Privacy Policy
This Privacy Policy explains how Omnexa AI collects, uses, discloses, stores, transfers, and protects personal information when you visit our website, contact us, engage with our content, book a consultation, use our services, or interact with AI systems, automations, integrations, or workflows provided by Omnexa.
Last updated: 14/07/2026
Name: Omnexa AI
Contact Email: omnexatech7@gmail.com
1. About Omnexa
Omnexa AI provides AI automation, AI employee development, voice AI systems, workflow automation, CRM automation, customer support automation, sales automation, appointment and booking automation, and related AI-powered business systems.
Our services are primarily provided in a business-to-business context. We help organizations design, deploy, connect, manage, and improve AI systems that support business operations, customer communication, internal workflows, and service delivery.
2. What This Privacy Policy Is About
This Privacy Policy explains how we handle personal information relating to:
• Website visitors • Prospective clients • Clients and client representatives • Business contacts • Newsletter subscribers • People who book consultations or strategy sessions • Individuals who contact us through email, website forms, calls, or messages • Vendors, partners, contractors, and professional contacts • Users who interact with Omnexa-powered AI systems, where applicable • Individuals whose information is provided to us by clients as part of a project
“Personal information” means any information that can identify a person directly or indirectly. This may include obvious details such as name, email address, phone number, and business contact information, as well as technical details such as IP address, device information, cookie identifiers, usage logs, chat content, call transcripts, or workflow activity where those details relate to an identifiable person.
3. When This Policy Does Not Apply
In many cases, Omnexa provides services to business clients as a service provider, processor, contractor, or technical implementation partner.
Where we process personal information only on behalf of a client, the client is usually responsible for deciding why and how the data is used. In that situation, the client’s own privacy policy may apply to the individuals whose personal information is processed through an Omnexa-powered system.
For example, if you interact with an AI receptionist, AI support agent, booking assistant, sales follow-up workflow, voice AI system, or automated customer service flow provided by one of our clients, that client may be the main controller of your personal information.
If you have questions about how one of our clients uses your information, you should contact that organization directly. We may assist them where appropriate, but we may not be able to respond directly to certain requests if we are only acting on their behalf.
This Privacy Policy also does not apply to current or former employees, job applicants, or contractors where a separate internal privacy notice applies.
4. Our Role: Controller and Processor
Depending on the situation, Omnexa may act as either a data controller or a data processor.
We may act as a controller when we decide how and why personal information is used, such as when we collect website analytics, manage sales inquiries, send business communications, run our website, or manage our own client relationships.
We may act as a processor when we process personal information on behalf of a client, such as when we build, host, connect, maintain, or support AI systems that process the client’s customer, employee, prospect, or business data.
Where we act as a processor, we process personal information according to our agreement with the client and their lawful instructions.
5. The Basics of Our Privacy Practices
To make this Privacy Policy easier to understand, these are the key points:
• We operate mainly in a business-to-business environment. • We collect personal information to run our website, communicate with prospects, provide services, support clients, and improve our systems. • We may process personal information through AI systems, automation workflows, third-party integrations, communication tools, CRMs, calendars, support tools, and voice or messaging systems. • We do not sell personal information. • We may work with trusted third-party providers to host, secure, operate, analyze, communicate, bill, and deliver our services. • Our business may be registered in the United Kingdom, but our team members, contractors, and service providers may work from different countries. • Where personal information is accessed or transferred internationally, we aim to use appropriate safeguards where required by law. • We retain personal information only for as long as needed for the purposes described in this Policy, unless a longer period is required by law, contract, security, accounting, tax, dispute resolution, or legitimate business needs. • Clients remain responsible for ensuring that personal information they provide to Omnexa has been collected and shared lawfully. • AI outputs should be reviewed by humans where they may affect individuals in important, sensitive, regulated, or high-impact situations.
