Privacy Policy
Effective Date: January 1, 2026 · Last Updated: October 9, 2026
Executive Privacy Summary
OmniAgent OS ("OmniAgent", "we", "us") operates a Generative Engine Optimization (GEO) and agentic discovery platform. We process business metadata, structured catalog schemas, and public web context so AI answer engines (ChatGPT, Claude, Perplexity, Google AI Overviews) recommend businesses accurately. We do not sell, rent, or trade personal data. Payment processing and tax remittance are managed by Polar as Merchant of Record.
1. Data Controller Information
For the purposes of the European Union General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK Data Protection Act 2018 ("UK GDPR"), and applicable international privacy legislation, the Data Controller responsible for your personal data is:
Entity: OmniAgent OS Infrastructure
Primary Domain: https://omniforce.run
Data Protection Office (DPO): privacy@omniforce.run
Regulatory Representative Contact: legal@omniforce.run
2. Categories of Personal Data We Process
Depending on how you interact with our platform, we collect and process the following categories of data:
- Account & Identity Credentials: Name, business email address, encrypted password credentials (hashed using scrypt Key Derivation Function with cryptographically random salt), and session tokens.
- Tenant & Domain Management Data: Domain names you connect, verified Schema.org entity metadata, corporate catalogs, public founder/executive credentials submitted for verified biographical grounding, and platform integrations (e.g. WordPress, Shopify, FastMCP).
- Billing & Commercial Records: Subscription tier, Polar customer ID, billing cycle status, and invoice history. Payment card numbers, CVCs, and bank details are processed directly and exclusively by our Merchant of Record, Polar.sh, and are never stored on or transmitted through OmniAgent OS servers.
- AI Search Telemetry & Beacon Data: When you deploy our public machine manifests (/llms.txt, /schema.jsonld) or beacon scripts, our telemetry engine records incoming request headers (User-Agent string, referring AI engine, IP address truncated or pseudonymized for crawler attribution), HTTP request paths, and access timestamps.
- Technical Diagnostic Data: Browser user agent, operating system, and system performance logs to maintain operational security and DDoS resilience.
3. Legal Bases for Processing (GDPR Art. 6)
Under GDPR and UK GDPR, we process personal data under the following legitimate legal bases:
Contractual Performance
Provisioning user authentication, tenant isolation, synthetic radar audits, and generating machine-readable discoverability files.
Legitimate Interests
Preventing fraud, identifying malicious scraping, monitoring AI crawler bot patterns, and optimizing platform network efficiency.
Legal Obligation
Compliance with tax, corporate accounting, anti-fraud, and law enforcement statutory obligations.
Consent
Where voluntary consent is explicitly provided, such as opting into product update bulletins or research pilots.
4. AI Engines & Generative Discoverability Processing Notice
OmniAgent OS publishes machine-readable manifests (/llms.txt, /llms-ctx.txt, /schema.jsonld) and tool endpoints (FastMCP / A2A) intended to be crawled and ingested by search engines and autonomous AI agents (such as OpenAI GPTBot, Anthropic ClaudeBot, PerplexityBot, and Google-Extended).
Our Commitments Regarding AI Transparency:
- We only publish business context and entity claims that you, the operator, have explicitly configured or authorized.
- We do NOT use private customer data to train foundation frontier models.
- Biographical grounding is strictly sourced from verified canonical links provided by the operator to protect against AI hallucinations.
5. Third-Party Sub-processors & Data Transfers
We work with trusted enterprise sub-processors to deliver platform services:
| Sub-processor | Purpose | Location | Transfer Mechanism |
|---|---|---|---|
| Neon Database Inc. | Serverless Postgres DB & Tenant Data Storage | EU (Frankfurt) / US | Standard Contractual Clauses (SCCs) / DPF |
| Polar Software Inc. | Merchant of Record, Global VAT/Sales Tax, Invoicing | US / Global | Data Processing Addendum & SCCs |
| Cloudflare, Inc. | Edge DNS, CDN Caching, DDoS Protection | Global Edge Network | EU-US Data Privacy Framework (DPF) |
| Upstash Inc. | Redis Cache & Distributed Rate Limiting | EU / US | Standard Contractual Clauses (SCCs) |
6. Data Retention & Deletion
We retain personal data only for as long as necessary to fulfill the purposes set out in this Privacy Policy:
- Account Data: Retained for the duration of your active subscription or account. Upon account deletion request, all tenant credentials, knowledge nodes, and API keys are permanently expunged within 30 calendar days.
- Telemetry & Crawler Logs: Raw crawler telemetry is retained on a rolling 90-day cycle, after which event data is permanently aggregated or pruned.
- Statutory Invoices: Payment receipts and tax records retained by Polar as Merchant of Record are kept in accordance with applicable tax statutory periods (typically 7–10 years).
7. Your Rights Under GDPR & UK GDPR
If you reside within the European Economic Area (EEA) or the United Kingdom, you hold the following statutory rights:
- Right of Access (Art. 15): Obtain confirmation and copy of your personal data processed by us.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal information.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of your personal data where retention is no longer justified.
- Right to Restriction of Processing (Art. 18): Restrict processing under statutory circumstances.
- Right to Data Portability (Art. 20): Receive your tenant knowledge data in a structured, machine-readable format (JSON/JSON-LD).
- Right to Object (Art. 21): Object to processing founded on legitimate interests.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local Data Protection Authority (e.g. CNPD in Portugal, ICO in the UK, BfDI in Germany, CNIL in France, or EDPB).
8. Notice for California Residents (CCPA & CPRA)
Under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"):
- No Sale or Sharing of Personal Information: OmniAgent OS does not sell personal information and has not sold personal information in the preceding 12 months. We do not share personal information for cross-context behavioral advertising.
- Right to Know & Delete: California consumers may request disclosure of data categories collected, or request deletion of their personal information without discriminatory treatment.
- Sensitive Personal Information: We do not collect or process sensitive personal information for purposes other than providing our core SaaS services.
9. Cookies & Tracking Technologies
We adhere strictly to the EU ePrivacy Directive (Directive 2002/58/EC). We use essential first-party cookies necessary for authentication and session integrity:
Name: omniagent_session
Type: Strictly Necessary / Essential (Exempt from consent requirement under ePrivacy Art. 5(3))
Attributes: HttpOnly, Secure, SameSite=Lax, Path=/
Purpose: Cryptographic user session authentication signed with HMAC-SHA256
Lifespan: 30 days or until explicit logout
10. Technical & Organizational Security Measures
In compliance with Article 32 of the GDPR, we implement state-of-the-art technical and organizational measures to ensure security appropriate to the risk:
- Cryptographic Password Protection: Passwords are never stored in plaintext and are hashed using scrypt (memory-hard key derivation function) with unique 16-byte random salts.
- Encryption in Transit: TLS 1.3 enforced across all public endpoints and API gateways.
- Tenant Isolation: Multi-tenant isolation enforced at the database connection layer with tenant-scoped session context.
- Signed Checkout & Payloads: Checkout sessions and webhook payloads are cryptographically signed using HMAC-SHA256.
11. Contact & Exercising Your Privacy Rights
To exercise any of your data protection rights, request data export, or submit inquiries regarding our privacy compliance, please contact our Data Protection Office:
Requests are processed free of charge within 30 days pursuant to GDPR Art. 12(3).