In short
This policy covers the website and your Omega Work account. It does not cover the data you put inside your workspaces: that data is yours, you decide about it, and we process it only on your instructions — see the Data Processing Agreement.
- Your data is stored on servers of IONOS SE in Germany, in the European Union. Only subscription payment data handled by Stripe may also be processed in the United States (see section 6).
- We use no advertising or profiling cookies, no third-party analytics, and we do not sell or rent personal data to anyone.
- Every workspace lives in its own separate database: there is no shared table containing all customers’ data.
- You can ask us at any time to see, correct or delete your data by writing to amministrazione@outlinedigital.it.
1. Who is responsible for your data
The controller is OutLine Digital Agency, which provides the service under the brand Omega Work.
- Controller
- OutLine Digital Agency (sole trader), Via Dalmazia 36, 76125 Trani (BT), Italy — VAT IT08978680729
- Registered office
- Via Dalmazia 36, 76125 Trani (BT), Italy
- Privacy contact
- amministrazione@outlinedigital.it
- General contact
- amministrazione@outlinedigital.it · +39 327 609 2869
- Data protection officer
- Not appointed. The conditions of GDPR art. 37 are not met: processing personal data is not our core activity, it is not carried out on a large scale and it does not involve regular and systematic monitoring of individuals. Privacy requests go to the contact above.
- Representatives
- We are established in the European Union, so we need no representative there. We have not appointed a representative in the United Kingdom (UK GDPR art. 27). We have not appointed a representative in Switzerland: the conditions of art. 14 of the Federal Act on Data Protection (large-scale, regular and high-risk processing as a controller) are not met. You can always contact us directly at amministrazione@outlinedigital.it, in English, German or French.
2. Two different roles
We process personal data in two situations that the law keeps separate. Which one applies decides whom you should contact.
- We are the controller when you visit the website, open an account, subscribe, or write to us for support. Here we decide what to collect and why: this is what this policy describes.
- We are a processor (or service provider) when a business uses Omega Work for its own work, colleagues, customers or suppliers. There the business is the controller, not us: we provide the software and process that data only to run it, following the business’s instructions. If you are a member, guest or contact of a business that uses Omega Work, your requests go to that business, which is the only one that can decide about your data.
3. What we collect and why
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| First and last name, email address, password (stored only as a hash, never in readable form), preferred language | Creating your account, signing you in, linking you to your workspaces | Performance of a contract — art. 6(1)(b) | Until the account is deleted — at your request, or together with the workspace — and for no more than 30 days after that |
| Name of the business, country, time zone, answers given during onboarding | Setting up the workspace for your organisation | Performance of a contract — art. 6(1)(b) | As long as the workspace exists |
| IP address, browser type, date and time of access, pages served; the version and platform of the mobile app, if you use it; the IP address from which a password reset is requested | Running the website, protecting it from abuse and intrusion, investigating incidents | Legitimate interest in security — art. 6(1)(f); recital 49 | 12 months |
| Acceptance of terms and policies: document, version, date, IP address, browser | Being able to prove when you accepted what | Legal obligation of accountability — arts. 5(2) and 7(1); performance of a contract | 10 years after the contract ends |
| Billing details: company name, VAT or tax number, address, billing email | Issuing and keeping invoices | Legal obligation — art. 6(1)(c) (tax and accounting law that applies to us) | 10 years |
| Subscription and payment data: plan, amounts, dates and outcome of charges, refunds, type and last four digits of the payment method (never the full number, which only Stripe sees) | Collecting fees, handling renewals, cancellations, the money-back guarantee and refunds, defending ourselves in a dispute | Performance of a contract — art. 6(1)(b); legal obligation — art. 6(1)(c); legitimate interest in defending legal claims — art. 6(1)(f) | 10 years after the contract ends |
| Contract sent as a PDF, its digital fingerprint and the record of sending | Giving you the contract on a durable medium and being able to prove what was agreed | Performance of a contract — art. 6(1)(b); legal obligation — art. 6(1)(c) | 10 years after the contract ends |
| Messages you send us for support and our replies | Answering and keeping track of what was done | Performance of a contract — art. 6(1)(b) | 24 months after the request is closed |
| Requests to delete an account: email address, language, date, confirmation and outcome (no IP address) | Carrying out the request and being able to show that we did | Legal obligation — arts. 12, 17 and 5(2) | 24 months; a request never confirmed, 30 days after its link expires |
| Log of support access to your workspace | Being able to show you who entered, when and for how long | Legitimate interest in accountability; contractual obligation towards you | 24 months |
Where a period in the table has ended, the data is deleted at our next periodic review — which we carry out at least every six months — unless a legal obligation or a pending dispute requires us to keep it longer.
