PRIVACY AND DATA PROTECTION POLICY – SACHA OMON AI
Version dated October 4, 2026 – International (European Union / United States)
1. Purpose of this Policy
This Privacy and Data Protection Policy (the “Policy”) explains how personal data is collected, used, hosted, transferred, protected, retained and deleted in connection with the services marketed under the Sacha Omon AI brand.
It applies in particular to websites and services accessible through `sacha-omon.app`, `sacha-omon.ai`, `sacha-omon.com`, their subdomains, interfaces, dashboards, widgets, hosted pages, APIs, AI agents, voice services, connected channels, lead-generation tools, advertising tools and other official services operated under the Sacha Omon brand.
This Policy covers two distinct situations:
1. processing for which Sacha Omon itself determines the purposes and essential means of processing, including account, billing, commercial-relationship, security and own-website usage data; and
2. processing performed on behalf of a business Customer, including conversations, prospects, contacts, RAG documents, CRM data, calls, messages, appointments and other data that the Customer entrusts to the Solution or causes the Solution to process.
Where Sacha Omon processes data on behalf of a Customer, the Customer generally remains the controller, or itself acts as a processor on behalf of its own principal, and Sacha Omon acts as processor or subprocessor, as applicable. The corresponding obligations are supplemented by the Data Processing Agreement (“DPA”) applicable to the contractual relationship.
This version replaces any prior privacy policy applicable to the Sacha Omon Services. Any prior description of the architecture or technical providers that is inconsistent with this Policy is superseded by this version.
2. Identity of the Operator and Controller
The Services are operated under the brand and trade names “Sacha Omon” / “Sacha Omon AI” by a business registered in Israel.
For processing for which Sacha Omon determines the purposes and essential means, the controller is Sacha Omon AI, operator of the Service.
Operator location: Netanya, Israel.
Privacy and data-protection contact: `sacha@sacha-omon.com`.
The operator’s full legal and contractual details are provided in the applicable contractual, billing or order documents.
In this Policy, “Sacha Omon” and “Sacha Omon AI” mean the registered operator of the Service and, following any lawful incorporation, contribution, reorganization, assignment, merger, acquisition, novation or transfer of the business, the entity that succeeds it in operating the Solution.
3. Proprietary Technology, Sacha Engine and Architecture
Sacha Omon AI is proprietary software developed and operated by Sacha Omon. The application core, agentic orchestration, Sacha Engine, RAG mechanisms, workflows, interfaces, dashboards, Builder, Booking and Call functions, and the other proprietary components of the Solution are developed and controlled by Sacha Omon, subject to third-party libraries, infrastructure, networks, APIs or services expressly used to provide certain functions.
The core of the Solution is deployed on Cloudflare infrastructure and on Sacha Omon’s proprietary components. Sacha Omon controls its proprietary application logic, agentic orchestration, RAG mechanisms and software stack, while third-party infrastructure, networks, APIs or services are used only where required to provide specific functions.
The Solution is designed using a “single-tenant” architecture at the application-environment and logical-data-isolation level: one Customer’s data and configuration are separated from those of other Customers. This does not necessarily mean that each Customer has a physically dedicated server, unless expressly agreed otherwise in writing.
Third-party services may nevertheless be required for certain functions, including telephony, SMS, WhatsApp, Messenger, payments, advertising campaigns, e-mail delivery, certain artificial-intelligence models or services, fraud detection, or other integrations requested or enabled by the Customer. Use of a third-party service does not grant that third party any ownership rights in Sacha Engine, the Solution or Sacha Omon’s proprietary technology.
4. Our Data-Protection Roles
4.1 Data for Which Sacha Omon Acts as Controller
Sacha Omon acts as controller in particular for data necessary for:
- creating and administering Customer accounts;
- managing the commercial and contractual relationship;
- billing, payment monitoring and accounting;
- assistance and support;
- platform security and prevention of fraud and abuse;
- technical logging required for operation and security;
- management of visitors to its own websites;
- its professional communications and, where permitted, its marketing communications; and
- compliance with legal, tax, regulatory and judicial obligations.
4.2 Data Processed on Behalf of a Customer
Where a Customer uses Sacha Omon to interact with its prospects, customers, employees, suppliers or other end users, Sacha Omon generally processes the relevant data only to provide the Services and on the Customer’s instructions.
This may include conversations, forms, callback requests, appointments, lead data, CRM data, messages, attachments, RAG content, histories, call recordings or transcripts, communications metadata and data originating from integrations enabled by the Customer.
