Privacy Policy
This Privacy Policy explains how omni.az (the “Platform”, “we”), operated by Azerizone MMC, collects, uses, stores, shares and deletes personal data, including data received from Google APIs.
1. Data we collect
- Account data of our customers’ employees: name, email, role, sign-in and security data.
- Customer communication data that businesses process through the Platform: messages, calls and call recordings, leads, comments, deals, meetings and tasks.
- Integration data: OAuth tokens and account identifiers of services a user connects (for example Google, Microsoft, Meta, TikTok), and the data those services return within the permissions the user granted.
2. How we use data
We use data only to provide and operate the Platform: handling customer requests, processing leads and comments, scheduling meetings, analytics for the business that owns the data, security and support. We do not sell personal data and do not use it for advertising.
3. Google user data (Google Calendar)
An employee of a business that uses omni.az may connect their own Google account to sync their calendar. This is optional and initiated by the employee.
3.1. What we access
openid,email— the email address of the connected Google account, to show which account is connected.calendar.calendarlist.readonly— the list of the user’s calendars (names and IDs), so the user can choose which calendar omni.az writes to.calendar.app.created— to create a separate secondary calendar named “omni.az” and manage events in it, if the user chooses that option.calendar.events— to read events of the user’s primary calendar (title, start and end time, all-day flag, busy/free status and event ID; starting from the previous day) and to create, update and delete the events that omni.az itself adds to the calendar chosen by the user.
We do not read event attendees, descriptions, locations or attachments of the user’s own events, and we do not change or delete events that omni.az did not create.
3.2. How we use it
- Busy times are used to show the employee’s availability inside omni.az and to prevent customers and colleagues from booking a time that is already taken. Colleagues see only busy intervals; event titles are visible only to the employee who connected the account.
- Meetings and tasks with a due time that are created in omni.az are added to the chosen Google calendar and kept in sync; for online meetings a Google Meet link may be created.
3.3. Storage and protection
OAuth access and refresh tokens are stored encrypted. Data is stored on our servers with per-company isolation at the database level and transmitted only over HTTPS. Access to production systems is limited to authorised staff.
3.4. Sharing
We do not sell, rent or transfer Google user data to third parties. It is not shared with other companies using the Platform. It may be processed only by our infrastructure (hosting) providers on our behalf, or disclosed when required by law.
3.5. Retention and deletion
Data is kept while the calendar is connected. When the user (or their company administrator) disconnects the calendar, or the employee’s account is deactivated, we delete the events omni.az created in Google Calendar (or the whole “omni.az” calendar), revoke our access token at Google, and erase the stored tokens and all synced event data from our database. A user can also revoke access at any time at myaccount.google.com/permissions, or request deletion by email (section 6).
3.6. Limited Use
omni.az’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide the user-facing calendar features described above. We do not use it for advertising, we do not use it to develop, improve or train generalised AI or machine learning models, and humans do not read it unless the user has given explicit consent, it is necessary for security purposes or to comply with applicable law.
4. Other third-party platforms
When a user connects other accounts (for example Meta, Instagram, TikTok, WhatsApp, Microsoft), we access data only within the permissions granted and process it according to the rules of those platforms. The user can disconnect an integration at any time.
5. Storage and security
Integration tokens are encrypted, data of each company is isolated at the database level (row-level security), and all traffic is encrypted with TLS.
6. Your rights and data deletion
You can request access to, correction of or deletion of your account and related data by writing to info@azerizone.net.
7. Changes
We may update this policy; the current version is always published on this page with its date.
8. Contact
Azerizone MMC · info@azerizone.net