This page describes how Omnifys processes data on behalf of clients and which categories of subprocessors we rely on. It exists so your security and compliance teams can complete due diligence quickly.

Our processing principles

  • Client data is processed only as required by the agreed workflow, under a signed agreement.
  • Client data is never used to train public or shared models.
  • Access is role-based and logged; agents operate through permissioned APIs.
  • Data is exported or deleted on request at the end of an engagement.

Subprocessor categories

We use vetted providers in the following categories. A current named list, with regions, is available on request and included in client agreements: cloud hosting and infrastructure; large language model API providers (15+ leading models, selected per task); payment processing; email delivery; workflow orchestration (e.g. n8n, Zapier); and monitoring/analytics.

Questions? Email privacy@omnifys.com — we respond within 5 business days.