You can save a copy of this disclosure using your browser’s Print function.
This English translation is provided for information. The document version remains unchanged; publication of this translation alone does not request renewed acceptance or alter earlier acceptance receipts.
1. Controller and contacts
Giampaolo Rao, Via Carpinetana Ovest 18, 00037 Segni (RM), Italy; tax code RAOGPL76L15C858V; contact info@omniagents.it. This notice concerns the website, commercial contacts and accounts managed by the Supplier; section 13 describes processing of data from Google services connected to OmniAgents. Privacy requests may be sent to the contact above.
2. Scope and parties
This notice covers the website, contacts and Provider commercial data. The OmniAgents work archive is on the Customer’s Mac or Windows computer. The Customer sets purposes and authorisations for their activities; the Provider is processor only for processing actually entrusted under the Business DPA, not merely because the local app is used. The Provider is controller for its own commercial data, duties and services described here. The commercial relay at omniagents.link retains the Customer’s name, email and country, licence and computer identifiers and related dates (activation, trial, renewal, termination and release), to administer the contract, receipts and service emails. It also retains information necessary to prevent a second trial after repurchase and enforce the limit of one support release every 30 days. The Provider is controller for this commercial processing: the bases are contract performance, applicable obligations and, for abuse prevention, legitimate interests subject to necessity and proportionality assessment and the right to object where applicable. Retention is limited to the relationship and, afterwards, what is necessary for those purposes, duties and protection of rights; it does not include a general copy of the local archive. Releasing a licence does not mean immediately deleting receipts or data lawfully retained. AI requests and PayPal payments follow the separate flows and roles described here.
3. Data and purposes
Processing covers account identifiers and contacts, roles, organisation affiliation, tax and contractual data, accepted versions, payment references, support tickets, technical identifiers and security records. Card data is managed by the payment service provider under the chosen flow; OmniAgents retains necessary references and must not record the full card number or security code.
Accounts, contractual performance and pre-contractual requests are handled on a contractual basis when the data subject is a party; for legal-entity contacts, on an assessed and documented legitimate interest in managing the relationship. Tax compliance and binding requests are based on applicable obligations. Security, abuse prevention and defence of rights require an assessment of necessity and balancing of interests. Marketing unnecessary for the service requires a separate basis and, where required, revocable consent: contract acceptance does not incorporate it.
4. Analytics and AI
The statistics described below use minimised identifiers and counts, without chat, email or document text. Pseudonymous data is not automatically anonymous. The Customer chooses the compatible AI provider and authorised content to send under their own account and terms. The local app does not give the Provider general access to content.
5. Recipients and transfers
Cloudflare, Inc.: the infrastructure for the omniagents.link relay, used to connect devices, forward permitted flows and manage authentication, routing and security. Meta content may be held temporarily in memory while being forwarded; technical installation, device, authorisation, delivery and security records are separate from content. The relay is not a persistent message archive. Content from Google sources (Gmail, Drive, Contacts, Calendar and Photos) is excluded from these relay flows.
Google Firebase Cloud Messaging (FCM): delivery of push alerts in mobile apps supporting notifications. Delivery on iPhone also involves Apple Push Notification service (APNs). Tokens and installation/device identifiers are pseudonymous personal data; these providers also process technical data needed to operate their services. Alerts generated by OmniAgents have generic content and do not include message text, senders, attachments or Google-source data. See section 18.
Aruba S.p.A.: info@omniagents.it, service emails and support correspondence. Sites by OpenAI, on Cloudflare infrastructure: the website, collection of the statistics described in section 11 and their administration.
AI providers and services you connect: receive data needed for the functions you request, under your permissions and applicable account relationship. Their privacy role depends on the service and contract; connecting them does not by itself make them our subprocessors. A local model can process data on your computer; other integrations still have their own data flows. Meta is involved only for connected Meta channels, as described in section 14.
These providers’ infrastructure may involve processing outside the European Economic Area. The applicable basis depends on the entity and service engaged: an applicable adequacy decision, or contractual safeguards and measures required by law. We do not claim exclusively European storage or unverified contractual safeguards. To request information about recipients and safeguards for your service, write to info@omniagents.it. Firebase privacy and security; Apple privacy.
