Legal

Privacy Policy

What personal data Omnified collects, why, who it is shared with, how long it is kept and your rights under India's Digital Personal Data Protection Act, 2023.

Effective 6 October 2026 · Last updated 6 October 2026

This policy explains what personal data Omnified collects, why, who it is shared with, how long it is kept and the rights you have over it. It is written for India first: the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the rules made under it, and the Information Technology Act, 2000 with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the SPDI Rules) to the extent they still apply.

1. Who we are

Omnified is operated by ZERONOMY SUSTAINABLITY PRIVATE LIMITED (“Omnified”, “we”, “us”). Our registered office and corporate identity number are on the Company information page. This policy covers our website, our web application, our APIs and our AI-agent (MCP) interface (together, the Services).

2. Our two roles: Data Fiduciary and Data Processor

We handle personal data in two different capacities, and your rights depend on which.

As a Data Fiduciary

We decide why and how we process the personal data of people who visit our website, sign up, use the Services on behalf of their organisation, buy a subscription, or write to us. For this data we are the Data Fiduciary under the DPDP Act and this policy applies in full.

As a Data Processor for our customers

Our customers are mostly regulated businesses (banks, fund managers, payment companies, fintechs and others) that use Omnified to verify their own clients (KYC/KYB), run their compliance programme and keep their policies. When a customer sends us personal data about its clients, staff or counterparties (for example identity documents submitted for verification) the customer is the Data Fiduciary and we process that data only on its instructions, under our contract with it (Customer Data).

If you are one of our customer’s clients or staff and want to access, correct or erase your data, or withdraw consent, please contact that business directly: it decides what happens to your data. If you write to us instead, we will pass your request to the customer concerned and tell you we have done so.

3. Personal data we collect as a Data Fiduciary

  • Account data: your name, work e-mail address, password (stored only as a salted hash by our authentication provider), your organisation, your role and invitations you send or accept.
  • Billing data: billing name, e-mail, phone number and address, GSTIN, invoices, and the record of each payment (order and payment references, amount, payment method and a masked card or UPI reference). Card, UPI and bank details are entered on Razorpay’s checkout and never reach our systems.
  • Content you give the Services: questions you ask the regulatory rulebook and research workspace, documents you upload, policies and drafts you write, acknowledgements, comments and approvals.
  • Usage data: which features you use and when, credits consumed, sign-up and onboarding steps, and an audit trail of significant actions in your organisation’s workspace.
  • Enquiries: the name, e-mail address, company and message you send through our contact form or by e-mail, and our replies.
  • Technical data: IP address, the approximate country derived from it (used to suggest your currency and region), browser and device information, and security and error logs.
  • Cookies and similar technologies: see section 13 and our Cookie Policy.

4. Customer Data we process as a Data Processor

Depending on what a customer configures, Customer Data can include its clients’ and counterparties’ names, dates of birth, addresses, nationality, government identification numbers, images of identity and address documents, photographs and liveness or face-match results produced by the verification provider the customer selects, screening and risk results, case notes and decisions, and details of company directors, shareholders and beneficial owners. It can also include the names and e-mail addresses of a customer’s staff who acknowledge its policies.

Some of this is sensitive personal data or information under the SPDI Rules, such as financial information and biometric information. We process it only to provide the Services the customer has asked for, with the safeguards in section 10. The customer is responsible for giving its clients notice, obtaining any consent required (including for Aadhaar-based verification under the Aadhaar Act, 2016), and for keeping records as the Prevention of Money-laundering Act, 2002 and its sector regulator require.

5. Why we use personal data, and on what basis

We process personal data only for a lawful purpose and on one of the grounds the DPDP Act allows: your consent (section 6), or a legitimate use (section 7), for example where you have voluntarily given us data for a specified purpose and not objected, or where the law requires us to process it.

  • to create and secure your account and let your organisation manage its users;
  • to provide the Services you use, including AI-generated answers and drafts;
  • to bill you, issue GST tax invoices, collect payments and keep accounting records;
  • to send service messages (sign-up confirmation, password reset, invitations, invoices, policy acknowledgement requests and security notices);
  • to answer enquiries and provide support;
  • to keep the Services secure, prevent fraud and abuse, and investigate incidents;
  • to understand, in aggregate, how the Services are used so we can improve them;
  • to comply with law, respond to lawful requests from authorities, and establish or defend legal claims.