4. When we enter your workspace
To solve a problem, our support may need to see the application as you see it. This access is not a permanent privilege and does not use your credentials:
- it happens only when you ask for help, or when a fault in the service has to be fixed;
- a dedicated temporary access is created inside your workspace and expires on its own after 15 minutes;
- while it lasts it has the permissions of an administrator of the workspace — which is what lets us see the problem as you see it — so the person who uses it looks only at what your request requires;
- every access is recorded and shown to the owner and the administrators of your workspace in Admin console → Privacy and compliance: when it started, how long it lasted, who opened it and why, and how many files were downloaded during it; the owner also receives an email as soon as an access is opened; the full data export is blocked for the whole duration of the access; the log is kept for 24 months.
Anyone who uses this access is bound by a duty of confidentiality.
5. Who we share data with
We do not disclose or transfer data to third parties for their own purposes. Only authorised staff of OutLine Digital Agency, bound by confidentiality, and the providers we need to run the service, engaged as processors, can access it.
The complete and current list of providers that process data contained in your workspaces is on the Sub-processors page.
To collect subscription fees we use Stripe Payments Europe, Limited (Dublin, Ireland), which receives the data needed for payment — name, email, billing address, VAT number and payment-method details — and processes it partly as our processor and partly as an independent controller for its anti-money-laundering, anti-fraud and regulatory obligations, under its own privacy policy (stripe.com/privacy). Service emails — contract, receipts, trial and renewal notices — are sent from our mailbox and relayed by Aruba S.p.A. (Italy).
Together with those details Stripe receives the name of the workspace, the sign-in email address of its owner, the language of the account and our internal reference numbers, so that each payment can be matched to its subscription.
We may also disclose data to courts or regulators where the law requires it. In that case, unless an order forbids it, we tell you.
6. Where your data is stored and international transfers
The infrastructure is entirely in the European Union: servers of IONOS SE in Germany. Our service providers are in Germany, Italy and Ireland. The data in your workspaces and your account is not transferred outside the European Economic Area by us.
The one exception concerns subscription payment data: Stripe may also process it through Stripe, Inc. (United States), which participates in the EU-U.S. Data Privacy Framework, on the basis of the European Commission’s adequacy decision of 10 July 2023 (GDPR art. 45) and, as a fallback, the standard contractual clauses (GDPR art. 46).
Our customers are outside the European Union, so personal data travels from your country to the EU when you use the service, and back to you when you access it. The United Kingdom and Switzerland recognise the EU as providing an adequate level of protection; the European Commission, for its part, has recognised the United Kingdom, Switzerland, New Zealand and — for organisations subject to PIPEDA — Canada. For everyone else we protect the data according to the GDPR, which gives a level of protection at least comparable to that of your local law; where the law requires an instrument for sending an organisation’s data back to it, the Data Processing Agreement provides one. In the countries where your data is processed — Germany, Italy and Ireland and, for payment data, the United States — courts and public authorities can obtain access to it in the cases, and with the safeguards, that their law provides.
7. How we protect it
Technical and organisational measures are described in full on the Security Measures page. In brief: traffic encrypted in transit, passwords stored only as a hash with a strong algorithm, credentials of connected services encrypted at rest, a separate database for each workspace, role-based permissions, logged and time-limited support access, daily backups.
8. Your rights
You can exercise your rights at any time by writing to amministrazione@outlinedigital.it. We reply within one month, which may be extended by two further months for complex requests (GDPR art. 12(3)), free of charge unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.
- Access (art. 15): find out what data we hold and get a copy.
- Rectification (art. 16): have inaccurate or incomplete data corrected.
- Erasure (art. 17): have it deleted, where we are not legally required to keep it.
- Restriction (art. 18): have it frozen instead of deleted, for example while you contest its accuracy.
- Portability (art. 20): receive it in a machine-readable format. The owner and the administrators of a workspace can export all of its data themselves, whenever they like.
- Objection (art. 21): object to processing based on legitimate interest, explaining your situation.
