Odrazio Privacy Policy
Esta página no está disponible en tu idioma. Se muestra la versión en inglés.
This Policy explains how Odrazio processes personal data. It is not a statement that every use is lawful without the permissions and safeguards described below.
1. Controller, scope, and contact
For the Service described here, Odrazio is responsible for the personal-data processing described in this Policy (“we”, “us”, or “Controller”).
For privacy requests, consent withdrawal, or suspected unauthorised cloning, contact [email protected] with the subject “Privacy” or “Clone Abuse”. This Policy applies to our websites, dashboard, APIs, support interactions, and related Services. It does not replace an organisation customer’s own duties where that customer decides why and how it processes another person’s data.
2. Personal data we may process
Account and contact data: email address, name if supplied, account identifier, authentication method, password hash where a password is used, and account preferences.
Third-party sign-in data: the identity-token claims needed to authenticate you, such as a verified email address and basic profile information, when you choose a supported third-party sign-in method.
Source Material and Clone data: photos, selfies, reference images, video, voice recordings, reference scripts, face or voice characteristics derived for the requested Service, Clone configurations, and the relationship between an account and its Clones.
Generation data: prompts, scripts, selected languages and settings, generated audio, images and video, task identifiers, error messages, and metadata needed to run, recover, secure, or bill a generation.
Payment and subscription data: customer and order identifiers, product or plan, purchase status, subscription status, and payment-related records received from our payment provider. We do not intentionally store full payment-card numbers.
Technical and security data: IP address where logged, approximate device and browser information, signup anti-abuse fingerprint if supplied, request method/path/status/latency for API use, timestamps, session records, authentication events, and security or abuse reports.
Communications and rights-claim data: messages to support, reports, evidence of consent or authority, identity or representative information needed to resolve a dispute, and our response records.
3. Voice, face, and sensitive or biometric data
A voice recording, face image, voice characteristic, or face-related representation may be personal data and may constitute biometric data or special-category data under applicable law when processed for unique identification or in another regulated context. We treat this category as high risk.
We process this material only to provide the avatar, voice-cloning, text-to-speech, talking-video, security, and abuse-prevention functions you request, or for another purpose clearly disclosed to you. You must not upload another person’s voice or likeness unless you have the Valid Permission described in the Terms. Where explicit consent is legally required, you must obtain it from the Data Subject before submission, and we may ask for evidence. Refusal to provide the Source Material necessary for a Clone means that we cannot provide that clone-related feature.
4. Why we process data and our legal bases
To provide the Service, authenticate users, create and manage accounts, store requested media, run requested generations, deliver output, calculate credits, and provide support. Our basis is performance of a contract or steps requested before entering one.
To process special categories or biometric data where required for the requested clone feature. Our basis is your or the relevant Data Subject’s explicit consent, another lawful basis, or both, as required by applicable law.
To prevent fraud, impersonation, unauthorised cloning, account abuse, security incidents, and infringement; to enforce the Terms; and to keep audit records. Our basis is legitimate interests in protecting people, the Service, and our legal position, balanced against your rights, and where applicable legal obligations.
To process tax, payment, accounting, consumer, and law-enforcement records when required. Our basis is legal obligation or a legitimate interest in establishing, exercising, or defending legal claims.
To send non-essential marketing or use data beyond providing the requested Service only where we have a suitable legal basis, including consent where required. We do not intentionally use identifiable Source Material, Clones, or private output to train our proprietary general-purpose models or market the Service without separate, clearly disclosed permission.
5. How we share data and use processors
We share only the data reasonably necessary for a provider to perform the requested function. Depending on the features you use, recipients may include the following categories of service providers:
Cloud-storage and content-delivery providers: to store uploaded and generated media and make it available through the Service.
AI image-inference and model providers: to process prompts and reference material needed for requested AI image generation.
Voice-processing providers: to process reference audio and related inputs needed for requested voice-cloning jobs.
Audio/video generation providers: to process inputs needed for requested text-to-speech, talking-video, video-enhancement, and related generation jobs.
Identity and authentication providers: to provide a third-party sign-in option only when you choose it.
