Ask a team running Odoo whether they have backups and the answer is always yes. Ask how much work they would lose if the database died at three in the afternoon, and how long it would take before invoices could be issued again, and the answers get vague. Those two questions are the entire subject. Everything else — where the copy lives, how often the job runs, which button triggers it — is detail underneath them.
Two numbers decide everything
The first is how much data you can afford to lose, measured in time. If your last good copy is from 2am and the failure happens at 3pm, you have lost a day of orders, payments and stock moves, and you will spend the following week rebuilding them from email and memory. The second is how long you can be down. For a professional services firm, a few hours is an inconvenience. For a warehouse shipping same-day or a retail chain mid-promotion, it is revenue that never comes back.
Write both numbers down before you evaluate any hosting arrangement, because they decide what you actually need to buy. A business that can absorb a day of loss and a day of downtime needs something very different from one that cannot lose an hour, and paying for the second when you need the first is as much a mistake as the reverse.
Where a nightly backup quietly fails
A nightly dump answers "do we have a backup" with yes, and answers "how much would we lose" with "up to twenty-four hours". That gap stays invisible until the day it matters.
Point-in-time recovery is what closes it. Instead of restoring to last night's snapshot, you restore the database to a chosen moment: five minutes before the bad import, or the instant before someone ran a mass update with the wrong filter selected. Plemo managed hosting runs automated backups with point-in-time recovery for exactly this reason. Most real incidents are not hardware failures. They are human actions with a precise timestamp, and the value of a recovery point is that it can sit just before that timestamp.
The second quiet failure is the filestore. Odoo keeps attachments — signed contracts, invoice PDFs, scanned delivery notes — outside the database itself. A backup that captured only the database restores a system where every document link is broken, which you discover at the worst possible moment. Ask explicitly whether attachments are included, and confirm it by opening one after a test restore.
A restore you have never rehearsed is a guess
Backup jobs report on themselves. A green status means the job ran. It does not mean the archive is readable, that the restore fits inside the downtime you assumed, or that the person who knew the procedure still works here.
The only way to know is to restore somewhere that is not production. Staging and sandbox environments turn that into a routine exercise instead of a crisis experiment: restore a recent copy into a separate environment, time it, open a few reports, confirm the attachments resolve. Do it once and you have replaced an assumption with a measured number. Do it twice a year and the number stays true as your data grows.
That growth is the part teams underestimate. A 5GB database and a 300GB database do not behave alike, and the second is where "we will just restore it" becomes a very long afternoon.
What to check with any Odoo host
- Can you recover to an arbitrary point in time, or only to the last scheduled snapshot?
- Are attachments and the filestore included, and does a restored system open its documents?
- How long does a full restore of your database take? Ask for a measured number at your size, not a general reassurance.
- Can your team rehearse a restore in a staging environment, without a support ticket and without touching production?
- Who performs the recovery at 2am on a public holiday, and how do you reach that person?
- When was a restore from these backups last actually performed, by anyone?
The last question sorts providers faster than any feature list. A provider that restores regularly will answer it immediately.
The part hosting cannot decide for you
Managed hosting handles the mechanics. The backups run, the recovery points exist, monitoring is in place, and the environments are there to test in. What it cannot do is decide how much loss and downtime your business is willing to accept, or know that your month-end close has quietly become the window where an outage costs ten times what it costs on an ordinary Tuesday. Those are operational decisions and they belong with the people who own the process.
If you want the mechanics handled while your team keeps the decisions, that is the shape of Plemo managed hosting and our managed support and SLA work. The useful version of that conversation starts with your two numbers, not with a list of features.
