Legal
Privacy Policy
Effective: 1 April 2026 Version: 1.0 Regulation: GDPR · UK GDPR

Plain-English Summary: We collect only what we need to run OmniGate. We don't sell your data. You can request access, deletion, or a copy at any time. We're bound by GDPR and UK GDPR. Read on for the full details.

Contents
  1. Who We Are
  2. What Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Data Retention
  6. Third-Party Integrations & Processors
  7. International Data Transfers
  8. Cookies & Tracking
  9. Your Rights
  10. Children's Privacy
  11. Security
  12. Changes to This Policy
  13. Contact & Complaints

1. Who We Are

OmniGate operates the autonomous AI integration platform available at omnigate.io and related subdomains. For the purposes of the GDPR and UK GDPR, OmniGate is the data controller of the personal data described in this policy.

Contact: omnigate@polsia.app

2. What Data We Collect

2.1 Account & Contact Data

2.2 Usage & Technical Data

2.3 Agent & Integration Configuration Data

2.4 Customer Data (Processed on Your Behalf)

Where your agents process data from your integrated systems, that data is Customer Data under our Terms of Service. We process it only to deliver the Service and do not access it except for troubleshooting at your request or as required by law. A Data Processing Agreement (DPA) governs such processing — contact us to obtain one.

2.5 Data We Do Not Collect

3. How We Use Your Data

PurposeData UsedLegal Basis
Providing and operating the ServiceAccount, usage, configurationContract performance
Billing and payment processingAccount, billingContract performance
Customer supportAccount, communicationsContract performance / Legitimate interest
Security monitoring & fraud preventionTechnical, usageLegitimate interest
Product improvement & analyticsAnonymised usage dataLegitimate interest
Legal complianceAs requiredLegal obligation
Marketing communications (opt-in only)Email, nameConsent
AI model improvement (aggregate, de-identified only)Anonymised interaction patternsLegitimate interest

We do not sell, rent, or share your personal data with third parties for their own marketing purposes.

4. Legal Basis for Processing

Under GDPR Article 6, we process personal data on the following bases:

5. Data Retention

Data TypeRetention PeriodReason
Account & contact dataDuration of account + 30 daysService delivery; post-termination export window
Billing records7 years from transactionLegal / tax obligation
Agent activity logs90 days (configurable per plan)Debugging, audit, compliance
Integration credentialsDeleted on revocation or account terminationSecurity
Customer Data (processed by agents)As specified in DPA; default 30 days post-terminationCustomer retention policy
Server access logs30 daysSecurity monitoring
Marketing opt-in recordsUntil consent withdrawn + 1 yearEvidence of consent
Support communications3 yearsReference for future support

After the relevant retention period, data is permanently deleted or anonymised such that it can no longer be linked to an individual.

6. Third-Party Integrations & Processors

We use carefully selected sub-processors to operate the Service. All sub-processors are bound by data processing agreements and subject to GDPR-equivalent protections:

Sub-processorPurposeLocation
RenderCloud infrastructure & hostingUSA (SCCs applied)
Neon (PostgreSQL)Database hostingUSA (SCCs applied)
AnthropicAI model inferenceUSA (SCCs applied)
StripePayment processingUSA/EU (SCCs applied)
Postmark / SendGridTransactional emailUSA (SCCs applied)
CloudflareCDN, DDoS protectionGlobal (EU region available)

We do not permit sub-processors to use your data for their own purposes beyond providing the contracted service. Our full list of sub-processors is available on request.

7. International Data Transfers

Some of our sub-processors operate outside the European Economic Area (EEA) or UK. Where personal data is transferred to countries not recognised as providing an adequate level of protection, we rely on:

You may request a copy of the applicable transfer mechanism by contacting us at omnigate@polsia.app.

8. Cookies & Tracking

8.1 Cookies We Use

Cookie NameTypePurposeDuration
Session tokenStrictly necessaryKeeps you logged inSession
_og_visitorAnalytics (first-party)Anonymous visitor ID for usage analytics1 year
_og_prefsFunctionalRemembers your dashboard preferences1 year
_stripe_*Payment (third-party)Fraud prevention by StripeSession / 1 year

8.2 Managing Cookies

Strictly necessary cookies cannot be disabled without breaking the Service. For analytics and functional cookies, you may opt out via your browser settings or our cookie preference centre. Most browsers allow you to block or delete cookies — consult your browser documentation for instructions.

8.3 No Third-Party Ad Tracking

We do not use advertising networks, retargeting pixels, or third-party tracking tools that track your behaviour across other websites.

9. Your Rights

Under GDPR and UK GDPR, you have the following rights regarding your personal data. We will respond to all valid requests within 30 days (extendable to 90 days for complex requests, with notice).

Right of Access

Obtain a copy of the personal data we hold about you.

Right to Rectification

Correct inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data where we have no legal basis to retain it.

Right to Restriction

Ask us to restrict processing while a dispute is resolved.

Right to Portability

Receive your data in a structured, machine-readable format (JSON or CSV).

Right to Object

Object to processing based on legitimate interest or direct marketing.

Automated Decision Rights

Request human review of any purely automated decisions that significantly affect you.

Withdraw Consent

Withdraw consent at any time without affecting prior lawful processing.

To exercise any of these rights, email omnigate@polsia.app with the subject line "Data Subject Request". We will verify your identity before processing the request. Requests are free of charge unless manifestly unfounded or excessive.

10. Children's Privacy

The Service is directed at businesses and professionals aged 18 and over. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at omnigate@polsia.app and we will delete it promptly.

11. Security

We implement technical and organisational measures appropriate to the risk, including:

No system is perfectly secure. In the event of a personal data breach that poses risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email and update the "Effective" date above. Continued use of the Service after notification constitutes acceptance of the updated policy. For significant changes (e.g., new processing purposes), we will obtain fresh consent where required.

13. Contact & Complaints

For privacy-related queries or to exercise your rights:

OmniGate Privacy Team
Email: omnigate@polsia.app
Subject: "Privacy Request — [Your Name]"

If you are not satisfied with our response, you have the right to lodge a complaint with: