Privacy Policy
Last updated September 18, 2026
The Omni Labs ("we", "us", "our") operates theomni-labs.com and the Omni platform. We are the data controller for personal data collected through this website. This policy explains what we collect, why, and the rights available to you under applicable data protection law, including the EU/UK General Data Protection Regulation ("GDPR"), Saudi Arabia's Personal Data Protection Law ("PDPL"), the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), and Turkey's Law No. 6698 on the Protection of Personal Data ("KVKK").
1. Who we are
The Omni Labs is the data controller (or "Veri Sorumlusu" under KVKK) responsible for the personal data described in this policy. You can reach us at [email protected] for any data protection request.
2. What we collect
Through our contact form, we collect the name, work email address, company name, and message content you choose to submit. We do not use advertising or cross-site tracking cookies on this site. If we introduce analytics in the future, it will be privacy-preserving and cookie-free by default (e.g. Cloudflare Web Analytics), or will be gated behind a consent banner if it requires cookies.
3. Why we process it, and our legal basis
- To respond to your enquiry — legal basis: our legitimate interest in responding to business enquiries (GDPR Art. 6(1)(f)), your consent by submitting the form (PDPL, UAE PDPL, KVKK Art. 5), or steps taken at your request prior to entering a contract (GDPR Art. 6(1)(b)).
- To deliver and support the Omni platform, if you become a customer — legal basis: performance of a contract.
- We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Cross-border data transfers
Depending on your deployment (SaaS, private cloud, or dedicated instance), your data may be processed in the region you select at onboarding (currently Saudi Arabia, Turkey, UAE, or other regions on request). Where personal data is transferred internationally — for example between our team and a subprocessor, or between regions — we rely on appropriate safeguards such as standard contractual clauses (GDPR Ch. V), or equivalent mechanisms required under Saudi PDPL, UAE PDPL, and KVKK (Art. 9) for cross-border transfer. Enterprise customers can request a data residency commitment restricting processing to a specific jurisdiction as part of a dedicated deployment.
5. Data retention
Contact form submissions are retained only as long as needed to respond to your enquiry, or for the duration of a customer relationship plus a reasonable period to meet legal, accounting, or contractual obligations. We delete or anonymize data once it is no longer needed for these purposes.
6. Your rights
Depending on where you are, you have some or all of the following rights. Contact [email protected] to exercise any of them — we will respond within the timeframe required by the applicable law (typically 30 days).
- Under GDPR (EEA/UK individuals): right of access, rectification, erasure, restriction of processing, data portability, objection to processing, the right to withdraw consent at any time, and the right to lodge a complaint with your local supervisory authority.
- Under Saudi PDPL: the right to be informed, to access your data, to request correction, to request destruction of data no longer needed, and to know the source of any data collected about you (subject to statutory exceptions).
- Under UAE PDPL: the right to request access, to obtain a copy of your data, to correct or erase inaccurate or outdated data, to restrict or object to processing, to data portability, and to withdraw consent.
- Under Turkey's KVKK (Art. 11): the right to learn whether your data is processed, to request information about that processing, to learn the purpose of processing and whether data is used accordingly, to know third parties to whom data is transferred domestically or abroad, to request correction of incomplete or inaccurate data, to request deletion or destruction of data (and to have that request communicated to any third parties data was shared with), to object to a result produced solely by automated analysis that is to your detriment, and to claim compensation for damages arising from unlawful processing.
7. Security
We apply encryption in transit and at rest, role-based access control, and audit logging to protect personal data. See our Security page for more detail. In the event of a personal data breach affecting your rights, we will notify affected individuals and the relevant supervisory authority within the timeframe required by applicable law (e.g. 72 hours under GDPR where feasible).
8. Children's data
Our website and services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.
9. Changes to this policy
We may update this policy as our practices or applicable law evolve. Material changes will be reflected by updating the "Last updated" date above.
10. Contact us / lodge a complaint
For any question, request, or complaint about how we handle your personal data, contact [email protected]. If you are not satisfied with our response, you may have the right to lodge a complaint with your local data protection authority (for example, your national GDPR supervisory authority in the EEA/UK, the Saudi Data & AI Authority (SDAIA), the UAE Data Office, or Turkey's Personal Data Protection Authority (KVKK Kurumu)).