Privacy Policy
This policy explains what personal data we handle, why, how long we keep it and the rights available to individuals. We are registered in England and Wales under company number 12341379, with our registered office at 47 Cannon Street, Birmingham, B2 5EF. Our ICO registration number is ZB066023.
Last updated: 16 July 2026
Overview
The SaaSy People Ltd ("we", "us", "our") operates OmniSaaSy, a service that relays customer messages, reviews and comments between connected support and social platforms and your Intercom workspace. OmniSaaSy acts as a bridge: it passes messages between the connected platforms and Intercom. It processes message content for operational purposes only, such as measuring message length, identifying the type or source of a message (for example whether a reply was sent by an agent or an automated system) and handling text encoding such as unicode. It does not use artificial intelligence to interpret the meaning of messages or to generate replies or message content.
1. Our role: controller and processor
OmniSaaSy is used by businesses (our "Customers") to manage conversations with their own customers and prospects. Our data protection role depends on whose data is being processed:
- Processor. For the message content, reviews, comments and related personal data of a Customer's own customers and prospects that flows through OmniSaaSy, the Customer is the data controller and we act as their data processor. We process this data on the Customer's documented instructions under a Data Processing Agreement.
- Controller. For the account, billing and service administration data relating to the Customer's administrative users of OmniSaaSy, we act as the data controller. The remainder of this policy describes that controller processing, and applies alongside our Data Processing Agreement for processor activities.
2. What we collect
Account data
Name, email address, organisation, role and authentication metadata, including OAuth tokens where you sign in through a connected provider such as Intercom or Google.
Product usage
The platforms you connect, the relay and routing settings you configure, the conversations relayed through the service, the actions your agents take in the app and audit log events recording activity.
Relayed message content
The messages, reviews, comments and direct messages, together with associated metadata, that OmniSaaSy retrieves from the platforms a Customer connects (for example Trustpilot, Facebook, Instagram, Google Play, Google Business Profile and X) and relays to and from Intercom. OmniSaaSy stores only the message data required for relay, audit logging and retry, retained for the period described in section 8. This content is processed on behalf of, and under the control of, the Customer.
Billing data
Plan assignments, ledger entries and invoices. Where paid billing is enabled, our payment provider holds card details; we do not.
Technical data
IP address, user-agent, approximate location, session activity and audit log events. We use this for security, fraud prevention and rate limiting.
3. Why we process personal data
We process personal data to provide and operate the service, to authenticate users, to relay the content submitted through the platform, to operate billing, to respond to support requests, to keep the service secure, to improve the product and to meet our legal obligations.
4. Legal bases (UK GDPR)
- Contract. To provide the service you or your organisation has signed up for.
- Legitimate interests. Security, fraud prevention, service improvement and aggregated analytics, balanced against the rights of individuals.
- Legal obligation. Accounting, tax and cooperation with regulators.
Where we act as processor for Customer-controlled personal data, we process it on the Customer's documented instructions; the Customer is responsible for identifying the legal basis for that processing.
5. Sub-processors
We use the following sub-processors to deliver the service. Contractual data protection terms, including UK GDPR Article 28 obligations, flow down to each:
- Hetzner Online GmbH (Germany, EEA): primary application hosting and compute.
- Amazon Web Services EMEA SARL (Luxembourg): encrypted backup storage in the AWS London (eu-west-2) region, UK.
- Intercom R&D Unlimited Company (Ireland, EEA): the ticketing platform into which conversations are relayed.
In addition, the messaging, review and social platforms a Customer chooses to connect (for example Trustpilot, Meta (Facebook and Instagram), Google (Google Play and Google Business Profile), and X) process personal data under their own terms as part of that integration.
6. Data residency
Primary application and database hosting is located in the EEA (Hetzner, Nuremberg, Germany). Encrypted backups are held in the UK (AWS, London region). Where a Customer connects third-party platforms, those providers may process data outside the UK and EEA under their own arrangements as described in section 7.
7. International transfers
Our own processing of personal data takes place within the UK and EEA. Transfers outside the UK and EEA arise only where a Customer chooses to connect third-party platforms. Where such transfers occur, they are made under the UK/EU-US Data Privacy Framework where the recipient is certified, or under Standard Contractual Clauses together with the UK International Data Transfer Addendum, supplemented by additional safeguards where appropriate.
8. Retention
Retention periods for Customer-controlled data are agreed with each Customer and recorded in the Data Processing Agreement. As an indicative position:
- Operational message data and audit logs are held for up to 90 days.
- Backups are rotated and expire within 90 days.
- Account and billing records are retained for up to 7 years in line with UK tax law.
Where a Customer organisation is closed, associated data is deleted within 30 days, except where we are required to retain it for legal reasons.
9. Your rights
Individuals have the right to access, correct, delete and export the personal data we hold about them, and to object to processing based on legitimate interests. Where we act as processor, requests relating to Customer-controlled data are passed to the relevant Customer, who is responsible for responding as controller. Requests relating to data we control can be sent to [email protected]. If you believe we have not respected your rights, you may complain to the UK Information Commissioner's Office at ico.org.uk.
10. Cookies
The OmniSaaSy application uses only strictly necessary cookies for authentication and session management. It does not use advertising cookies. Our marketing website uses a consent management platform to obtain lawful consent for any analytics or marketing cookies, in line with PECR and UK GDPR.
11. Security
We encrypt personal data in transit (TLS 1.2 or higher) and at rest (AES-256), apply role-based access control on a least-privilege basis, enforce multi-factor authentication on production and administrative accounts, and log employee access to Customer data. Our information security management system is certified to ISO/IEC 27001. Our security overview provides further detail, and researchers can contact [email protected].
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified to organisation owners at least 30 days before they take effect.
13. Contact
For any privacy-related question, write to [email protected], or to The SaaSy People Ltd, 47 Cannon Street, Birmingham, B2 5EF.