PRIVACY POLICY — OMNIANT & OMNII
Effective Date: October 5, 2026
Last Updated: October 5, 2026
This Privacy Policy explains how Gio Celenza MGMT, operating through Omniant, handles information in the Omniant websites and OMNII portal and installable web app that link to this Policy (“Services”). Omniant is a division of Gio Celenza MGMT rather than a separate incorporated entity. References to “we,” “us,” or “our” mean Gio Celenza MGMT operating through that division.
This Policy covers our handling of information. Google, Cloudflare, and other third-party services also have policies governing their own activities. This Policy does not make information public merely because it is entered into the portal, and it does not replace a separate client-records policy where that policy applies.
1. Information We Handle
Depending on the features you use, we handle:
- Account and profile information: Google account identifiers, name, email address, profile picture, account status, roles, organizational affiliations, assigned manager, profile text, and a business phone number or scheduling information you provide;
- Portal content: requests, request status, messages, group names and membership, attachments, announcements, notifications, document information, and agreement-status records;
- Connected-service information: authorized Gmail, Google Calendar, and Google Drive information, as described below;
- Authentication information: session identifiers, session expiry, integration access and refresh tokens, and connection status;
- Preferences: appearance settings, remembered-device choices, and other settings you save;
- Device and activity information: browser or device description, timestamps, approximate location derived from network information, session activity, and records of supported login and administrative actions. Infrastructure providers may also process IP addresses, request details, and error logs; and
- Notification and assistant information: browser push-subscription endpoints and delivery keys, notification payloads, assistant questions, recent conversation history, and the limited context used to answer them.
We receive information from you, authorized users who manage or share records involving you, connected services you authorize, and requests made by your browser. Avoid submitting passwords, private keys, unnecessary sensitive identifiers, or information you are not authorized to share.
2. Why We Use Information
We use information to authenticate users, provide features, route requests, support management workflows, share records with authorized people, display messages and connected information, deliver alerts, save preferences, answer assistant questions, resolve support issues, prevent abuse, investigate security incidents, and meet applicable legal obligations.
We do not sell personal information or use connected Google user data for advertising. We do not use Google user data to develop, improve, or train generalized or non-personalized AI or machine-learning models.
3. Google Sign-In and Authorized Integrations
Sign-in. Google sign-in supplies identity information used to identify your approved account. Your Google password is entered with Google, not directly into OMNII.
Gmail. If you connect Gmail, OMNII uses read-only access to display inbox entries, senders, recipients where available, subjects, dates, snippets, labels, read status, and the contents of emails you open. The Gmail permission can authorize broader read access than the limited inbox page displays. OMNII currently does not send, modify, or delete Gmail messages. Inbox information is retrieved from Google for display; the portal is not designed as a permanent backup of your mailbox.
Google Calendar. If you connect Calendar, OMNII accesses event information to display your calendar, upcoming items, and management meeting information. Information can include event titles, times, descriptions, locations, meeting links, and attendee information where supplied. Authorized event actions depend on the permissions granted and the controls offered in the portal. Scheduling pages can also embed Google appointment pages, which interact directly with Google.
Google Drive. Where document features are configured, OMNII may access file and folder information and perform authorized document-upload or sharing actions. Shared document access is governed by the relevant folder, file, and portal permissions. Do not assume another user's account gives you access to their entire Drive.
Tokens and control. Access and refresh tokens are stored to maintain authorized integrations without repeatedly asking you to sign in. These credentials are handled by the backend and are not intended for display to other users. You may disconnect supported integrations through OMNII and may revoke access through Google Account connections. Revocation stops future authorized access once it takes effect, but does not by itself delete independent portal records, shared documents, or copies already received by others. Contact us to request deletion of retained information.
Limited Use. OMNII's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user data and developer policy.
Connected Google data is used only for the disclosed user-facing features. Transfers are limited to providing those features with your consent, necessary security purposes, legal obligations, or other circumstances expressly permitted by Google's policy. Humans may access this data only with documented consent for specific data, where necessary for security or legal compliance, or within another exception permitted by Google's policy. Administrative status alone is not blanket authorization to read connected Google data.
4. OMNII Assistant and AI Processing
The OMNII Assistant uses Cloudflare Workers AI. When you use it, your question and a limited recent conversation history are sent for model processing, together with your name and role and selected information available to your account.
The current assistant context includes limited calendar event titles and times, request details, announcements, and notifications. When your question concerns email, it can also include connected inbox subjects, senders, dates, read status, and short snippets. The current integration does not supply full Gmail message bodies or private portal chat messages as automatically gathered assistant context. If you paste such content into your question, that content becomes part of the submitted prompt.
This processing supports answers and summaries for you; it is not permission to use your data to train generalized AI models. Google-connected information must only be included after the relevant disclosure and authorization for that use. You can choose not to use the assistant and can disconnect relevant Google integrations.
The assistant's access is based on your existing permissions. Answers may reveal sensitive details on your screen, so consider where you use it. Cloudflare processes the inference request under its applicable service terms. This Policy does not promise that all provider processing is instantaneous or that every provider log is immediately erased.
5. Who Can Receive Information
Information may be made available to:
- Intended recipients and group members: messages, attachments, and information you share in a conversation;
- Authorized managers and administrators: profile, organizational, request, document, and administrative records within their permitted responsibilities. This does not override the restrictions on connected Google data described above;
- Service providers: Cloudflare for hosting, database, storage where configured, security, logs, and AI processing; Google for sign-in, Gmail, Calendar, Drive, appointment embeds, and linked services; and browser notification providers for push delivery;
- Other external services you choose to use: for example, Google Voice when opening a call link, or a linked document or website; and
- Persons or authorities where necessary: to comply with applicable law, respond to valid legal process, investigate abuse, or protect lawful rights and safety. Google data remains subject to the additional restrictions above.
