OMEGAWRIGHT / Privacy
Effective July 10, 2026
Section 1. Definitions
1.1 “Company,” “we,” “us,” and “our” mean Blockchain Omega Ltd, a Colorado company with its registered office at 1500 N Grant St, Ste R, Denver, CO 80203, USA, trading as “Omegawright.”
1.2 “Site” means the website located at omegawright.com and any successor, mirror, or related subdomain operated by Company.
1.3 “Services” means the software development and maintenance services Company provides to Clients under an Engagement Agreement, as described in Section 3 (Service Description) and in Section 4 of the Terms of Service.
1.4 “Terms of Service” means Company’s terms of service published at omegawright.com/terms, as amended from time to time, which is incorporated into this Privacy Policy by reference. Capitalized terms used and not defined in this Privacy Policy have the meanings given in the Terms of Service.
1.5 “Personal Data” means any information relating to an identified or identifiable natural person, and includes “personal information” as used in applicable U.S. state privacy statutes.
1.6 “Data Subject” means the natural person to whom Personal Data relates, including a “consumer” as defined under applicable U.S. state privacy statutes.
1.7 “Controller” means the entity that determines the purposes and means of processing Personal Data (or the equivalent role under applicable Data Protection Law, including a “business” under U.S. state privacy statutes).
1.8 “Processor” means the entity that processes Personal Data on behalf of, and under the documented instructions of, a Controller (or the equivalent role under applicable Data Protection Law, including a “service provider” or “contractor” under U.S. state privacy statutes).
1.9 “Data Protection Law” means all applicable laws and regulations governing the processing of Personal Data, including, where applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the UK General Data Protection Regulation as it forms part of UK law by virtue of the Data Protection Act 2018 (“UK GDPR”), and applicable U.S. state privacy statutes, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations (“CCPA”).
1.10 “Client” means any individual or entity that has entered into, or is negotiating toward, an Engagement Agreement with Company.
1.11 “Client Customers” means the customers, users, employees, or other individuals whose Personal Data a Client collects, controls, or processes in connection with the Client’s own business.
1.12 “Subprocessor” means a third party engaged by Company to process Personal Data on Company’s behalf in Company’s capacity as a Processor or Controller, as applicable.
1.13 “Supervisory Authority” means an independent public authority responsible for monitoring the application of Data Protection Law, including the UK Information Commissioner’s Office and the data protection authority of an EU member state with jurisdiction over the relevant processing.
Section 2. Scope and Roles
2.1 This Privacy Policy describes how Company handles Personal Data in two distinct capacities, which this Privacy Policy addresses separately because the applicable obligations differ:
(a) Company as Controller. With respect to Personal Data that Company collects about Site visitors, prospective Clients, business contacts, and Company’s own personnel and vendor contacts, Company acts as a Controller. Sections 4 through 12 and Section 14 of this Privacy Policy primarily address this capacity.
(b) Company as Processor. With respect to Personal Data that a Client, or a Client Customer, submits to or through a Deliverable that Company builds or maintains for a Client, Company acts, in most engagements, as a Processor on the Client’s documented instructions, and the Client acts as Controller of that Personal Data. Section 13 (Client and Client Customer Data; Processor Role) addresses this capacity.
2.2 This Privacy Policy governs the Site and Company’s Controller-capacity processing described in Section 2.1(a). It does not govern a Client’s own privacy practices toward its Client Customers, which are addressed by the Client’s own privacy policy and, as between Company and the Client, by the applicable Engagement Agreement and any data processing addendum.
2.3 This Privacy Policy applies to omegawright.com and does not apply to third-party websites or services linked from the Site, including a Third-Party Service described in Section 9, each of which is governed by its own privacy policy.
Section 3. Service Description
3.1 Consistent with Section 4 of the Terms of Service, Company provides software development and maintenance services to Clients. These Services, and the data Company processes while providing them, are distinct from, and not to be confused with, a Client’s own services, business, or its data practices toward its Client Customers, which are addressed in Section 13.
Section 4. Personal Data We Collect
4.1 Contact and quote form data. When you submit the Site’s contact form or quote request form, Company collects the name, email address, business name, and project description you provide, together with any other information you choose to include in your message.
4.2 Booking data. When you book a call through the Site’s scheduling interface, the booking is processed by a third-party scheduling provider under that provider’s own privacy policy, as noted in Section 9.2(c). Company receives the name, email address, and meeting details (including any notes you enter) needed to conduct the meeting.
4.3 Site usage data. Company operates self-hosted website analytics infrastructure to understand aggregate Site usage, such as pages visited, referring source, device and browser type, and approximate geographic region derived from IP address. This infrastructure is operated by Company rather than a separate third-party analytics company, and Company’s implementation does not set a persistent cross-site tracking cookie.
