

PRIVACY POLICY
Effective Date: 1 January 2025
Last Updated: 20 May 2026
This Privacy Policy (“Privacy Policy”) explains how Omnixis Artificial Intelligence Developing LLC, license number 1467676, with registered office at Parklane Tower, Business Bay, Dubai, United Arab Emirates (“Omnixis”, “we”, “us”, or “our”) collects, uses, processes, stores, transfers, discloses, and protects personal data in connection with our websites, AI calling platform, telephony services, APIs, integrations, dashboards, subscription services, and related products and services (collectively, the “Services”).
This Privacy Policy is designed to support compliance with applicable privacy and data protection laws, including:
UAE Personal Data Protection Law (“UAE PDPL”);
UK GDPR;
EU GDPR;
applicable U.S. state privacy laws including the California Consumer Privacy Act, as amended by the CPRA (“CCPA/CPRA”);
applicable telecom, recording, marketing, and consumer protection laws.
By accessing or using the Services, you acknowledge this Privacy Policy.
1. IMPORTANT ROLE DISTINCTION
Depending on the context, Omnixis may act as either:
1.1 Controller / Business
Omnixis acts as a controller, business, or equivalent legal role when processing personal data for our own operational purposes, including:
account creation;
subscription management;
billing;
analytics;
fraud prevention;
marketing;
customer support;
onboarding;
platform security;
product improvement.
1.2 Processor / Service Provider
Omnixis acts as a processor, service provider, or equivalent role when processing personal data on behalf of Customers through the Services.
This includes processing:
lead lists;
contact data;
CRM records;
call recordings;
transcripts;
AI-generated summaries;
campaign data;
appointment data;
customer-uploaded information.
Where Omnixis acts as processor/service provider:
the Customer controls the purposes and means of processing;
the Customer is responsible for ensuring lawful processing;
individuals should contact the relevant Customer directly regarding privacy requests relating to Customer-controlled data.
2. SCOPE OF THIS PRIVACY POLICY
This Privacy Policy applies to personal data processed through:
our websites;
dashboards;
subscription flows;
billing portals;
APIs;
AI calling workflows;
telephony systems;
recordings;
transcriptions;
integrations;
CRM syncs;
support channels;
onboarding;
marketing communications.
This Privacy Policy does not apply to third-party websites, services, or platforms not controlled by Omnixis.
3. PERSONAL DATA WE COLLECT
We may collect the following categories of personal data.
3.1 Account and Business Information
Including:
name;
business name;
job title;
email address;
business address;
billing address;
phone number;
login credentials;
account preferences;
subscription details.
3.2 Billing and Payment Information
Payments may be processed through providers such as Stripe.
We may process:
billing records;
transaction history;
payment metadata;
invoices;
tax information;
payment status.
We generally do not store complete payment card numbers.
3.3 Customer Data
Customers may upload or process:
lead lists;
phone numbers;
CRM exports;
scripts;
prompts;
notes;
emails;
appointment information;
CSV files;
business prospect data;
workflow data;
campaign data.
Customers are solely responsible for ensuring they possess lawful rights and permissions to process such data.
3.4 Call, Voice, and Communication Data
The Services may process:
call recordings;
audio streams;
voice data;
transcripts;
AI summaries;
call metadata;
timestamps;
caller/callee numbers;
sentiment analysis;
appointment outcomes;
conversation analytics;
call routing data.
All calls processed through the Services may be recorded and transcribed by default unless otherwise configured by Customer.
3.5 AI and Automation Data
We may process:
prompts;
workflow logic;
AI agent configurations;
generated outputs;
automation instructions;
analytics;
scheduling data;
AI interaction data.
3.6 Technical and Usage Data
We may automatically collect:
IP addresses;
browser information;
operating system data;
device information;
usage analytics;
authentication logs;
API usage logs;
security events;
geolocation approximations;
timezone data;
network information;
cookies and similar technologies.
3.7 Support and Communication Data
Including:
support tickets;
emails;
onboarding discussions;
meeting notes;
chat messages;
troubleshooting information.
