Legal

Privacy Policy

Last updated: 16 March 2026

1. Introduction

Omniday ApS ("Omniday", "we", "us", or "our"), a company incorporated and registered in Denmark (CVR number: 41509775), is the data controller responsible for your personal data.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.omniday.ai and use our services (the "Platform"). It is written in compliance with the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 and the Danish Data Protection Act (Databeskyttelsesloven).

2. Data We Collect

We may collect the following categories of personal data:

CategoryExamplesLegal Basis (GDPR Art. 6)
Identity & ContactFull name, email, phone number, company nameArt. 6(1)(b) — contractual necessity
Account DataLogin credentials, workspace settingsArt. 6(1)(b) — contractual necessity
Usage DataPages visited, features used, session durationArt. 6(1)(f) — legitimate interest
Technical DataIP address, browser type, device identifiersArt. 6(1)(f) — legitimate interest
Communication DataSupport tickets, chat transcripts processed by the PlatformArt. 6(1)(b) — contractual necessity
Cookie & TrackingCookie identifiers, analytics eventsArt. 6(1)(a) — consent

3. How We Use Your Data

4. Data Sharing & Sub-Processors

We do not sell your personal data. We share data only with trusted sub-processors that are bound by GDPR-compliant Data Processing Agreements (DPAs):

The complete register of named sub-processors is public at /trust/subprocessors and mirrored in our data processing agreement, with at least 30 days' notice before a sub-processor is added or replaced. Processing of personal data by our sub-processors takes place within the EU. Where a sub-processor's corporate group includes non-EEA entities, Standard Contractual Clauses (SCCs) are in place as a safeguard in accordance with GDPR Articles 44–49.

Your data is never used to train the underlying AI models we rely on — this is contractually guaranteed by our infrastructure providers and applies regardless of which provider we use.

We may use de-identified, aggregated data to improve the quality and performance of our own AI features. This never includes your customers' personal data in identifiable form.

5. International Data Transfers

Processing of personal data takes place within the EU — AI processing, conversation data, logs and storage included (see the layer-by-layer overview at /trust/data-locations). We do not transfer personal data outside the EEA as part of normal operation. As a safeguard for any incidental third-country access — for example where a sub-processor's corporate group includes non-EEA entities — we rely on:

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law.

7. Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights under GDPR Articles 15–22:

To exercise any of these rights, contact us at hello@omniday.ai. We will respond within 30 days as required by GDPR.

8. Cookies

We use cookies in accordance with the Danish Executive Order on Cookies (Cookiebekendtgorelsen) and the ePrivacy Directive. For details, see our on-site Cookie Consent Banner. You can manage or withdraw cookie consent at any time.

9. Security

We implement industry-standard technical and organisational measures to protect your data, including TLS 1.2+ encryption in transit, AES-256 encryption at rest, and role-based access controls. For more detail, see our Security page.

10. Children's Privacy

Our Platform is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app notification at least 30 days before they take effect. Your continued use of the Platform after the effective date constitutes acceptance.

12. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet):

13. Contact

For any questions about this Privacy Policy or your personal data:

Privacy Policy – Omniday