VERSION 2026-10-10.1 · 10 OCTOBER 2026

Privacy Notice

1. Who is responsible

Abontech, India operates Omni and the Abontech products. Contact meet@abontech.com for privacy questions or requests. For account, security and billing administration, we decide the processing purposes. For customer-uploaded contacts, conversations and scheduling information, the customer organization usually determines the business purpose and we provide the instructed service. Our role and obligations depend on the particular processing and applicable law.

If a business contacted you through our products, that business also has responsibilities for its outreach and its own copies. You may contact the sender and Abontech. We may verify identity and authority before disclosing or changing records; never send a password, OTP or full payment-card number.

2. Information processed

Account information includes name, email, identity-provider identifier, organization membership, roles, verification status, security/session records and the version/time of terms acceptance. Business information can include names, business email addresses, phone numbers, profile URLs, company/domain details, custom fields, lists, tags and suppression choices.

Messaging data can include connected sender/account identifiers, recipients, subjects, message bodies, attachments handled by the relevant feature, provider/message/thread IDs, campaign and sequence IDs, timestamps, delivery/reply events, classifications and operator notes. Where enabled, tracking links or pixels can produce open/click events and technical request data. Opens may be generated by proxies or bots and are not proof of human interest.

Calendar information can include availability, connected-calendar identifiers and tokens, permitted event details needed for conflict checking/synchronization, bookings, invitee answers, guest details, reminders and host-authorized webhook events. Finder processes search inputs, candidate addresses, DNS/SMTP checks and result history. Billing information includes credit grants/reservations/charges, order references, amount, status and reconciliation records; a payment provider handles payment instruments.

Do not submit passwords in contact notes, unnecessary sensitive personal information, children’s data, or information you lack authority to provide. Provider credentials and session material are used for authorized connections, not as content for intent analysis.

3. Sources and purposes

Information comes from you and your members, authorized imports/transfers, connected providers, people who reply or book, available public/business research sources, and technical events generated by use of the service. We use it for verified sign-in, organization permissions, connected accounts, requested outreach and scheduling, reply handling, available organization-specific analysis, billing, support, abuse prevention and recovery.

The Data, Replies & Retention Notice identifies the content-and-timing signal system that is planned and distinguishes it from current reply classification. We do not combine customers’ private conversations into a shared prospect database or authorize cross-customer model training through signup. The same prospect appearing in two organizations does not merge those organizations’ private histories.

The applicable basis for processing may be your service instructions/contract, consent where required, legal obligations, or legitimate interests where recognized and properly assessed. A customer must establish its own lawful basis and notices for prospect/recipient data. Accepting these terms is not consent from every person in an imported list.

4. Sharing and international processing

Authorized members see records according to product permissions. Requested transfers send selected fields to the chosen destination product/workspace. A common login does not grant every member access to every sender account or another organization.

We use Google Cloud for the GCP-hosted products and Omni, and Contabo for Email Finder. Identity, storage, backup, transactional email, monitoring, payment and connected provider services process information necessary to their function. Research or analysis features can use configured local models or providers such as Anthropic, OpenAI or Google, depending on the feature and configuration. Only the inputs needed for the enabled operation should be sent; customer records are not made public merely because a provider processes them.

Provider operations and support can involve countries outside India or your location. Applicable transfer safeguards and provider terms must be observed. We do not promise that every product or backup stays in one country. Contact us for the current arrangement relevant to your deployment or a required data-processing agreement.

We may disclose limited records when lawfully required, to investigate abuse/security issues, or to establish or defend a legal claim. A business transfer does not remove existing privacy obligations. We do not sell customer contact lists or message content.

5. Google-connected data

The use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements, and applicable Google Workspace policies. Mailbox data is used for disclosed email features; calendar data is used for scheduling and synchronization. Connecting a calendar does not authorize mining private calendar content for outreach intent.

Google-connected information is not used for advertising profiles, sold, or used to train or improve generalized/shared AI models. Any permitted personalized feature must remain within the appropriate user-facing use case and provider restrictions. The proposed after-closure archive/analysis policy does not override a provider’s deletion, retention or permanent-copy restrictions.

Human access to Google data is limited to the circumstances permitted by those policies, such as your specific affirmative authorization, necessary security/abuse investigation or legal obligations. You may disconnect an integration and revoke access through your Google Account connections. Disconnecting stops future authorized access; it does not recall messages already delivered to another person.

6. Retention, closure and backups

Retention depends on the data and purpose. Active organizational contacts/conversations generally remain until the organization removes them or an applicable rule requires deletion. Ordinary account closure is not the same as an erasure request. A 30-day recovery request window does not promise that shorter-lived Finder results or already-deleted provider data can be restored.

Some closed-workspace business records and derived signals do not have a fixed automatic expiry. They may be held in a restricted archive while a specific disclosed purpose remains necessary and lawful. We review requests to erase or restrict such data; this notice is not a waiver allowing perpetual retention of all identifiable records. Continued post-closure analysis is planned, not activated by this notice or the signup checkbox.

Finder’s ordinary result history and encrypted operation replay payloads use a three-day window in the application. A result explicitly saved/transferred elsewhere is a separate copy with that destination’s retention. Omni transfer payloads normally expire after 24 hours; operation status, deduplication and billing evidence can remain.

Credit/payment ledgers, acceptance evidence, minimal security/dispute records and suppression identifiers may need longer retention for a lawful purpose. We do not retain complete message content merely because a minimal billing or opt-out record is needed. Legal holds are restricted to the affected records and reviewed when the hold ends.

Omni and Finder automated off-host backups have a 30-day cloud lifecycle; completed local backup uploads use a 14-day policy. Isolated recovery copies and other products’ backups must be assessed separately; these windows are not a universal promise covering every copy. Backup expiry is not a substitute for deleting active copies. Recovery must respect valid prior erasure/restriction requests and cannot silently reopen a closed account.

7. Security and device storage

Safeguards include authenticated access, organization/product permission checks, protected transport, restricted credentials, audit records and encrypted operational backups where configured. These controls do not mean that all content is end-to-end encrypted or inaccessible to the service when processing it. No system can promise absolute security.

Omni uses essential cookies and browser storage for sessions, sign-in state and interface preferences. The Omni installable app caches its static offline explanation, stylesheet and icon; its service worker does not cache authentication, wallet or customer API responses. Customer-directed email tracking is distinct from website advertising tracking. Browser/provider tools let you clear storage or revoke connections, with possible loss of sessions or functionality.

8. Your choices and rights

Depending on applicable law, you may request access, correction, export/portability, erasure, restriction or objection, withdraw consent for a consent-based purpose, and complain to the relevant regulator. Mandatory rights apply even if you accepted these terms. Withdrawal does not make earlier lawful processing unlawful, but it can require stopping a purpose or deleting affected data.

Email meet@abontech.com with the relevant organization and request type. We verify identity, locate the affected products and respond within the applicable legal deadline, explaining any lawful exception or extension. A team member’s request does not automatically authorize deletion of every record belonging to their employer or other people.

For a closure request, specify whether you mean your login, a sender connection, or the whole organization. For erasure, say that you are requesting erasure; closure alone is not treated as proof that every shared record must be destroyed. You can also ask us to stop proposed post-closure analysis or challenge a particular retention purpose.

9. Updates

This notice carries a version and effective date. We communicate material changes and obtain new permission where required before changing a consent-based purpose. New optional purposes are not silently covered by an old signup checkbox. Previous published versions remain available for reference.

Related documents

Keep a copy of the version you accept. Your browser’s Print command can save this page as a PDF.