Support communications may be processed through providers such as Zendesk and Slack.
3.8 Compliance, Fraud, and Verification Data
We may process:
identity verification information;
fraud signals;
sanctions screening results;
compliance records;
abuse reports;
payment risk indicators;
telecom risk data.
3.9 Sensitive and Special Category Data
The Services are not intended for the processing of sensitive personal data unless expressly agreed in writing.
Customers shall not upload or process:
health data;
government ID numbers;
children’s data;
financial account credentials;
biometric templates;
other regulated sensitive data;
unless legally permitted and properly safeguarded.
4. BIOMETRIC, VOICE, AND SYNTHETIC AUDIO DATA
Voice recordings and related audio data may be regulated as biometric data under certain laws.
Omnixis currently provides standardized voice synthesis options and does not authorize Customers to upload or clone third-party voices unless expressly permitted in writing.
Customers remain solely responsible for obtaining:
recording consent;
biometric consent;
publicity rights;
personality rights;
AI disclosure consents;
telecom disclosures;
required under Applicable Laws.
Omnixis does not sell biometric data and does not independently create biometric templates except where operationally necessary for the Services.
5. SOURCES OF PERSONAL DATA
We may collect personal data from:
Customers;
end users;
uploaded lead lists;
CRM integrations;
websites;
forms;
telecom providers;
payment processors;
analytics tools;
public business sources;
integrations;
support interactions;
AI workflows.
6. HOW WE USE PERSONAL DATA
We may use personal data for the following purposes.
6.1 Providing the Services
Including:
operating AI workflows;
processing calls;
generating transcripts;
generating AI summaries;
scheduling appointments;
syncing CRM data;
assigning numbers;
enabling dashboards;
routing calls;
processing automations.
6.2 Billing and Subscription Management
Including:
subscription management;
recurring billing;
overage billing;
payment processing;
fraud prevention;
invoice generation;
tax handling.
6.3 Customer Support and Onboarding
Including:
support responses;
onboarding;
troubleshooting;
implementation support;
technical assistance.
Authorized Omnixis personnel may access Customer Data on a limited need-to-know basis for:
support;
troubleshooting;
abuse investigation;
fraud prevention;
legal compliance;
operational maintenance.
6.4 Security, Fraud, and Abuse Prevention
Including:
detecting abuse;
telecom risk management;
spam prevention;
fraud detection;
sanctions screening;
carrier complaint investigation;
enforcing our Terms;
securing infrastructure.
6.5 Compliance and Legal Obligations
Including:
complying with laws;
responding to lawful requests;
protecting legal rights;
maintaining records;
supporting audits;
investigating misuse.
6.6 Product Improvement and Analytics
Including:
internal analytics;
benchmarking;
service optimization;
reliability improvement;
debugging;
platform performance analysis;
operational monitoring.
We may generate aggregated and anonymized analytics from platform usage.
6.7 Marketing and Communications
Including:
newsletters;
onboarding emails;
product updates;
webinar invitations;
B2B marketing communications;
retargeting campaigns;
advertising measurement.
Customers may unsubscribe from marketing emails using the unsubscribe link included in communications.
Transactional, billing, legal, security, and operational communications may still be sent after marketing opt-out.
7. LEGAL BASES FOR PROCESSING
Where required by law, we rely on one or more of the following legal bases:
contract performance;
legitimate interests;
consent;
legal obligations;
protection of legal rights;
fraud prevention;
business operations;
substantial public interest where applicable.
Our legitimate interests may include:
operating the Services;
fraud prevention;
telecom abuse prevention;
analytics;
platform security;
service improvement;
B2B marketing;
operational reliability.
8. AI PROCESSING, AUTOMATION, AND PROFILING
The Services may use automated processing to:
classify leads;
score conversations;
analyze sentiment;
schedule appointments;
route calls;
generate AI responses;
create summaries;
automate workflows.
Customers are solely responsible for ensuring their use of automated processing complies with Applicable Laws, including disclosure, consent, human review, and objection requirements.
