Legal · Data Processing

Data Processing Policy

Last updated · 21 July 2026

This policy describes how OMS AI Nexus™ (“OMS”) processes personal data on behalf of customers who use the platform. When customers upload or generate content in their workspace, OMS acts as a data processor and the customer is the data controller. For account, billing, and marketing data, OMS acts as an independent controller.

1. Roles & responsibilities

  • Controller (Customer): determines the purposes and means of processing workspace data and is responsible for the lawful basis of the data they submit.
  • Processor (OMS): processes workspace data only on documented instructions from the customer, per these terms and the Terms of Service.
  • Sub-processors: engaged only under written contracts imposing equivalent obligations.

2. Scope, purpose & categories

  • Subject matter: provision of the OMS AI Nexus platform (Workora AI, OMS Developer AI, BanglaGPT, AEGIS Security).
  • Duration: for the term of the customer's subscription plus retention windows required by law.
  • Data categories: account identifiers, workspace content (documents, prompts, embeddings, conversation history), usage telemetry, security logs.
  • Data subjects: customer's authorized users, staff, and any individuals referenced in workspace content.

3. Sub-processors

OMS uses vetted infrastructure and AI providers to deliver the platform. Current sub-processor categories:

  • Managed database & auth hosting (backend platform provider).
  • Edge compute & CDN (application delivery).
  • AI model providers routed via the OMS AI Nexus AI Gateway (chat, embeddings, vision).
  • Payment processing (Stripe, when enabled by the customer).
  • Transactional email delivery.

Customers will receive at least 30 days' notice before a material change to sub-processors and may object under the Terms.

4. International transfers

Where personal data is transferred outside the customer's jurisdiction, OMS relies on recognized transfer mechanisms including the EU Standard Contractual Clauses (2021), the UK IDTA, and equivalent safeguards. OMS performs a transfer risk assessment before adding a sub-processor located outside the EEA/UK.

5. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Row-Level Security (RLS) enforced on every tenant table; multi-tenant isolation by workspace.
  • Mandatory MFA (AAL2) for administrative and Founder accounts.
  • Audit logs for authentication, admin actions, and workspace-level access.
  • Least-privilege access, secret rotation, and quarterly access reviews.
  • Backups with tested restore procedures (RTO ≤ 1h for platform data).

6. Data subject rights

Where OMS is a processor, requests from data subjects are forwarded to the customer (controller) without undue delay. Where OMS is a controller (account/billing), individuals may exercise access, correction, deletion, portability, restriction, and objection rights by writing to the contact below. OMS will respond within 30 days as required by GDPR / UK GDPR / CCPA.

7. Breach notification

OMS will notify affected customers without undue delay, and in any case within 72 hours of confirming a personal data breach, with sufficient information for the customer to meet its own notification obligations.

8. Retention & deletion

Workspace data is retained while the subscription is active. On termination, customer data is deleted or returned within 30 days, except where retention is required by law (e.g., invoicing records).

9. Contact & DPO

Data protection questions: omsit.official@gmail.com. Please mark the subject line “Data Processing Request”.

This policy describes current app-visible practices and standard contractual commitments; enterprise customers may sign a full Data Processing Addendum (DPA) on request.