We do not sell personal data, and we do not use Customer Data to train generative AI models.

7. Who we share personal data with

We share personal data only with service providers that process it for us under written contracts requiring confidentiality and security (our sub-processors), and only as much as each needs. The categories are:

  • Database, authentication and file storage (Supabase), hosted in the data region of the customer’s organisation;
  • Application hosting, content delivery and network security (Cloudflare);
  • AI model providers that generate answers and drafts, read and extract text from documents, and rank search results (Anthropic, Cohere), and a search-embedding provider (Voyage AI);
  • AI document reading of KYC documents (Anthropic, in the United States): when a customer uploads an identity document (an image or PDF) in our KYC console, we send it to Anthropic to read the text and extract the person’s details, such as name, date of birth and ID number. This is Customer Data, processed on the customer’s instructions. Each customer organisation can switch AI document reading off in its KYC settings; its documents are then not sent to Anthropic or any other AI provider, stay in the organisation’s data region, and are keyed by hand by the customer’s reviewers. Public regulatory documents (laws, rules and regulators’ notices) that we read to build our rulebooks are not personal data and are read by AI regardless of this setting;
  • AI reading of uploaded policy documents (Anthropic and Voyage AI, in the United States): when a customer uploads a policy or procedure to our Policy Register, we send it to Anthropic to extract its text and the text to Voyage AI to index it for search and coverage checks. This is Customer Data, processed on the customer’s instructions; it may contain personal data, such as the names of policy owners or staff. Each customer organisation can switch AI reading of uploaded policies off in its Policy Register settings; its uploads are then not sent to Anthropic, Voyage AI or any other AI provider, stay in the organisation’s data region, and are stored without their sections being parsed or their coverage checked;
  • Identity-verification providers that a customer’s verification routing selects (for example Sumsub), for Customer Data only;
  • Payments (Razorpay), for billing data;
  • Transactional e-mail (Resend);
  • Website analytics (Google Analytics), on our public website pages only;
  • Web fonts (Google Fonts): our pages load fonts from Google’s servers, so Google receives your IP address and browser details when a page loads.

A current list of sub-processors is available on request from hello@getomnified.com. We may also disclose personal data when the law requires it (for example to a court, a regulator, or a law-enforcement agency acting under a lawful order), to protect the rights, property or safety of our users or the public, or to a successor business in a merger or acquisition, which will be bound by this policy.

8. Where data is stored and cross-border transfers

Omnified runs in regional data cells: each cell has its own database and file storage in its region, and a customer’s organisation lives in one cell. Some of the sub-processors above are based outside India (several in the United States) and process data there when they perform their service, for example when a question or a document is sent to an AI model. In particular, identity documents uploaded to our KYC console are sent to Anthropic in the United States for AI document reading, and policy documents uploaded to our Policy Register are sent to Anthropic and Voyage AI in the United States for AI reading, unless the customer has switched these off (section 7). Section 16 of the DPDP Act permits transfers outside India except to countries the Central Government restricts by notification; we do not transfer personal data to a restricted country, and we require the same protection of our sub-processors wherever they are. Where a customer’s sector regulator requires data to stay in India, the customer can tell us and we will agree the configuration with it in writing.

9. How long we keep personal data

  • Account data: while your account is active, and then for as long as needed to close it, settle any dispute and meet legal obligations.
  • Billing and tax records: for the period company and tax law require (the Companies Act, 2013 and the GST laws currently require up to eight years).
  • Audit trail: at least five years, because our customers rely on it to evidence their own compliance, including record-keeping under the Prevention of Money-laundering Act, 2002.
  • Security and access logs: for the periods required by applicable law.
  • Enquiries: as long as needed to respond and follow up.
  • Customer Data: as the customer instructs under its contract. After the contract ends, on the customer’s written request we provide an export of its Customer Data and then delete or anonymise it within 30 days of the request, unless the law requires it to be kept.