PayPal (Europe) S.à r.l. et Cie, S.C.A. processes identification data, recurring authorisation, payment references and state for its own purposes and duties under PayPal Privacy. It does not thereby receive the local archive. Checkout is a preview: no orders or data sent to PayPal. Business details, including breach notification within 24 hours of awareness, appear in Business Privacy and the DPA.
6. Retention
The local archive and Customer copies remain under their control, without a contractual expiry date. For copies held by the Provider on the Customer’s behalf, the post-termination return/export period is 30 days, subject to other instructions or applicable duties; local export remains available. Commercial accounts, receipts and administrative documents follow duties and criteria applicable to the relationship and protection of rights, limited to necessary data. Specific website-statistics and availability-notice periods appear in the relevant sections.
7. Rights and complaints
Data subjects may request access, rectification, erasure, restriction and, where applicable, portability and objection by writing to the published privacy contact. Identity is verified proportionately. Responses follow statutory deadlines, normally one month, with any justified extensions. Consent may be withdrawn without affecting prior lawful processing. Complaints may be lodged with the Italian Data Protection Authority or competent authority, and judicial remedies may be sought. For data managed on a Customer’s behalf, requests are forwarded to the relevant controller with assistance.
8. Provision of data, cookies and decisions
Data requested for access, security, contracts or billing is necessary for those functions; the interface distinguishes other optional data. Acknowledging the privacy notice is not marketing consent. Strictly necessary website tools are separate from optional navigation analytics: the latter remain disabled until a valid choice where required. Refusal does not prevent page viewing, and the choice may be changed. Contract acceptance alone does not authorise profiling or advertising. The described configuration does not authorise solely automated decisions producing legal or similarly significant effects on people. Italian Data Protection Authority guidelines on cookies and tracking.
9. Website and service metrics
The website may measure visits, pages viewed, action clicks and links to downloads or stores. A click does not prove a file was downloaded or an app installed. The envisaged design uses minimised data and avoids form content, emails, passwords and confidential URL parameters; pseudonymous identifiers remain personal data when attributable to a person. Commercial events, such as activation, payment and termination, derive from actual corresponding records. Platform administration envisages usage, status and consumption counts with periods and provenance, without general access to customers’ chats, documents or Knowledge. The inventory of trackers actually activated must be published before collection.
10. Exercising rights and updates
Requests should state the relationship with OmniAgents and the right to be exercised, avoiding unnecessary complete documents or credentials. Proportionate identity checks are permitted. Erasure is not absolute where limited retention is legally required; portability and objection apply under GDPR conditions. You may contact the Italian Data Protection Authority. Updates identify version and date: a new text does not retroactively legitimise a different purpose. General Data Protection Regulation.
11. Website and software statistics and registration
Privacy preferences are remembered in the browser and may be changed from the footer. Optional statistics are disabled until you choose “Accept statistics”. Refusal does not prevent browsing, document downloads or use of links.
The website uses a first-party collector: it records sessions, pages without parameters, referral limited to the domain, button clicks, product and platform. A random visitor identifier expires after 90 days; a session expires after 30 minutes of inactivity. Analytics events do not collect form text, chats, documents, emails or IP addresses. Events can be consulted for 90 days; expired events are deleted on the next collection or consultation operation. Withdrawal stops new collection and removes browser identifiers.
The website administrator panel uses the owner’s authenticated access and displays aggregated data. Distribution services, software and the commercial system may provide separate download, activation and subscription events without private content.
Software usage statistics and registration. The free OmniAgents and Business terms describe pseudonymous usage statistics provided for in the contractual relationship; that clause is separate from optional website analytics. They are included in acceptance of the terms at registration and also apply during any trial and paid use; they do not require a separate optional checkbox. Accepting a contract is not blanket consent to processing and does not by itself make every item of data necessary.
Account registration and acceptance of terms may involve identity, email and contractual receipts. These are separate from statistical reports, which contain technical installation and environment identifiers, usage counts, outcomes, token use and costs where available, connection status, technical alerts, platform and version. Reports are pseudonymous, not anonymous, because identifiers may be linked to a registered installation. Reports do not include names or email addresses, chat or message text, documents, photos, contacts, private Knowledge, credentials or full URLs.
