Legal
Data protection measures
Draft — pending legal review
1. System access control
Access to production systems requires an individual named account. Shared logins are not used. Administrative access is reached over an encrypted connection only, never over the open internet, and accounts lock after repeated failed sign-in attempts.
Multi-factor authentication is required on every account that can reach production or the systems that hold credentials. Credentials are stored in a password manager, never in code, tickets or chat. Accounts are removed the day a person stops working with us.
2. Data access control
Access follows least privilege: a person is granted only the data their work requires, and read-only wherever read-only is enough. Bid-stream data is handled in aggregate for reporting and troubleshooting; individual records are opened only where a specific technical investigation needs them.
Administrative actions and data exports are logged with the account, action and timestamp. Logs are reviewed when an incident or an anomaly in traffic is being investigated.
3. Physical access control
We operate no data centre of our own. Serving and storage run with commercial cloud and hosting providers whose facilities enforce their own physical access controls. Our own working devices are encrypted at rest, screen-locked, and carry no unencrypted copies of partner data.
4. Organisational and operational security
Responsibility for data protection sits with the operating team rather than a separate department; the person who runs a system is accountable for how it handles data. Staff and contractors are bound by confidentiality terms and are briefed on data handling at least annually, and again whenever a process changes.
Endpoints run current operating systems with automatic updates and anti-malware protection enabled. Changes to production are reviewed before release and can be rolled back. We do not claim any external certification or audit result; where a partner requires one, we will say so plainly rather than imply it.
5. Transfer control
Data in transit is encrypted with TLS on every interface, including bid endpoints, reporting and internal tooling. We do not accept or send partner data over unencrypted transports, email attachments or consumer file-sharing services.
We operate across Asia-Pacific, so data may be processed outside the country in which it was collected. Cross-border transfers are made on contractual terms with the counterparty, and the categories of data involved are described in the Data Processing Addendum.
6. Data retention
Request-level data is kept only as long as it is needed to serve, bill and troubleshoot, then deleted or reduced to aggregate counts that identify no device or person. Aggregated reporting is kept for the commercial period it covers. Enquiry details submitted through this site are kept for the correspondence they relate to and deleted on request.
Deletion or access requests can be sent to contact@omniad.ai and are acknowledged in writing.
7. Job control
Where we process data on a partner's instruction, we act only within that instruction and within the contract that records it. Sub-processors are used only for hosting, serving and standard business tooling, are bound by equivalent obligations, and are named to a partner on request. We do not sell partner data or use it to build audiences of our own.
8. Data Processing Addendum
A Data Processing Addendum covering roles, purposes, data categories, sub-processors and transfer terms is available on request from contact@omniad.ai. We will sign a partner's own DPA where its terms match how we actually operate.