6. What We Collect, Keep, and Why
We collect different types of personal information depending on how you interact with Omnexa. The table below explains common situations, the types of data involved, how we use it, the lawful basis we may rely on, and who it may be shared with.
| Situation | Personal Information We May Collect | How We Use It | Lawful Basis | Who We May Share It With |
|---|---|---|---|---|
| If you browse our website | IP address, browser type, device type, operating system, page views, referral source, approximate location, language settings, session activity | To display the website, improve performance, understand visitor behavior, detect errors, and protect the website | Legitimate interests; consent where required for non-essential cookies | Hosting providers, analytics providers, security tools, CDN providers |
| If you use website forms | Name, email address, phone number, company name, role, message content, service interest, submitted form details | To respond to inquiries, qualify requests, book calls, and provide relevant information | Legitimate interests; pre-contract steps; consent where applicable | CRM tools, email providers, scheduling tools, internal team members |
| If you book a consultation | Name, email, phone number, company, meeting time, meeting notes, business needs, calendar details | To schedule, confirm, prepare for, and follow up on consultations | Pre-contract steps; legitimate interests | Calendar providers, CRM tools, video meeting platforms, email providers |
| If you communicate with us | Emails, messages, call details, support requests, attachments, notes, screenshots, transcripts where applicable | To respond to you, provide support, manage requests, and maintain records | Legitimate interests; contract; legal obligation where applicable | Email providers, support tools, internal team members, contractors assisting with support |
| If you become a client | Business contact details, contract details, billing details, project requirements, workflow information, communication records | To manage the client relationship, deliver services, invoice, support, and maintain records | Contract; legitimate interests; legal obligation | Accounting tools, CRM tools, payment providers, professional advisers, internal team members |
| If we design AI systems for your business | Business rules, processes, policies, pricing, FAQs, service details, documents, training materials, workflow instructions | To build, train, configure, test, deploy, and maintain business-specific AI systems | Contract; legitimate interests | AI infrastructure providers, automation platforms, cloud hosting providers, internal technical team |
| If users interact with Omnexa-powered AI systems | Chat messages, voice inputs, call transcripts, prompts, uploaded files, responses, customer details, booking requests, support issues, CRM records, workflow logs | To provide AI responses, execute workflows, book appointments, route requests, summarize conversations, and support service delivery | Contract; processor obligations; legitimate interests; consent where required | Client systems, AI service providers, automation tools, communication providers, CRM platforms |
| If we connect third-party integrations | OAuth tokens, API keys, integration metadata, account IDs, user IDs, permissions, connected tool activity | To connect client tools, enable workflows, move data between systems, and maintain integrations | Contract; legitimate interests; consent where applicable | Third-party platforms, API providers, automation tools, hosting providers |
| If we provide voice AI or call automation | Caller name, phone number, call recording where enabled, transcript, call summary, call intent, booking details, routing decisions | To answer calls, qualify requests, book appointments, create summaries, and improve call workflows | Contract; legitimate interests; consent where required by law | Voice providers, telephony platforms, CRM tools, calendar tools, client systems |
| If we provide sales or CRM automation | Lead details, contact history, email activity, call notes, qualification data, deal stage, follow-up records | To qualify leads, update CRM records, trigger follow-ups, route leads, and support sales operations | Contract; legitimate interests | CRM platforms, email tools, automation platforms, internal team members |
| If we provide customer support automation | Customer questions, support tickets, product issues, account information, chat logs, resolution notes, escalation details | To answer routine questions, create tickets, route issues, generate summaries, and support customer service | Contract; legitimate interests; processor obligations | Support platforms, CRM tools, AI providers, client systems |
| If you subscribe to updates | Email address, name, company, communication preferences, engagement data | To send newsletters, insights, resources, product updates, and marketing communications | Consent; legitimate interests for B2B communications where permitted | Email marketing platforms, CRM tools, analytics providers |
| If you attend webinars or events | Name, email, company, role, attendance records, questions, feedback, event preferences | To manage event registration, attendance, follow-up, and related communications | Consent; legitimate interests; contract where applicable | Webinar platforms, event tools, email providers, CRM tools |
