OmnionAI

Privacy Policy

Effective date: July 6, 2026 · Last updated: August 27, 2026

This Privacy Policy explains how 1001660987 Ontario Inc. ("OmnionAI," "we," "us") collects, uses, and shares personal information in connection with the OmnionAI AI phone-receptionist service (the "Service"). It applies to our business customers ("Customers") and to individuals who call a phone number answered by the Service ("Callers"). This Policy is incorporated into our Terms of Service; your use of the Service is also subject to those Terms, including their disclaimers and limitations of liability. Customers should also read the Data Processing Addendum, which governs how we handle personal information on a Customer's behalf.

Roles. For information processed on behalf of a Customer's business (such as call transcripts and caller details), the Customer is the controller and OmnionAI acts as a processor / service provider that handles the information under the Customer's instructions and our agreement with them. For our own account, billing, and website data, OmnionAI is the controller.

Two things worth knowing up front. First, we do not currently retain call audio — calls are transcribed in real time and the transcript is stored; the audio itself is not saved by us. Second, our primary application infrastructure is in the United States, while service providers may process information in other locations. Both points are explained below.
Draft review status. This legal copy requires owner/counsel approval before production publication.

Information we collect

Call audio, transcripts, and consent

What actually happens on a call. The Service answers the call, converts speech to text in real time, and stores the resulting transcript together with the details the receptionist extracted from it. We do not currently save a recording of the audio. A Customer may configure the Service to announce that a call may be recorded or monitored, and some Customers are required by law to do so. If we introduce audio recording as a feature, we will update this Policy and the disclosure before doing so.

Consent is the Customer's responsibility. Transcription and monitoring can be subject to "one-party" or "all-party / two-party" consent laws depending on where the Caller and the business are located. Our Customers are responsible for ensuring that any required notice is given and any required consent is obtained, and for keeping the spoken disclosure enabled and accurate. If you are a Caller and you do not consent, please end the call and contact the business by another method.

Speaking with an AI. The receptionist is an automated system, not a person. If a Caller asks whether they are speaking with a person, a robot, a bot, an AI, or a recording, the Service is configured to answer truthfully and immediately. Customers can also enable a proactive announcement at the start of the call, and are responsible for doing so where their jurisdiction requires it.

Automated processing. The Service uses AI to transcribe, summarize, classify urgency, and — where the Customer enables it — offer appointment times and take bookings. These outputs are probabilistic and can be wrong. No decision that produces legal or similarly significant effects about a Caller is made solely by automated means. A Caller who wants a human to review something the receptionist did should contact the business they called, or contact us using the details below.

How we use information

What we do not do. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising. We do not use Caller call content — or any transcript, embedding, or other derivative of it — to train, fine-tune, or improve any general-purpose AI model, whether ours or a third party's. We do not use it for advertising. We do not use it for our own independent purposes at all: we process it only to deliver the Service to the Customer whose line was called, as set out in our Data Processing Addendum.

Try NIO demo requests

When you ask NIO to call you for a Try NIO demonstration, we collect your first name, business name and type, submitted phone number, and one-time authorization evidence. We keep verification evidence when verification is required and completed, as well as the requested call and outcome, consultation intent when you select the booking link, and any manual inquiry response. We use this information to place and document the requested demo, for abuse prevention, to send a limited team notification, to respond manually to your inquiry, and to maintain compliance records.

We also keep approved attribution: source, campaign, keyword/search theme, creative or ad identifier, and landing-page variant, for lead-source and campaign measurement. The authorization covers the requested one-time AI-generated demo call to the submitted number. It does not authorize recurring automated marketing calls or messages. If required verification is not completed, we cannot place that demo call. A member of our team may manually respond to your inquiry; recurring email, SMS, or automated marketing requires the permission applicable to that channel and jurisdiction.

When configured for this flow, Anthropic receives the submitted business name and type to prepare a pre-call role-play brief. To verify when required and place the call, we use the telephony and voice providers identified below. The operational Try NIO lead record does not add device, referrer, gclid, or CRM capture. Separately, only after you accept optional analytics, Google Ads receives a completion event so we can measure whether an ad produced a successful Try NIO request. That event does not include your name, business name, phone number, verification code, or call contents; Google may process browser/device information, page URL, and ad/click attribution for conversion measurement under its own privacy terms. A booking-link click records consultation intent only; Google Calendar remains the booking authority and the team updates any consultation status manually.

Service providers / subprocessors

We share information with vendors that help us run the Service, under contracts that limit their use of the information. These currently include:

ProviderPurposeProcessing location
RenderCloud hosting, application servers and databaseUnited States
LiveKit CloudReal-time voice call infrastructureUnited States
TelnyxTelephony carrier, phone numbers and SMSUnited States
OpenAIReal-time speech and language model that conducts the callUnited States
AnthropicPre-call Try NIO role-play brief from submitted business name/type; post-call transcript summarisation and extraction; in-dashboard assistantUnited States
Fish AudioText-to-speech voice, where enabled for a CustomerUnited States
ElevenLabsAlternative text-to-speech voice — optional and off by defaultUnited States
ResendTransactional and notification emailUnited States
TwilioFallback SMS deliveryUnited States
GoogleCalendar scheduling (only where the Customer connects it) and consented Google Ads conversion measurementUnited States
Scheduling providersOnboarding scheduling, only when configured for that purposeVaries by configured provider
StripePayment processingUnited States
CloudflareContent delivery and network security for our websiteGlobal edge network
FirstPromoterAffiliate/partner referral tracking and commission attribution (only sets a cookie when you arrive via a partner referral link)United States

We keep this list current and will update it when we add or remove a provider. Customers who want advance notice of changes should see the Data Processing Addendum. We may also disclose information to comply with law, enforce our terms, or protect rights and safety, and in connection with a business transfer (e.g., merger or acquisition).

