Privacy Policy & Terms and Conditions
Omni-Channel Solutions — AI Visibility & Digital Marketing Services
Part I — Privacy Policy
1. Introduction
Omni-Channel BPO, Inc. d.b.a. Omni-Channel Solutions (“Omni-Channel,” “we,” “us,” or “our“) provides AI visibility analysis, search/answer-engine optimization, web crawling, prompt research, and digital marketing services through its proprietary platform suite, which includes Omni 360, OmniSpark, OmniFlare, OmniCrawl, and OmniDash (collectively, the “Services“). This Privacy Policy explains what information we collect from clients, prospective clients, website visitors, and the publicly accessible properties we are authorized to analyze, how we use that information, and the rights you have over it.
This Policy is written for clients and data subjects in the United States, Canada, and the United Kingdom. By engaging our Services, visiting our website, or providing us with information, you acknowledge and accept the practices described in this Policy. If you do not agree with this Policy, please do not use the Services or submit information to us.
2. Information We Collect
2.1 Information you provide directly
- Identity & contact data: name, business name, job title, business email, phone number, mailing address, and time zone.
- Account & authentication data: usernames, hashed passwords, MFA tokens, and API keys you generate within our platform.
- Billing data: billing address, taxpayer identification number (e.g., EIN, GST/HST number, VAT number), invoicing details, and payment-method metadata. Card numbers are processed by PCI-DSS-compliant payment processors and are not stored on our systems.
- Communications: messages, support tickets, meeting recordings (with consent), and any documents you share with us.
- Marketing preferences: consent flags, subscription status, and topical interests.
2.2 Information we collect from your business properties (with authorization)
To deliver AI visibility, SEO, AEO, GEO, LLO, and related analyses, we collect data from the digital properties you authorize us to scan. This includes:
- Website content & structure: HTML, rendered DOM, headers, sitemaps, robots.txt, structured data (schema.org / JSON-LD), canonical signals, hreflang, and on-page text.
- Technical metadata: server response codes, response times, technology stack signals, hosting/CDN fingerprints, certificate data, and bot-access posture (e.g., GPTBot, ClaudeBot, PerplexityBot accessibility).
- Public marketing assets: blog posts, landing pages, product pages, public press releases, and other content you publish.
- Search & LLM visibility data: brand-mention frequency, citation patterns, and synthetic-query results returned by large language models we are authorized to test against (OpenAI, Anthropic Claude, Google Gemini, self-hosted Ollama).
- Third-party signals you authorize: Google Analytics 4, Google Search Console, Google Ads, HubSpot, social-media insight APIs, Cordial, and similar tools, accessed only with your explicit grant.
OmniBot/1.0 (+https://omnichannelsolutions.ai/bot; itsupport@OmniChannelsol.com) and respects robots.txt by default.
2.3 Information collected automatically
- Usage data: pages viewed, features used, click paths, and timestamps within our platform.
- Device & log data: IP address, browser type and version, operating system, referring URL, and approximate geolocation derived from IP.
- Cookies and similar technologies: see Cookies & Tracking.
2.4 Information from third parties
We may receive enrichment data from licensed providers (e.g., DataForSEO, Hunter.io, Apify, Explorium / Vibe Prospecting) and from public sources (e.g., LinkedIn public profiles, company registries) for the purpose of lead generation, contact validation, and competitive analysis on behalf of clients who have engaged us for those services.
3. How We Use Information
We use information for the following purposes:
- Service delivery: running scans, generating Omni Score reports, building dashboards, and producing deliverables.
- AI visibility analysis: evaluating how your brand appears in LLM responses, search engines, and answer engines across our 8–9 pillar framework (SEO, AEO, GEO, LLO, AIR, RAG, SGE, MCP, Cross-Pillar) and 485-metric library.
- Marketing analysis & campaign support: building audience segments, validating contact lists, generating UTM frameworks, and running campaign analytics.
- Marketing email outreach on your behalf (where contracted), in compliance with applicable law — see Section 10.
- Account management & billing.
- Customer support, training, and product improvement.
- Security, fraud prevention, and abuse detection.
- Legal compliance and enforcement of our Terms.
We do not sell or “share” personal information as those terms are defined under California law. We do not use client data to train third-party general-purpose AI models.
4. Legal Basis for Processing
Where the UK GDPR applies, we process personal data under one or more of the following lawful bases:
- Contract — to perform our agreement with you (Art. 6(1)(b)).
- Legitimate interests — to operate, secure, and improve our Services and to conduct B2B outreach to relevant business contacts (Art. 6(1)(f)).
- Consent — for marketing communications where required, and for non-essential cookies (Art. 6(1)(a)).