If you ask us to erase your personal data (see section 11), or you withdraw consent and no other ground for keeping it applies, we will erase it or irreversibly anonymise it within 30 days of your verified request, except what the law requires us to keep. We require our processors to protect the data they process for us and to delete it when it is no longer needed for our instructions.

10. Security safeguards

We protect personal data with reasonable security safeguards, as section 8(5) of the DPDP Act and section 43A of the IT Act require, under a documented information-security programme that includes:

  • encryption in transit (TLS) and at rest;
  • separation of every customer’s data by row-level security in the database, and role-based access inside each organisation;
  • API keys stored only as hashes, platform administration limited to named administrators, and two-person (maker-checker) approval for high-risk decisions in the product;
  • a tamper-evident (hash-chained) audit log of significant actions;
  • logs of access and errors, used to investigate suspected unauthorised access;
  • due diligence on sub-processors and contracts that bind them to equivalent safeguards.

Personal data breaches

If a personal data breach affects data for which we are the Data Fiduciary, we will inform the Data Protection Board of India and each affected person without delay, as the DPDP Act and Rules require, describing what happened, the likely consequences, what we are doing about it and what you can do to protect yourself, and will follow up with the Board within 72 hours. If a breach affects Customer Data, we inform the customer without undue delay so it can meet its own obligations.

11. Your rights

For personal data we hold as a Data Fiduciary you have the right, under sections 11 to 14 of the DPDP Act, to:

  • access a summary of your personal data and the processing we carry out, and the identities of the Data Fiduciaries and Data Processors we have shared it with;
  • correction, completion and updating of inaccurate or incomplete data;
  • erasure of data that is no longer needed for the purpose it was collected for, unless the law requires us to keep it;
  • grievance redressal, through the process on our Grievance Redressal page;
  • nominate another person to exercise these rights on your behalf in the event of your death or incapacity.

To exercise a right, write to hello@getomnified.com from the e-mail address on your account, or tell us how we can verify your identity. We will respond within the period the DPDP Rules set, and aim to do so within 15 days. You also have duties under section 15 of the DPDP Act, including not to impersonate another person, not to suppress material information when providing data for an identity document, and not to register a false or frivolous grievance.

12. Children and persons with disability

The Services are for businesses and are not directed at children (under 18). We do not knowingly process a child’s personal data as a Data Fiduciary. If we need to, we will first obtain verifiable consent from the child’s parent or lawful guardian as section 9 of the DPDP Act and the DPDP Rules require, and we will not track, monitor the behaviour of, or target advertising at children. The same applies to the lawful guardian of a person with a disability. If you believe we hold a child’s data without such consent, write to hello@getomnified.com and we will delete it. Where Customer Data concerns a minor (for example a minor’s bank account opened by a guardian), the customer is responsible for obtaining verifiable parental consent.

13. Cookies

We use a small number of cookies and browser-storage entries to keep you signed in, remember your preferences and protect the site. On our public website pages only (not in the signed-in application, and not on sign-in, invitation or inspector links) we also measure use with Google Analytics, which currently loads without asking for your consent first. Our Cookie Policy lists them, covers the fonts we load from Google, and explains how to control them.

14. The Data Protection Board of India

If you are not satisfied with how we have handled your grievance, you may complain to the Data Protection Board of India under section 13(3) of the DPDP Act, after first using our grievance redressal process.

15. Contact and grievance officer

Privacy questions and requests: hello@getomnified.com. Our Grievance Officer is Shubham Khandelwal, Grievance Officer & Data Protection Officer, reachable at hello@getomnified.com. Full contact details, postal address and response times are on our Grievance Redressal page.

We are not currently notified as a Significant Data Fiduciary and so do not have a statutory Data Protection Officer. The privacy contact above answers, on our behalf, questions about the processing of your personal data, as section 8(9) of the DPDP Act requires.

16. Changes to this policy

We will update this policy when our processing or the law changes. The date at the top shows when it last changed. If a change is material we will tell account holders by e-mail or in the product before it takes effect and, where the change needs your consent, ask for it again.