This Privacy Policy explains how 1001660987 Ontario Inc. ("OmnionAI," "we," "us") collects, uses, and shares personal information in connection with the OmnionAI AI phone-receptionist service (the "Service"). It applies to our business customers ("Customers") and to individuals who call a phone number answered by the Service ("Callers"). This Policy is incorporated into our Terms of Service; your use of the Service is also subject to those Terms, including their disclaimers and limitations of liability. Customers should also read the Data Processing Addendum, which governs how we handle personal information on a Customer's behalf.
Roles. For information processed on behalf of a Customer's business (such as call transcripts and caller details), the Customer is the controller and OmnionAI acts as a processor / service provider that handles the information under the Customer's instructions and our agreement with them. For our own account, billing, and website data, OmnionAI is the controller.
What actually happens on a call. The Service answers the call, converts speech to text in real time, and stores the resulting transcript together with the details the receptionist extracted from it. We do not currently save a recording of the audio. A Customer may configure the Service to announce that a call may be recorded or monitored, and some Customers are required by law to do so. If we introduce audio recording as a feature, we will update this Policy and the disclosure before doing so.
Consent is the Customer's responsibility. Transcription and monitoring can be subject to "one-party" or "all-party / two-party" consent laws depending on where the Caller and the business are located. Our Customers are responsible for ensuring that any required notice is given and any required consent is obtained, and for keeping the spoken disclosure enabled and accurate. If you are a Caller and you do not consent, please end the call and contact the business by another method.
Speaking with an AI. The receptionist is an automated system, not a person. If a Caller asks whether they are speaking with a person, a robot, a bot, an AI, or a recording, the Service is configured to answer truthfully and immediately. Customers can also enable a proactive announcement at the start of the call, and are responsible for doing so where their jurisdiction requires it.
Automated processing. The Service uses AI to transcribe, summarize, classify urgency, and — where the Customer enables it — offer appointment times and take bookings. These outputs are probabilistic and can be wrong. No decision that produces legal or similarly significant effects about a Caller is made solely by automated means. A Caller who wants a human to review something the receptionist did should contact the business they called, or contact us using the details below.
What we do not do. We do not sell personal information, and we do not "share" it for cross-context behavioural advertising. We do not use Caller call content — or any transcript, embedding, or other derivative of it — to train, fine-tune, or improve any general-purpose AI model, whether ours or a third party's. We do not use it for advertising. We do not use it for our own independent purposes at all: we process it only to deliver the Service to the Customer whose line was called, as set out in our Data Processing Addendum.
When you ask NIO to call you for a Try NIO demonstration, we collect your first name, business name and type, submitted phone number, and one-time authorization evidence. We keep verification evidence when verification is required and completed, as well as the requested call and outcome, consultation intent when you select the booking link, and any manual inquiry response. We use this information to place and document the requested demo, for abuse prevention, to send a limited team notification, to respond manually to your inquiry, and to maintain compliance records.
We also keep approved attribution: source, campaign, keyword/search theme, creative or ad identifier, and landing-page variant, for lead-source and campaign measurement. The authorization covers the requested one-time AI-generated demo call to the submitted number. It does not authorize recurring automated marketing calls or messages. If required verification is not completed, we cannot place that demo call. A member of our team may manually respond to your inquiry; recurring email, SMS, or automated marketing requires the permission applicable to that channel and jurisdiction.
When configured for this flow, Anthropic receives the submitted business name and type to prepare a pre-call role-play brief. To verify when required and place the call, we use the telephony and voice providers identified below. The operational Try NIO lead record does not add device, referrer, gclid, or CRM capture. Separately, only after you accept optional analytics, Google Ads receives a completion event so we can measure whether an ad produced a successful Try NIO request. That event does not include your name, business name, phone number, verification code, or call contents; Google may process browser/device information, page URL, and ad/click attribution for conversion measurement under its own privacy terms. A booking-link click records consultation intent only; Google Calendar remains the booking authority and the team updates any consultation status manually.
We share information with vendors that help us run the Service, under contracts that limit their use of the information. These currently include:
| Provider | Purpose | Processing location |
|---|---|---|
| Render | Cloud hosting, application servers and database | United States |
| LiveKit Cloud | Real-time voice call infrastructure | United States |
| Telnyx | Telephony carrier, phone numbers and SMS | United States |
| OpenAI | Real-time speech and language model that conducts the call | United States |
| Anthropic | Pre-call Try NIO role-play brief from submitted business name/type; post-call transcript summarisation and extraction; in-dashboard assistant | United States |
| Fish Audio | Text-to-speech voice, where enabled for a Customer | United States |
| ElevenLabs | Alternative text-to-speech voice — optional and off by default | United States |
| Resend | Transactional and notification email | United States |
| Twilio | Fallback SMS delivery | United States |
| Calendar scheduling (only where the Customer connects it) and consented Google Ads conversion measurement | United States | |
| Scheduling providers | Onboarding scheduling, only when configured for that purpose | Varies by configured provider |
| Stripe | Payment processing | United States |
| Cloudflare | Content delivery and network security for our website | Global edge network |
| FirstPromoter | Affiliate/partner referral tracking and commission attribution (only sets a cookie when you arrive via a partner referral link) | United States |
We keep this list current and will update it when we add or remove a provider. Customers who want advance notice of changes should see the Data Processing Addendum. We may also disclose information to comply with law, enforce our terms, or protect rights and safety, and in connection with a business transfer (e.g., merger or acquisition).
