How we work
Security and access
You are giving an outside party a login to the system that runs your company. This page says exactly what we do with it. It is written to be checked, not just read.
Last updated 15 September 2026.
1. The access we ask for
A named user in your Odoo, called Wellstreak, with rights limited to the apps a request touches. Not a shared admin login. Where your Odoo supports two-factor authentication (Odoo Online does), we turn it on for that user.
You create the user, you can see what it has done, and you can disable it at any time. Disabling it ends our access immediately.
For a first request we prefer a test copy of your database rather than production. Odoo Online lets you create one in a few clicks.
2. Nothing reaches production without your written yes
We read freely. We never write to your production Odoo without your explicit, written approval that names the change. “Go ahead” isn’t enough; “yes, activate the invoice automation on production” is.
Before we write anything we confirm which database we are in, so a change meant for a test copy cannot land in production by mistake.
Changes that touch accounting, stock, manufacturing, or confirmed sales and purchase orders get an independent check against your approval before they run. Anything that crosses a locked period, or changes who can see financial data, is treated the same way.
3. Test first, then production
Two lanes. New features, such as automations, reports and workflows, are built and verified on a test copy first. Only then, with your approval, are they deployed to production, and we check them again there without changing anything else.
Changes that are exactly what you asked for, such as a data correction you have specified record by record, can go directly to production once you have approved them in writing. The approval names the change; we confirm the database, do it, verify it read-only, and leave the note.
Before we change an existing record or setting in bulk, we save its previous state so it can be put back.
4. Every change leaves a trace
Each record we create or change gets an internal note in your Odoo: Edited by Wellstreak, followed by what was done. You can search for it at any time.
Everything we build for you is delivered as a folder with a plain description of what it does, the code, a deploy script, and the test log. Automations, actions and scheduled jobs we create carry a Wellstreak: prefix in their name, and they are listed in a small register app inside your Odoo that only your chosen users can see.
5. Your data stays in your Odoo
We work inside your instance. We don’t export your database, and we don’t copy it to our systems. When a task needs an extract of individual records, for example to analyse a mis-posting, we delete it when the task is done, and in any case within 30 days after our access ends.
Personal data we come into contact with inside your Odoo is processed on your instructions under our Data Processing Agreement. That agreement also lists our sub-processors.
6. If something goes wrong
If we cause an error in your data, or become aware of a security incident that affects it, we tell you without undue delay and no later than 48 hours after we know: what happened, what is affected, and what we have done about it. Then we fix it, on your instructions, at no charge.
7. Backups and recovery
Backups of your Odoo stay with you and your hosting provider. Odoo Online keeps daily backups; on your own server, your backup routine applies. Before larger changes, such as a migration, we ask you to take a fresh backup, and we keep the previous state of anything we change so it can be restored.
8. Leaving
If you stop the subscription, you disable the Wellstreak user and our access ends. Everything we built stays in your Odoo, with the register and the delivery folders, so anyone can see what exists and maintain it. Nothing depends on us staying.
9. You set the pace
If you would rather see this in practice before opening the door wide, start on a test copy. You decide when production comes into play, and for which requests.
Questions about any of this? Use the contact page.