4.4 Correspondence. If you email Company directly, Company collects the contents of that correspondence and your contact details.
4.5 Company does not knowingly collect special categories of Personal Data (such as health, biometric, or precise geolocation data) through the Site, and asks that you not include such information in a form submission or message.
Section 5. Sources of Personal Data
5.1 Company collects Personal Data described in Section 4 directly from you when you submit it through the Site, through the scheduling provider, or by email, and, with respect to Site usage data, automatically as you interact with the Site.
Section 6. How We Use Personal Data
6.1 Company uses Personal Data described in Section 4 to: (a) respond to inquiries and quote requests; (b) schedule and conduct calls; (c) evaluate, negotiate, and, where the parties proceed, perform an Engagement Agreement; (d) operate, secure, and improve the Site and the Services, including understanding how the Site is used so Company can improve it; (e) comply with legal, tax, accounting, and regulatory obligations; and (f) establish, exercise, or defend legal claims.
6.2 Company collects information about Clients, Users, and their use of the Services in order to provide the Services requested and to improve those Services and the Site over time; Company does not use Personal Data described in Section 4 to build a profile of a Data Subject for purposes unrelated to those stated in this Section 6.
Section 7. Legal Bases for Processing (GDPR / UK GDPR)
7.1 Where GDPR or UK GDPR applies to Company’s processing of Personal Data as Controller, Company relies on the following lawful bases, as applicable to the specific processing activity:
(a) Contract (Article 6(1)(b)): processing necessary to respond to your inquiry, negotiate an Engagement Agreement, or perform an Engagement Agreement to which you or your organization is a party;
(b) Legitimate interests (Article 6(1)(f)): processing necessary for Company’s legitimate interests in operating and securing the Site, understanding aggregate Site usage, and marketing its Services in a manner proportionate to the interests and rights of Data Subjects;
(c) Legal obligation (Article 6(1)(c)): processing necessary to comply with a legal or regulatory obligation to which Company is subject; and
(d) Consent (Article 6(1)(a)): where Company relies on consent for a specific processing activity, that consent may be withdrawn at any time as described in Section 14.
Section 8. No Sale, Rental, or Trading of Personal Data
8.1 Company does not sell, rent, trade, or otherwise make available for monetary or other valuable consideration any Personal Data of a Site visitor, Client, Client contact, or Client Customer, whether processed by Company as Controller or as Processor. Company has not sold or shared Personal Data, as those terms are defined under the CCPA, in the twelve (12) months preceding the effective date of this Privacy Policy, and does not intend to do so.
8.2 Disclosures described in Section 9 (Third-Party Services and Subprocessors) are made to enable those third parties to perform services on Company’s behalf, or, in the case of the scheduling provider, to provide a service you have requested, and do not constitute a sale, rental, or trade of Personal Data.
Section 9. Third-Party Services and Subprocessors
9.1 Company discloses Personal Data described in Section 4 to third-party providers in the following categories, each engaged to support the Site or the Services:
(a) Payment processing. Used to process payments Company bills to Clients under an Engagement Agreement.
(b) Email delivery. Used to send and receive correspondence arising from the Site’s contact and quote forms.
(c) Scheduling. Used to manage bookings and calendar invitations, as described in Section 4.2.
(d) Hosting and content delivery. Used to host and serve the Site.
(e) Analytics. As described in Section 4.3, Company’s website analytics infrastructure is self-hosted; to the extent the underlying infrastructure runs on a third-party cloud or hosting provider, that provider does not independently use the analytics data for its own purposes.
9.2 This Privacy Policy identifies these categories rather than binding Company to a specific named provider, so that Company may change providers within a category without amending this Privacy Policy. An informational, non-binding list of the providers currently used within each category appears in Annex A. Annex A may be updated without a corresponding amendment to the binding text of this Privacy Policy, provided the categories in this Section 9 remain accurate.
9.3 Where a Subprocessor processes Personal Data on Company’s behalf, Company enters into a written agreement with that Subprocessor imposing data protection obligations consistent with this Privacy Policy and, where required, with GDPR Article 28 or the equivalent provision of applicable Data Protection Law.
9.4 Company may also disclose Personal Data: (a) to comply with a legal obligation, court order, or governmental request; (b) to protect the rights, property, or safety of Company, its Clients, or the public; (c) in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protection; and (d) with your consent.
