This policy explains what OODTC ("OODTC", "we", "us") collects when you use oodtc.tech or our software, AI, and automation services — including data accessed through connected platforms such as X (Twitter), Meta/WhatsApp, Slack, and others — and the choices you have over it.
OODTC is a software company providing custom software development, AI agents, workflow automation, API integrations, and related infrastructure services, operated from the domain oodtc.tech. This Privacy Policy applies to our marketing website, client dashboards, automation platform, and any connected third-party integrations we operate on a client's behalf.
By using our website or services, you agree to the collection and use of information as described here. If you don't agree, please don't use our services, or contact us first with questions at privacy@oodtc.tech.
We collect information in three ways: what you give us directly, what our systems collect automatically, and what we access through platforms you connect to our automations.
A core part of what we build is automation that connects to third-party platforms — including but not limited to X (Twitter), Meta technologies (Facebook, Instagram, WhatsApp Business), Slack, Discord, Google Workspace, and CRM or webhook-based tools. This section explains how that access works.
When you or your team connect a platform account to an OODTC automation, access is granted through that platform's own official authentication flow (typically OAuth). We do not request or store your platform password, and we never access a connected account outside the scopes you explicitly approve.
Depending on the automation you configure, this may include: posts, messages, or mentions relevant to the workflow; contact and profile information needed to route a message; and metadata (timestamps, IDs) required to avoid duplicate actions. We request the minimum scope necessary for the automation to function — never broader account access "just in case."
| Platform | How we use access | What we don't do |
|---|---|---|
| X (Twitter) API | Posting, reading mentions/DMs, and automations explicitly configured by the account owner, per X's Developer Agreement and Policy. | No off-platform data storage beyond what the workflow requires; no use for surveillance or profiling. |
| WhatsApp Business / Meta | Sending and receiving messages through the WhatsApp Business Platform for the automations you configure. | No use of message content for advertising; no sharing with unrelated third parties. |
| Slack / Discord | Reading and posting messages in channels the workspace admin has authorized. | No access to channels or DMs outside the granted scope. |
| Other platforms | Any additional platform we integrate follows the same principle: official API, minimum scope, use limited to your automation. | No workaround access methods (e.g. unauthorized scraping) are used to reach a platform's data. |
We comply with each connected platform's own developer policy and terms of service. If a platform's policy imposes stricter requirements than this document, the platform's policy controls for data accessed through that integration.
We do not use data accessed through a client's connected platform accounts to train general-purpose AI models, build advertising profiles, or sell to data brokers.
Where the UK/EU GDPR applies, we rely on one or more of the following bases: performance of a contract (delivering the service you've engaged us for), legitimate interests (securing our systems, improving our services), consent (marketing communications, optional cookies), and legal obligation (tax and accounting records).
We keep personal data only as long as needed for the purpose it was collected for:
You can request earlier deletion at any time; see Section 8.
Depending on where you live, you may have some or all of the following rights over your personal data:
To exercise any of these rights, email privacy@oodtc.tech. We aim to respond within 30 days.
We apply technical and organizational safeguards appropriate to the sensitivity of the data involved, including encryption in transit (TLS), access controls on our infrastructure, VPN-gated administrative access, and least-privilege scoping for platform API credentials. No system is 100% secure, and we can't guarantee absolute security, but we treat credential and data handling as a first-class engineering concern, not an afterthought.
Our infrastructure and team may operate from locations outside your own country. Where personal data is transferred internationally, we take reasonable steps to ensure it remains protected consistent with this policy and applicable law, including the use of standard contractual safeguards where required.
Some services we build use AI models to classify, draft, or route content (for example, drafting a reply or tagging a message). Where an automation materially affects you and relies solely on automated decision-making, we design for a human review point, and you may request human review of a specific automated action by contacting us.
Our services are directed at businesses and are not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy as our services or legal obligations change. Material changes will be reflected by an updated "Last updated" date at the top of this page, and, where appropriate, communicated directly to active clients.
Questions about this policy or how your data is handled: