Trust Center
Your data security is our foundation
Omniday is built on enterprise-grade security principles. We implement rigorous technical and organisational measures to protect your data and your customers' data at every layer.
Encryption
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. API keys and tokens are stored only as SHA-256 hashes — never in plaintext.
EU-Based Infrastructure
Hosted in the EU. Personal data is processed and stored within the EU.
Access Controls
We enforce role-based access control (RBAC) with the principle of least privilege. All access to production systems requires multi-factor authentication and is logged for audit purposes.
Monitoring & Detection
Real-time threat detection with automated monitoring and alerting around the clock for anomalous behaviour.
Incident Response
We maintain a documented incident response plan. In the event of a personal data breach, we will notify you without undue delay so you can meet your 72-hour deadline to the supervisory authority (GDPR Article 33).
Security Specifics
Each business's data is logically separated per tenant in every query. Encryption in transit (TLS 1.2+) and at rest (AES-256) throughout. Chat messages are scrubbed of personal data before export to our observability tooling.
Data Processing
When you use Omniday to process your customers' interactions, we act as a Data Processor under GDPR Article 28. We process data only on your documented instructions. A GDPR Article 28 data processing agreement (DPA) is available on request — contact hello@omniday.ai.
Sub-Processors
We use a small set of carefully selected sub-processors, each vetted for GDPR compliance and bound by a data processing agreement. The full named register — who processes what, in which region, on which transfer basis — is public at /trust/subprocessors. We notify you at least 30 days before adding or replacing a sub-processor, giving you the right to object.
AI Transparency
Your customers are always told they're talking to an AI — the chat widget carries built-in disclosure in line with the EU AI Act (Article 50). By default, AI-drafted email replies require human approval before sending.
AI processing of your data takes place within the EU.
Your data is never used to train the underlying AI models we rely on — this is contractually guaranteed by our infrastructure providers and applies regardless of which provider we use.
We may use de-identified, aggregated data to improve the quality and performance of our own AI features. This never includes your customers' personal data in identifiable form.
Responsible Disclosure
If you discover a security vulnerability in our Platform, please report it responsibly to hello@omniday.ai. We ask that you give us reasonable time to investigate and patch before public disclosure. We do not pursue legal action against researchers who act in good faith.
Questions?
For security inquiries, contact us at hello@omniday.ai. For privacy-related queries, see our Privacy Policy.