Privacy policy

Version 0

Beta text (placeholder, version 0). OmnaBase wrote this text for the closed beta; a lawyer-reviewed version will replace it. It describes what the service actually does with data today.

1. Who is responsible

Kriesi Media GmbH, Lange Gasse 50, 1080 Vienna, Austria (full details in the imprint) runs OmnaBase. For questions about your data write to [email protected].

OmnaBase handles personal data in two roles:

2. Data of people with an account

What we process

Why, and on what legal basis

We do not use your data for advertising, we do not sell it, and we do not profile you.

3. Cookies and the browser

We set only what the service needs to work:

No analytics, no advertising cookies, no tracking pixels. Because nothing optional is set, there is no cookie banner. The browser sends error reports to Sentry (see the processors below) so we can fix bugs; these reports carry a request id, not your name.

4. Your rights

You have the right to access the data we hold about you, to have it corrected or deleted, to receive it in a portable form, to restrict or object to its processing where it rests on our legitimate interest, and to withdraw a consent you gave. In the app you can export and delete your own account data from your profile. For anything else write to [email protected]. You can also complain to the Austrian data protection authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at) or the authority of your country.

5. Data of a workspace's customers

A company that uses OmnaBase receives its customers' messages in the workspace. For this data the company is the controller and we are its processor. What the service does with it:

6. Who processes data for us (sub-processors)

Company Where What for
Amazon Web Services EMEA SARL Frankfurt (eu-central-1) the servers, the database, file storage, mail sending and receiving, queues, backups
Cloudflare, Inc. the edge in front of the app, EU-first routing the domain, DDoS protection, the bot check (Turnstile), the status page
Google Cloud (Vertex AI) the EU (Google's European region) the Gemini models that classify tickets, compute embeddings for search and knowledge retrieval, and draft where chosen
Anthropic, PBC United States the Claude model that drafts replies and runs code investigations during the beta
Stripe Payments Europe, Ltd. Ireland subscriptions, card payments, invoices, VAT
Sentry (Functional Software, Inc.) EU data region error reports from the server and the browser

What reaches the AI providers: the ticket's text, the company's knowledge excerpts the assistant retrieved, the customer facts the company's own systems answered, and, for an investigation, excerpts of the company's product code. Never the raw mail file, never the card data. Under the agreements with these providers, the data is not used to train their models.

Transfers outside the EU. Claude prompts go to Anthropic in the United States during the beta; the transfer rests on the EU standard contractual clauses in Anthropic's data processing addendum. Cloudflare and Sentry hold data in the EU with their own clauses for support access. Everything else stays in the EU. We intend to move the Claude route to an EU region when it becomes available to us.

7. How long we keep data

What Kept
Account data until you delete your account (from your profile)
Tickets, messages, attachments, customers while the workspace lives, or until the company deletes them
A deleted workspace 7 days of grace in which it can be brought back, then removed
Database backups 30 days; point-in-time recovery 7 days (deleted data stays in a backup until it ages out)
Export archives (a zip we mailed a link to) 7 days
The deletion ledger (ids and fingerprints of what a deletion removed, never an address) 35 days
Raw inbound mail that opened no ticket (loops, duplicates, unknown recipient) 90 days
Spam tickets 30 days
Live-update events (which ticket changed) 7 days
Request logs on the server rotated, at most a few days
Invoices and billing records as tax law requires (7 years in Austria)
Error reports at Sentry, AI requests at the providers per their terms; we do not ask them to keep anything

8. Security

Data travels encrypted (TLS, also between our services and the database); files and backups are stored with Amazon's encryption at rest in Frankfurt. Every workspace's data is isolated by row-level security in the database, so one customer's code paths cannot read another's rows. Access to the production systems is limited to the people who run the service, with key-based access and no shared passwords. Attachments are checked against their declared type and served with download headers. We keep an audit log of settings changes in each workspace.

9. Changes

We update this policy when the service changes; the version date at the top tells you when. Material changes are announced in the app.

Kriesi Media GmbH, Vienna, 2026.