- Legal obligation — to comply with tax, accounting, and regulatory requirements (Art. 6(1)(c)).
For Canadian data subjects, we rely on consent (express or implied) under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. For US data subjects, we process information consistent with applicable state privacy laws (including CCPA/CPRA in California, VCDPA in Virginia, CPA in Colorado, CTDPA in Connecticut, UCPA in Utah, and similar statutes in other states).
5. Data Sharing & Third-Party Subprocessors
We share information only with vetted subprocessors that are contractually bound to confidentiality and data-protection obligations consistent with this Policy. Our current key subprocessors include:
| Subprocessor | Purpose | Region |
|---|---|---|
| Hetzner Online GmbH | VPS hosting, compute | Germany / Finland (EU) |
| Supabase | Self-hosted database instance; managed cloud where applicable | Self-hosted on Hetzner; managed in US/EU |
| Vercel | Frontend hosting | Global edge network |
| Anthropic | LLM inference (Claude API) | USA |
| OpenAI | LLM inference (synthetic query testing) | USA |
| Gemini API, Analytics, Search Console, Ads | USA / Global | |
| DataForSEO | SERP and keyword data | USA |
| Cordial / HubSpot | Email delivery and CRM (where contracted) | USA |
| Stripe / PayPal / [PAYMENT PROVIDER] | Payment processing | USA / Global |
An updated subprocessor list is available on request via itsupport@OmniChannelsol.com. We may also disclose information when required by law, valid legal process, or to protect the rights, property, or safety of Omni-Channel, our clients, or the public.
6. Data Security & SOC 2 Alignment
We design our systems and operating practices in alignment with the SOC 2 Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, and Privacy). Although a formal SOC 2 Type II report is [in progress / planned for [DATE] / not yet attested — choose one], our controls include:
- Encryption in transit (TLS 1.2+ everywhere) and encryption at rest for databases and backups.
- Least-privilege access with role-based access control, MFA on all administrative accounts, and audited access logs.
- Network isolation: private networks, firewalled services, no exposed management ports (Docker Engine, database ports, Redis are bound to localhost or private networks only).
- Secrets management via environment variables and a dedicated secrets store; no secrets in source control.
- Backups & disaster recovery: automated, encrypted backups with documented restore procedures.
- Monitoring & incident response: log retention, alerting, and a documented incident-response runbook.
- Vendor risk management: subprocessors are reviewed for security posture before onboarding.
- Code & change management: peer review, version control (GitHub), and CI/CD with security checks.
No security program eliminates all risk. In the event of a personal-data breach that is reasonably likely to result in risk to affected individuals, we will notify affected clients and, where required, regulatory authorities within the timeframes mandated by applicable law (e.g., 72 hours under UK GDPR; “without unreasonable delay” under PIPEDA where the breach poses real risk of significant harm; without unreasonable delay under applicable US state breach-notification statutes).
7. Data Retention
- Active client data: retained for the duration of the engagement plus a default 24 months for trend analysis and historical reporting, unless a shorter period is contractually agreed.
- Crawl artifacts & technical scan data: retained up to 12 months by default.
- Billing & tax records: retained for at least 7 years in accordance with applicable US, Canadian, and UK tax and accounting requirements (e.g., IRS guidance, CRA 6-year minimum, HMRC 6-year minimum).
- Marketing-list data: retained until the data subject unsubscribes or requests deletion, plus a short period required to honor suppression lists (which we are legally required to maintain).
- Upon termination of services, you may request export and deletion of your data; see Section 8.
8. Your Rights
8.1 United States — California (CCPA / CPRA)
California residents have the rights to: (a) know what personal information we collect, use, disclose, and retain; (b) delete personal information; (c) correct inaccurate personal information; (d) opt out of the “sale” or “sharing” of personal information (we do not sell or share as those terms are defined); (e) limit the use and disclosure of sensitive personal information; and (f) non-discrimination for exercising these rights. You may designate an authorized agent to act on your behalf.
8.2 United States — Other States
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy statutes have rights of access, correction, deletion, portability, and opt-out of targeted advertising or profiling, as provided by the applicable state law. We honor universal opt-out signals (e.g., Global Privacy Control) where required.
8.3 Canada (PIPEDA & provincial privacy laws)
Canadian residents have the rights, under PIPEDA and applicable provincial laws (including Quebec’s Law 25, Alberta PIPA, and BC PIPA), to: (a) access personal information we hold about them; (b) request correction of inaccurate information; (c) withdraw consent (subject to legal or contractual restrictions); and (d) file a complaint with the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner.
