omvio Privacy Policy
How omvio collects, uses, shares and deletes personal data, including data received from WhatsApp, Messenger and Instagram.
Version 1.0 · effective . Previous versions are available on request from legal@aa-labs.co.
This Privacy Policy explains how A & A Labs (“we”, “us”) handles personal data in connection with omvio, our unified business messaging inbox available at https://omvio.app.
1. Two different roles — read this first
omvio is sold to businesses. That means the same product handles two very different kinds of personal data, and our legal responsibility differs for each. The rest of this policy is easier to follow once this distinction is clear.
| Whose data | Example | Our role |
|---|---|---|
| Customer data — the business that subscribes to omvio and its team members | An agency signs up; its owner and five agents create accounts | Controller. We decide why and how this data is processed. |
| End-user data — the people who message that business | A shopper WhatsApps the agency’s client about an order | Processor. The business is the controller; we process on its documented instructions under our Data Processing Addendum. |
If you messaged a business and want your conversation deleted, that business controls it. We will help — see Your rights — but we will normally act through, or notify, the business you contacted.
2. What we collect
2.1 Account and customer data (we are the controller)
- Account details — name, work email address, hashed password, job role, team membership, and the workspace (“tenant”) you belong to.
- Authentication data — session records, login timestamps, IP address and user agent recorded for security, and invitation tokens.
- Billing data — subscription plan, billing status, invoice history and payment identifiers. We never receive or store full card numbers. Card details are entered directly with the payment provider you check out through and are held by them, not by us.
- Channel credentials — the access tokens and account identifiers you supply when you connect a WhatsApp number, Facebook Page, Instagram business account or online store. These are encrypted at rest and are never returned to the browser or included in any export.
- Configuration — your labels, canned replies, automation rules, knowledge-base documents, message templates, notification preferences and AI provider settings.
- Usage and diagnostics — feature usage counters, message volume against plan limits, audit-log entries for administrative actions, and application error logs.
2.2 End-user data (we are the processor)
When you connect a channel, omvio receives and stores the conversations that flow through it so your team can work them from a shared inbox:
- Message content — the text, images, audio, video, documents, stickers and location pins exchanged between the end user and your business.
- Message metadata — platform message ids, timestamps, direction, and delivery/read status.
- Contact records — the end user’s phone number or platform-scoped id, display name and profile picture as provided by the platform, plus any notes, tags, custom fields or segment membership your team adds.
- Commerce context — where you connect Shopify or WooCommerce, the customer, order and cart records we sync so an agent can see them beside the conversation.
- Lead and campaign data — records created by your forms, campaigns and automations.
We do not decide what is said in these conversations, who is contacted, or how long you keep them beyond the limits in section 7. You do.
2.3 Data we receive from Meta
omvio integrates with the WhatsApp Business Platform, Facebook Messenger and Instagram. With your authorisation, we receive from Meta only what those integrations require:
| Permission | What we receive | Why |
|---|---|---|
whatsapp_business_messaging |
Inbound and outbound WhatsApp messages and their delivery statuses | To show conversations in your inbox and send your replies |
whatsapp_business_management |
Connected phone numbers, WABA details, approved message templates | To let you pick a number and send approved templates |
pages_messaging |
Messenger conversations for Pages you connect, and sender-scoped ids | To deliver Messenger threads into the shared inbox |
pages_show_list |
The list of Pages you administer | So you can choose which Page to connect |
pages_read_engagement |
Page profile data and engagement on your own posts | To show context beside conversations and report on published posts |
pages_manage_posts |
Write access to publish posts you compose in omvio | To publish and schedule your Page posts |
instagram_basic |
Your connected Instagram business account and its profile | To identify the account being connected |
instagram_manage_messages |
Instagram Direct messages for that account | To deliver Instagram DMs into the shared inbox and send replies |
instagram_content_publish |
Write access to publish media you compose in omvio | To publish and schedule your Instagram posts |
business_management |
Which Business Manager assets the connecting user may link | To resolve permissions correctly during connection |
Our commitments on Meta platform data. In line with the Meta Platform Terms, the WhatsApp Business Messaging Policy and the Developer Policies, we:
- use platform data only to provide and improve the omvio features you have enabled;
- never sell, rent or license platform data;
- never use it for advertising — including ad targeting, ad measurement, building audiences, or determining eligibility for anything;
- never transfer it to data brokers, ad networks, information resellers or monetisation partners;
- never use it to build a profile of a person for any purpose other than serving the business they contacted;
- never use message content to train general-purpose or third-party AI models (see section 5);
- encrypt it in transit and at rest, and delete it on request or when it is no longer needed for the purpose above.
2.4 Data we do not collect
- Payment card numbers, CVVs or bank credentials.
- Special-category data (health, biometrics, religion, political opinion and similar) as a deliberate collection. If such data appears inside a message your customers send you, we process it only as message content on your instructions.
- Data from anyone under 16. omvio is a business tool and is not directed at children.
3. How we use data, and our legal basis
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the inbox, publishing and automation features | Account data, channel credentials, conversation data | Performance of a contract (Art. 6(1)(b)); for end-user data, processing on the controller’s instructions (Art. 28) |
| Billing, invoicing, tax and dunning | Account and billing data | Contract and legal obligation (Art. 6(1)(b), (c)) |
| Security, abuse prevention, rate limiting and audit logging | Authentication data, IP address, audit logs | Legitimate interests (Art. 6(1)(f)) — keeping the service secure |
| Support, incident response and debugging | Account data, error logs, and — with your permission — specific records | Contract and legitimate interests |
| Service notices, security alerts and billing emails | Account contact details | Contract and legitimate interests |
| Product marketing to business contacts | Work email address | Consent, or legitimate interests where permitted; unsubscribe in any email |
| Aggregate product analytics and capacity planning | Usage counters that identify no individual | Legitimate interests |
4. Who we share data with
We do not sell personal data. We share it only in these situations:
- Within your workspace. Conversations and contacts are visible to the members of your tenant according to their role. Owners and administrators can see all conversations in the workspace; agents see conversations assigned to them or ones they participate in.
