising trackers or third-party analytics scripts.

How we use it

To assess your application and recommend a suitable programme.

To administer your enrolment, issue certificates and provide course materials.

To reply to enquiries you send us.

To protect the service — rate limiting, detecting repeated failed sign-ins and maintaining a security audit log.

Where it is stored

Records are held in Cloudflare D1. Session tokens and rate-limit counters are held in Cloudflare KV with automatic expiry. Uploaded files and issued certificates are held in Cloudflare R2.

Session cookies are HTTP-only, SameSite=Lax and, in production, Secure. They expire after seven days.

Your rights

You may request a copy of the data we hold about you, ask us to correct it, or ask us to delete your account and associated records. Write to us and we will respond within a reasonable period.

Contact

Data protection enquiries: admissions@odonexo.academy