Privacy Policy
1. Company Information
Welcome to OmniflonexAi ("Company", "we", "our", or "us"). OmniflonexAi is an independent digital & AI agency operated by a Sole Proprietor based in Gwalior, Madhya Pradesh, India. This Privacy Policy outlines how we collect, process, store, protect, and handle personal data when you visit our website (omniflonexai.com) or engage our digital services.
2. Information We Collect
We collect information necessary to process custom orders, deliver software and digital media, handle billing, and communicate project timelines:
- Personal Identifiers: Full Name, Work Email Address, Phone Number, WhatsApp Contact, Company / Brand Name, Billing Address, Country.
- Project Data: Project briefs, branding assets, custom logos, text scripts, media uploads, domain credentials, and technical specifications.
- Technical Data: Standard server request data (such as IP address, browser type, and operating system) that our hosting provider records automatically for security and reliability purposes.
3. How We Use Your Information
Your data is processed strictly for legitimate business execution:
- To execute, deliver, and maintain custom AI websites, UI/UX designs, motion graphics, and video production.
- To issue formal invoices, process billing through PCI-compliant gateways, and provide proposal estimates.
- To send project updates, delivery notifications, and priority customer support communications.
- To prevent fraudulent transactions, cyber attacks, unauthorized access, and breach of terms.
OmniflonexAi guarantees that client personal data is NEVER sold, rented, or monetized for commercial advertising.
4. Payment Processing & Security
All online transactions are processed through certified PCI-DSS compliant third-party payment gateways including Stripe, Razorpay, PayPal, and Payoneer. OmniflonexAi never stores credit card numbers, debit card PINs, CVVs, or bank account credentials on its own servers.
5. AI Processing & Third-Party Platforms
Our production workflow integrates state-of-the-art Artificial Intelligence tools (large language models, 3D WebGL renderers, voice synthesizers). Project briefs and raw assets uploaded for processing may be submitted via secure API connections to specialized AI providers. AI-generated outputs undergo human quality review prior to final dispatch.
6. Cookies & Tracking Technologies
We utilize essential, functional, and performance cookies to enable session state persistence (e.g., currency selection, cart drawer items, project wizard progress) and site speed optimization. For full details, view our Cookie Policy.
7. Data Retention & Security Standards
We implement administrative, encryption, and technical safeguards to prevent unauthorized access or disclosure. We retain personal data only for as long as it is required for the purpose it was collected, after which it is deleted or irreversibly anonymised.
- Enquiry & lead data (no engagement): 12 months from last contact.
- Active client project files & correspondence: duration of the engagement + 24 months (for support, revisions and dispute defence).
- Invoices, billing and tax records: 8 financial years, as required under Indian tax and accounting law.
- Account & login data: until you delete your account, then up to 30 days in backups.
- Server / security logs: up to 90 days.
Where a longer period is mandated by applicable law, or where data is required to establish, exercise or defend a legal claim, retention is extended only for that purpose.
8. Client Rights & Data Management
Depending on where you are located, you have the rights set out below. To exercise any of them, email compliance@omniflonexai.com with the subject line "Data Rights Request". We acknowledge every request within 72 hours and resolve it within 30 days.
A. India — Digital Personal Data Protection Act, 2023 (DPDP Act). As a Data Principal you have the right to: (i) obtain a summary of the personal data we process and the processing activities undertaken; (ii) correction, completion, updating and erasure of your personal data; (iii) nominate another individual to exercise your rights in the event of your death or incapacity; and (iv) grievance redressal through our Grievance Officer (Section 11 below) before approaching the Data Protection Board of India. OmniflonexAi acts as a Data Fiduciary for data you provide to us directly.
B. EU / UK / EEA — GDPR and UK GDPR. Where the GDPR or UK GDPR applies, you have the right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection to processing (including direct marketing), and the right not to be subject to solely automated decision-making producing legal effects. You may also lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). Our lawful bases for processing are: performance of a contract (service delivery and billing), legitimate interests (site security, service improvement), legal obligation (tax and accounting), and consent (marketing communications).
C. Withdrawal of consent & marketing opt-out. Where processing is based on consent, you may withdraw that consent at any time — this does not affect the lawfulness of processing carried out before withdrawal. You can opt out of marketing email at any time using the unsubscribe link in any message, or by emailing compliance@omniflonexai.com. Transactional messages relating to an active project or invoice are not marketing and cannot be opted out of while the engagement is live.
D. Cross-border transfers. OmniflonexAi is based in India and serves clients in the United States, United Kingdom, UAE, Canada and Australia. Your data may therefore be processed outside your country of residence, including on infrastructure operated by our processors (for example Google Firebase and our hosting provider). Where required, such transfers are made under appropriate safeguards including Standard Contractual Clauses and equivalent contractual protections with each processor. We do not transfer personal data to any country to which such transfer is restricted under applicable law.
E. Children's data. Our services are intended for businesses and are not directed at children. We do not knowingly collect personal data of any individual under 18 years of age. If we become aware that we have collected such data, we will delete it promptly. A parent or guardian who believes a child has provided us data may write to compliance@omniflonexai.com.
F. No sale of personal data. We do not sell, rent, or trade personal data, and we do not use client project data to train third-party AI models without the client's explicit written permission.
9. Contact Information
For privacy inquiries or compliance requests, contact us at:
OmniflonexAi • Gwalior, Madhya Pradesh, India • Email: hello@omniflonexai.com • Business Hours: Mon–Sat 9:00 AM – 6:00 PM IST.
10. Grievance Officer (India — DPDP Act 2023 & IT Rules 2021)
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the contact details of our Grievance Officer are published below:
- Name: Divyanshu Jain
- Designation: Grievance Officer & Data Protection Contact, OmniflonexAi (Sole Proprietorship)
- Email:
compliance@omniflonexai.com - Address: Gwalior, Madhya Pradesh, India
- Working hours: Monday – Saturday, 9:00 AM – 6:00 PM IST
Every grievance is acknowledged within 72 hours of receipt and resolved within 30 days. If you are not satisfied with the outcome, you may escalate to the Data Protection Board of India (for Data Principals in India) or to your local supervisory authority (for users in the EU/UK).
11. Changes to this Policy
We may update this Privacy Policy to reflect changes in our services, technology or legal obligations. The version number and effective date at the top of this document are updated whenever a change is made. Material changes affecting your rights are communicated by email to active clients at least 14 days before they take effect. Continued use of our website or services after the effective date constitutes acceptance of the updated policy.