8.4 United Kingdom (UK GDPR & Data Protection Act 2018)
UK residents have the rights of access, rectification, erasure (“right to be forgotten”), restriction, data portability, and objection, as well as the right to withdraw consent and to lodge a complaint with the UK Information Commissioner’s Office (ICO).
8.5 How to exercise your rights
Send a written request to itsupport@OmniChannelsol.com. We will verify your identity (to prevent unauthorized disclosure) and respond within the period required by applicable law (typically 30–45 days, extendable where permitted). We will not discriminate against you for exercising any privacy right.
9. International Data Transfers
Omni-Channel uses subprocessors located in the United States, the European Union, the United Kingdom, and other regions. Where personal data is transferred across borders, we rely on appropriate safeguards such as:
- The UK International Data Transfer Addendum and, where applicable, the EU Standard Contractual Clauses (SCCs) for transfers from the UK or EU to other countries.
- The EU-US Data Privacy Framework and the UK extension to it, where our US subprocessors are certified.
- Adequacy decisions issued by the UK ICO or European Commission where applicable.
- For Canadian data, contractual safeguards consistent with PIPEDA’s “comparable level of protection” standard.
- Your explicit consent, in those instances when it is required.
10. Marketing Emails & Anti-Spam Compliance
When we send marketing emails — either to our own prospects or on behalf of clients we are contracted to support — we comply with applicable anti-spam laws, including:
- US CAN-SPAM Act (15 U.S.C. § 7701 et seq.): truthful headers and “From” lines; non-deceptive subject lines; clear identification as an advertisement; a valid physical postal address; a clear, working unsubscribe mechanism honored within 10 business days.
- Canada’s Anti-Spam Legislation (CASL): express or implied consent before sending commercial electronic messages, sender identification, and a clearly visible unsubscribe mechanism that is honored within 10 business days.
- UK Privacy and Electronic Communications Regulations (PECR) and UK GDPR: lawful basis (typically consent, or the “soft opt-in” for existing customers in B2C contexts), prominent unsubscribe in every message, and respect for objections to direct marketing.
- Telephone Consumer Protection Act (TCPA) compliance for any SMS or call-based campaigns we operate on behalf of US clients.
You may unsubscribe from any of our marketing communications at any time by clicking the unsubscribe link in any email or by contacting itsupport@OmniChannelsol.com. Transactional and service-related communications (e.g., billing, security alerts, account notices) are not subject to unsubscribe and will continue while your account is active.
11. HIPAA (Limited Applicability)
Omni-Channel’s standard Services are not designed to receive, store, or process Protected Health Information (PHI) as defined under the US Health Insurance Portability and Accountability Act (HIPAA). Clients should not transmit PHI to us through standard channels.
Where a client is a HIPAA Covered Entity or Business Associate and requires HIPAA-regulated services, Omni-Channel may, on a case-by-case basis, execute a Business Associate Agreement (BAA) and provision a HIPAA-aligned environment. Until a BAA is executed and a HIPAA environment is provisioned, we cannot accept PHI, and any PHI inadvertently submitted will be deleted upon discovery.
12. Cookies & Tracking
Our website and platform use first-party cookies and similar technologies for authentication, session management, security, and analytics. Where required by law (notably under the UK PECR and applicable US state laws), we present a cookie banner that lets you accept, reject, or granularly manage non-essential cookies. We honor Global Privacy Control (GPC) signals where applicable. You may also control cookies through your browser settings.
13. Children’s Privacy
Our Services are intended for businesses and adult professionals. We do not knowingly collect personal information from children under 13 in the United States (per the Children’s Online Privacy Protection Act, COPPA), under 13 in Canada, or under 13 in the United Kingdom (with parental consent considerations up to age 16 under UK GDPR). If you believe we have inadvertently collected information from a minor, please contact us so we can delete it.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the “Last updated” date and, where appropriate, by direct notice (email or in-platform). Continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
Part II — Terms and Conditions
1. Acceptance of Terms
These Terms and Conditions (“Terms“) govern your access to and use of the Services provided by Omni-Channel Solutions. By signing a Statement of Work (SOW), Master Services Agreement (MSA), order form, or by accessing or using any Service, you (“Client” or “you“) agree to be bound by these Terms. If you are accepting on behalf of a company or other legal entity, this will be interpreted as you representing that you have authority to bind that entity.
2. Definitions
- “Client Data” — data, content, and materials submitted to or generated by the Services on Client’s behalf, including data collected from Client’s authorized properties.
- “Deliverables” — reports, dashboards, analyses, audits, scripts, and other tangible outputs produced for Client under an SOW.