Omnixis does not independently make legally binding decisions relating to:
employment;
insurance eligibility;
lending;
legal eligibility;
healthcare diagnosis;
on behalf of Customers unless expressly agreed in writing.
9. AI TRAINING AND MODEL IMPROVEMENT
Omnixis does not use Customer recordings, transcripts, or Customer Data to train generalized AI models unless Customer expressly opts in or separately agrees in writing.
We may use:
anonymized data;
aggregated analytics;
telemetry;
operational metrics;
for:analytics;
fraud prevention;
abuse prevention;
benchmarking;
service optimization;
operational improvement.
10. COOKIES AND TRACKING TECHNOLOGIES
We may use:
cookies;
pixels;
analytics tools;
local storage;
session technologies;
advertising technologies.
These technologies may support:
authentication;
analytics;
website functionality;
advertising measurement;
retargeting;
marketing attribution;
fraud prevention.
We may use technologies provided by:
Google Analytics;
Meta;
LinkedIn;
other analytics and advertising providers.
Where required by law, Omnixis may implement consent mechanisms or cookie preference tools.
A separate Cookie Policy may provide additional information.
11. HOW WE SHARE PERSONAL DATA
We may share personal data with the following categories of recipients.
11.1 Service Providers and Subprocessors
Including providers supporting:
cloud hosting;
telecom infrastructure;
AI processing;
transcription;
analytics;
payment processing;
CRM syncing;
security;
customer support.
These providers may include:
OpenAI;
Twilio;
Telnyx;
Stripe;
AWS;
Azure;
MongoDB;
Cloudflare;
ElevenLabs;
Zendesk;
Slack;
CRM providers.
Omnixis may add, replace, or modify subprocessors at any time.
11.2 Customer-Directed Integrations
Where Customers enable integrations or CRM syncing, Omnixis may transfer data to those third-party systems at Customer’s direction.
Two-way syncs may result in data duplication, synchronization delays, or inconsistent deletion states between systems.
Omnixis is not responsible for third-party integration behavior.
11.3 Legal and Regulatory Requests
We may disclose personal data where reasonably necessary to:
comply with laws;
respond to regulators;
respond to courts;
respond to telecom carriers;
cooperate with law enforcement;
enforce agreements;
prevent fraud;
protect rights and safety.
Where legally permitted and commercially reasonable, Omnixis may challenge or narrow overbroad requests.
11.4 Corporate Transactions
Personal data may be transferred in connection with:
merger;
acquisition;
restructuring;
financing;
bankruptcy;
asset sale;
corporate transaction.
12. INTERNATIONAL DATA TRANSFERS
Omnixis operates globally.
Personal data may be transferred to, processed in, or accessed from jurisdictions outside the individual’s country of residence.
Omnixis may store and process data globally, subject to applicable legal requirements and commercially reasonable safeguards.
Transfers may occur to jurisdictions including:
UAE;
United States;
United Kingdom;
European Economic Area;
other jurisdictions where our providers operate.
Where required, Omnixis may rely on:
contractual safeguards;
standard contractual clauses;
data processing agreements;
adequacy decisions;
other lawful transfer mechanisms.
13. DATA RETENTION
We retain personal data only for as long as reasonably necessary for:
providing the Services;
compliance;
security;
fraud prevention;
operational needs;
dispute resolution;
enforcing agreements;
legitimate business purposes.
Unless otherwise required:
recordings;
transcripts;
logs;
analytics;
may generally be retained for up to twelve (12) months.
Retention periods may vary depending on:
plan type;
legal requirements;
operational needs;
enterprise agreements;
backup cycles.
Customers are responsible for exporting and backing up Customer Data.
Customers currently may export data but may not independently delete recordings or transcripts through the platform.
Deleted data may persist temporarily in:
backups;
archives;
disaster recovery systems;
logs.
14. SECURITY
Omnixis uses commercially reasonable safeguards designed to protect personal data, including:
encryption in transit where commercially reasonable;
backups;
audit logging;
access controls;
infrastructure monitoring;
authentication mechanisms.
