ALL SYSTEMS OPERATIONAL99.99% UPTIME SLA
24/7 SUPPORT: +44 20 3807 5021

LEGAL

Privacy Policy

How Omega Cloud collects, uses and protects personal data across our London, Sofia and Singapore operations.

Last reviewed: 19 August 2026

1. Who we are

Omega Cloud Ltd ("Omega Cloud", "we", "us") provides cloud infrastructure, cybersecurity and managed IT services from regional hubs in London, Sofia and Singapore. Our registered office is [REGISTERED OFFICE ADDRESS] and our company number is [COMPANY NUMBER].

For anything described in this policy, contact us at [email protected].

2. The two roles we act in

As a controller — for data about visitors to this website, prospects and contacts at client organisations, and job applicants. We decide why and how that data is processed, and this policy governs it.

As a processor — for data held inside systems we operate on a client's behalf. There, the client is the controller and the terms of the signed services agreement and data processing agreement govern, not this policy.

3. What we collect

  • Contact and enquiry data — name, work email, organisation, telephone number and the content of your message when you submit a form or request an audit.
  • Technical data — IP address, browser and device type, pages viewed, referring URL and approximate location derived from IP. Collected through cookies and similar technologies, and only to the extent you consent.
  • Correspondence — emails, tickets and call notes exchanged with our support and engineering teams.
  • Recruitment data — CVs and application details you send us, held for the duration of the recruitment process.

We do not seek special category data through this website. Please do not include it in a form submission.

4. Why we process it, and on what basis

  • To respond to enquiries and provide services — performance of a contract, or steps taken at your request before entering one.
  • To operate, secure and improve the site — our legitimate interest in a functioning, defended service. This includes rate limiting, bot mitigation and abuse prevention.
  • To measure how the site is used — your consent, given through the cookie banner and withdrawable at any time.
  • To meet legal and regulatory obligations — including accounting, tax and lawful requests from competent authorities.

5. Who we share it with

We do not sell personal data. We share it only with service providers who process it on our instructions under written terms:

  • Email delivery and marketing platforms used to answer enquiries and send operational notices.
  • Infrastructure, CDN and security providers who host and protect this site.
  • Analytics providers, where you have consented to analytics cookies.
  • Professional advisers, auditors and insurers, where necessary and confidential.

A current list of sub-processors is available to clients on request from [email protected].

6. International transfers

We operate across the United Kingdom, the European Union, the United Arab Emirates and Singapore, so personal data may be transferred between those regions. Where data leaves the UK or EEA, transfers are covered by an adequacy decision or by Standard Contractual Clauses together with a transfer risk assessment. Details are available on request.

7. How long we keep it

  • Enquiry and contact records — [RETENTION PERIOD, e.g. 24 months] after our last contact with you.
  • Client contract and billing records — the term of the contract plus the period required by law.
  • Recruitment records — [RETENTION PERIOD, e.g. 6 months] after the process closes, unless you agree to a longer period.
  • Website analytics — the retention window configured in the analytics platform, currently [ANALYTICS RETENTION].

8. Your rights

Subject to the applicable law, you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing carried out on the basis of legitimate interests. Where processing rests on consent, you may withdraw it at any time without affecting prior processing.

To exercise a right, email [email protected]. We respond within one month. If you are not satisfied, you may complain to your supervisory authority — in the United Kingdom, the Information Commissioner's Office.

9. Security

We apply the controls expected of an infrastructure provider: encryption in transit and at rest, least-privilege access with multi-factor authentication, network segmentation, logging and monitoring, documented incident response, and regular review of our suppliers. No system is absolutely secure; we notify affected parties and regulators where a breach requires it.

10. Changes

We update this policy when our processing changes. The review date at the top always reflects the current version.