LEGAL
How Omega Cloud collects, uses and protects personal data across our London, Sofia and Singapore operations.
Last reviewed: 19 August 2026
Omega Cloud Ltd ("Omega Cloud", "we", "us") provides cloud infrastructure, cybersecurity and managed IT services from regional hubs in London, Sofia and Singapore. Our registered office is [REGISTERED OFFICE ADDRESS] and our company number is [COMPANY NUMBER].
For anything described in this policy, contact us at [email protected].
As a controller — for data about visitors to this website, prospects and contacts at client organisations, and job applicants. We decide why and how that data is processed, and this policy governs it.
As a processor — for data held inside systems we operate on a client's behalf. There, the client is the controller and the terms of the signed services agreement and data processing agreement govern, not this policy.
We do not seek special category data through this website. Please do not include it in a form submission.
We do not sell personal data. We share it only with service providers who process it on our instructions under written terms:
A current list of sub-processors is available to clients on request from [email protected].
We operate across the United Kingdom, the European Union, the United Arab Emirates and Singapore, so personal data may be transferred between those regions. Where data leaves the UK or EEA, transfers are covered by an adequacy decision or by Standard Contractual Clauses together with a transfer risk assessment. Details are available on request.
Subject to the applicable law, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting prior processing.
To exercise a right, email [email protected]. We respond within one month. If you are not satisfied, you may complain to your supervisory authority — in the United Kingdom, the Information Commissioner's Office.
We apply the controls expected of an infrastructure provider: encryption in transit and at rest, least-privilege access with multi-factor authentication, network segmentation, logging and monitoring, documented incident response, and regular review of our suppliers. No system is absolutely secure; we notify affected parties and regulators where a breach requires it.
We update this policy when our processing changes. The review date at the top always reflects the current version.