As we are established in Italy, our lead supervisory authority is the Italian Data Protection Authority (Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy — gpdp.it). You can also complain to the authority of your own country, listed in the next section.
If you are unhappy with the way we have handled your data or a request, tell us at amministrazione@outlinedigital.it: we acknowledge every complaint within 30 days, look into it and tell you the outcome.
9. Notes for your country
The GDPR applies to everything we do, wherever you are. The law of your own country may give you further rights: the notes below say what they are, how quickly we answer and where you can complain. They concern the data for which we are the controller (section 3).
- United Kingdom
- The UK GDPR and the Data Protection Act 2018 give you the rights described in section 8; we answer within one month. If you are unhappy with how we have handled your data, complain to us first at amministrazione@outlinedigital.it: we acknowledge a complaint within 30 days, look into it without undue delay and tell you the outcome. You can also complain to the Information Commissioner’s Office (ico.org.uk/make-a-complaint) or go to court. Data sent from the United Kingdom to our servers is covered by the United Kingdom’s adequacy regulations for the European Economic Area.
- Switzerland
- Where the Federal Act on Data Protection (FADP) applies, you have the right to be told which data we hold about you — free of charge and normally within 30 days —, to have it corrected or deleted, to receive the data you gave us in a commonly used electronic format, and to object to its processing. Your data is processed in Germany, Italy and Ireland, which Switzerland recognises as providing adequate protection, and — for payment data handled by Stripe — in the United States, on the basis described in section 6. You can report a matter to the Federal Data Protection and Information Commissioner, Feldeggweg 1, 3003 Berne (edoeb.admin.ch), and bring a claim before the civil courts.
- Canada
- PIPEDA and, where they apply, the private-sector privacy laws of Québec (the Act respecting the protection of personal information in the private sector, as amended by Law 25), Alberta and British Columbia give you the right to access the personal information we hold about you, to have it corrected, to withdraw your consent subject to legal or contractual restrictions, and to challenge the way we comply. In Québec you can also ask to receive computerised information you provided in a structured, commonly used technological format, and to have information de-indexed or no longer disseminated where the law provides for it. We answer within 30 days. Your information is stored and processed outside Canada — in Germany, Italy and Ireland and, for payment data, in the United States — where it is subject to the laws of those countries and may be accessed by their courts and authorities. Our website uses no technology that identifies, locates or profiles you. The person in charge of the protection of personal information is the owner of OutLine Digital Agency, Via Dalmazia 36, 76125 Trani (BT), Italy, amministrazione@outlinedigital.it. You can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca), in Québec to the Commission d’accès à l’information (cai.gouv.qc.ca), or to the Information and Privacy Commissioner of Alberta or of British Columbia.
- Australia
- Where the Privacy Act 1988 applies to us, this page is our privacy policy under the Australian Privacy Principles. You can ask for access to the personal information we hold about you and for its correction; we respond within 30 days and do not charge for the request. For a general enquiry you may contact us without saying who you are; to open an account we need to know. We hold your information in Germany, Italy and Ireland and, for payment data, in the United States: the recipients there are not bound by the Australian Privacy Principles, but by the GDPR or by the safeguards described in section 6. If you think we have breached the Principles, write to us at amministrazione@outlinedigital.it: we reply within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner, GPO Box 5288, Sydney NSW 2001 (oaic.gov.au).
- New Zealand
- Where the Privacy Act 2020 applies to us, you can ask us to confirm whether we hold personal information about you, to give you access to it and to correct it; if we do not agree to a correction, you can ask us to attach to the information a statement of the correction you asked for. We decide on a request within 20 working days. Your information is held in Germany, Italy and Ireland, under the GDPR. Our privacy officer is the owner of OutLine Digital Agency, reachable at amministrazione@outlinedigital.it. If you are not satisfied with our reply, you can complain to the Office of the Privacy Commissioner (privacy.org.nz).
- United States
- There is no general federal privacy law. We do not sell personal information, do not share it for cross-context behavioural advertising, do not use it for targeted advertising or profiling, and use sensitive information — your password, in hashed form — only to sign you in. The categories of personal information we collect, the purposes and the retention periods are those in section 3: identifiers and contact details, account and billing records, payment records, and internet activity in our access logs. We collect them from you or from your organisation and disclose them only to the service providers named in section 5. We are below the thresholds at which the California Consumer Privacy Act and the other state privacy laws apply to a business; even so, whichever state you live in, you can ask us to tell you what we hold about you, to give you a copy, to correct it or to delete it. Write to amministrazione@outlinedigital.it, yourself or through an agent you have authorised in writing: we reply within 45 days and never treat you differently for asking. If we decline a request you can ask us to review the decision, and you can contact the Attorney General of your state. For the data that our customers keep in their workspaces we act as their service provider or processor (see the Data Processing Agreement).