Under the GDPR, Sacha Omon then acts as processor or subprocessor, depending on the Customer’s role. Under applicable Israeli law, Sacha Omon may act as a “holder” or external service provider processing data on behalf of the database controller. Under applicable U.S. laws, including in California, Sacha Omon may act as a “service provider” or “contractor” where the statutory conditions are met.
The Customer remains responsible for the lawfulness of collection, the purpose of processing, notices provided to individuals, consents where required, the retention period it configures, and the instructions it gives to Sacha Omon.
5. Individuals Concerned
Depending on the context, individuals concerned may include:
- representatives, officers, employees, contractors and authorized users of Customers;
- visitors to Sacha Omon websites;
- Sacha Omon prospects and business contacts;
- Customer prospects, customers and end users who interact with a Sacha Omon agent;
- persons who contact a Customer through Web, WhatsApp, Messenger, e-mail, SMS or telephone where those channels are connected;
- persons whose data is contained in documents, catalogs, knowledge bases, CRM systems or integrations supplied by a Customer;
- persons concerned by advertising campaigns or lead-generation forms managed at a Customer’s request; and
- persons who interact with support, security, compliance or billing teams.
6. Categories of Data Processed
Depending on the Services used and the information actually provided, Sacha Omon may process the following categories.
6.1 Account and Professional Identification Data
First name, last name, job title, company, business address, e-mail address, telephone number, account identifiers, role, permissions, language, country, preferences, login information and other data required to manage the account.
6.2 Contractual, Billing and Payment Data
Subscribed offer, order history, invoices, transaction identifiers, payment status, currency, tax information, billing country and data required to process payments. Full payment-card data is normally processed directly by the payment provider or Merchant of Record and is not intended to be stored by Sacha Omon.
6.3 Customer Data, RAG and Knowledge-Base Data
Documents, catalogs, offers, pricing, scripts, procedures, FAQs, business rules, technical documents, internal policies, text, files, website content, product information, CRM data, integration data, custom attributes and other information provided or selected by the Customer to build or populate its RAG environment.
6.4 Prospect, Contact and End-User Data
First name, last name, company, e-mail address, telephone number, address, geographic area, stated need, form responses, qualification information, contact history, lead source, appointments, notes, commercial status and other information communicated by the person or supplied by the Customer to the Service.
6.5 Conversations and Omnichannel Communications
Web messages, WhatsApp messages, Messenger messages, e-mails, SMS, audio messages, attachments, prompts, agent responses, conversation history, reactions, feedback, handoffs to a human, timestamps, channel used and related identifiers.
6.6 Voice, Telephony and Recordings
Where voice functions are enabled: calling or called number, call identifiers, date, time, duration, status, routing, audio, recording where enabled and lawful, transcription, summary, tags, actions generated from the call and associated technical metadata.
Call recording is not systematic. It depends on the Customer’s configuration, enabled functions and applicable law. The Customer remains responsible for providing any information or notice, and obtaining any consent, legally required from called or calling persons.
By default, Sacha Omon does not use voice or recordings to create a biometric identifier, voiceprint or biometric model intended to identify or authenticate a person. Such a function may be enabled only if expressly offered, contractually authorized and implemented with the notices, consents and safeguards required by applicable law.
6.7 Advertising and Lead-Generation Data
Where the Customer enables Alix or advertising connections: advertising-account identifiers, campaigns, ad sets, advertisements, audiences, forms, lead data, conversion events, budgets, statistics, costs, results, campaign attributes, advertising content, measurement data and information required to manage Meta or Google campaigns.
6.8 Technical and Security Data
IP address, device type, browser, operating system, language, session identifiers, access logs, authentication events, error logs, latency, performance, usage, security events, anti-fraud data, diagnostic information, API requests and other technical data required for operation, security or maintenance of the Solution.
6.9 Support Data
Support requests, exchanges with the Customer, screenshots, transmitted files, diagnostic records, tickets, resolution history and information required to provide assistance.
7. Sources of Data
We may receive data:
- directly from a Customer, an authorized user or an end user;
- from a form, landing page, widget or page hosted by Sacha Omon;
- from channels that the Customer chooses to connect to the Solution;
- from a CRM, calendar, catalog, file or other system connected by the Customer;
- from Meta, WhatsApp, Messenger, Google or other platforms enabled by the Customer;
- from a communications provider such as Twilio where the relevant functions are used;
- from a payment provider or Merchant of Record such as Paddle where the Customer purchases a Service through it;
- from Sacha Omon technical logs and security systems; and
- from public or professional sources where lawful and necessary for the business relationship.