| If we process payments or invoices | Billing contact details, invoice records, payment status, transaction references, tax information | To process payments, manage invoices, maintain financial records, and comply with accounting obligations | Contract; legal obligation | Payment processors, accounting tools, banks, accountants |
| If we monitor security and abuse | IP address, access logs, login records, device information, suspicious activity, error logs | To protect systems, prevent misuse, detect fraud, investigate incidents, and maintain service integrity | Legitimate interests; legal obligation | Security providers, hosting providers, monitoring tools, legal advisers |
| If we handle legal or compliance matters | Contract records, communications, service records, relevant files, identity information, dispute materials | To comply with legal obligations, respond to lawful requests, enforce agreements, and defend claims | Legal obligation; legitimate interests | Lawyers, regulators, courts, insurers, professional advisers |
| If we use contractors or remote team members | Business contact data, project data, access permissions, workflow records, communication records | To deliver services, provide technical support, manage projects, and operate globally | Contract; legitimate interests | Authorized contractors, team members, secure collaboration tools |
| If we receive data from clients | Customer data, employee data, lead data, support records, workflow inputs, documents, CRM data | To provide services on behalf of the client and operate agreed AI systems or automations | Processor obligations under contract | Authorized subprocessors, client-approved platforms, technical service providers |
| If we improve services | Usage logs, system performance data, error reports, anonymized or aggregated patterns, support trends | To improve reliability, usability, accuracy, security, and workflow performance | Legitimate interests; consent where required | Analytics tools, monitoring providers, internal team members |
We may also use personal information where necessary to comply with legal requirements, enforce our terms, protect our rights, or respond to lawful requests from authorities.
Where possible, we may aggregate, anonymize, or de-identify information so it no longer identifies individuals. We may use such non-identifiable information to improve our services, analyze trends, and enhance business operations.
7. Lawful Bases for Processing
Where UK GDPR, EU GDPR, or similar privacy laws apply, we process personal information only where we have a lawful basis.
The lawful bases we may rely on include:
Contract We may process personal information where it is necessary to perform a contract or take steps before entering into a contract. For example, we may use contact details to provide services, manage client accounts, deliver AI systems, or respond to service requests.
Legitimate Interests We may process personal information where it is necessary for our legitimate business interests, provided those interests are not overridden by individual rights and freedoms.
Examples include improving our website, responding to business inquiries, securing our systems, managing client relationships, conducting B2B marketing, preventing fraud, supporting service delivery, and improving operational performance.
Consent We may rely on consent where required, such as for certain marketing communications, non-essential cookies, optional data uses, or certain types of sensitive data. Where we rely on consent, you may withdraw it at any time.
Legal Obligation We may process personal information where necessary to comply with legal, tax, accounting, regulatory, court, or law enforcement obligations.
Vital Interests In rare cases, we may process personal information where necessary to protect someone’s life or physical safety.
8. AI and Personal Information
Omnexa provides AI-enabled services. Personal information may be processed when individuals interact with AI agents, AI employees, voice AI systems, chat assistants, booking agents, support agents, sales workflows, CRM automations, or other AI-powered systems we build or manage.
AI-related processing may include:
• Prompt text • Chat messages • Uploaded documents or files • Voice inputs • Call recordings where enabled • Call transcripts • AI-generated outputs • Conversation summaries • Customer support tickets • Appointment requests • Sales qualification details • CRM records • Calendar details • Email content • Workflow activity • Integration metadata • System logs • Error reports • Usage data
We use this information to provide, operate, secure, monitor, troubleshoot, support, and improve Omnexa services.
Where we use third-party AI providers, automation platforms, or infrastructure providers, personal information may be processed through those systems as necessary to deliver the service.
Unless otherwise agreed in writing, Omnexa does not intentionally use client personal information to train public AI models. Where data is used to improve systems, we aim to use anonymized, de-identified, aggregated, or permission-based data where appropriate and legally permitted.
