Data Processing Agreement
This agreement governs personal data that Damian Jabłoński tribe processes on your behalf when Omnia connects to accounts you control. It applies under Art. 28 GDPR, forms part of the Terms of Service, and takes effect the moment you connect your first account. No signature is needed, though we will sign a copy on request.
In effect from
1.Parties and roles
Processor: Damian Jabłoński tribe, ul. Modlińska 61, lok. 106, 03-199 Warszawa, Poland, NIP 5243008010 ("we", "us").
Controller: you, the customer using Omnia ("you").
For data we read from, or write to, the accounts you connect, you decide the purposes and means, and we act only for you. Data about you as our customer — your account, your invoices — is different: there we are the controller, and the Privacy Notice governs it.
2.Subject matter and duration
The subject matter is the processing needed to provide Omnia to you: connecting to your accounts, running the automations you configure, and reporting on the results.
This agreement lasts as long as we process personal data for you, and the obligations that by their nature survive — confidentiality, deletion, and assistance — continue after it ends.
3.Nature and purpose of the processing
We carry out the following operations on your instruction: collection, storage, retrieval, use, transmission to platforms you have connected, restriction, erasure and destruction — for the sole purpose of operating the automations you have configured and showing you their results.
4.Your instructions
We process personal data only on your documented instructions. Your instructions are given by configuring the Service, by connecting an account, and by what you ask the Omnia chat to do. This agreement and the Terms of Service are your initial complete instruction.
We will tell you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and we may suspend that processing until it is resolved.
If Union or Member State law requires us to process beyond your instructions, we will inform you before doing so, unless that law forbids the notice on important grounds of public interest.
5.Confidentiality
Everyone we authorise to process your personal data is bound by a confidentiality obligation, whether by contract or by statute, and is given access only to what their task requires.
6.Security
We implement appropriate technical and organisational measures under Art. 32 GDPR, taking into account the state of the art, the cost of implementation, and the risk to individuals. Annex 2 lists them.
We review the measures and may change them, provided the level of protection is not reduced.
7.Sub-processors
You give general authorisation for us to engage sub-processors. We use them for hosting and infrastructure, e-mail delivery, error monitoring, language-model inference and payment handling.
We keep a current list of sub-processors and provide it on request from team@omnia-inteligance.com. We will give you at least 30 days notice before adding or replacing one, and you may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a refund of the unused prepaid fee.
Every sub-processor is bound by written terms imposing the same obligations as this agreement. We remain fully liable to you for their performance.
8.Helping you answer individuals
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in fulfilling your duty to respond to requests to exercise rights under Chapter III GDPR — access, rectification, erasure, restriction, portability and objection.
If an individual contacts us directly about data we process for you, we will not respond on the substance. We will refer them to you and pass the request on without undue delay.
9.Personal data breach
We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting data we process for you.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide everything at once, we will provide it in phases without further undue delay.
We assist you in meeting your own obligations under Art. 33 and 34 GDPR. We do not notify your supervisory authority or your data subjects on your behalf unless you ask us to in writing.
10.Impact assessments
We assist you, on request and taking into account the information available to us, with data protection impact assessments under Art. 35 GDPR and with prior consultation of the supervisory authority under Art. 36.
11.Return and deletion
When you close your account or this agreement ends, you may export your data from the console. On your written request within 30 days of termination we will return it in a commonly used machine-readable format.
After those 30 days we delete the personal data we process for you, and instruct our sub-processors to do the same, unless Union or Member State law requires us to keep it — in which case we keep only what the law requires, for only as long as it requires, and continue to protect it under this agreement.
Backups are overwritten on our normal cycle, which completes within 90 days of deletion.
12.Audits
We make available to you the information necessary to demonstrate compliance with Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
Audits take place during business hours, on at least 30 days notice, no more than once a year unless a breach or a supervisory authority gives cause, and must not disrupt our operations or reveal another customer’s data. The auditor must be bound by confidentiality and must not be our competitor. You bear the cost of the audit; we bear the cost of our own cooperation.
13.International transfers
We process your personal data in the European Union. We do not transfer it outside the European Economic Area unless a valid transfer mechanism applies — an adequacy decision, or the European Commission Standard Contractual Clauses, with any supplementary measures a transfer impact assessment shows to be needed.
Where the Standard Contractual Clauses apply, Module Three (processor to sub-processor) or Module Two (controller to processor) is incorporated by reference, with Annex 1 and Annex 2 below supplying the required annexes.
14.Liability and precedence
The liability provisions of the Terms of Service apply to this agreement, save that nothing limits liability that Art. 82 GDPR imposes towards data subjects.
If this agreement conflicts with the Terms of Service on a question of data protection, this agreement prevails. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.
15.Annex 1 — details of the processing
Categories of data subjects: the individuals whose data is present in the accounts you connect — typically your contacts, your customers, your employees or collaborators, and the recipients or authors of messages your automations read or send.
Categories of personal data: identification and contact data (name, e-mail address, telephone number, profile identifiers); message and content data (the body of communications, attachments, comments, posts); usage and interaction data produced by your automations; and any other data present in the connected account that your configured automation reads.
Special categories: Omnia is not designed for data under Art. 9 or 10 GDPR, and we ask you not to configure automations that process it. If your connected account nevertheless contains such data, you remain responsible for the lawfulness of processing it, and the measures in Annex 2 apply to it as they do to everything else.
Frequency: continuous, for as long as an automation is active.
Retention: as set out in the "Return and deletion" section above.
16.Annex 2 — technical and organisational measures
- Encryption — TLS for all data in transit; access tokens and credentials stored encrypted at rest; passwords stored as salted hashes, never recoverable.
- Access control — individual accounts for personnel, least-privilege access to production, and access reviewed when a role changes or ends.
- Tenant isolation — data is separated per tenant, and every query is scoped so that one customer cannot read another customer’s data.
- Logging — access to production systems and changes to configuration are logged; logs are retained and reviewable.
- Resilience — regular backups, tested restoration, and the ability to restore availability after an incident.
- Secure development — changes go through automated quality gates before release, and dependencies are monitored for known vulnerabilities.
- Personnel — everyone with access is bound by confidentiality and instructed on their data protection obligations.
- Incident response — a defined process for detecting, assessing and reporting a breach within the timescale in this agreement.