You can save a copy of this disclosure using your browser’s Print function.
1. Controllers, processor and contact
Giampaolo Rao, Via Carpinetana Ovest 18, 00037 Segni (RM), Italy, tax code RAOGPL76L15C858V, info@omniagents.it, is controller for managing commercial relationships, administrator and user contacts, his own service, support, security and his own legal obligations. This notice covers OmniAgents Business for Mac and Windows and the connected iPhone and Android apps, for companies and professionals.
The Customer controls its organisation, personnel, customer and correspondent data and determines purposes, access and content retention. Giampaolo Rao acts as processor only for processing actually entrusted to him under the Business DPA. Local software and connector availability do not give the Provider access to the entire archive. For questions about the relationship or Provider processing, write to info@omniagents.it.
2. Business account, users and sources
The relationship may involve company or professional identification and tax details; administrator, contact-person and user names, email addresses and contact details; organisation identifiers, roles, invitations, licence status, sessions and devices; accepted versions and contractual receipts; and support requests. When payments become available, necessary order, invoice and payment references will be processed under the actual summary and payment service.
Data is supplied by the individual or Customer administrator, or generated during authorised use. Technical identifiers, IP addresses and access, delivery and error records may be processed for infrastructure operation and security. We do not request passwords or card security codes by email. Customer administrators access user data within their assigned roles.
3. Purposes and legal bases
Managing and activating the relationship with a professional who is personally party to the contract: Article 6(1)(b) GDPR, to the extent necessary for that contract. Company contact, administrator and user relationships, access controls, security, abuse prevention and support: Article 6(1)(f), based on legitimate interests in managing and protecting the service and business relationship, subject to rights balancing and minimisation. Tax and other legally required obligations: Article 6(1)(c). Usage statistics are described in section 8.
Accepting terms is not blanket consent to processing. Connector authorisation or an operating-system permission enables the requested function within its purpose and applicable legal basis. Any consent required for an optional function may be withdrawn without affecting the lawfulness of prior processing. The Customer determines the legal basis for content processed for its own purposes.
4. Content, AI and permissions
Documents, photos, contacts, messages, calendar, Knowledge and connected-source content are processed for operations requested by the Customer within actual permissions. The Customer selects a compatible AI model and client and the relevant account; necessary data may be sent to the chosen service within permitted sources and channels. A local model may process on the computer; other integrations retain their own data flows.
Local conversation learning is initially enabled and can be disabled: this stops new learning without deleting existing memory. It does not authorise general model training by the Provider or other providers. We do not sell content for advertising. The Customer assigns proportionate roles; Business APIs do not replace those controls. External actions follow permissions and confirmations required by the workflow.
5. Google APIs and Limited Use
The restrictions in the Google API Disclosure also apply to Business. Use of information received from Google APIs and its transfer to other apps adhere to the Google API Services User Data Policy, including Limited Use requirements. Data is used for user-requested features within granted permissions, not for advertising or training generalised AI models.
Google content from Gmail, Drive, Contacts, Calendar and Photos is excluded from the relay. A remote AI connection is not an alternative route for sending that content: the user may use their AI client’s own Google connection. Local access, file or photo selection and authorised operations follow the applicable flow. Revoking a connection does not automatically erase copies already imported or retained by Google; revocation and deletion outcomes must be checked separately.
6. Meta, WhatsApp and relay
Only if the Customer connects its Meta channels does the service process selected account and asset identifiers and permissions, and content needed for requested functions, such as messages, their references and permitted attachments. Facebook, Messenger, Instagram and WhatsApp retain their own rules, permissions and retention. The relay routes authorised flows to the connected installation: content may remain temporarily in memory during forwarding; technical installation, device, permission and delivery records are separate from the message archive.
Relay service status. The currently published relay transits permitted flows and does not provide a persistent Meta-content queue for retrieval while the computer is offline. The offline queue approved for a subsequent release is not active in the published service. Recovery of every event received offline is not guaranteed. Any activation will require an updated description of processing, limits and retention before it begins.
Local disconnection and provider revocation are separate operations; unconfirmed outcomes should be completed in provider settings. See the Meta data deletion instructions. We do not promise automatic deletion of every Customer or provider copy.
7. iPhone and Android apps and notifications
The OmniAgents iPhone and Android apps connect a mobile device to an authorised computer. Pairing involves technical installation and device identifiers, device name, platform, language and connection credentials; these are not anonymous data.
If your installed version supports notifications and you enable them, the app requests the system permission and associates an FCM token and language with the device on the relay. FCM delivers alerts on Android; on iPhone it also uses APNs. Alerts generated by the relay say only that you have new messages in OmniAgents: they do not contain sender details, text, attachments or Google content. This restriction concerns alert content; it does not make tokens anonymous or eliminate technical data processed by Google and Apple.
You can disable notifications in the app and in operating-system settings. Disabling them in the app requests removal of the token from the relay and deletion of the FCM token; the outcome may depend on connectivity and the external service. Revoking a phone or confirmed removal of an installation removes its relay associations. These actions do not prove immediate deletion of all providers’ technical data or copies, which follow their own retention rules. Firebase information; How APNs tokens work.
Notification permission serves the optional function you request and does not authorise promotional messages. Access to photos, files, the camera or sharing tools remains tied to the actions and permissions you choose. Personal and Business apps use their respective account and, in Business, organisation roles. Store availability is stated only when a version is actually distributed.
8. Aggregated and pseudonymous statistics
Software usage statistics and registration. The OmniAgents Personal and Business terms describe pseudonymous usage statistics provided for in the contractual relationship; that clause is separate from optional website analytics. They are included in acceptance of the terms at registration and also apply during any trial and paid use; they do not require a separate optional checkbox. Accepting a contract is not blanket consent to processing and does not by itself make every item of data necessary.