Clients remain responsible for determining whether AI systems are appropriate for their use case and for ensuring that appropriate human review, transparency, and safeguards are in place where AI outputs may affect individuals in important, sensitive, regulated, or high-risk contexts.
9. Client Data and Enterprise Use
Many Omnexa services are delivered to businesses. In those cases, clients may provide access to their tools, systems, data, documents, customer records, employee records, CRM data, support tickets, communications, workflows, and business processes.
Clients are responsible for ensuring that:
• They have the lawful right to share personal information with Omnexa. • Relevant individuals receive appropriate privacy notices. • Any required consent, contractual basis, legitimate interest, or other lawful basis is in place. • Omnexa is informed of any industry-specific or regulatory requirements. • AI outputs are reviewed where appropriate. • Access permissions granted to Omnexa are authorized and proportionate.
Where Omnexa acts as a processor, we process client data according to the client’s instructions and applicable service agreement.
10. Sensitive Personal Information
We do not usually seek to collect sensitive personal information unless it is necessary for a specific service or provided to us as part of a client workflow.
Sensitive personal information may include information relating to health, biometric data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, criminal offence data, or similar protected categories under applicable law.
If a client’s workflow involves sensitive personal information, the client must inform Omnexa before implementation so appropriate safeguards, access controls, legal bases, and contractual terms can be considered.
Omnexa does not knowingly process sensitive personal information for marketing purposes.
11. Cookies and Similar Technologies
Our website may use cookies, pixels, tags, local storage, and similar technologies.
Cookies may be used to:
• Keep the website functioning properly • Improve website performance • Remember preferences • Understand visitor activity • Analyze traffic • Improve content and user experience • Measure marketing campaigns • Protect against fraud or misuse
Cookies may include:
Essential Cookies These are necessary for the website to function and cannot usually be switched off.
Analytics Cookies These help us understand how visitors use our website, which pages are visited, and how we can improve the experience.
Functional Cookies These remember preferences or support enhanced website functionality.
Marketing Cookies These may be used to understand campaign performance or deliver more relevant content where permitted.
Where required by law, we will request consent before placing non-essential cookies on your device.
You can usually manage cookies through your browser settings. If we use a cookie consent tool, you may manage preferences through the cookie settings link or banner on our website.
If you disable cookies, some website features may not work properly.
12. Marketing Communications
We may send marketing communications, newsletters, insights, educational resources, event invitations, service updates, or AI automation content to business contacts where permitted by law.
You can opt out of marketing emails at any time by clicking the unsubscribe link in our emails or contacting us directly.
We may still send non-marketing communications where necessary, such as service updates, security alerts, legal notices, billing messages, or project-related communications.
13. What We Share With Third Parties
We may share personal information where necessary to operate our business, provide services, support clients, comply with law, or protect our rights.
Service Providers and Vendors We may share personal information with trusted service providers, including:
• Website hosting providers • Cloud infrastructure providers • AI model providers • Automation platforms • CRM systems • Email providers • Calendar and scheduling tools • Voice and telephony providers • SMS and messaging providers • Payment processors • Accounting and invoicing tools • Analytics providers • Security and monitoring tools • Customer support platforms • Project management tools • File storage providers • Legal, accounting, tax, consulting, and insurance advisers
Contractors and Remote Team Members Omnexa may work with team members, contractors, technical specialists, or service providers located in different countries. Where access to personal information is necessary, we aim to limit access based on role, project need, authorization, and confidentiality obligations.
Client Systems and Integrations Where we build or manage AI systems for a client, personal information may be shared with or transmitted through the client’s own systems, such as CRMs, calendars, email accounts, phone systems, databases, support tools, payment systems, or communication platforms.
Legal and Regulatory Disclosures We may disclose personal information where necessary to:
• Comply with law • Respond to court orders or lawful requests • Cooperate with regulators or authorities • Enforce agreements • Protect our rights, property, safety, or operations • Prevent fraud, misuse, or security incidents • Support legal claims or dispute resolution • Handle corporate transactions, restructuring, merger, or acquisition activity
Business Transfers If Omnexa is involved in a merger, acquisition, sale, restructuring, financing, or transfer of business assets, personal information may be shared as part of that transaction, subject to appropriate safeguards.