Where your information is processed

OmnionAI is a Canadian company, and our primary application infrastructure is located in the United States. Our application servers, background workers, and database — which holds transcripts, caller details, bookings, and account records — are hosted in the United States (Oregon). Service providers may process information in other locations, including a scheduling provider when configured; see the table above for provider categories and processing locations.

Personal information about Canadian Customers and Canadian Callers may be stored or processed in the United States and other locations where our service providers operate, and may be subject to lawful access under the laws of those locations. We remain accountable for that information under Canada's PIPEDA and use contractual and technical safeguards with each provider. Where we transfer personal data from the EEA or the UK, we rely on appropriate transfer mechanisms as described in the Data Processing Addendum. If we introduce a Canadian-hosted option, we will say so explicitly rather than implying it.

Partner and affiliate data

If you join our partner / affiliate / ambassador program, we (and our program provider FirstPromoter) also process: your name and email; your referral link, click, signup and commission activity; payout details you provide (such as a PayPal or Wise address); and any tax information required to pay you. This information is used only to run the program — tracking referrals, calculating and paying commissions, preventing fraud, and meeting tax obligations — and is retained while you remain in the program and as required by law afterwards. The rights described under "Your rights" below apply to partner data too.

Google user data

When a Customer connects their Google Calendar, OmnionAI requests the Google Calendar (calendar.events) permission solely to check the connected calendar's availability and to create the appointments our receptionist books on the Customer's behalf. OmnionAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer or use it for any purpose other than providing the calendar scheduling feature. A Customer can disconnect Google Calendar at any time from their dashboard, which revokes our access.

Data retention

We keep personal information only as long as we need it, and different records have different lifetimes:

When a Customer's account is closed, we delete or de-identify Customer Data as described in the Data Processing Addendum, except where we must retain it by law.

Security

We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS), hashed passwords, session tokens that are stored only in hashed form, application-layer separation of each Customer's data, timing-safe comparison of secrets, signature verification on payment webhooks, restrictions on the addresses our servers will call out to, and rate limiting on sensitive endpoints. Access to production systems is limited to the people who need it.

We want to be straightforward about the limits of that statement: we do not currently hold SOC 2, ISO 27001, or any equivalent certification, and we do not claim one. No system is perfectly secure, and we cannot guarantee absolute security. AI-generated transcripts, summaries, and other outputs may contain errors and should be reviewed before being relied upon. To the maximum extent permitted by law, our liability relating to personal information and the Service is subject to the disclaimers and limitations of liability in our Terms of Service.

If something goes wrong. If we become aware of a breach of security that creates a real risk of significant harm, we will notify affected Customers without undue delay and, where we act as a processor, within 72 hours of becoming aware, and we will report to regulators and maintain records where the law requires. To report a suspected vulnerability or incident, email security@omnionai.tech.

Your rights

Depending on where you live — for example under Canada's PIPEDA, Quebec's Law 25, the EU/UK GDPR, or U.S. state privacy laws such as the CCPA/CPRA — you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to receive a portable copy, to withdraw consent, to object to or restrict certain processing, and to appeal a decision we make about your request. We do not sell or share personal information, and we do not use it for targeted advertising or profiling, so there is nothing to opt out of in those categories.

How to make a request. Email privacy@omnionai.tech with enough detail for us to find your records — for a Caller, that is usually the phone number you called from or were reached at, and roughly when. We will acknowledge your request within 5 business days and respond substantively within 30 days, and we will tell you if we need a permitted extension. We may need to verify your identity before acting, and we will not charge you for a reasonable request. You may use an authorized agent where the law allows.

If you are a Caller and your request relates to a call you made to a business, that business is the controller of that information and is usually best placed to act. You may contact them directly, or contact us and we will action the request ourselves and notify the business — you do not have to chase two parties to get your data deleted. Deleting a record may mean the business loses the appointment or message associated with it.

Complaints. You may complain to us at any time, and you also have the right to complain to a regulator — in Canada, the Office of the Privacy Commissioner of Canada or your provincial authority (in Quebec, the Commission d'accès à l'information); in the EEA/UK, your local supervisory authority.

Cookies

We do not use cookies to build cross-site profiles of you or enable personalized advertising. We use necessary, preference, analytics, advertising-measurement, and referral cookies only as described here and through the consent choices available when non-essential technologies are enabled.

When you use certain third-party flows, those providers may set their own cookies on their own domains under their own policies — for example, Stripe during checkout and Google when you connect a Google Calendar. We do not control those cookies. See the Service providers / subprocessors section above.

If we introduce analytics or marketing technologies that are not strictly necessary beyond the categories described above, we will provide a consent mechanism and update this Policy first.

Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child's information has reached us, contact privacy@omnionai.tech and we will delete it.

Changes

We may update this Policy from time to time; material changes will be posted here with a new effective date, and we will notify Customers by email where the change materially affects them.

Contact

1001660987 Ontario Inc., Ontario, Canada — the entity responsible for the personal information described in this Policy.

Privacy and data-subject requests: privacy@omnionai.tech
Security and vulnerability reports: security@omnionai.tech
Legal notices: legal@omnionai.tech
General support: support@omnionai.tech

Our Privacy Officer can be reached at privacy@omnionai.tech.

HomeTerms of ServiceData Processing AddendumLog in