Section 10. International Data Transfers
10.1 Company is based in the United States and processes Personal Data in the United States and in the jurisdictions where its Subprocessors operate. Where Company receives Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland, and that transfer is a restricted transfer under GDPR, UK GDPR, or Swiss data protection law, Company relies on an appropriate transfer mechanism, which may include: (a) the European Commission’s Standard Contractual Clauses; (b) the UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses; or (c) another mechanism recognized under applicable Data Protection Law, in each case together with a transfer risk or impact assessment where required.
10.2 Company does not currently offer goods or services to, or monitor the behavior of, data subjects located in the European Economic Area or the United Kingdom, and therefore has not designated a representative under GDPR Article 27 or the UK GDPR. If Company’s activities change such that a representative becomes required, Company will designate one and update this Section with that representative’s identity and contact details.
10.3 Where Company acts as Processor for a Client’s international transfers in connection with the Services, the transfer mechanism applicable to that processing is addressed in the data processing addendum referenced in Section 13.4, rather than in this Section 10.
Section 11. Data Retention
11.1 Company retains Personal Data described in Section 4 only for as long as reasonably necessary for the purposes described in Section 6, to comply with applicable legal, tax, or accounting obligations, to resolve disputes, and to enforce Company’s agreements.
11.2 Absent a longer retention requirement under applicable law or a specific engagement’s needs, Company’s default retention periods are: (a) contact and quote form submissions that do not lead to an engagement, twenty-four (24) months from last contact; (b) booking and scheduling data, retained per the scheduling provider’s own retention practice and, in Company’s own records, twenty-four (24) months from the meeting date; and (c) records related to an executed Engagement Agreement, retained for the duration of the engagement plus seven (7) years. These periods are maintained in greater detail in Company’s internal data retention schedule, available on request.
11.3 Site usage data described in Section 4.3 is retained in aggregate or pseudonymized form and is not used to re-identify a specific Data Subject.
Section 12. Data Security
12.1 Company maintains administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, appropriate to the nature of the Personal Data involved and consistent with prevailing industry practice (a “best-efforts security posture”). No method of transmission or storage is completely secure, and Company cannot guarantee absolute security.
12.2 Consistent with Section 12.2 of the Terms of Service, Company disclaims liability, to the maximum extent permitted by applicable law, for a security incident that originates, in whole or in part, in a third-party or supply-chain compromise, including a compromise of a Subprocessor, open-source dependency, hosting provider, or other vendor in Company’s or a Client’s software supply chain, whether or not related to Company.
12.3 If Company becomes aware of a security incident affecting Personal Data for which it acts as Controller, Company will notify affected Data Subjects and, where legally required, the applicable Supervisory Authority or regulator, without undue delay and consistent with applicable Data Protection Law. Notice obligations with respect to Personal Data for which Company acts as Processor are addressed in the applicable data processing addendum.
Section 13. Client and Client Customer Data; Processor Role
13.1 In the course of providing Services, Company may process Personal Data that a Client controls, including Personal Data of that Client’s own Client Customers, as part of building, hosting, or maintaining a Deliverable. In that capacity, Company acts as a Processor (or equivalent) on the Client’s documented instructions, and the Client acts as the Controller (or equivalent, including “business” under CCPA) of that Personal Data.
13.2 Company does not determine the purposes or means of a Client’s processing of its Client Customers’ Personal Data, does not independently use that Personal Data for Company’s own purposes, and does not sell, rent, or trade that Personal Data, consistent with Section 8.
13.3 Company cannot and does not govern, and bears no liability for, a Client’s own collection, use, disclosure, retention, security practice, or other processing of its Client Customers’ Personal Data, including where that Client fails to obtain a valid legal basis, fails to honor a Data Subject’s rights request, or otherwise processes that data unlawfully. As between Company and a Client, responsibility for the lawfulness of that processing, and for responding to Client Customers and Supervisory Authorities with respect to it, rests solely with the Client in its capacity as Controller. This allocation reflects the respective legal roles of Controller and Processor under Data Protection Law and does not depend solely on contractual language.
13.4 Where required by Data Protection Law or requested by a Client, Company makes available a data processing addendum (“DPA”) governing Company’s processing of Personal Data as a Processor for that Client, addressing the subject matter, duration, nature, and purpose of processing, the categories of Personal Data and Data Subjects, the parties’ respective obligations, Subprocessor authorization and flow-down obligations, audit rights, deletion or return of data on termination, and the international transfer mechanism applicable to that engagement. A Client seeking a DPA should contact Company as described in Section 19.