- “Platform” — the Omni 360 suite, including OmniSpark, OmniFlare, OmniCrawl, OmniDash, and any successor or related tools.
- “SOW” — a Statement of Work, order form, or proposal mutually executed by the parties describing specific services, fees, and timelines.
3. Services Description
Omni-Channel provides AI visibility scoring, search/answer-engine optimization, web crawling, prompt and competitive research, marketing analytics, lead generation, email validation and outreach support, dashboards, and related advisory services to clients in the United States, Canada, and the United Kingdom. Specific deliverables, scope, fees, and timelines are defined in each SOW.
4. Client Authorization to Scan and Analyze
By engaging the Services, Client represents and warrants that:
- Client owns, controls, or has the necessary rights and permissions to authorize Omni-Channel to crawl, scan, query, and analyze each digital property submitted for analysis (including websites, sitemaps, APIs, analytics accounts, and ad accounts).
- Client has obtained all necessary consents from data subjects whose personal data may be present in materials shared with Omni-Channel, and has informed those data subjects in accordance with applicable law.
- Client will not submit, upload, or expose to the Services any data classified as Protected Health Information (PHI) under HIPAA, payment card numbers (PAN) outside of approved PCI flows, or other regulated data, unless a separate written agreement (e.g., a BAA) is in place.
- Client’s instructions to Omni-Channel — including third-party properties Client wishes us to analyze for competitive benchmarking — comply with all applicable laws, including the US Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act 1990, the Canadian Criminal Code provisions on unauthorized computer access, and all other applicable laws.
Omni-Channel reserves the right to refuse, pause, or limit any scan that it reasonably believes may violate law, third-party terms of service, or robots.txt restrictions that we are not authorized to bypass.
5. Acceptable Use
Client shall not, and shall not permit any third party to:
- Use the Services for any unlawful, fraudulent, deceptive, or harmful purpose.
- Use the Services to harass, defame, or violate the privacy of any individual.
- Send spam or unlawful marketing communications, or use email lists obtained without lawful basis.
- Attempt to gain unauthorized access to the Platform, other clients’ data, or any underlying systems.
- Reverse-engineer, decompile, or attempt to extract the source code of the Platform, except to the limited extent permitted by mandatory law.
- Resell, sublicense, or white-label the Services without prior written consent.
- Introduce malware, viruses, or any code intended to harm or disrupt the Platform or third-party systems.
6. Intellectual Property
Omni-Channel IP. The Platform, the Omni 360 scoring framework, the 485-metric library, OmniBot, source code, methodologies, software, and all related intellectual property are and remain the exclusive property of Omni-Channel.
Client IP. Client retains all rights in Client Data and pre-existing materials Client provides.
Deliverables. Subject to full payment of fees, Omni-Channel grants Client a perpetual, worldwide, non-exclusive, non-transferable license to use the Deliverables for Client’s internal business purposes. Omni-Channel retains ownership of underlying methodologies, templates, know-how, and any tools embedded in or used to generate the Deliverables.
Aggregated & de-identified data. Omni-Channel may use aggregated, de-identified data derived from the Services to improve the Platform, build benchmarks, and conduct research, provided that such data does not identify Client or any individual.
7. Confidentiality
Each party agrees to protect the Confidential Information of the other using at least the same degree of care it uses to protect its own confidential information of like kind, but no less than a reasonable standard of care. Confidential Information may be used only to perform under these Terms and disclosed only to personnel and subprocessors with a need to know who are bound by confidentiality obligations no less protective than those herein. Confidentiality obligations survive termination for five (5) years, except that trade secrets remain protected for as long as they qualify as trade secrets under applicable law.
8. Fees, Payment & Refunds
- Fees are set forth in the applicable SOW or order form, exclusive of sales tax, GST/HST, VAT, withholding tax, or other taxes, which are Client’s responsibility (except for taxes on Omni-Channel’s net income).
- Invoices are payable within 15 days of issuance unless otherwise stated. Late amounts accrue interest at 1.5% per month or the maximum permitted by law, whichever is lower.
- All fees are stated in US Dollars (USD) unless otherwise specified in the SOW.
- Setup fees and one-time fees are non-refundable. Subscription fees, where prepaid, are non-refundable except as required by law or as expressly agreed in an SOW.
- Omni-Channel may suspend Services for non-payment after written notice and a 10-day cure period.
9. Warranties & Disclaimers
Omni-Channel warrants that it will perform the Services in a professional and workmanlike manner consistent with industry standards and the applicable SOW.
EXCEPT AS EXPRESSLY SET FORTH IN THESE TERMS, THE SERVICES AND DELIVERABLES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” OMNI-CHANNEL SOLUTIONS DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ACCURACY OF AI-GENERATED OUTPUTS.