Transmission to omniagents.it requires an installation recognised by the service and a signed request. Only reports actually sent by enabled installations are collected: visiting this website alone does not activate transmission from the software. Received reports are retained for 180 days from receipt; technical event deduplication keys for 91 days. Their purpose is to assess reliability and operation, without advertising, individual profiling or model training.
Article 6(1)(b) GDPR applies to processing necessary for a contract with the individual; legitimate interest applies to reliability measurement and improvement within the balancing and minimisation required by Article 6(1)(f). You may object to the latter processing on grounds relating to your situation by writing to info@omniagents.it. This edition does not reactivate withdrawn consent or rewrite earlier receipts. Hosting security records remain separate from optional website analytics. Report administration is restricted to authorised personnel.
12. Live reading, received messages and adding to memory
When you connect a source (Google, Meta, WhatsApp Business, iCloud or an app in "Apps"), connecting it does not by itself fetch your history.
- Live reading. Content from connected sources is read when you open a section or run a search, and shown to you.
- Received messages. For Messenger, Instagram and WhatsApp Business, OmniAgents only receives messages that arrive after you connect, and keeps them on your computer to show them in Messages.
- Folders. Computer folders you add in Sources are checked every hour for new or changed files.
- Earlier content. It enters OmniAgents only if you pick it with "Add" or explicitly ask your AI to find and import it.
- free edition memory. Only what you choose with the section's "Add" button enters the "In memory" section: first you pick the source or app, then the individual items.
- Learning. If you have authorized processing of connected sources, while your connected AI is open OmniAgents may ask it to process newly received content to update your memory and summaries. Content goes only to the AI you chose; without that authorization or an active session nothing is sent.
- Where it stays. Everything stays on your computer, in the OmniAgents folder that only your user account can access. Tokens and access keys are encrypted; to protect content too, we recommend disk encryption (FileVault on Mac, BitLocker on Windows). You can delete it from the app at any time; deleting it in OmniAgents does not delete the original in the source.
Conversations and internal memory.
Local learning from conversations is part of how OmniAgents operates under the terms you accept. It is initially enabled: conversation content may contribute to internal memory and the context used by the assistants. You can turn it off in the app; turning it off stops new learning and does not automatically delete memories already created. Local learning is separate from the AI provider’s model training and from the aggregated usage statistics provided for in the contract. Your data remains yours. Sending content to your chosen AI follows the connections, authorizations and requests you have configured.
Acceptance of the terms describes how the service works; it does not replace separate consent where required for other processing. The restrictions on Google data remain those in section 13.
13. Google user data
OmniAgents requests, in a single consent, the permissions for the Google services listed below, displayed in Google’s window. You can revoke them at any time:
- Gmail: reading messages, preparing drafts in the Gmail Drafts folder and sending emails only after your confirmation;
- Google Calendar: reading and, if you authorise it, creating or modifying events after confirmation;
- Google Contacts: reading;
- Google Drive: reading files you authorise for import. The
drive.readonlypermission technically permits reading and downloading files in your Drive; it is not a permission limited to individual photos or files chosen in a picker; - Google Photos: only photos you select in the Google picker;
- Basic identity (
openid,email): to show which Google account is connected.
Use. Google data is used only to provide visible app functions you requested: finding messages, documents, appointments and contacts, building context for your requests, preparing replies you approve and performing actions you confirm.
Storage. Google data is not stored or processed on Supplier servers. It remains on your computer; tokens are encrypted. Google data never passes through the omniagents.link relay or any other OmniAgents server: it is read and processed only on your computer. When you use your AI from your phone, it reads Gmail and Google Drive through its own official Google connection (for example the Gmail and Google Drive connectors of Claude or ChatGPT), not through OmniAgents. In OmniAgents Business it is stored in the Customer environment specified in the contract.
Sharing and AI. Google data is sent only to the AI you chose and connected and, if you explicitly ask for a single request, to apps connected in “Applications” (for example: “use this photo for the invitation in Canva”). Only data necessary for that request is sent, never automatically and to no other recipient. It is not stored or processed on our servers. Actions in Google services use the respective Google APIs directly from your computer. Data is not sold or used for advertising, profiling or retargeting. It is not transferred to data brokers. It is not used to create, train or improve general artificial-intelligence or machine-learning models. No person reads your Google data except with your explicit consent for specific content, for security needs or legal obligations.
