O

The Omni Labs

AI-Native Enterprise OS

PlatformContactTalk to us
← Back to home

Privacy Policy

Last updated September 17, 2026

The Omni Labs ("we", "us", "our") operates theomni-labs.com and the Omni platform. We are the data controller for personal data collected through this website. This policy explains what we collect, why, and the rights available to you under applicable data protection law, including the EU/UK General Data Protection Regulation ("GDPR"), Saudi Arabia's Personal Data Protection Law ("PDPL"), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), and Turkey's Law No. 6698 on the Protection of Personal Data ("KVKK").

1. Who we are

The Omni Labs is the data controller (or "Veri Sorumlusu" under KVKK) responsible for the personal data described in this policy. You can reach us at hello@theomni-labs.com for any data protection request.

2. What we collect

Through our contact form, we collect the name, work email address, company name, and message content you choose to submit. We do not use advertising or cross-site tracking cookies on this site. If we introduce analytics in the future, it will be privacy-preserving and cookie-free by default (e.g. Cloudflare Web Analytics), or will be gated behind a consent banner if it requires cookies.

3. Why we process it, and our legal basis

4. Cross-border data transfers

Depending on your deployment (SaaS, private cloud, or dedicated instance), your data may be processed in the region you select at onboarding (currently Saudi Arabia, Turkey, UAE, or other regions on request). Where personal data is transferred internationally — for example between our team and a subprocessor, or between regions — we rely on appropriate safeguards such as standard contractual clauses (GDPR Ch. V), or equivalent mechanisms required under Saudi PDPL, UAE PDPL, and KVKK (Art. 9) for cross-border transfer. Enterprise customers can request a data residency commitment restricting processing to a specific jurisdiction as part of a dedicated deployment.

5. Data retention

Contact form submissions are retained only as long as needed to respond to your enquiry, or for the duration of a customer relationship plus a reasonable period to meet legal, accounting, or contractual obligations. We delete or anonymize data once it is no longer needed for these purposes.

6. Your rights

Depending on where you are, you have some or all of the following rights. Contact hello@theomni-labs.com to exercise any of them — we will respond within the timeframe required by the applicable law (typically 30 days).

7. Security

We apply encryption in transit and at rest, role-based access control, and audit logging to protect personal data. See our Security page for more detail. In the event of a personal data breach affecting your rights, we will notify affected individuals and the relevant supervisory authority within the timeframe required by applicable law (e.g. 72 hours under GDPR where feasible).

8. Children's data

Our website and services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.

9. Changes to this policy

We may update this policy as our practices or applicable law evolve. Material changes will be reflected by updating the "Last updated" date above.

10. Contact us / lodge a complaint

For any question, request, or complaint about how we handle your personal data, contact hello@theomni-labs.com. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority (for example, your national GDPR supervisory authority in the EEA/UK, the Saudi Data & AI Authority (SDAIA), the UAE Data Office, or Turkey's Personal Data Protection Authority (KVKK Kurumu)).

This policy is drafted to reflect the substantive requirements of GDPR, Saudi PDPL, UAE PDPL, and Turkey's KVKK, but it is a template, not a substitute for legal advice. Actual compliance also depends on your real operational practices — subprocessor data processing agreements, security certifications, breach response procedures, and (if required by your data volumes or activities) appointing a Data Protection Officer or Saudi/UAE-equivalent representative. Have this reviewed by a qualified lawyer licensed in each jurisdiction you operate in before relying on it commercially.