Account registration and acceptance of terms may involve identity, email and contractual receipts. These are separate from statistical reports, which contain technical installation and environment identifiers, usage counts, outcomes, token use and costs where available, connection status, technical alerts, platform and version. Reports are pseudonymous, not anonymous, because identifiers may be linked to a registered installation. Reports do not include names or email addresses, chat or message text, documents, photos, contacts, private Knowledge, credentials or full URLs.
Transmission to omniagents.it requires an installation recognised by the service and a signed request. Only reports actually sent by enabled installations are collected: visiting this website alone does not activate transmission from the software. Received reports are retained for 180 days from receipt; technical event deduplication keys for 91 days. Their purpose is to assess reliability and operation, without advertising, individual profiling or model training.
Article 6(1)(b) GDPR applies to processing necessary for a contract with the individual; legitimate interest applies to reliability measurement and improvement within the balancing and minimisation required by Article 6(1)(f). You may object to the latter processing on grounds relating to your situation by writing to info@omniagents.it. This edition does not reactivate withdrawn consent or rewrite earlier receipts. Hosting security records remain separate from optional website analytics. Report administration is restricted to authorised personnel.
9. Recipients and services involved
Cloudflare, Inc.: the infrastructure for the omniagents.link relay, used to connect devices, forward permitted flows and manage authentication, routing and security. Meta content may be held temporarily in memory while being forwarded; technical installation, device, authorisation, delivery and security records are separate from content. The relay is not a persistent message archive. Content from Google sources (Gmail, Drive, Contacts, Calendar and Photos) is excluded from these relay flows.
Google Firebase Cloud Messaging (FCM): delivery of push alerts in mobile apps supporting notifications. Delivery on iPhone also involves Apple Push Notification service (APNs). Tokens and installation/device identifiers are pseudonymous personal data; these providers also process technical data needed to operate their services. Alerts generated by OmniAgents have generic content and do not include message text, senders, attachments or Google-source data. See section 7.
Aruba S.p.A.: info@omniagents.it, service emails and support correspondence. Sites by OpenAI, on Cloudflare infrastructure: the website, collection of the statistics described in section 8 and their administration.
AI providers and services you connect: receive data needed for the functions you request, under your permissions and applicable account relationship. Their privacy role depends on the service and contract; connecting them does not by itself make them our subprocessors. A local model can process data on your computer; other integrations still have their own data flows. Meta is involved only for connected Meta channels, as described in section 6.
These providers’ infrastructure may involve processing outside the European Economic Area. The applicable basis depends on the entity and service engaged: an applicable adequacy decision, or contractual safeguards and measures required by law. We do not claim exclusively European storage or unverified contractual safeguards. To request information about recipients and safeguards for your service, write to info@omniagents.it. Firebase privacy and security; Apple privacy.
10. International transfers
A local installation does not exclude processing abroad by features using relay, notifications, support, hosting or Customer-selected services. Processing under Provider control is subject to GDPR Chapter V conditions: an applicable adequacy decision or appropriate safeguards and necessary measures for the actual service. We do not claim that all data remains in the EEA or that unverified contractual safeguards are in place. Information about relevant recipients, countries and safeguards may be requested from info@omniagents.it; the DPA and its annex also apply to processing entrusted by the Customer.
11. Retention and deletion
Accounts, roles and licences are processed for the relationship and its termination; contractual receipts and administrative and accounting records may be retained for applicable legal obligations and protection of rights. Support retains correspondence needed to address and manage requests. Technical records follow operational, security, incident investigation and resolution needs, with restricted access; they are not a general content archive.
Received statistical reports have the 180-day retention and deduplication keys the 91-day retention described in section 8. Content on the published relay remains in transit as described in section 6. Device associations and tokens are removed according to the outcome of disabling or revocation procedures; providers’ technical data and copies may follow separate periods. The Customer manages local archive, export and backup retention; entrusted data follows the return-or-deletion choice and DPA obligations. Immediate erasure of copies outside Provider control is not promised. The dedicated procedure is Delete a Business account.
12. Rights and complaints
Where provided by the GDPR, you may request access, rectification, erasure, restriction and portability, and object to legitimate-interest processing on grounds relating to your situation. Any consent may be withdrawn without retroactive effect. Write to info@omniagents.it identifying the request and relevant relationship, without credentials or unnecessary content; we may verify your identity proportionately.
For content controlled by the company, contact the Customer or its privacy contact: the Provider assists under the DPA and forwards relevant requests. You may complain to the Italian data protection authority or another competent supervisory authority. Using support or service procedures does not limit that right.
13. Required data and user choices
Data needed to identify the relationship, authorise access and meet obligations must be provided to use the relevant functions: its absence may prevent activation, access or billing. Connecting a source, enabling notifications or sending material to support remains tied to the requested function. The Customer informs users about company settings and roles. Statistics are not used for advertising, individual profiling or solely automated decisions with legal effects; this statement does not concern decisions the Customer independently makes using its own content.
14. Version and related documents
Business edition 2026-10-10.3, dated 10 October 2026. This notice is separate from Personal and does not rewrite earlier receipts. Material processing changes will be made available through the applicable flow before activation. See also the Business terms, Commercial terms, DPA and Security documents. The relevant notice continues to apply to the website and its optional analytics; visiting the site does not enable software statistics.
Legal sources: GDPR — Articles 6, 21, 28, 32 and 33.
For information: info@omniagents.it.