Privacy statement
Last updated: September 3, 2026
1. Introduction
Omcircle (“we”, “us”) attaches great importance to protecting your personal data. This statement explains which data we collect, why we collect it and how we handle it. We process personal data in accordance with the General Data Protection Regulation (GDPR).
2. The contact form
When you send a message through our contact form, we process:
- Your name
- Email address
- Company name
- The content of your message
- The page you wrote it on, and the conversation if you left the message in the chat
You get a confirmation by email straight away, with your own message in it. If you want to add something, you can reply to it.
We may also collect limited, anonymised technical data (such as browser type) to keep the website working properly. Which cookies this site places and what we measure is set out under Cookies.
3. The chat
In the chat you are talking to an AI assistant, not to a member of staff. It puts its answers together itself, so they can contain mistakes; what that means is set out in the disclaimer. If you ask for a human, the assistant hands the conversation over and we get in touch with you.
If you ask a question in the chat window at the bottom right, we process:
- The messages you type and the answers you get
- The page where you started the conversation, and the page you came from
- The language the conversation is in
- The IP address you hold the conversation from
Why that IP address. Every answer the chat gives costs money, and the key the chat window uses to talk to our service sits in the HTML of every page. Without an origin we cannot step in when someone abuses that. We use the address for that purpose only: not to recognise you when you come back, not for statistics and not for advertising. After 30 days we delete it, while the conversation itself stays for as long as the retention below runs.
Legal basis. Our legitimate interest (article 6(1)(f) GDPR): being able to answer visitors' questions about our services straight away, and protecting our service against abuse.
What the model gets. Your question, the ongoing conversation and the parts of our own site that relate to that question. This goes to OpenAI to have an answer written. Under the OpenAI API terms, data submitted this way is not used to train models.
Before a conversation starts Cloudflare Turnstile runs a bot check. Cloudflare processes technical data from your browser to establish that you are not a script. That check applies per conversation, not per message.
If you leave your details in the chat (your name, email address, company and what it is about), we treat that as a message to us: see chapter 2.
We may read conversations back to see which questions keep coming up and to improve the answers. That is why we keep a conversation in which you left no details for 90 days and no longer; if you do leave your details, the conversation belongs to your request and we keep it for 12 months.
What not to put in it. The chat is meant for questions about our services. Do not put special categories of personal data or confidential company information in it.
4. The AI scan
If you request an AI scan, we process your name, your email address, the website you enter and the optional note you type in yourself. When you confirm, we also record the time and your IP address as evidence that you gave consent.
Legal basis. For sending you the scan, that basis is your consent (article 6(1)(a) GDPR). You give that consent by clicking the confirmation link in the email. If you do not, nothing happens: we do not read your site, we do not send a scan, and we delete your request within 24 hours.
For reading the website you entered, we rely on our legitimate interest (article 6(1)(f) GDPR). Because we require your email address to be on the same domain as the site you have scanned, it is always a site you are connected to yourself.
What we read. Only publicly accessible pages of the website you entered, up to a maximum of twelve pages per scan. What we take from them is the structure of the site: which tools are running, which forms are present, which pages exist and which are missing.
What we do not do. We do not log in anywhere and we do not look at anything that is not publicly on the site. We do not search social media. We do not process names or other details of your staff, even if they appear on the site.
The retrieved text. We keep it for at most 30 days, purely so we can check whether our analysis is correct. After that the system deletes it automatically. The analysis itself works on characteristics we derive from the pages (which tools are running, how many fields a form has), not on the page text itself.
Withdrawing consent. You can withdraw your consent at any time by getting in touch. We will delete your data straight away.
5. Why we process this data
- To answer your request and get in touch with you
- To answer your question in the chat
- To counter abuse of the chat
- To run and send the AI scan you requested
- To improve our services and website
- To comply with legal obligations
6. How long we keep your data
| Data | Retention |
|---|---|
| A scan request you do not confirm | 24 hours, then deleted automatically |
| The text we retrieve from your website | 30 days, then deleted automatically |
| The scan we send you | 12 months, so we can look it up if you get in touch about it |
| Your name, email address, domain, note and consent record | 12 months |
| The IP address you use in the chat | 30 days |
| A chat conversation where you left no details | 90 days |
| A chat conversation where you did leave your details | 12 months |
| Messages through the contact form | As long as needed to handle your question |
| Visitor statistics in Google Analytics | At most 2 months on Google's servers |
7. Sharing with third parties
We never sell your data. To deliver the service we use a number of parties, each of which may only process what its own part requires:
| Party | For what | Location |
|---|---|---|
| Resend | Sending the confirmation email, your message and the scan | United States |
| OpenAI | Analysing the characteristics read from the site, and writing the answers in the chat | United States |
| Cloudflare | Bot check before a conversation in the chat starts | United States |
| Supabase | Storing your request, your message, your conversation, your consent and the scan | European Union |
| Railway | Running the scan and the chat, and processing your message | European Union |
| Vercel | Hosting this website | United States |
| Statistics about how the website is used; configured privacy-friendly and turned off with one click, see Cookies | United States |
We conclude a data processing agreement with all of these parties. For parties outside the European Union we use the standard contractual clauses of the European Commission.
8. Security
We take appropriate technical and organisational measures to protect your data against loss or unlawful processing.
9. Your rights
You have the right to access, correct or delete your data. You can also object to the processing and withdraw your consent. Get in touch with us to do so.
10. Contact
Questions about this statement or about your data? Get in touch through the contact form on our website.
11. Data controller
Omcircle
Gentiaanstraat 23
9731 BN Groningen
Netherlands
Chamber of Commerce: 91549264
VAT ID: NL004899208B06
This is a translation of the Dutch original. In case of any discrepancy, the Dutch version prevails.