10. If you do not provide the data
Name, email and password are needed to create the account: without them we cannot provide the service. Billing details are needed to activate a paid subscription. Everything else is optional, and leaving it out does not stop you from working.
12. Children
Omega Work is a service for businesses: it is not intended for children and we do not knowingly collect children’s data to open an account. If we discover that an account has been opened by a child, we close it and delete the data.
13. Changes to this policy
Each version has a number and an effective date, and previous versions remain available on request. If a change concerns purposes or legal bases, we tell you by email and when you sign in, at least 30 days in advance.
14. The mobile apps
The Omega Work apps for iOS and Android (com.omegasuiteapp.work) are another way of reaching the same account. You sign in with an account that already exists — an account cannot be created, and nothing can be bought, in the apps — and they show the same data as the web application. What is described in the rest of this policy applies to them too; this section adds what is specific to a phone.
| Permission | When the app asks for it | What happens to the data | If you refuse |
|---|---|---|---|
| Camera | To take a photo that you attach to a task. | The photo is uploaded to the workspace only when you attach it. | You can still attach an existing file. |
| Photos and files | To attach to a task an image or a file that is already on your device. | Only the items you pick are uploaded. The app cannot read the rest of your library. | Nothing is attached. |
- What stays on the device. The sign-in token are kept in the protected storage of the operating system; your profile, your preferences and the files you download are kept in the app’s own storage. Signing out or uninstalling the app removes them.
- What the app sends us. What you see and do in the application, as on the web, plus the version of the app and whether it runs on iOS or Android. It sends no device name, model, advertising identifier or contact list.
- Notifications. The apps do not use push notifications today. If they are added, your device will ask you first, and this section and the Sub-processors page will be updated beforehand.
- No third-party tools. The app contains no analytics, advertising, tracking or crash-reporting tools from other companies: it talks to our servers and to nobody else.
- No tracking. We do not track you across other companies’ apps and websites, and the apps show no advertising.
- Children. The apps are business tools for the staff of our customers. They are not directed at children.
15. Deleting your account and your data
You can ask at any time for your Omega Work account, and the data linked to it, to be deleted — whether you use the website or the mobile apps. It costs nothing.
How. Open the page Delete your account — no need to sign in — or, inside the application, Settings → Account → Delete account, and give the email address of your account. We send a confirmation link to that address, valid for 24 hours, so that nobody can ask for someone else’s account to be deleted: nothing is deleted until you open the link and confirm. We do not store your IP address for this. You can also write to amministrazione@outlinedigital.it with the subject “Delete my account”, from the email address of the account. A confirmed request is carried out straight away — at the latest within 30 days — and we confirm it by email, in your language.
- You are the owner of a workspace. Deleting your account also deletes the workspaces you own — their database and their files, for every member — and their members lose access. If one of them still has a subscription that renews, nothing is deleted: cancel the subscription first (or ask us to transfer the workspace to another owner), then confirm again. The confirmation page lists these workspaces before you confirm. Article 14 of the Terms of Service says what happens to backups.
- You were given access by an organisation — as a colleague or a guest. We delete your sign-in account (name, email address, password, sessions, API keys, devices) and remove you from that organisation’s workspaces. The records about you inside the organisation’s workspace — tasks, comments, files you created — belong to the organisation, which decides, within the limits of the law, whether to keep them: we pass your request on to its owner and administrators. You can also ask an administrator of that organisation to remove your access.
- No account uses your address. If your data is inside a workspace of one of our customers but you never had an account, confirming the request passes it to our privacy team, which forwards it to that customer and answers you within 30 days.
- What we keep. Only what the law requires us to keep, or what we need to defend a legal claim, for the periods in section 3: invoices and accounting records, the record of contractual acceptances (which shows who accepted) and the documents of the subscription. The record of a deleted workspace keeps the customer’s business name and tax identifiers; your name and email address are removed from it, and only a one-way fingerprint of the address remains, used solely to grant the free trial once per customer.