Revocation and deletion. Disconnecting on this computer stops this installation from connecting to and using the source. To also request revocation of the authorization at Google or Meta, select “Remove access everywhere” when confirming revocation. The app distinguishes local disconnection from the provider’s revocation outcome. If the provider does not confirm revocation, the outcome remains unconfirmed; credentials needed for a retry may remain encrypted on your computer so that revocation can be retried, without reactivating source acquisition. You can also revoke authorization directly in your Google or Meta account security settings. Disconnecting or revoking access does not automatically delete data already imported into your archive: deleting data is a separate operation.
To delete your account and local data, follow the Delete account page. Local deletion and remote revocation have separate outcomes; external copies are not removed.
Use with other apps. Google data is sent to an app connected in "Apps" only if you explicitly ask, for that single request (for example: "use this photo for the flyer"). Only the necessary data is sent, never automatically.
Limited Use. OmniAgents’ use and transfer to other apps of information received from Google APIs comply with the Google API Services User Data Policy, including Limited Use requirements.
The English description is available on the Google API Data Disclosure page.
14. Meta platform data (Facebook, Instagram, Messenger, WhatsApp)
If you connect your own Meta account, OmniAgents asks Meta only for the permissions needed by the features you choose:
- Facebook Pages: the list of Pages you manage and select in Meta's dialog; the business portfolios you select, to find the Pages and WhatsApp Business Accounts they own; the photos your Page published, when you choose to import them; receiving your Page's webhook notifications.
- Messenger: reading messages received by your Page and sending a reply only after you have read and confirmed it in the app.
- Instagram (professional account linked to your Page): the account username, reading the direct messages it receives, and sending a reply only after your confirmation; the photos published by your Instagram account, when you choose to import them.
- WhatsApp Business (Meta's official login window): your WhatsApp Business Account and the phone number you choose; receiving incoming messages; sending a reply only after your confirmation.
- Basic profile (Facebook name and ID): to show which account is connected.
Use. Meta data is used only to show you, inside the app, the messages and content of your own channels, to let you search them, and to prepare a reply draft that you read, can edit and send yourself. OmniAgents never sends a message without your confirmation, never sends promotional or unsolicited messages, does not use Meta data for advertising, profiling or retargeting, does not sell it and does not transfer it to data brokers.
Storage. In OmniAgents (free edition) access tokens are stored encrypted and imported messages stay on your own computer. The provider does not keep a server-side archive of Meta content from the free edition. The omniagents.link relay forwards login responses and notifications to your connected computer; it may hold them temporarily in memory while forwarding them, without persistently archiving their content. Relay security metadata is separate from message content. Imported messages remain in the app until you delete them. Business uses the customer environment described in the contract. The relay runs on Cloudflare (Cloudflare, Inc.), which acts as our processor for data in transit.
Sharing. For AI processing, Meta content is sent to the AI model you have chosen and connected, and only when you ask for a reply or a search and, if you have authorized processing of connected sources, when your connected AI processes received messages to update your memory (section 12). OmniAgents does not use Meta data to train AI models and does not authorise that use. Connections to an AI provider must respect this restriction; that provider’s retention terms and your account settings remain separate from the local archive.
Reading and adding. Messages received by your Pages, your Instagram professional account and WhatsApp Business after you connect are kept on your computer and shown in Messages. Only the messages you choose with "Add message" enter the "In memory" section. Meta data is sent to an app connected in "Apps" only if you ask, for that single request.
Revocation and deletion. Disconnecting on this computer stops this installation from connecting to and using the source. To also request revocation of the authorization at Google or Meta, select “Remove access everywhere” when confirming revocation. The app distinguishes local disconnection from the provider’s revocation outcome. If the provider does not confirm revocation, the outcome remains unconfirmed; credentials needed for a retry may remain encrypted on your computer so that revocation can be retried, without reactivating source acquisition. You can also revoke authorization directly in your Google or Meta account security settings. Disconnecting or revoking access does not automatically delete data already imported into your archive: deleting data is a separate operation.
