Privacy policy
Version 0
Beta text (placeholder, version 0). OmnaBase wrote this text for the closed beta; a lawyer-reviewed version will replace it. It describes what the service actually does with data today.
1. Who is responsible
Kriesi Media GmbH, Lange Gasse 50, 1080 Vienna, Austria (full details in the imprint) runs OmnaBase. For questions about your data write to [email protected].
OmnaBase handles personal data in two roles:
- For people with an account (team members who sign in) and for visitors of our own pages, we are the controller: we decide what is processed and why. Sections 2 to 4 are about this.
- For the customers of a workspace (the people who write to a company that uses OmnaBase), the company running the workspace is the controller and we are its processor: we process their data on that company's instructions, under the data processing agreement. Section 5 is about this. If you wrote to a company that uses OmnaBase and want to exercise your rights, please contact that company; it can export and delete your data with the tools we give it.
2. Data of people with an account
What we process
- Account data: your name, your e-mail address, the sign-in codes we send you, your sessions (a cookie and the device's browser type), your profile settings (language, time zone, notification preferences, away status).
- What you do in the workspace: the replies, notes, tags and settings you write, who you assigned a ticket to, the audit log of settings changes, your read markers and presence (who is looking at a ticket).
- Mail we send you: notifications, the morning summary, invitations, billing mails. Each carries an unsubscribe link for the notifications you can switch off.
- Billing data, where a workspace pays: the company's name, address and VAT ID, and the invoices. Card details are entered on Stripe's pages and never reach our servers.
- Technical data: the server's request logs (address, time, path, response), error reports with request ids, the bot check on sign-in and forms.
Why, and on what legal basis
- To provide the service you or your company signed up for (contract, Art. 6(1)(b) GDPR): accounts, workspaces, tickets, mail, notifications, billing.
- To keep the service secure and working (legitimate interest, Art. 6(1)(f) GDPR): logs, error reports, rate limits, the bot check, abuse detection.
- To meet legal duties (Art. 6(1)(c) GDPR): invoices and tax records.
We do not use your data for advertising, we do not sell it, and we do not profile you.
3. Cookies and the browser
We set only what the service needs to work:
- the session cookie that keeps you signed in;
- Cloudflare's cookie that distinguishes browsers from bots at the edge;
- Turnstile's challenge on the sign-in page and on public forms (Cloudflare's bot check, which replaces picture puzzles).
No analytics, no advertising cookies, no tracking pixels. Because nothing optional is set, there is no cookie banner. The browser sends error reports to Sentry (see the processors below) so we can fix bugs; these reports carry a request id, not your name.
4. Your rights
You have the right to access the data we hold about you, to have it corrected or deleted, to receive it in a portable form, to restrict or object to its processing where it rests on our legitimate interest, and to withdraw a consent you gave. In the app you can export and delete your own account data from your profile. For anything else write to [email protected]. You can also complain to the Austrian data protection authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at) or the authority of your country.
5. Data of a workspace's customers
A company that uses OmnaBase receives its customers' messages in the workspace. For this data the company is the controller and we are its processor. What the service does with it:
- Messages arrive by mail or through a web form, with the sender's name, address, text and attachments, and are stored as tickets. Licence keys or site addresses a customer claims are stored with the customer.
- The AI assistant reads a ticket and the company's knowledge base to draft an answer; where the company switched automatic replies on, it sends sure answers with a footer saying a person will read the customer's reply. The assistant's providers are named below. The company's resolved tickets are used as knowledge for drafts only where the company switched that on.
- When the company deletes a customer, the customer's rows and files are removed and a fingerprint (a one-way hash of the address) is kept so that a mail delivered late does not recreate the deleted person. The company can also export a customer's data.
- A workspace's members may, where the owner allows it, connect their own AI app, which then reads the customer data the member may see; the company decides and answers for that (see the terms and the DPA).
6. Who processes data for us (sub-processors)
| Company | Where | What for |
|---|---|---|
| Amazon Web Services EMEA SARL | Frankfurt (eu-central-1) | the servers, the database, file storage, mail sending and receiving, queues, backups |
| Cloudflare, Inc. | the edge in front of the app, EU-first routing | the domain, DDoS protection, the bot check (Turnstile), the status page |
| Google Cloud (Vertex AI) | the EU (Google's European region) | the Gemini models that classify tickets, compute embeddings for search and knowledge retrieval, and draft where chosen |
| Anthropic, PBC | United States | the Claude model that drafts replies and runs code investigations during the beta |
| Stripe Payments Europe, Ltd. | Ireland | subscriptions, card payments, invoices, VAT |
| Sentry (Functional Software, Inc.) | EU data region | error reports from the server and the browser |
What reaches the AI providers: the ticket's text, the company's knowledge excerpts the assistant retrieved, the customer facts the company's own systems answered, and, for an investigation, excerpts of the company's product code. Never the raw mail file, never the card data. Under the agreements with these providers, the data is not used to train their models.
Transfers outside the EU. Claude prompts go to Anthropic in the United States during the beta; the transfer rests on the EU standard contractual clauses in Anthropic's data processing addendum. Cloudflare and Sentry hold data in the EU with their own clauses for support access. Everything else stays in the EU. We intend to move the Claude route to an EU region when it becomes available to us.
7. How long we keep data
| What | Kept |
|---|---|
| Account data | until you delete your account (from your profile) |
| Tickets, messages, attachments, customers | while the workspace lives, or until the company deletes them |
| A deleted workspace | 7 days of grace in which it can be brought back, then removed |
| Database backups | 30 days; point-in-time recovery 7 days (deleted data stays in a backup until it ages out) |
| Export archives (a zip we mailed a link to) | 7 days |
| The deletion ledger (ids and fingerprints of what a deletion removed, never an address) | 35 days |
| Raw inbound mail that opened no ticket (loops, duplicates, unknown recipient) | 90 days |
| Spam tickets | 30 days |
| Live-update events (which ticket changed) | 7 days |
| Request logs on the server | rotated, at most a few days |
| Invoices and billing records | as tax law requires (7 years in Austria) |
| Error reports at Sentry, AI requests at the providers | per their terms; we do not ask them to keep anything |
8. Security
Data travels encrypted (TLS, also between our services and the database); files and backups are stored with Amazon's encryption at rest in Frankfurt. Every workspace's data is isolated by row-level security in the database, so one customer's code paths cannot read another's rows. Access to the production systems is limited to the people who run the service, with key-based access and no shared passwords. Attachments are checked against their declared type and served with download headers. We keep an audit log of settings changes in each workspace.
9. Changes
We update this policy when the service changes; the version date at the top tells you when. Material changes are announced in the app.
Kriesi Media GmbH, Vienna, 2026.