Introduction

365 Omni ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered omnichannel customer communication platform (the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

This Privacy Policy applies to all users of the platform, including businesses, agents, and end customers who communicate through our platform.

Information We Collect

We collect information to provide and improve our Service. The types of information we collect depend on how you use the platform and which channels you integrate.

Account Information

When you create an account, we collect your name, email address, company name, phone number, and billing information. This information is necessary to establish and maintain your workspace.

Facebook Login and Meta Platform Data

When you connect Facebook Login or Meta Platform services (including Facebook Pages, Facebook Messenger, and Facebook Comments), we collect:

  • Your Facebook Page ID, name, and access tokens
  • Conversation metadata and message content from customers who message your Page
  • Page insights and engagement data necessary for analytics
  • Public profile information associated with the connected Facebook account

We only access the minimum data required to provide the Service, as authorized by you through Meta's permission system.

Messenger API Data

Through the Facebook Messenger API integration, we collect:

  • Message content, attachments, and media exchanged between your business and customers
  • Messenger conversation IDs and timestamps
  • Sender PSID (Page-Scoped ID) for message routing
  • Message delivery and read receipts

Instagram Graph API Data

Through Instagram integration (Direct Messages and Comments), we collect:

  • Instagram Business Account ID and username
  • Direct message conversations, including text, images, videos, and story replies
  • Comment content and metadata from your Instagram posts
  • Customer Instagram user IDs for conversation management

WhatsApp Business API Data

Through WhatsApp Business API integration, we collect:

  • WhatsApp Business Account information and phone number
  • Message content, including text, images, documents, and audio messages
  • Customer phone numbers and WhatsApp IDs
  • Message status updates (sent, delivered, read, failed)
  • Template message usage and quality metrics

LinkedIn API Data

Through LinkedIn API integration, we collect:

  • LinkedIn Company Page ID and name
  • LinkedIn message conversations and content
  • Connection metadata for conversation routing

X (Twitter) API Data

Through X (Twitter) API integration, we collect:

  • Twitter account information and user ID
  • Direct message conversations and content
  • Mention and reply data from your Twitter profile
  • Engagement metrics for analytics purposes

Communication Data

All messages, attachments, files, images, and other content sent through the platform are stored to provide the Service. This includes:

  • Conversation history across all connected channels
  • Internal notes and agent annotations
  • Customer profiles and interaction history
  • Automation logs and AI-generated responses

Usage and Analytics Data

We automatically collect information about how you use the Service, including:

  • Login timestamps and session duration
  • Features used and interaction patterns
  • Response times, conversation volumes, and resolution rates
  • Device information, browser type, and operating system
  • IP address and approximate geographic location

How We Use Your Information

We use the collected information for the following purposes:

  • Providing the Service: To route messages, display conversations, deliver notifications, and enable team collaboration.
  • AI Features: To power AI auto-reply, sentiment analysis, language detection, and smart suggestions. AI processing occurs within our secure infrastructure.
  • Analytics: To generate reports on team performance, response times, conversation volumes, and customer satisfaction metrics.
  • Improving the Service: To analyze usage patterns, identify bugs, and develop new features.
  • Communication: To send product updates, billing information, security alerts, and support communications.
  • Compliance: To meet legal obligations, enforce our Terms of Service, and protect the rights and safety of our users.

Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • With Your Consent: We share information when you explicitly authorize us to do so.
  • Service Providers: We engage third-party vendors to host infrastructure, process payments, provide analytics, and deliver emails. These providers are contractually bound to protect your data.
  • Channel Providers: When you connect a channel (e.g., WhatsApp, Messenger), we exchange data with the respective platform provider as necessary to deliver messages. This data handling is governed by the provider's terms.
  • Legal Requirements: We may disclose information if required by law, court order, or governmental regulation, or to protect our rights, property, or safety.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction.

Data Security

We implement comprehensive security measures to protect your data:

  • Encryption in Transit: All data transmitted to and from our platform is encrypted using TLS 1.3.
  • Encryption at Rest: Data stored on our servers is encrypted using AES-256 encryption.
  • Access Controls: Role-based access control ensures only authorized team members can access sensitive data.
  • Audit Logging: All access to customer data is logged and monitored for suspicious activity.
  • Security Audits: We conduct regular SOC 2 Type II audits and penetration testing.
  • Incident Response: We maintain a documented security incident response plan and notify affected users promptly in the event of a breach.

Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Specifically:

  • Account Data: Retained until account deletion. Upon deletion, we delete or anonymize your data within 30 days, except where legal retention requirements apply.
  • Conversation Data: Retained for the duration of your subscription plus 90 days. You can export or delete conversation data at any time.
  • Backup Data: Retained in encrypted backups for up to 90 days before being purged.
  • Analytics Data: Aggregated, de-identified analytics data may be retained indefinitely for business intelligence purposes.
  • Legal Holds: Data subject to legal holds may be retained until the hold is lifted.

Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data, subject to certain exceptions.
  • Right to Restrict Processing: Request limitation of how we use your data.
  • Right to Data Portability: Request a copy of your data in a structured, machine-readable format.
  • Right to Object: Object to the processing of your data for direct marketing or legitimate interests.
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at privacy@365omni.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.

California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights:

  • Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: Request deletion of personal information we have collected, subject to certain exceptions.
  • Right to Opt-Out: We do not sell your personal information. If this practice changes, we will provide notice and the ability to opt out.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To exercise your CCPA rights, contact us at privacy@365omni.com. We will verify your identity before processing your request.

Children's Privacy

Our Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child under 16 has provided us with personal information, we will take steps to delete such information promptly.

If you believe a child has provided us with personal information, please contact us at privacy@365omni.com immediately.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure adequate protection for cross-border data transfers through:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved SCCs for transfers from the EEA and UK.
  • Data Processing Agreements (DPAs): We enter into DPAs with all sub-processors to ensure data protection obligations are contractually enforced.
  • Data Centers: Our infrastructure is hosted in SOC 2-certified data centers located in the United States and Europe. Enterprise customers can request data residency in specific regions.

Cookies and Analytics

We use cookies and similar tracking technologies to collect usage data and improve the Service. For detailed information about the cookies we use and your choices, please see our Cookie Policy.

We use analytics services (including Google Analytics) to understand how the Service is used. These services collect information such as page visits, feature usage, and error reports. You can opt out of Google Analytics by installing the Google Analytics opt-out browser add-on.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and, where appropriate, via email. The "Last Updated" date at the top of this policy indicates when it was last revised.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

For GDPR-related inquiries, you may contact our EU representative at eu-rep@365omni.com.

We will acknowledge your request within 5 business days and respond within 30 days.