Privacy Policy

Work in progress.

Overview
#

We are reviewing and updating the OmegaSafe Cloud privacy policy before opening registration. OmegaSafe Cloud is not currently accepting registrations.

The completed policy will be published here before the service becomes available. For questions in the meantime, contact legal@omega-safe.com.

4. Cookies and similar browser storage
#

This section is being reviewed and will be published before registration opens.

12. How long do we keep your personal data?
#

When you deactivate an eligible account, a 30-day recovery period begins. Your account is scheduled for automatic deletion after that period. If you complete reactivation before the recovery period ends, the scheduled deletion is cancelled.

Registrations that are never activated and key-sharing invitations expire after 30 days. Pending replacement-email data is removed no later than seven days after its verification code expires. Invitations are removed earlier when accepted, declined, withdrawn, or when the addressed user’s account is erased. Salted email-delivery anti-abuse hashes are used only for security and are automatically purged after their 30-day retention period.

Some information may remain after account deletion where we must retain it for legal, tax, accounting, fraud-prevention, or dispute purposes. Protected backup copies may also remain unavailable for ordinary use until their fixed retention period expires. The completed policy will identify those categories and periods before registration opens.

Security and operational logs may contain an IP address, timestamp, request method and path, response and timing information, user agent, security events, and pseudonymous account or service references. Request query strings are excluded from our access-log format. We use these logs for service delivery, troubleshooting, reliability, abuse and fraud control, rate limiting, security, and support. Access is restricted. The retention controls being applied are designed to delete all managed service, infrastructure, deployment, and authorised operator copies within a strict maximum of 30 days. Account deletion does not rewrite these logs; under those controls, any related entry remains restricted only until its scheduled expiry and is not used to recreate the account.

Registration remains closed while we complete the full policy and the remaining launch governance. The retention controls described above are deployed across the live service and authorised operator systems and were verified during the production deployment on 31 July 2026. They govern scheduled expiry rather than rewriting retained operational records early.

13. Your data rights under GDPR
#

This section is being reviewed and will be published before registration opens.