Where data has not been collected directly from the individual, the identity of the source depends on the service used and, for Customer Data, primarily on the Customer that chose to submit the data or connect the relevant source.
8. Purposes of Processing and Legal Bases
Where Sacha Omon acts as controller, data may be used for the following purposes.
8.1 Providing and Administering the Services
Account creation, Service activation, authentication, user management, dashboard availability, assistance, performance of the contract, subscription configuration and monitoring.
Legal basis: performance of a contract or pre-contractual steps; legitimate interests for contacts of a legal entity where applicable law permits.
8.2 Billing, Payment, Tax and Accounting
Issuing and retaining invoices, payment monitoring, collection of unpaid amounts, tax obligations, supporting documentation and accounting reconciliation.
Legal basis: performance of a contract, legal obligation and legitimate interests in establishing, exercising or defending rights.
8.3 Security, Fraud Prevention and Platform Protection
Detection of abnormal access, prevention of abuse, spam, attacks, fraud, account takeover, prohibited use, security incidents and protection of persons, Customers and the Solution.
Legal basis: legitimate interests, performance of a contract and, where applicable, legal obligation.
8.4 Support and Service Improvement
Diagnosis, troubleshooting, performance measurement, error correction, improvement of interfaces and features, and analysis of Service quality.
Legal basis: performance of a contract and legitimate interests in maintaining and improving the Service.
8.5 Sacha Omon’s Own Marketing Communications
Information about the Services, new features, business invitations or professional content, only where such communications are permitted by applicable law.
Legal basis: consent where required; otherwise legitimate interests where B2B outreach is permitted.
8.6 Legal Compliance and Defense of Rights
Responding to legal obligations, legally binding requests, audits, disputes, claims, investigations, sanctions, inspections and regulatory requirements.
Legal basis: legal obligation and legitimate interests in protecting our rights and those of our Customers.
Where Sacha Omon acts as processor, the legal basis for processing is determined by the Customer, and Sacha Omon processes the data on the Customer’s documented instructions in accordance with the DPA and applicable contract.
9. Artificial-Intelligence Processing and Agentic Operation
Sacha Omon uses artificial-intelligence technologies to understand requests, retrieve information from the Customer’s RAG, produce responses, summarize exchanges, qualify prospects, extract information, propose actions, prepare follow-ups, facilitate appointment booking, process voice interactions and perform other configured tasks.
Processing may include converting a message or call into text, analyzing context, retrieving relevant information from Customer data, generating a response, executing an authorized tool or action, and recording history required for conversational continuity.
Sacha Engine is Sacha Omon’s proprietary orchestration and execution engine. Depending on enabled features, Sacha Engine may call third-party infrastructure, communications or artificial-intelligence services acting as processors or technical service providers. Those providers do not become owners of Customer data or of Sacha Engine merely because of their technical involvement.
Sacha Omon must not be used, without appropriate safeguards, to make a fully automated decision producing legal effects or similarly significant effects on an individual where applicable law requires human intervention, an impact assessment, specific notice or other safeguards. The Customer is responsible for determining whether its use case requires such safeguards.
10. No Cross-Customer Training on Customer Data
Sacha Omon does not use RAG documents, conversations, recordings, CRM data, lead data or other Customer Data to train a general model intended to be shared among Customers or commercialized to third parties as a model trained on a Customer’s data.
Customer Data may be processed within the Customer’s environment to provide, secure, diagnose and improve the Service provided to that Customer. Sacha Omon may also use aggregated or reasonably de-identified technical, statistical or performance data to measure, secure and improve the platform, provided that such data does not reasonably identify the Customer, an end user or a natural person.
Where a third-party model or compute provider is used for an enabled feature, Sacha Omon seeks to structure that provider’s role so that the data is processed to provide the relevant service and in accordance with the confidentiality and data-protection commitments applicable to the professional service used.
11. Customer Data and Ownership of Content
The Customer retains its rights in Customer Data and Customer Content. This Policy does not transfer to Sacha Omon ownership of the Customer’s catalogs, documents, trademarks, knowledge bases, CRM data, commercial content or personal data.
Sacha Omon receives only the technical rights required to host, index, retrieve, technically transform, transmit, display and process such data to the extent necessary to provide the Services and follow the Customer’s instructions.