We do not sell personal information.
14. Subprocessors and Third-Party Processing
To provide our services, Omnexa may use subprocessors and technical service providers that process personal information on our behalf.
These may include hosting providers, AI infrastructure providers, model providers, automation platforms, communication tools, CRM systems, monitoring tools, and other vendors required to operate Omnexa services.
Where appropriate, we aim to use written agreements requiring subprocessors to protect personal information, process it only for authorized purposes, and apply appropriate confidentiality and security measures.
Omnexa may maintain a list of key subprocessors or provide it to clients upon request where required by contract.
15. International Data Transfers and Remote Team Access
Omnexa may be registered in the United Kingdom, but our team members, contractors, service providers, technical partners, and infrastructure providers may be located in different countries.
This means personal information may be accessed, transferred, processed, or stored outside the United Kingdom, including in countries that may not provide the same level of data protection as the UK.
Where required by law, we aim to protect international transfers using appropriate safeguards. These may include:
• Transfers to countries recognized as providing adequate protection • The UK International Data Transfer Agreement • The UK Addendum to the EU Standard Contractual Clauses • Contractual commitments with service providers • Data processing agreements • Access controls • Encryption or secure transmission where appropriate • Role-based permissions • Confidentiality obligations • Limiting access to what is necessary • Security review of tools and vendors where appropriate
Clients should notify Omnexa before implementation if they require specific data residency, transfer restrictions, hosting locations, compliance standards, or geographic access controls.
16. Where We Store Personal Information
Personal information may be stored in cloud systems, hosting environments, collaboration tools, CRM platforms, AI infrastructure, automation systems, communication tools, and client-connected platforms.
Storage locations may vary depending on the tools used for a particular service.
Where a client requires a specific storage location or data residency arrangement, this must be agreed in writing before implementation.
17. How We Secure Personal Information
We aim to apply appropriate technical and organizational measures to protect personal information against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
These measures may include:
• Access controls • Role-based permissions • Authentication safeguards • Password protection • Encryption where appropriate • Secure cloud infrastructure • Monitoring and logging • Confidentiality obligations • Limited access based on need • Vendor review where appropriate • Secure file handling • Internal security practices • Incident response procedures • Data minimisation • Regular review of access where practical
However, no digital system, AI tool, integration, communication channel, or online transmission can be guaranteed to be completely secure.
If you believe your personal information or an Omnexa-connected system has been accessed without authorization, please contact us immediately.
18. How We Retain and Delete Personal Information
We retain personal information only for as long as necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention depends on factors such as:
• The nature of the information • The purpose for which it was collected • The length of our relationship with you or the client • Contractual requirements • Legal, tax, accounting, or regulatory obligations • Security and fraud prevention needs • Dispute resolution or legal claims • Service monitoring, troubleshooting, or support needs
General retention examples may include:
| Data Category | Typical Retention Approach |
|---|---|
| Website analytics data | Retained for a limited period needed for analytics and performance review |
| Contact form inquiries | Retained while responding and for a reasonable period for business records |
| Consultation records | Retained for sales, follow-up, and client relationship management |
| Client contact and account data | Retained for the duration of the relationship and a reasonable period afterwards |
| Contracts, invoices, and billing records | Retained as required for tax, accounting, legal, and compliance purposes |
| Project documents and workflow materials | Retained for the duration of the project and as needed for support, maintenance, or legal records |
| AI service logs and workflow records | Retained as needed for monitoring, troubleshooting, security, audit, support, and service improvement |
| Marketing data | Retained until you unsubscribe or until no longer needed for legitimate business purposes |
| Security logs | Retained as needed to protect systems and investigate incidents |
When personal information is no longer needed, we may delete it, anonymize it, de-identify it, or securely retain it where legally permitted.
19. Data Accuracy
We aim to keep personal information accurate and up to date where necessary for the purposes for which it is processed.
