Legal

Privacy Policy

Last updated: 1 August 2026

1. Who we are

Omniron AI Limited (“Omniron AI”, “we”, “us” or “our”) provides compliance automation software that helps UK insurance brokers meet their FCA Consumer Duty obligations. We are the data controller responsible for your personal data for the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

Omniron AI Limited

Level 30, The Leadenhall Building
122 Leadenhall Street
London EC3V 4AB

Email: m.saed@omniron.co.uk

2. What data we collect

We collect and process the following categories of personal data:

  • Account and contact data — names, business email addresses, telephone numbers, job titles, and the name of your firm when you register for, or enquire about, our services.
  • Client interaction data — the content and metadata of emails within the designated inbox you connect, which may include personal data relating to your clients, and in some cases special category data or information about vulnerable customers.
  • Usage and technical data — IP address, device and browser information, log data, and how you interact with our platform.
  • Communications data — records of correspondence when you contact us for support or sales enquiries.

3. How we use your data and our lawful basis

We only use your personal data when the law allows us to. The lawful bases we rely on under the UK GDPR are:

  • Contract — to provide, operate, and support our services, including reading and categorising client emails against the four FCA Consumer Duty outcomes and flagging complaints and vulnerable customers.
  • Legitimate interests — to improve and secure our platform, prevent fraud and misuse, and communicate with you about your account, provided your interests and rights do not override ours.
  • Legal obligation — to comply with our regulatory, accounting, and legal requirements.
  • Consent — where required, for example for certain marketing communications, which you may withdraw at any time.

Where we process client interaction data on your behalf as part of delivering the service, we act as a data processor and you remain the data controller for that data. This processing is governed by a separate data processing agreement.

4. Who we share it with

We do not sell your personal data. We share it only with:

  • Service providers — trusted sub-processors who host our infrastructure, provide analytics, and support our platform, all bound by contractual confidentiality and data protection obligations.
  • Professional advisers and authorities — where required to comply with the law, respond to lawful requests, or protect our legal rights.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to appropriate safeguards.

Where any personal data is transferred outside the UK, we ensure appropriate safeguards are in place, such as the UK International Data Transfer Agreement or addendum to the EU Standard Contractual Clauses.

5. How long we keep it

We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, regulatory, accounting, or reporting requirements. Client interaction data is retained for the duration of your agreement with us and deleted or returned in accordance with that agreement. Account and contact data is generally retained for up to six years after your relationship with us ends, reflecting statutory limitation periods. When data is no longer required, we securely delete or anonymise it.

6. Your rights under UK GDPR

Subject to certain conditions, you have the following rights in relation to your personal data:

  • the right to be informed about how your data is used;
  • the right of access to a copy of your personal data;
  • the right to rectification of inaccurate or incomplete data;
  • the right to erasure (the “right to be forgotten”);
  • the right to restrict processing;
  • the right to data portability;
  • the right to object to processing based on legitimate interests or direct marketing;
  • rights relating to automated decision-making and profiling.

To exercise any of these rights, please contact us at m.saed@omniron.co.uk. We will respond within one month. You will not usually have to pay a fee.

7. Complaints

We would prefer the opportunity to address your concerns before you approach the regulator, so please contact us in the first instance. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection, at ico.org.uk.

8. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify you by email.

Built with v0