Sub-processors

The complete list of third parties that process personal data on behalf of OmniOS OÜ. Each is bound by a written agreement under Article 28 GDPR to act only on our instructions. If a company is not on this page, it does not get your data.

In force from
Version
1.1
Issued by
OmniOS OÜ

Version 1.1 adds § 3b, separating data sources from processors.

1Infrastructure

ProviderPurposePersonal data receivedLocation & transfer basis
OVH SAS (France)Hosting, compute, database, object storage and backups. Everything the Service runs on.All service data at rest, including account records, billing metadata and logs. OVH does not access it in the ordinary course.Servers in Frankfurt, Germany. EU — no third-country transfer.
Cloudflare, Inc. (United States) and Cloudflare Germany GmbHDNS, CDN, WAF, DDoS mitigation, TLS termination and cookieless web analytics.IP address, user agent, requested URL, timestamp, TLS metadata. No account or billing content.Global edge network. SCCs under Cloudflare's data processing addendum.

2Product services

ProviderPurposePersonal data receivedLocation & transfer basis
Stripe Payments Europe, Ltd. (Ireland)Card payments, subscription billing, invoices and the customer billing portal.Name, email, billing address, country, card details (which go to Stripe directly and never reach us), subscription and payment history.Ireland, with onward transfer within the Stripe group under SCCs. Stripe is a controller in its own right for fraud prevention and its regulatory obligations.
Google Ireland Limited"Sign in with Google", only if you choose it over an email and password.Google account identifier, email address, display name, avatar URL.Ireland. EU, with onward transfer to Google LLC under SCCs.
OpenAI (OpenAI Ireland Limited for EEA customers; OpenAI, L.L.C.)The language model behind the Vi AI assistant and behind news summarisation.The text of your Vi AI prompts and the assistant's replies. No account identifier, no email, no billing data.United States. SCCs under OpenAI's data processing addendum. Under its API terms, API content is not used to train its models and is retained for a limited abuse-monitoring window only.
Telegram (Telegram FZ-LLC)Delivery of the alerts you configure, only if you connect a Telegram account.Your Telegram chat identifier and the text of the alerts you asked for.Outside the EEA. Transfer is necessary to perform the contract you asked for (Art. 49(1)(b) GDPR) — you chose the delivery platform.

3Transactional email

Account email — sign-in links, password resets, billing receipts, security notices and the change notifications these documents require — is delivered over authenticated SMTP. The delivery provider is named in the row below and is bound by an Art. 28 processing agreement.

ProviderPurposePersonal data receivedLocation & transfer basis
SMTP delivery provider — to be confirmed before launchSending transactional email.Recipient email address, message subject and body, delivery outcome.To be recorded here once the provider is fixed. Choose an EU-established provider so this row needs no transfer mechanism.

3bData sources, which are not processors

These are where the market data comes from. They process nothing on our behalf and receive nothing about you: our systems read their public endpoints, and the request carries our infrastructure's address, never yours. They are listed so the boundary is visible.

SourceWhat we readWhat they receive about you
Cryptocurrency exchanges (24+ venues)Public trades, order books, tickers and funding data.Nothing.
Public blockchains, including Polygon via public RPC providersOn-chain transactions and balances.Nothing.
Polymarket public data, Gamma and CLOB APIsPublic markets, prices, order books, trades, resolutions and the public leaderboard, including the profile names participants chose.Nothing. We do not hold an account on your behalf and never send them your identity.

If you follow a link from the Service to one of these venues, you are dealing with them directly under their terms, and what they collect from that point is described in their policies, not ours.

4What we deliberately do not use

  • No advertising networks, ad exchanges or retargeting pixels. None, on any page.
  • No Google Analytics, Google Tag Manager or any Google tag. Removed from both vultax.com and the terminal in September 2026.
  • No session-replay or heatmap tools. We do not record your screen or your mouse.
  • No data brokers. We buy no personal data and enrich no profile.
  • No customer-data platform or marketing automation suite holding a copy of the user base.

5Changes to this list

This page is the authoritative list. Before we add a sub-processor that will handle customer personal data, we publish it here at least 30 days in advance and, for customers with a signed data processing agreement, email the notification address on the agreement.

A business customer may object to a new sub-processor on reasonable data-protection grounds within those 30 days by writing to [email protected]. If we cannot offer a workaround, you may terminate the affected subscription and we will refund the unused part of what you have paid.

Where a change is forced on us with less notice — a provider withdrawing a service, or a security incident requiring an immediate move — we make the change and publish it here as soon as we can, with the reason.