However:
no system is completely secure;
no AI platform is error-free;
no telecom network is completely secure;
no internet transmission is fully secure.
Customers remain responsible for:
protecting credentials;
configuring access permissions;
securing integrations;
lawful usage;
endpoint security.
15. INCIDENTS AND DATA BREACHES
Omnixis may investigate security incidents, suspicious activity, telecom abuse, fraud, and unauthorized access.
Where required by Applicable Laws, Omnixis may provide breach notifications within commercially reasonable timeframes after becoming aware of a qualifying incident.
Customers remain responsible for:
their own compliance obligations;
regulator notifications;
end-user notifications;
where legally required.
16. PRIVACY RIGHTS
Depending on jurisdiction, individuals may have rights to:
access personal data;
correct personal data;
delete personal data;
restrict processing;
object to processing;
withdraw consent;
request portability;
opt out of certain processing;
lodge complaints with regulators.
We may require identity verification before responding to requests.
Where Omnixis acts as processor/service provider, requests may be referred to the relevant Customer.
Requests may be submitted to:
privacy@omnixis.ai
17. CALIFORNIA PRIVACY DISCLOSURES
Where applicable under California law:
Omnixis does not knowingly sell personal information for monetary compensation.
Certain analytics or advertising activities may constitute “sharing” under California law depending on interpretation.
California residents may have rights relating to:
access;
correction;
deletion;
opt-out;
non-discrimination;
limitation of sensitive information use where applicable.
Requests may be submitted to:
privacy@omnixis.ai
18. UK, EEA, AND UAE RIGHTS
Where UK GDPR, EU GDPR, or UAE PDPL applies, individuals may have rights relating to:
access;
rectification;
erasure;
portability;
objection;
restriction;
withdrawal of consent.
Complaints may also be submitted to applicable supervisory authorities.
19. TELEMARKETING, RECORDING, AND AI DISCLOSURE RESPONSIBILITY
Customers are solely responsible for ensuring that their use of the Services complies with:
telemarketing laws;
DNC laws;
recording laws;
AI disclosure laws;
consent laws;
telecom laws;
privacy laws.
Omnixis does not guarantee that use of the Services complies with any law or regulation.
Customers remain solely responsible for:
obtaining required consents;
providing required disclosures;
lawful campaign operation;
maintaining compliance records.
Omnixis may suspend campaigns creating:
legal risk;
carrier risk;
fraud risk;
spam risk;
reputational risk;
regulatory risk.
20. CHILDREN’S PRIVACY
The Services are not intended for individuals under eighteen (18) years old.
Omnixis does not knowingly collect children’s data.
21. MARKETING TESTIMONIALS AND CASE STUDIES
Omnixis may use:
customer names;
logos;
testimonials;
campaign metrics;
case studies;
only with Customer consent or as otherwise permitted by agreement.
22. AGENCY AND MULTI-PARTY DATA RESPONSIBILITY
If Customers upload data relating to:
clients;
affiliates;
agencies;
third parties;
the Customer remains solely responsible for ensuring lawful processing and authorization.
23. DATA PROCESSING ADDENDUM
Where applicable, Omnixis may enter into a Data Processing Addendum (“DPA”) governing:
processor obligations;
subprocessors;
security measures;
international transfers;
deletion;
audit rights;
data subject requests.
If a DPA conflicts with this Privacy Policy, the DPA governs for covered processing.
24. CHANGES TO THIS PRIVACY POLICY
Omnixis may modify this Privacy Policy at any time.
Changes become effective upon posting unless otherwise stated.
Where legally required, Omnixis may provide additional notice.
Continued use of the Services after updates constitutes acknowledgment of the updated Privacy Policy.
25. CONTACT
Omnixis Artificial Intelligence Developing LLC
License No. 1467676
Parklane Tower, Business Bay
Dubai, United Arab Emirates
Privacy Contact: privacy@omnixis.ai
Legal Contact: legal@omnixis.ai