Conversely, ownership of Customer Data grants the Customer no rights in Sacha Engine, Sacha Omon software, proprietary workflows, interfaces, code, orchestration models, dashboards or other intellectual-property elements of Sacha Omon.
12. Voice, Calls, SMS, WhatsApp, Messenger and E-mail
Where the Customer enables communications channels, data required for their operation may be transmitted to the relevant provider or network.
Twilio may be used as a carrier or technical provider for certain calls, SMS, voice functions, routing, numbers, recordings or communications services. Meta/WhatsApp may process data required for WhatsApp or Messenger communications. Telecommunications carriers and destination networks also process certain metadata required to route communications.
The Customer remains responsible for the lawfulness of its campaigns, calls, messages, contact lists, consents, opt-ins, unsubscribe preferences, scripts and contact hours. It must comply with rules applicable in the countries where it contacts individuals, including rules governing outreach, call recording and electronic communications.
13. Alix, Meta Ads, Google Ads and Advertising Data
Where the Customer uses Alix or connects a Meta Ads or Google Ads account, Sacha Omon may receive or transmit data required to create, manage, optimize, measure and monitor campaigns, including lead or conversion data where configured by the Customer.
This processing is performed on behalf of the Customer and under its instructions, except where Meta, Google or another operator independently determines certain processing purposes under its own terms and policies.
Sacha Omon does not sell Customer Data to Meta or Google. Where the Customer voluntarily enables an advertising integration, transmission of data to the relevant platform is an operation requested by the Customer to run the campaign, measure conversions or provide the enabled feature. The Customer is responsible for the lawfulness of that transmission and for configuring its advertising accounts.
14. Payments and Merchant of Record
Payments may be processed by Paddle or by another payment provider or Merchant of Record identified at the time of the Order.
Where a Merchant of Record is involved, it may act as reseller of the product and as an independent controller for certain payment, billing, tax, fraud-prevention and compliance data. Sacha Omon receives only the information required to activate the Service, provide support, manage the Customer relationship and satisfy its own accounting or contractual obligations.
This Policy does not replace the privacy policy of the payment provider applicable at checkout.
15. Cookies and Similar Technologies
Sacha Omon websites may use cookies, local storage, pixels or similar technologies to:
- ensure essential operation of the site and sessions;
- secure authentication and prevent fraud;
- remember certain choices;
- measure site use and performance;
- enable features requested by the user; and
- where permitted and, if necessary, after consent, measure the effectiveness of marketing campaigns.
Strictly necessary cookies may be placed without consent where permitted by applicable law. Non-essential cookies that require consent must be activated only after the required consent has been obtained in the relevant territories.
Where a preference-management mechanism is available, the user may change their choice at any time. A separate Cookie Policy may supplement this Policy and describe the cookies actually deployed.
16. Technical Data, Service Data and Aggregated Data
Sacha Omon may generate technical data relating to operation of the Service, such as performance statistics, latency, error rates, volumes, feature usage, consumption, security events, availability, diagnostics and technical metrics.
Where such data contains personal data, it is processed in accordance with this Policy and only for legitimate purposes such as security, support, billing, abuse prevention and improvement of the Service.
Sacha Omon may freely use aggregated or reasonably de-identified statistical or performance data, including to improve the Solution, plan capacity, evaluate features and produce internal statistics, provided that such data does not reasonably identify a natural person or reveal a Customer’s confidential information.
17. Sale, Advertising Sharing and Monetization of Data
Sacha Omon does not sell Customer Data or end-user personal data in exchange for payment.
Sacha Omon does not use Customer Data to build cross-customer advertising profiles or to conduct behavioral advertising for the benefit of third parties.
Where the Customer enables an advertising integration or third-party channel, certain data may be transmitted to that third party on the Customer’s instructions, as explained in this Policy. Such functional transmission does not mean that Sacha Omon sells Customer Data.
18. Sensitive Data and Special Categories
By default, the Solution is not designed to receive highly sensitive data that is unnecessary for the Customer’s use case.
Unless there is a specific written agreement and appropriate safeguards are implemented, the Customer must not intentionally submit or cause Sacha Omon to process biometric data used to identify a person, detailed medical data, genetic data, passwords, full payment-card numbers, authentication secrets, data concerning a person’s sex life, political opinions, religious beliefs, trade-union membership, criminal-offense data, government identification numbers or other categories of data subject to enhanced protection, where such data is not strictly necessary and lawful.