Transactional-email providers: to send verification, account-recovery, and other service messages.
Payment and subscription providers: to create customer, checkout, order, subscription, and payment-status records for paid Services.
Professional advisers, competent authorities, or affected parties: only when reasonably necessary to handle legal claims, safety incidents, fraud, consent disputes, or legal obligations.
Providers process data under their own applicable terms and privacy commitments. We do not permit them to use data for unrelated purposes on our behalf, but their independent legal obligations and practices may apply. We may change providers as the Service changes and will update this Policy when a material change affects the categories, purpose, or safeguards for personal data.
6. Retention and deletion
We keep personal data for no longer than reasonably necessary for the purposes in this Policy, unless a longer period is required or permitted by law. The operational criteria are as follows:
Account data is generally kept while your account remains active and afterwards only as necessary for closure, security, disputes, tax, accounting, or legal requirements.
Source Material, Clones, and generated media are generally kept until you delete them through available product controls, ask us to delete them, close your account, or we remove them for safety or legal reasons, subject to the limits below.
Access, session, anti-abuse, and security records are retained for the period reasonably necessary to secure the Service, investigate incidents, enforce the Terms, and meet legal obligations. Refresh sessions are designed to expire after the applicable session period.
Payment, order, and tax records are kept for the statutory retention period and for the resolution of payment disputes.
Backups and processor systems may retain a deleted item for a limited technical cycle. We will restrict further active use and delete or anonymise it when the relevant backup cycle, legal hold, or dispute requirement ends.
Deleting content from the Service cannot guarantee deletion from a user’s own devices, a recipient’s devices, third-party publication platforms, or material already downloaded, copied, or lawfully preserved for evidence. We will take reasonable steps within systems we control.
7. Security and access controls
We use reasonable technical and organisational measures designed for the nature of the Service, including access controls, authentication, encrypted transport where supported, role-based administrative access, logging, rate limits, and processor management. No internet service, AI model, cloud system, or transmission can be guaranteed absolutely secure. Please protect account credentials and do not submit sensitive material that you are not authorised to share.
8. Your rights and how to exercise them
Subject to applicable law and verification of your identity or authority, you may request access, a copy, correction, completion, deletion, restriction, portability, objection to processing based on legitimate interests, withdrawal of consent, or information about a significant automated decision. You may also ask us to stop or remove a Clone that represents you, even if you do not have an Odrazio account. Send requests to [email protected] with the subject “Privacy”. We may ask for proportionate information to prevent fraudulent requests and will respond within the period required by applicable law.
If you believe that processing infringes Serbian data-protection law, you may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection of the Republic of Serbia (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti), without limiting any other legal remedy. If you live elsewhere, you may also have the right to complain to your local supervisory authority.
9. Automated safety measures
We may use automated tools to detect suspected fraud, impersonation, unauthorised cloning, harmful prompts, policy violations, and security risk. These measures may cause a request to be delayed, refused, limited, or reviewed. They are not intended to make a solely automated decision with legal or similarly significant effects about you. If a safety decision materially affects you, you may ask for human review at [email protected], except where immediate action is necessary to prevent harm or comply with law.
10. Children
The self-service Service is not directed to children and does not permit the cloning of minors. If you believe that a minor’s personal data, voice, or likeness was submitted, contact [email protected] with the subject “Clone Abuse” so that we can investigate and take appropriate action.
11. Cookies and local storage
We use limited technical storage for language preference, authentication, and cookie-consent choices. When Google Analytics 4 is configured, it loads only after you opt in to analytics through Cookie Settings. It is used to understand public-site usage, not to run advertising or marketing tracking. See the Cookie Policy for the current list and controls.
12. Changes to this Policy
We may update this Policy when the Service, Operator, processors, legal requirements, or security practices change. We will post the new version and, for material changes, provide reasonable notice and obtain a new consent where law requires it. The version and effective date at the top show when this Policy was last changed.
13. Language
English, Serbian, and Chinese versions may be made available for convenience. If they differ, the English version controls to the extent permitted by mandatory law; a Serbian version controls where mandatory Serbian law requires it.