See Meta data deletion for Meta-specific instructions.
The current relay does not provide a persistent Meta-content queue for retrieval while the computer is offline. Delivery depends on the connected computer being available and any retries by the source service; recovery of every message received while offline is not guaranteed. Any changes to this processing will be documented before activation.
15. Connected apps (third-party apps via MCP)
If you choose to, you can connect third-party apps that offer AI-assistant access based on the MCP standard. The connection happens in the app's own sign-in window: you choose the app and grant the permissions, under that provider's terms and privacy policy; the provider acts as an independent controller of the data you keep with it.
- What we store: the app's address, the list of its tools and your preferences (enabled tools), and the access keys issued by the app, encrypted on your computer. The keys are never shown to the AI or sent to our servers.
- When we send data to the app: only when you ask the AI to use it. Only the data needed for your request is sent (for example the text of a note to create or the words to search for). Lookups happen at your request; every change runs only after your explicit confirmation in the OmniAgents app.
- Chosen AI: content returned by the app may be processed by the AI you chose in OmniAgents, as already described for that AI in this policy.
- Revocation: When you revoke a connection in Apps, OmniAgents stops using the connected app and deletes the user credentials stored on this computer for that connection, including tokens and any client registration secrets. Local removal and revocation at the app are separate outcomes: the interface indicates whether remote revocation was confirmed. If it was not confirmed, you can complete it in the security settings of the relevant app. Revoking a connection does not delete content already held by the third-party app.
- Legal basis: performance of the service you requested.
16. Availability notice
If you ask to be notified, we use your email address and preferred system (Mac or Windows) only to write to you once, when OmniAgents is available. Legal basis: your request (Art. 6(1)(b) GDPR). We don't use the address for marketing or share it with third parties. The data is stored on the service hosting the website (Sites by OpenAI, Cloudflare infrastructure) and the notice is sent from info@omniagents.it (Aruba). We delete it after the notice or, at the latest, after 12 months. You can ask for deletion at any time at info@omniagents.it.
17. Account deletion
To delete your account and local data, follow the Delete account page. Local deletion and remote revocation have separate outcomes; external copies are not removed.
18. Mobile apps and notifications
The OmniAgents iPhone and Android apps connect a mobile device to an authorised computer. Pairing involves technical installation and device identifiers, device name, platform, language and connection credentials; these are not anonymous data.
If your installed version supports notifications and you enable them, the app requests the system permission and associates an FCM token and language with the device on the relay. FCM delivers alerts on Android; on iPhone it also uses APNs. Alerts generated by the relay say only that you have new messages in OmniAgents: they do not contain sender details, text, attachments or Google content. This restriction concerns alert content; it does not make tokens anonymous or eliminate technical data processed by Google and Apple.
You can disable notifications in the app and in operating-system settings. Disabling them in the app requests removal of the token from the relay and deletion of the FCM token; the outcome may depend on connectivity and the external service. Revoking a phone or confirmed removal of an installation removes its relay associations. These actions do not prove immediate deletion of all providers’ technical data or copies, which follow their own retention rules. Firebase information; How APNs tokens work.
Notification permission serves the optional function you request and does not authorise promotional messages. Access to photos, files, the camera or sharing tools remains tied to the actions and permissions you choose. free and Business apps use their respective account and, in Business, organisation roles. Store availability is stated only when a version is actually distributed.
19. Business accounts and users
In Business, Giampaolo Rao is controller for commercial records, administrator and user contacts, contract management, security of his own service, support and his own legal obligations. The Customer controls organisation content and instructions to its users; Giampaolo Rao acts as processor only for processing actually entrusted to him under the DPA. Local installation and connector compatibility do not give the Provider access to the entire archive.
Administrators manage permissions, invitations and departing users within available roles. Section 11 applies to usage statistics during paid use as well; the Google API Limited Use restrictions in section 13 also apply to Business. Sections 14 and 18 apply to Meta, WhatsApp and mobile notifications. Business APIs are available only under the permissions and availability of the relevant environment. Rights concerning organisation data may be exercised through the Customer as controller; the Provider supplies the required assistance for processing on the Customer’s behalf. See Business account deletion.
For information: info@omniagents.it.