If a Customer wishes to use the Service for a use case involving sensitive data, it must first verify the legal basis, security obligations, impact assessments, required contracts and restrictions of the relevant Service.
19. Minors
Sacha Omon Services are B2B services intended for professionals and are not designed to be purchased or administered by minors.
A Customer must not use the Solution to intentionally target children or collect their data in a manner that would violate applicable rules concerning protection of minors, parental consent or advertising directed to children.
Any content involving sexual exploitation of a minor, grooming, sexualization of children or any other child sexual abuse material is strictly prohibited and may result in immediate suspension, preservation of evidence and reports required by applicable law.
20. Recipients and Subprocessors
Access to data is limited to persons and providers that need it to provide, secure, administer or support the Services.
Depending on enabled features, categories of recipients or subprocessors may include:
- Cloudflare, for cloud infrastructure, network, security, execution and certain storage or processing services;
- Twilio and associated telecommunications carriers, for telephony, SMS, voice or certain communications services;
- Meta, WhatsApp or Messenger where the Customer enables those channels;
- Google where the Customer enables Google Ads, Google APIs or other Google integrations;
- Paddle or another payment provider / Merchant of Record where payment is processed through it;
- AI-model, compute or technical-service providers where their involvement is necessary for an enabled function;
- professional advisers such as lawyers, accountants, auditors, insurers or consultants where necessary and subject to confidentiality obligations; and
- authorities or courts where disclosure is legally required.
The list of material subprocessors may change as the Solution evolves. An up-to-date list may be requested at `sacha@sacha-omon.com` and may also be published on a dedicated “Subprocessors” page.
Where required, Sacha Omon imposes contractual confidentiality, security and data-protection obligations appropriate to the provider’s role.
21. Hosting, Regions and International Transfers
Sacha Omon is operated from Israel and marketed internationally, including in Europe and the United States.
The architecture allows primary processing of certain Customer environments to be configured in a European region or a U.S. region depending on the Customer’s location, Service configuration, subscribed options and applicable contractual or regulatory requirements.
Cloudflare operates a global network. Depending on the Cloudflare products used and localization options enabled, certain network, security, routing operations or metadata may transit through or be processed in several countries. A promise of exclusive data residency in a particular territory applies only where it is expressly stated in an Order, DPA or specific localization commitment and the corresponding technical controls have been enabled.
Where personal data is transferred from the European Economic Area, the United Kingdom, Israel or another territory to a country that does not provide the required level of protection, Sacha Omon uses, where required by law, recognized mechanisms such as Standard Contractual Clauses, a UK addendum, contractual protection commitments or another valid transfer mechanism.
Third-Party Services used by the Customer may also process data in the territories contemplated by their own infrastructure and terms.
22. Retention Periods
Sacha Omon does not retain data longer than necessary having regard to the purposes described in this Policy, Customer instructions, the DPA, legal requirements and security or legal-defense needs.
The following criteria generally apply:
22.1 Customer Data Processed as Processor
Customer Data is retained for the duration of the Service and in accordance with the retention policy configured or agreed with the Customer. At the end of the contract, it is returned or deleted in accordance with the DPA and applicable instructions.
After the Service ends or a valid deletion request is received, production data remaining under Sacha Omon’s control is deleted or rendered inaccessible within the period stated in the DPA or, if no specific contractual period applies, within a reasonable technical period taking into account the architecture used. Residual backup copies, where they exist, are deleted or overwritten according to their normal technical cycle and are not restored to production systems except where required for restoration, legal obligation or a security incident. Where a specific maximum period is contractually required, it is stated in the applicable Order or DPA.
22.2 Account Data and Business Relationship
Such data is retained during the contractual relationship and thereafter for the period necessary to manage post-contractual obligations, claims, security and defense of rights.
22.3 Invoices and Accounting Records
Such data is retained for the period required by applicable tax, accounting and legal rules, which may extend for several years after the relationship ends.
22.4 Security Logs and Technical Data
Such data is retained for the period necessary for diagnosis, security, abuse prevention and incident investigation. The period may be extended where an incident, dispute, fraud or legal obligation justifies it.
22.5 Sacha Omon’s Own Prospecting Data
Such data is retained for a period proportionate to the business relationship or the most recent relevant contact, then deleted or archived when continued retention is no longer justified.
Where a legal retention obligation applies, the relevant data may be isolated and retained solely to satisfy that obligation.