Section 14. Your Rights
14.1 GDPR / UK GDPR Rights
Where GDPR or UK GDPR applies to Company’s processing of your Personal Data as Controller, you have the right to: (a) request access to your Personal Data; (b) request rectification of inaccurate Personal Data; (c) request erasure of your Personal Data; (d) request restriction of processing; (e) object to processing carried out on the basis of legitimate interests; (f) request portability of Personal Data you have provided to Company, where technically feasible; (g) not be subject to a decision based solely on automated processing, including profiling, that produces a legal or similarly significant effect (Company does not currently engage in such decision-making with respect to Site visitors); and (h) lodge a complaint with a Supervisory Authority, including the UK Information Commissioner’s Office (ico.org.uk) or the data protection authority of your EU member state of habitual residence, place of work, or place of the alleged infringement.
14.2 CCPA / U.S. State Privacy Rights
Where the CCPA or another applicable U.S. state privacy statute applies, you have the right to: (a) know what Personal Data Company has collected, used, disclosed, and, per Section 8, not sold or shared, about you; (b) request deletion of your Personal Data, subject to applicable exceptions; (c) request correction of inaccurate Personal Data; (d) opt out of the sale or sharing of Personal Data or of processing for cross-context behavioral advertising (Company does not sell or share Personal Data or engage in cross-context behavioral advertising, per Section 8); (e) limit the use or disclosure of sensitive Personal Information, to the extent applicable; and (f) not receive discriminatory treatment for exercising these rights.
14.3 Exercising Your Rights
You may exercise a right described in this Section 14 by contacting Company as described in Section 19. Company will verify your request using information reasonably necessary to confirm your identity and will respond within the time period required by applicable Data Protection Law. Where a request relates to Personal Data that Company processes as a Processor on behalf of a Client, per Section 13, Company will direct the request to the applicable Client or assist the Client in responding, consistent with the parties’ data processing addendum.
Section 15. Children’s Privacy
15.1 The Site is directed to businesses and is not directed to children. Company does not knowingly collect Personal Data from a child under the age of 16 through the Site. If Company becomes aware that it has done so, Company will take reasonable steps to delete that Personal Data.
Section 16. Cookies and Similar Technologies
16.1 As described in Section 4.3, Company’s self-hosted website analytics does not set a persistent cross-site tracking cookie in its default configuration. If Company’s use of cookies or similar technologies changes, this Privacy Policy and any required consent mechanism will be updated accordingly.
Section 17. Third-Party Links and Services
17.1 The Site may link to or integrate with a Third-Party Service, including the scheduling provider described in Section 4.2 and Section 9.1(c). Each Third-Party Service is governed by its own privacy policy, which Company encourages you to review; Company is not responsible for the privacy practices of a Third-Party Service.
Section 18. Changes to This Privacy Policy
18.1 Company may amend this Privacy Policy from time to time. The current version states its effective date at the top of the document. Material changes will be indicated by updating that date and, where Company determines it appropriate, by additional notice on the Site.
Section 19. Contact Us
19.1 Questions about this Privacy Policy, requests to exercise a right described in Section 14, or requests for a data processing addendum described in Section 13.4, may be directed to [email protected] or by mail to Blockchain Omega Ltd, 1500 N Grant St, Ste R, Denver, CO 80203, USA.
19.2 Company has not designated a Data Protection Officer, none being required under GDPR Article 37 for Company’s current processing activities, and has not designated an EU or UK representative (see Section 10.2). If either is designated in the future, this Section will be updated with the relevant contact details.
Annex A. Informational List of Current Providers (Non-Binding)
This Annex is provided for transparency only. It is not part of the binding text of this Privacy Policy, does not limit or expand the categories described in Section 9, and may be updated without amending Section 9. Current as of the effective date above; subject to change without notice under this Annex. Each named third-party provider processes Personal Data under its own privacy policy, linked below, which Company does not control and which we encourage you to review.
- Scheduling: Cal.com: privacy policy at https://cal.com/privacy.
- Hosting and content delivery: Cloudflare (Cloudflare Pages and related infrastructure): privacy policy at https://www.cloudflare.com/privacypolicy/. Railway (private backend and database infrastructure for Company-operated systems): privacy policy at https://railway.com/legal/privacy.
- Email delivery: SendGrid (Twilio Inc.), or a functionally equivalent transactional email provider, for contact and quote form correspondence: privacy policy at https://www.twilio.com/en-us/legal/privacy.
- Analytics: self-hosted analytics infrastructure operated by Company; not a named third-party analytics company, and therefore no third-party analytics privacy policy applies to this processing.
- Payment processing (Client engagements): varies by engagement; commonly Stripe or a functionally equivalent processor, as selected for the specific engagement: Stripe privacy policy at https://stripe.com/privacy.
Omegawright, a trading name of Blockchain Omega Ltd. Questions about this document may be sent to [email protected].