OmnionAI is a Canadian company, and our primary application infrastructure is located in the United States. Our application servers, background workers, and database — which holds transcripts, caller details, bookings, and account records — are hosted in the United States (Oregon). Service providers may process information in other locations, including a scheduling provider when configured; see the table above for provider categories and processing locations.
Personal information about Canadian Customers and Canadian Callers may be stored or processed in the United States and other locations where our service providers operate, and may be subject to lawful access under the laws of those locations. We remain accountable for that information under Canada's PIPEDA and use contractual and technical safeguards with each provider. Where we transfer personal data from the EEA or the UK, we rely on appropriate transfer mechanisms as described in the Data Processing Addendum. If we introduce a Canadian-hosted option, we will say so explicitly rather than implying it.
If you join our partner / affiliate / ambassador program, we (and our program provider FirstPromoter) also process: your name and email; your referral link, click, signup and commission activity; payout details you provide (such as a PayPal or Wise address); and any tax information required to pay you. This information is used only to run the program — tracking referrals, calculating and paying commissions, preventing fraud, and meeting tax obligations — and is retained while you remain in the program and as required by law afterwards. The rights described under "Your rights" below apply to partner data too.
When a Customer connects their Google Calendar, OmnionAI requests the Google Calendar (calendar.events) permission solely to check the connected calendar's availability and to create the appointments our receptionist books on the Customer's behalf. OmnionAI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer or use it for any purpose other than providing the calendar scheduling feature. A Customer can disconnect Google Calendar at any time from their dashboard, which revokes our access.
We keep personal information only as long as we need it, and different records have different lifetimes:
When a Customer's account is closed, we delete or de-identify Customer Data as described in the Data Processing Addendum, except where we must retain it by law.
We use technical and organizational measures designed to protect personal information, including encryption in transit (TLS), hashed passwords, session tokens that are stored only in hashed form, application-layer separation of each Customer's data, timing-safe comparison of secrets, signature verification on payment webhooks, restrictions on the addresses our servers will call out to, and rate limiting on sensitive endpoints. Access to production systems is limited to the people who need it.
We want to be straightforward about the limits of that statement: we do not currently hold SOC 2, ISO 27001, or any equivalent certification, and we do not claim one. No system is perfectly secure, and we cannot guarantee absolute security. AI-generated transcripts, summaries, and other outputs may contain errors and should be reviewed before being relied upon. To the maximum extent permitted by law, our liability relating to personal information and the Service is subject to the disclaimers and limitations of liability in our Terms of Service.
If something goes wrong. If we become aware of a breach of security that creates a real risk of significant harm, we will notify affected Customers without undue delay and, where we act as a processor, within 72 hours of becoming aware, and we will report to regulators and maintain records where the law requires. To report a suspected vulnerability or incident, email security@omnionai.tech.
Depending on where you live — for example under Canada's PIPEDA, Quebec's Law 25, the EU/UK GDPR, or U.S. state privacy laws such as the CCPA/CPRA — you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to receive a portable copy, to withdraw consent, to object to or restrict certain processing, and to appeal a decision we make about your request. We do not sell or share personal information, and we do not use it for targeted advertising or profiling, so there is nothing to opt out of in those categories.
How to make a request. Email privacy@omnionai.tech with enough detail for us to find your records — for a Caller, that is usually the phone number you called from or were reached at, and roughly when. We will acknowledge your request within 5 business days and respond substantively within 30 days, and we will tell you if we need a permitted extension. We may need to verify your identity before acting, and we will not charge you for a reasonable request. You may use an authorized agent where the law allows.
If you are a Caller and your request relates to a call you made to a business, that business is the controller of that information and is usually best placed to act. You may contact them directly, or contact us and we will action the request ourselves and notify the business — you do not have to chase two parties to get your data deleted. Deleting a record may mean the business loses the appointment or message associated with it.
Complaints. You may complain to us at any time, and you also have the right to complain to a regulator — in Canada, the Office of the Privacy Commissioner of Canada or your provincial authority (in Quebec, the Commission d'accès à l'information); in the EEA/UK, your local supervisory authority.
We do not use cookies to build cross-site profiles of you or enable personalized advertising. We use necessary, preference, analytics, advertising-measurement, and referral cookies only as described here and through the consent choices available when non-essential technologies are enabled.
localStorage holds your session token and basic preferences so you stay signed in and the Service works. It is essential to providing the Service you request, is cleared when you log out, and does not require cookie consent in most jurisdictions.When you use certain third-party flows, those providers may set their own cookies on their own domains under their own policies — for example, Stripe during checkout and Google when you connect a Google Calendar. We do not control those cookies. See the Service providers / subprocessors section above.
If we introduce analytics or marketing technologies that are not strictly necessary beyond the categories described above, we will provide a consent mechanism and update this Policy first.
The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child's information has reached us, contact privacy@omnionai.tech and we will delete it.
We may update this Policy from time to time; material changes will be posted here with a new effective date, and we will notify Customers by email where the change materially affects them.
1001660987 Ontario Inc., Ontario, Canada — the entity responsible for the personal information described in this Policy.
Privacy and data-subject requests: privacy@omnionai.tech
Security and vulnerability reports: security@omnionai.tech
Legal notices: legal@omnionai.tech
General support: support@omnionai.tech
Our Privacy Officer can be reached at privacy@omnionai.tech.