23. Security
Sacha Omon implements technical and organizational measures that are reasonable and proportionate to the risk in order to protect data against unauthorized access, loss, alteration, destruction, disclosure or unlawful use.
Depending on the relevant component, such measures may include:
- encryption of communications in transit;
- encryption or equivalent protections for stored data where supported by the relevant service;
- logical isolation of Customer environments;
- access controls and the principle of least privilege;
- authentication and session management;
- security logging and monitoring;
- network protections and anti-abuse mechanisms;
- backups or resilience mechanisms where applicable;
- incident-response procedures;
- confidentiality commitments for authorized persons; and
- evaluation and contractual governance of relevant subprocessors.
No system connected to the Internet can offer absolute security. The Customer must also protect its credentials, connected accounts, APIs, numbers, devices and administrator access, and promptly notify Sacha Omon of any suspected compromise.
In the event of a personal-data breach affecting processing carried out on behalf of a Customer, Sacha Omon notifies the Customer in accordance with the DPA and applicable law so that the Customer can meet its own obligations.
24. Rights of Individuals
Depending on the territory and applicable law, an individual may have, among others, the following rights:
- the right to be informed;
- the right of access to personal data concerning them;
- the right to rectification;
- the right to deletion;
- the right to restriction of processing;
- the right to object;
- the right to data portability where applicable;
- the right to withdraw consent without affecting the lawfulness of prior processing;
- rights relating to certain automated decisions or profiling; and
- the right to lodge a complaint with the competent data-protection authority.
To exercise a right relating to data for which Sacha Omon acts as controller, the individual may write to `sacha@sacha-omon.com`.
Sacha Omon may request information reasonably necessary to verify the requester’s identity and prevent fraudulent disclosure.
25. Requests Concerning a Customer’s Data
Where an end user exercises a right concerning data that Sacha Omon processes solely on behalf of a Customer, the Customer is the primary point of contact and remains responsible for responding.
If Sacha Omon receives such a request directly, Sacha Omon may direct the individual to the relevant Customer and, where permitted, forward the request to the Customer. Sacha Omon provides the Customer with reasonable assistance required by the DPA and applicable law.
26. Provisions for the European Economic Area and the United Kingdom
Where the GDPR or UK GDPR applies, Sacha Omon processes data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability.
For processing carried out on its own behalf, Sacha Omon relies, as applicable, on performance of a contract, compliance with a legal obligation, consent or its legitimate interests, subject to the required balancing test.
For processing carried out on behalf of a Customer, instructions, security measures, subprocessors, transfers, rights assistance, incidents, audits and deletion are governed by the applicable DPA.
Where data must be transferred to a territory not benefiting from an applicable adequacy mechanism, appropriate safeguards may be implemented, including the European Commission’s Standard Contractual Clauses and, for the United Kingdom, the UK addendum or mechanisms recognized under UK law.
Sacha Omon provides the information required by Articles 13 and 14 of the GDPR, including the identity and contact details of the controller, purposes and legal bases, categories of data and recipients, retention periods or criteria, international transfers and applicable rights.
Where Article 27 of the GDPR requires a controller or processor not established in the Union to appoint a representative in the Union, Sacha Omon makes that appointment and makes the representative’s contact details readily accessible. Appointment of a representative in the Union does not alter Sacha Omon’s responsibility under the GDPR.
Where a data-protection impact assessment is required for high-risk processing, Sacha Omon carries out the required assessment for its own processing and reasonably assists the Customer for processing performed on the Customer’s behalf, in accordance with the DPA.
27. Provisions for Israel
Sacha Omon is operated from Israel and applies Israeli privacy law where applicable, including the Privacy Protection Law, 5741-1981, as amended, data-security regulations and rules governing international transfers.
To the extent Sacha Omon acts on behalf of a Customer, the allocation of responsibilities takes into account the role of the database controller and the external service provider that holds or processes data on its behalf.
Where Israeli law requires a notification, registration, appointment of a responsible person or officer, security measures or a particular mechanism for an overseas transfer, Sacha Omon applies those requirements to the extent they apply to it.
28. California and Other U.S. Privacy Laws
Where the California Consumer Privacy Act (“CCPA”), as amended, or another U.S. privacy law applies to processing carried out by Sacha Omon as a “business” or “controller”, relevant residents have the rights provided by applicable law. Such rights may include access or right to know, correction, deletion, portability, opt-out of sale or sharing, opt-out of certain targeted advertising or profiling, limitation of certain uses of sensitive data, use of an authorized agent, and the right not to be discriminated or retaliated against for exercising a right.