A manager's scheduling embed may send browser information to its provider when loaded. External services can receive information directly from your browser and apply their own cookies and policies. Files intentionally shared with others may be retained by recipients independently of the portal.
6. Push Notifications
Enabling push notifications stores a subscription associated with your account and device session. The subscription contains an endpoint and delivery keys, not your Google password. Notification services associated with your browser or operating system, such as Google, Apple, Mozilla, or Microsoft, participate in delivery.
Notification content is encrypted for transmission through the push service, but can be visible to anyone looking at an allowed lock screen or notification preview. This does not make portal messaging end-to-end encrypted.
You can disable push notifications in OMNII and in your browser or device settings. Permission and enrollment are separate for each device. Signing out or revoking a session prevents further alerts for that session through OMNII's active-session checks; an alert already delivered or in transit may still appear. Disabling notifications does not erase notices already shown by your operating system.
7. Cookies, Local Storage, and the Installable App
OMNII uses session cookies to keep you signed in, short-lived authentication information during sign-in, and browser storage for preferences and app behavior. A remembered session is configured for up to 30 days; a shared-device session uses a shorter lifetime. Expiry, revocation, sign-out, and browser settings can end access sooner.
The installable web app uses a service worker and caches public app assets, such as icons and an offline page. It is not designed to cache private emails, portal messages, or API records for offline access. Private information may still be present in an open page's memory or other browser-managed storage while you use it.
Clearing cookies or browser storage may sign you out, reset local preferences, or require notification setup again. Third-party websites and embeds may use their own storage independently.
8. Activity Records and Session Information
OMNII keeps supported login, security, and administrative activity records to help authorized administrators investigate access and changes. These records can contain user identifiers, actions, timestamps, relevant record identifiers, and device or network context. The log is not represented as a complete recording of everything every person does.
Session information supports the “where you are logged in” controls. Approximate location may be inaccurate and is not a promise of precise device tracking. Authorized administrators may review activity logs for appropriate operational and security purposes.
9. Retention and Deletion
We retain information while needed for the feature, account, management record, security purpose, or applicable obligation for which it was collected.
- Trash: supported requests, announcements, and notifications are eligible for permanent deletion after 30 days in Trash. Scheduled cleanup performs removal; authorized users can permanently delete eligible items sooner where available. Restoration is possible before permanent deletion.
- Activity logs: routine activity-log cleanup is configured to remove entries older than 90 days.
- Sessions and push records: sessions have expiry and revocation controls. Expired sessions are not authorization for continued access. Invalid push subscriptions may be removed when the delivery service reports them expired.
- Google integrations: stored connection credentials support continued authorized access and are removed from OMNII's connection records through supported disconnection controls. Email and calendar retrieval does not replace Google's own retention practices.
- Other portal records: profiles, messages, attachments, documents, and management records do not all have an automatic 30-day deletion rule. They may remain while needed for ongoing participation, recordkeeping, disputes, security, or legal obligations.
Cleanup depends on the scheduled tasks being enabled and operating correctly. Permanent deletion from the active portal does not necessarily remove separate audit entries, provider logs, backup copies, recipient copies, or originals stored in Google or another service. Retained exceptions should be limited to a legitimate purpose; they are not permission to keep everything indefinitely.
To request account closure, access to your retained information, correction, or deletion, contact us below. We will verify the request as reasonably needed and explain applicable limits. You do not need to disclose a password to make a request.
10. Security and Processing Locations
We use authentication, role and membership checks, session controls, and encrypted web connections to protect access. No system can guarantee complete security. The portal is not represented as end-to-end encrypted or as having a certification it has not obtained.
Cloud service providers may process information in countries other than your own. We do not promise that all information is stored in one specific country. Provider policies and applicable legal requirements govern relevant international processing.
11. Your Choices and Rights
You can update supported profile information and preferences, manage connected services, control notification permissions, review and revoke your sessions, and use available Trash controls. Some changes require an authorized manager or administrator.
Depending on applicable law, you may have additional rights to access, correct, delete, or obtain a copy of information, object to or limit certain processing, or withdraw consent. Contact us to exercise an applicable right. We will respond within the period required by applicable law and will not deny a legal right merely because a matching self-service button is unavailable.
Withdrawing permission may prevent a related feature from working. It does not erase processing already lawfully carried out or remove a separate retention obligation. For Google-held information and settings, use Google's controls as well.
12. Minors
The Services are not intended for children under 13, and we do not knowingly seek their personal information. If you believe a child under 13 has supplied information, contact us so we can investigate and take appropriate action, including restricting access and deleting information where required.
Approved users who are minors may use the Services with parent or guardian involvement where required. A parent or guardian may contact us regarding a minor's information, subject to appropriate verification and applicable rights. A management relationship does not remove protections provided by law.
13. Changes and Contact
We may update this Policy when features or practices change. The revised version will display an updated date. We will provide appropriate notice of material changes and request consent where required before using information for a new purpose.
Omniant — a division of Gio Celenza MGMT
OMNII privacy, deletion, and support inquiries: management@giocelenzamgmt.com
Main website: www.giocelenzamgmt.com