Privacy policy
Version 2026-09-23
1. Controller
The controller of personal data processed by this service is inMotionMedia s. r. o., Záhradnícka 7, 811 07 Bratislava, Slovakia, company ID 44555253. Contact: oliver.goossens@gmail.com.
This service ("OMNI Connector") is a private bridge between the operator's devices, its OMNI system and the business platforms that the operator explicitly connects. Public surfaces are limited to this information, app downloads, invited-person sign-in ("OMNI Humans") and any conversational interfaces the operator chooses to publish.
2. What we process and why
- Device pairing: we store a hash of the issued device token, device type and last-use time for authentication and revocation.
- OMNI Humans: for an invited person we store the access-code hash, sign-in time, IP address of attempts for abuse prevention, and answers submitted on cards (text, images and voice transcripts).
- Voice: audio is recorded only after microphone activation, sent to speech-to-text processing, and deleted after transcription; the transcript remains with the related card or task.
- Public conversational interfaces, if enabled: submitted text or speech and voluntarily provided details are sent to a language-model provider to produce a reply and may be kept as conversation history.
- Technical records: IP address, browser type, request time, security events and bounded operational logs for security, troubleshooting and rate limiting.
- Cookies: "omni_human" for invited-person sign-in (at most 90 days) and "omni_locale_connector" for language choice (1 year). This origin uses no advertising or analytics cookies.
3. Meta, Facebook and Instagram integrations
- When an authorised administrator connects Meta business assets, we process the administrator or business identifier needed for authorisation; Facebook Page and Instagram professional-account IDs, names and usernames; granted permissions; media, post and campaign IDs; captions; publication status; and the limited engagement, advertising or diagnostic metadata needed for the requested operation.
- Access tokens and connection settings are stored encrypted and used only for authorised publishing, linking existing organic posts to ads, managing the operator's own campaigns, reporting requested results and troubleshooting failed operations. We never ask for or store a Facebook or Instagram password.
- Social content and advertising instructions are sent to Meta Platforms Ireland Limited through Meta APIs. Meta returns identifiers, status and results needed to confirm the operation. Meta processes data under its own terms and privacy policy.
- The integration is limited to assets the operator controls or is authorised to manage. We do not sell Meta data, use it to build unrelated advertising profiles, or disclose it for another party's independent marketing.
4. Legal basis
Sign-in, pairing, requested publishing and campaign operations, and handling task cards rely on performance of the arrangement with the user or asset owner and the operator's legitimate interest in running a secure business service (Art. 6(1)(b) and (f) GDPR). Voice recording and voluntarily supplied data rely on consent where required (Art. 6(1)(a) GDPR). Consent may be withdrawn at any time without affecting earlier lawful processing.
5. Recipients and service providers
Data is disclosed only where needed for the requested function or secure operation:
- Meta Platforms Ireland Limited – Facebook, Instagram and Marketing API operations selected by an authorised administrator.
- Soniox – speech-to-text transcription.
- Language-model providers enabled in the operator's current configuration (for example Anthropic, OpenAI, Google or Mistral) – processing prompts and producing replies.
- DigitalOcean, LLC – database hosting.
- The virtual-server provider hosting this service in the European Union.
We do not sell personal data.
6. Transfers outside the EEA
Some platform, speech-to-text and language-model providers may process data outside the European Economic Area, mainly in the United States. Where required, transfers rely on an adequacy decision such as the EU-U.S. Data Privacy Framework or on EU standard contractual clauses.
7. Retention
- Voice audio: deleted after transcription.
- Task answers and transcripts: for the life of the related task and the operator's documented task-record retention period.
- Meta access tokens: until revoked, disconnected, replaced or invalidated. Connection identifiers and publication, campaign and diagnostic receipts: while the integration is active and afterwards only for the shortest operational, security, audit or legal period that applies.
- Content published on Facebook or Instagram remains on those platforms until it is removed there by an authorised administrator; disconnecting this service does not itself remove platform content.
- Device credentials: until revoked or expired. Server and security logs: short-term and proportionate to security needs.
8. Your rights and deletion
You may request access, rectification, erasure, restriction, portability, object to processing and withdraw consent. Send requests to oliver.goossens@gmail.com or follow the dedicated data-deletion instructions at /data-deletion. We may verify that the requester is authorised for the affected account or business asset before acting.
If you believe processing breaches the law, you may complain to the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, dataprotection.gov.sk. The service performs no automated decision-making with legal effects and is not intended for persons under 16.
9. Security
Transport uses HTTPS with HSTS. Tokens and secrets are encrypted or stored as one-way hashes as appropriate, each connected client receives least-privilege credentials, sensitive endpoints require authentication, and operations are logged without exposing passwords or access tokens.
10. Changes
We may update this policy when the service or its integrations change. The current version is always available at this address. Version: 2026-09-23.