28.1 Notice at Collection and Categories of Personal Information
Where the CCPA applies, this section supplements the “Notice at Collection”. During the preceding twelve months, depending on the Services actually used, Sacha Omon may have collected the following categories of personal information: identifiers and business contact details; commercial and transaction information; Internet or network activity; account and authentication data; professional information; electronic communications data; audio and voice data where such functions are enabled; approximate location inferred from an IP address; advertising and conversion information; limited inferences required for qualification, routing or operation of the Service; and, only where supplied by the Customer or individual and lawfully processed, certain information that may fall within sensitive categories.
Sources include the individual, the Customer, authorized users, forms and hosted pages, connected channels, CRM systems and other integrations, enabled advertising or communications platforms, payment providers, technical and security logs and, where lawful, certain public or professional sources.
Purposes are those described in this Policy, including providing and administering the Service, carrying out Customer instructions, securing accounts and the platform, providing support, processing payments, measuring performance, preventing fraud and abuse, complying with law and, for Sacha Omon’s own data, carrying out permitted professional communications.
Categories of recipients and subprocessors are described in Section 20. Retention criteria by major processing category are described in Section 22 and Annex 1.
28.2 Sale, Sharing, Targeted Advertising and Universal Opt-Out Signals
Sacha Omon does not sell Customer Data or end-user personal data for monetary consideration. Sacha Omon does not use Customer Data for cross-context behavioral advertising for its own account.
If technologies used on Sacha Omon’s own websites constitute, in a particular territory, a “sale”, “sharing” or “targeted advertising” within the meaning of applicable law, Sacha Omon provides the required opt-out mechanisms and processes recognized universal opt-out signals, including where a signal such as Global Privacy Control must legally be honored.
28.3 Sensitive Data
Sacha Omon does not use or disclose sensitive personal information to infer characteristics of a person beyond what is reasonably necessary to provide, secure or comply with the Service, unless consent or another valid legal basis is required and obtained where applicable law so requires.
28.4 Service Provider / Processor / Contractor
Where Sacha Omon processes personal information on behalf of a Customer, it acts, under applicable law, as a “service provider”, “contractor” or “processor”. It then processes the data for the business purposes specified in the contract and DPA, under the Customer’s instructions and subject to restrictions applicable to that role.
28.5 Exercising Rights, Verification, Authorized Agents and Appeals
Requests concerning data for which Sacha Omon acts as controller may be sent to `sacha@sacha-omon.com`. Sacha Omon may request information reasonably necessary to verify the requester’s identity or authority. An authorized agent may submit a request where permitted by applicable law, subject to verification of the agent’s authority.
Where the law of a U.S. state provides an internal right to appeal a denial of a request, the individual may appeal by replying to the denial notice or writing to `sacha@sacha-omon.com` with the subject or reference “Privacy Appeal”. Sacha Omon processes the appeal within the period required by applicable law and, where required, identifies how to contact the competent authority.
28.6 Minors
Sacha Omon does not direct its Services to children under 13 and does not seek knowingly to collect their data for its own account. Sacha Omon does not knowingly sell or share, for its own account, personal information of persons under 16.
28.7 Updates to the U.S. Privacy Framework
Where the CCPA applies to Sacha Omon as a “business”, this section is reviewed and updated at least as frequently as required by applicable law.
29. Marketing Communications and Unsubscribe
Sacha Omon’s own marketing communications are sent only to the extent permitted by applicable rules.
Each recipient may use the unsubscribe mechanism included in the message where available or contact `sacha@sacha-omon.com` to request that Sacha Omon stop sending marketing communications.
Unsubscribing from marketing communications does not prevent operational or contractual communications necessary for an active account, security, billing or support.
Communications carried out by a Customer through Sacha Omon are the Customer’s responsibility, and the Customer must manage its own consents and unsubscribe requests.
30. Governmental, Judicial and Emergency Requests
Sacha Omon may disclose data where required by applicable law, an order, a court decision or a legally binding request, or where reasonably necessary to protect persons against a serious and imminent risk within the limits permitted by law.
Where legally permitted and reasonably possible, Sacha Omon seeks to limit disclosure to the data necessary and may notify the relevant Customer before disclosure where notice is not prohibited.
31. Assignment, Future LTD, Merger or Sale of the Business
In connection with formation of a company, contribution of the business, reorganization, financing, merger, acquisition, asset transfer, sale of technology or transfer of the Sacha Omon business, associated data and contracts may be transferred to the successor or acquiring entity where necessary for business continuity and permitted by applicable law.
