Roles
When an organization processes its customers’ telephone data through OMO, the organization usually determines the purpose and means of processing, while OMO follows its documented instructions. OMO may act as an independent controller for account, billing, and platform-security data.
Scope of processing
- Receiving and conducting a telephone session
- Speech-to-text conversion and response synthesis
- Execution of conversational workflow stages and business actions
- Storage of recordings, transcripts, technical events, and outcomes
- Support, monitoring, security and recovery
Documented instructions
Account configuration, active conversation process, API requests, order and contract are considered valid instructions. Upon detection of an illegal or clearly inappropriate instruction, OMO is entitled to suspend execution and request clarification.
sub-processors
The Services may use cloud infrastructure, telephony, voice AI, email, payment and monitoring providers. They receive only the necessary data and are subject to confidentiality and security obligations. A specific list is available under contract or on request.
Security and Incident
- Logical separation of users and workspaces
- Role-based access and audit trails
- Encryption in transport and separate storage of secrets
- Backups and controlled recovery procedures
- In the event of a confirmed incident, informing the user in accordance with the law and the contract
Help and delete
OMO reasonably assists the controller in data subject requests, security assessments and incident processing. At the end of the service, the data is returned, deleted or anonymized for the agreed period, unless the law requires longer storage.