You may contact us to request correction of inaccurate or incomplete personal information.
Clients are responsible for ensuring that data provided to Omnexa is accurate, current, and suitable for the intended workflow.
20. Automated Decision-Making and Profiling
Omnexa systems may support automation, routing, classification, scoring, prioritization, recommendations, summaries, and workflow actions.
Unless clearly stated in a client agreement or service-specific notice, Omnexa does not intend to use personal information for solely automated decisions that produce legal or similarly significant effects on individuals without appropriate human review.
Clients using Omnexa systems are responsible for ensuring that appropriate human oversight, review, appeal, transparency, and safeguards are in place where AI outputs may affect individuals in important or sensitive ways.
21. Children’s Privacy
Our website and services are intended for business users and are not directed at children.
We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate authorization, we will take reasonable steps to delete it or handle it in accordance with applicable law.
22. Third-Party Websites and Platforms
Our website and services may contain links to third-party websites, platforms, tools, or services.
We do not control and are not responsible for the privacy practices, content, security, or data handling of third-party websites or platforms.
You should review the privacy policies of any third-party services you use or connect with Omnexa systems.
23. Your Privacy Rights in the United Kingdom
If you are in the United Kingdom, you may have rights under UK data protection law, including:
• The right to access your personal information • The right to correct inaccurate or incomplete information • The right to request deletion of your personal information • The right to restrict certain processing • The right to object to certain processing • The right to object to direct marketing • The right to withdraw consent where processing is based on consent • The right to data portability where applicable • Rights relating to automated decision-making where applicable • The right to complain to the Information Commissioner’s Office
To exercise your rights, contact us at:
omnexatech7@gmail.com
We may need to verify your identity before responding.
Some rights may be limited where we need to retain information for legal, contractual, security, dispute resolution, or legitimate business reasons.
If your information is processed by Omnexa on behalf of one of our clients, we may direct your request to that client or assist them in responding.
24. Your Rights in the EU, EEA, and Switzerland
If you are located in the European Union, European Economic Area, or Switzerland, you may have similar privacy rights under applicable data protection laws.
These may include rights of access, correction, deletion, restriction, objection, data portability, withdrawal of consent, and rights relating to automated decision-making.
If Omnexa is required to appoint an EU representative because of its activities, we will provide the relevant representative details in this Privacy Policy or through another appropriate notice.
25. Your Rights in Other Regions
Depending on where you are located, you may have additional privacy rights under local privacy laws, including the right to request access, correction, deletion, information about data sharing, or to opt out of certain uses of personal information.
Omnexa does not sell personal information.
If you are in a region with specific privacy rights, you may contact us at:
omnexatech7@gmail.com
We will respond to applicable requests in accordance with relevant law.
26. How to Exercise Your Rights
To exercise privacy rights, please contact us using the email address provided in this Policy.
Please include enough information for us to understand your request and verify your identity.
We may ask for additional information before processing your request. If we cannot fulfill your request, we will explain why where required by law.
We aim to respond within the timeframe required by applicable law.
27. Complaints
If you have concerns about how we handle personal information, please contact us first so we can try to resolve the issue.
You also have the right to complain to the UK Information Commissioner’s Office, the UK data protection regulator.
ICO website: https://ico.org.uk ICO helpline: 0303 123 1113
If you are located outside the UK, you may also have the right to complain to your local data protection authority.
28. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, website, technology, legal requirements, business operations, or privacy practices.
When we update this Privacy Policy, we will revise the “Last updated” date at the top of this page.
Where required, we may notify you of material changes by email, website notice, or another appropriate method.
Your continued use of our website or services after updates are posted means you acknowledge the updated Privacy Policy.
29. Contact Us
If you have any questions, complaints, feedback, or privacy requests, please contact us:
Email: omnexatech7@gmail.com Business Name: Omnexa AI
Omnexa has not appointed a formal Data Protection Officer unless required by applicable law. Privacy questions and requests should be sent to the contact email above.