The entity succeeding the operator assumes the data-protection obligations applicable to the transferred information. Such a transfer does not authorize the acquirer to use Customer Data for purposes incompatible with the purposes for which it was collected, unless there is a valid legal basis and any notice required by law is provided.
32. Third-Party Links and Services
The Solution may contain links or connections to third-party services. Where a person leaves a Sacha Omon website or directly uses a third-party service, processing by that third party may be governed by its own privacy policy.
Sacha Omon is not responsible for a third party’s privacy practices where that third party acts as an independent controller. Where the third party acts as a processor for Sacha Omon, the relationship is governed in accordance with applicable obligations.
33. Changes to this Policy
Sacha Omon may update this Policy to reflect changes to the Solution, infrastructure, subprocessors, practices, obligations or applicable law.
The version date at the beginning of the document indicates the latest update. Where a change is material and the law requires notice, Sacha Omon provides appropriate notice before or when the new version takes effect.
Prior versions may be archived to maintain contractual and regulatory traceability.
34. Contact and Complaints
For any question regarding this Policy, to exercise a right or to report a privacy issue:
Sacha Omon AI
Netanya, Israel
E-mail: `sacha@sacha-omon.com`
Sacha Omon may request information reasonably necessary to verify a requester’s identity, protect data from fraudulent disclosure and determine the applicable role of Sacha Omon or the relevant Customer.
An individual may also lodge a complaint with the competent data-protection authority in their territory if they believe their rights have not been respected.
---
Customer Account
Main data: professional identity, e-mail, telephone, role and authentication. Purpose: create and administer the account. Sacha Omon’s principal role: controller. Retention: duration of the relationship plus the period necessary for post-contractual obligations.
Orders and Billing
Main data: offer, invoices, transaction and tax information. Purpose: payment, accounting and evidence. Sacha Omon’s principal role: controller; certain payment providers may act as independent controllers. Retention: period required by tax and accounting obligations.
RAG and Knowledge Base
Main data: documents, catalogs, rules, FAQs and business content. Purpose: power the agent and provide the Service. Sacha Omon’s principal role: processor on behalf of the Customer. Retention: duration of the Service followed by deletion in accordance with the DPA and applicable technical cycle.
Conversations
Main data: messages, prompts, responses, attachments and history. Purpose: respond, qualify, follow up and provide support. Sacha Omon’s principal role: processor. Retention: according to Customer configuration and the DPA.
Leads, CRM and Appointments
Main data: contact details, need, qualification, source and status. Purpose: sales management and appointments. Sacha Omon’s principal role: processor. Retention: according to Customer instructions and configuration.
Telephony and Voice
Main data: numbers, audio, recordings, transcripts and metadata. Purpose: calls, analysis, summary and follow-up. Sacha Omon’s principal role: processor. Retention: according to Customer configuration, applicable law and the DPA.
Advertising and Alix
Main data: campaigns, leads, events, budgets and performance. Purpose: campaign creation, management and measurement. Sacha Omon’s principal role: processor for the Customer; advertising platforms may have their own role. Retention: according to configuration and platform policies.
Logs and Security
Main data: IP, sessions, logs, errors and security events. Purpose: security, fraud prevention, diagnosis and availability. Sacha Omon’s principal role: controller for Sacha Omon’s own logs; processor for certain Customer logs. Retention: period proportionate to security and investigation needs.
Support
Main data: tickets, exchanges and diagnostic files. Purpose: resolve requests. Sacha Omon’s principal role: controller or processor depending on the content. Retention: period necessary for support and defense of rights.
Aggregated Data
Main data: non-identifying metrics. Purpose: performance, capacity and improvement. Sacha Omon’s principal role: controller where no person is identifiable. Retention: according to the platform’s legitimate needs.
Sacha Omon may use subprocessors or technical providers to perform the Services. Where they process personal data on behalf of Sacha Omon, they are selected taking into account their role, security measures, contractual commitments and applicable obligations.
Material subprocessors may operate in the following areas, among others: Cloudflare infrastructure, Twilio telephony and communications, Meta/WhatsApp/Messenger channels, Google services, payment and Merchant of Record, support tools, compute or AI-model providers, and other integrations enabled by the Customer.
The active list may change with the Service. The Customer may request the current list at `sacha@sacha-omon.com`.