- Sub-processors. Vendors that process data on our behalf under written contract — hosting, storage, email delivery, payments and similar. The current list, with the purpose and location of each, is published at omvio Sub-processors.
- The messaging platforms. Sending a reply necessarily transmits it to Meta (WhatsApp, Messenger, Instagram) for delivery, under their own terms.
- AI providers you configure. See section 5.
- Legal requirements. Where we must comply with a valid legal process. We will notify the affected customer unless legally prohibited.
- Corporate transactions. In a merger, acquisition or asset sale, subject to the acquirer honouring this policy. You will be notified before any transfer.
5. AI features
omvio includes optional AI features: suggested replies, automated chatbots and retrieval over a knowledge base you build. How your data is handled depends on how you configure them.
- You bring your own provider. In the normal configuration you supply credentials for an OpenAI-compatible AI provider. Prompts, retrieved knowledge-base passages and relevant conversation context are sent to that provider under your agreement with them. We are not a party to it; check their retention and training terms.
- Platform embeddings fallback. If a workspace has no working embedding provider configured, we may index knowledge-base documents using a platform-level embedding service so search still functions. This affects documents you upload to a knowledge base — not conversation content. It can be avoided entirely by configuring your own provider, and the provider currently used is named in the sub-processor list.
- No training on your data. A & A Labs does not use your messages, contacts or knowledge-base content to train, fine-tune or evaluate any AI model of ours or anyone else’s.
- Automated decisions. AI features draft and suggest; they do not make decisions with legal or similarly significant effects about any individual.
6. International transfers
omvio is operated from cloud infrastructure that may be located outside your country, and our sub-processors operate globally. Where personal data leaves the UK, EEA or another region with transfer restrictions, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with technical measures including encryption in transit and at rest. The hosting region for your workspace is listed in the sub-processor list.
7. How long we keep data
| Data | Retention |
|---|---|
| Conversations, messages, media and contacts | For as long as your workspace is active, or until you delete them. You control this; we do not impose an expiry. |
| After you close your account | Deleted within 30 days of closure. The grace period exists so an accidental closure can be reversed. |
| Verified deletion requests | Actioned within 30 days. |
| Encrypted backups | Rotated out within 90 days. Deleted records are not restored to live systems if a backup is ever used. |
| Application and security logs | 90 days. |
| Invoices and payment records | 7 years, as tax and accounting law requires. |
| Channel access tokens | Destroyed immediately when a channel is disconnected. |
8. Security
- All traffic is served over TLS. Data is encrypted at rest by the underlying storage, and channel credentials receive an additional layer of application-level encryption.
- Passwords are stored as salted hashes and are never recoverable in plaintext.
- Workspaces are isolated: every query is scoped to the tenant, and inbound messages that cannot be matched to an active channel are quarantined rather than filed under an arbitrary account.
- Access within omvio is role-based (owner, administrator, agent) and administrative actions are recorded in an audit log.
- Webhook deliveries from Meta and from payment providers are rejected unless their signature verifies.
- Staff access to production data is limited to those who need it for support or incident response, and is logged.
Our full security posture is described at Security Practices. Report a vulnerability to security@aa-labs.co. We will acknowledge a qualifying breach to affected controllers without undue delay and, where required, within 72 hours of becoming aware of it.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable format, and to withdraw consent. Under the CCPA/CPRA you may also request disclosure of the categories of personal information collected and opt out of “sale” or “sharing” — we do neither, so there is nothing to opt out of. We will not discriminate against you for exercising a right.
- If you have an omvio account, most rights can be exercised in the app, or by writing to privacy@omvio.app.
- If you messaged a business that uses omvio, contact that business first — they control the conversation. You may also write to us and we will route the request and assist the business in fulfilling it.
- To delete your data, follow the Data Deletion Instructions or use the deletion request form.
We respond within 30 days and may need to verify your identity first. If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority.
10. Removing omvio’s access from your Meta account
You can revoke omvio’s access at any time, independently of anything you ask us to do:
- Facebook → Settings & privacy → Settings → Apps and Websites → select omvio → Remove.
- Instagram → Settings → Website permissions → Apps and websites → omvio → Remove.
- WhatsApp Business → Meta Business Suite → Business settings → WhatsApp accounts → remove omvio’s access to the number.
Revoking access stops any further data flow immediately. It does not by itself delete data we already hold — request that through the deletion instructions. When Facebook notifies us that you have removed the app, our automated deletion callback records the request and returns a confirmation code you can use to track it.
11. Cookies
The omvio application uses strictly necessary cookies only: a session cookie to keep you signed in and a CSRF token to protect form submissions. It sets no advertising or cross-site tracking cookies. Cookies on this marketing website are described in the Cookie Policy.
12. Children
omvio is not directed at children and we do not knowingly collect personal data from anyone under 16. If you believe a child’s data has reached us, write to privacy@aa-labs.co and we will delete it.
13. Changes to this policy
We will post any change here with a new version number and effective date. For material changes affecting how we use personal data, we will notify account owners by email at least 30 days before the change takes effect. Superseded versions are available on request.
14. Contact us
- Controller: A & A Labs, Pakistan.
- Privacy enquiries: privacy@omvio.app
- Data protection contact: dpo@aa-labs.co
- Security: security@aa-labs.co