Privacy Policy
Omnisim — Version 1.0 Effective date: 1 August 2026
Authoritative version. This policy is made available in several languages for your convenience. In the event of any discrepancy in interpretation between those versions, this English version alone shall prevail.
1. Who processes your data
The data controller is:
Omnisim OÜ, a company incorporated under the laws of Estonia, registered with the Estonian Commercial Register (Tartu Maakohtu registriosakond) under registration code 17556339, having its registered office at Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Harju maakond, Estonia.
Contact: contact@getomnisim.com
2. What this policy covers — and what it does not
It covers the processing for which Omnisim itself decides the purposes and means:
- browsing the
getomnisim.comwebsite; - enquiries sent through the contact form;
- creating and managing an account on the NEXUS platform (
app.getomnisim.com); - the contractual relationship with Omnisim's professional customers.
It does not cover drivers' data — that of the people who book or take a session at a simulation centre. For that data, the controller is the centre, not Omnisim, which acts only as a processor, on the centre's instructions and on its behalf.
A driver wishing to exercise their rights must therefore contact the centre with which they booked or played. The centre publishes its own privacy policy; Omnisim does not determine its content. Omnisim's obligations as a processor are set out in Annex 2 to its Terms of Sale and Use.
3. What data is processed
3.1. Website visitors
The getomnisim.com website contains no advertising tracker, no audience measurement tool and no tracking cookie. No browsing profile is built.
The following are processed: the technical connection data necessary to deliver the pages (IP address, browser type, pages viewed), together with a language preference stored in a functional cookie.
3.2. People contacting Omnisim
Through the contact form: name, email address, company (optional), subject of the enquiry, content of the message, language, originating page, together with the IP address and browser identifier at the time of sending — the latter two being used exclusively to prevent abusive automated submissions.
3.3. Customers and NEXUS users
- On registration: company name, administrator's email address, country of establishment, language.
- On paid subscription: billing address and, where applicable, EU VAT number, collected by Stripe at the time of payment.
- During use: email address and role of each authorised user, connection logs, administrative actions, station licence activations, billing events, exchanges with support.
- Technical: application error reports, which may contain an IP address or a user identifier.
Omnisim processes no special category of data within the meaning of Article 9 GDPR, and stores no payment card data: payments are processed by Stripe, which alone holds it.
4. Why, and on what basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Responding to an enquiry sent through the contact form | Pre-contractual steps at the request of the person, or legitimate interest in replying |
| Creating and managing an account, providing the Services | Performance of the contract |
| Invoicing, collecting and recovering payment | Performance of the contract; legal obligation for accounting records |
| Providing support and assistance | Performance of the contract |
| Ensuring security, preventing fraud and abuse, logging access | Legitimate interest in protecting the platform and its users |
| Diagnosing errors and improving reliability | Legitimate interest in the proper operation of the service |
| Remembering the chosen language | Legitimate interest in serving the page in the right language |
| Complying with accounting and tax obligations | Legal obligation |
| Establishing, exercising or defending a legal claim | Legitimate interest |
| Sending information about the service to an existing customer | Legitimate interest, with a permanent right to object |
Where processing is based on Omnisim's legitimate interest, the data subject may object at any time under the conditions of section 9.
No decision producing legal effects is taken by automated means, and no profiling is carried out.
5. Where the data comes from
Data comes directly from the data subjects, with the exception of:
- billing and payment status data transmitted by Stripe;
- technical data generated automatically by browsing the website or using the platform.
Omnisim purchases no prospecting lists and collects no data from data brokers.
6. Who has access to it
Data is accessible to strictly authorised Omnisim personnel, and to the following technical providers, acting as processors:
| Provider | Role | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | European Union |
| Heroku (Salesforce) | Hosting of the application API | European Union |
| Vercel Inc. | Hosting of the website and web application | United States (EU–U.S. Data Privacy Framework) |
| Cloudflare | Delivery, protection, DNS resolution | Worldwide network |
| Stripe Payments Europe, Ltd. | Payment and billing | European Union |
| Mailgun (Sinch) | Sending transactional emails | European Union |
| Sentry | Application error logging | European Union |
No data is sold, rented or transferred for advertising purposes.
Data may also be disclosed to an administrative or judicial authority where required by law, and to Omnisim's advisers in defending its rights.
7. Transfers outside the European Union
Processing takes place within the European Union, save by way of exception. Where a transfer outside the European Economic Area occurs, it is governed by an appropriate safeguard within the meaning of Chapter V GDPR: an adequacy decision of the European Commission — in particular the EU–U.S. Data Privacy Framework, to which Vercel Inc. adheres — or, failing that, standard contractual clauses.
8. How long data is retained
| Data | Period |
|---|---|
| Enquiry sent through the contact form | 3 years from the last exchange |
| Customer account and users | Term of the contract, then 90 days (deletion period) |
| Customer content and settings | Term of the contract, then 90 days |
| Connection and security logs | 12 months |
| Application error reports | 90 days |
| Accounting records and invoices | Period required by Estonian accounting law |
| Records relating to VAT on electronically supplied services | Period required by the applicable regulations |
| Items useful as evidence in the event of a dispute | Until the applicable limitation periods have expired |
At the end of those periods, the data is deleted. Data retained under a legal obligation is held in restricted-access archives and is no longer used.
Data held in residual backups is no longer accessible in production and is erased in accordance with the backup rotation cycle.
9. Your rights
Every data subject has the following rights: access, rectification, erasure, restriction of processing, objection to processing based on legitimate interest, and portability of the data they have provided.
These rights are exercised at contact@getomnisim.com. Omnisim replies within one month, which may be extended by two months for complex requests, in which case the person is informed. Proof of identity may be requested in the event of reasonable doubt.
Drivers: contact your centre. Omnisim cannot reply directly to a request concerning data for which a centre is responsible; it will forward the request to the centre concerned.
Complaints. Any person may lodge a complaint with the Estonian Data Protection Inspectorate, the Andmekaitse Inspektsioon (Tatari 39, 10134 Tallinn, Estonia — info@aki.ee), or with the supervisory authority of their country of residence.
10. Cookies and trackers
The website and the platform use strictly necessary cookies only, which are exempt from consent within the meaning of Article 5(3) of Directive 2002/58/EC. That is why no consent banner is displayed: there is nothing to consent to.
| Cookie | Role | Duration |
|---|---|---|
| Language preference | Serving pages in the chosen language | 1 year |
| NEXUS authentication session | Keeping the user signed in | Duration of the session |
No advertising cookie, no third-party tracker and no audience measurement tool is placed.
11. Security
Omnisim implements appropriate technical and organisational measures, in particular: encryption of communications, segregation of access by client and by centre, authentication of administrative access, encryption of sensitive secrets at rest, access logging, rate limiting of public interfaces and regular backups.
In the event of a data breach likely to result in a high risk to the rights and freedoms of the data subjects, Omnisim shall inform them in accordance with Article 34 GDPR.
12. Changes to this policy
Omnisim may amend this policy. Any substantial change is brought to customers' attention by email or by message within NEXUS. The effective date shown at the head of the document indicates the applicable version.
13. Contact
For any question relating to data protection:
Omnisim OÜ — Sepapaja tn 6, Lasnamäe linnaosa, 15551 Tallinn, Harju maakond, Estonia contact@getomnisim.com