Omni-Channel does not guarantee specific search rankings, AI-citation outcomes, traffic levels, conversion rates, or revenue. Outputs that rely on third-party APIs (including LLM providers) are inherently probabilistic and may contain errors or hallucinations; Client is responsible for reviewing outputs before relying on them for material business decisions.
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL OMNI-CHANNEL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, DATA, OR BUSINESS OPPORTUNITIES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
OMNI-CHANNEL’S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED THE FEES PAID BY CLIENT TO OMNI-CHANNEL UNDER THE APPLICABLE SOW IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
The limitations in this section do not apply to: (a) Client’s payment obligations; (b) either party’s indemnification obligations; (c) breach of confidentiality; (d) gross negligence or willful misconduct; or (e) liabilities that cannot be excluded under applicable law (note that some jurisdictions, including certain US states and the UK, do not allow exclusion of certain warranties or liabilities).
11. Indemnification
By Client. Client will defend, indemnify, and hold harmless Omni-Channel from claims, damages, and costs arising out of (a) Client’s breach of these Terms, (b) Client Data, (c) Client’s lack of authorization to scan or analyze any property, or (d) Client’s violation of applicable law.
By Omni-Channel. Omni-Channel will defend, indemnify, and hold harmless Client from third-party claims that the Platform, as provided by Omni-Channel and used in accordance with these Terms, infringes a valid intellectual property right, subject to the limitations of liability above.
12. Term & Termination
- These Terms remain in effect while any SOW is active and until all obligations are satisfied.
- Either party may terminate for material breach with 30 days’ written notice if the breach is not cured within that period.
- Either party may terminate immediately for the other party’s insolvency, bankruptcy, or assignment for the benefit of creditors.
- Upon termination, Client will pay all undisputed fees through the effective termination date. Within 30 days of termination, Omni-Channel will, on request, return or delete Client Data, subject to backup-cycle and legal-retention exceptions.
- Sections that by their nature should survive (including IP, Confidentiality, Disclaimers, Limitation of Liability, Indemnification, Governing Law) survive termination.
13. Governing Law & Dispute Resolution
These Terms are governed by the laws of the State of Delaware, United States of America, without regard to conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
The parties will first attempt to resolve any dispute through good-faith negotiation for at least 30 days. Disputes that cannot be resolved through negotiation will be finally settled by binding arbitration administered by JAMS under its Comprehensive Arbitration Rules and Procedures, before a single arbitrator, with the seat of arbitration in [Wilmington, Delaware / New York, NY — choose one]. The arbitration will be conducted in English. Judgment on the award may be entered in any court of competent jurisdiction. Either party may seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property or confidential information.
Jurisdictional alternatives. Where Client is incorporated in Canada or the United Kingdom, the parties may agree in an SOW to alternative governing law and dispute-resolution terms (for example, the laws of England and Wales with arbitration in London under LCIA Rules; or the laws of the Province of Ontario with arbitration in Toronto under ADRIC Rules). Any such alternative must be set out in writing in the SOW.
Class-action waiver (US clients). To the extent permitted by law, the parties agree that any arbitration or claim will be conducted on an individual basis and not as part of a class, consolidated, or representative action.
14. Miscellaneous
- Entire agreement. These Terms, together with the Privacy Policy and any executed SOW or MSA, constitute the entire agreement between the parties and supersede all prior agreements on the subject matter.
- Order of precedence. In the event of conflict: (1) executed MSA, (2) executed SOW, (3) these Terms, (4) Privacy Policy.
- Assignment. Neither party may assign these Terms without the other’s prior written consent, except in connection with a merger, acquisition, or sale of substantially all assets.
- Force majeure. Neither party is liable for failures caused by events beyond reasonable control, including natural disasters, war, terrorism, civil unrest, government action, internet or power outages, or pandemics.
- Independent contractors. The parties are independent contractors. Nothing creates an agency, partnership, joint venture, or employment relationship.
- Severability. If any provision is held unenforceable, the remaining provisions remain in full force and effect.
- No waiver. Failure to enforce any provision is not a waiver of future enforcement.
- Notices. Notices must be in writing and sent to
itsupport@OmniChannelsol.com(for Omni-Channel) or to the email on file (for Client). - Export controls & sanctions. Client agrees to comply with all applicable US, UK, and Canadian export-control and sanctions laws, including the US Export Administration Regulations (EAR) and OFAC sanctions programs.
15. Contact Us
For privacy questions, data-subject requests, security concerns, or questions about these Terms, contact:
