Privacy Policy, HIPAA &
NDA Agreements.
Effective Date: August 16, 2026. A comprehensive, exhaustive overview of our data protection standards, strict compliance frameworks (HIPAA, SOC2, GDPR), client confidentiality protocols, and zero-trust engineering methodologies.
At Omeiro ("we," "our," or "us"), safeguarding your personal data, high-level enterprise transaction records, and proprietary project intellectual property is not merely a legal obligation—it is the foundational pillar of our engineering agency.
Because we service highly regulated industries—including massive healthcare networks, international law firms, and multi-national e-commerce retailers—we have engineered our data protection standards to exceed baseline legal requirements. This Privacy Policy exhaustively outlines what telemetry and personal data we collect, our cryptographic storage methods, our strict adherence to HIPAA and SOC2 frameworks, and our binding legal commitments to client confidentiality via Non-Disclosure Agreements (NDAs).
By accessing omeiro.com, initiating a digital architecture sprint, purchasing software licenses (e.g., Hostinger Cloud, Next.js setups, Elementor Pro), or engaging our Omeiro Agency Support infrastructure, you formally consent to the data practices meticulously detailed in this agreement.
1. Comprehensive Data Collection Protocols
To architect complex enterprise solutions, provision secure cloud environments, and execute high-velocity ad campaigns, we must collect specific, structured categories of information:
A. Identity, Financial, and Contractual Data
- Primary Contact Information: Full legal names, corporate email addresses, corporate physical addresses, and authorized mobile telephone numbers provided during the Scope of Work (SOW) execution or general inquiries.
- Infrastructure Credentials (Encrypted): Environment identifiers, domain names, API access tokens, and temporary OAuth scopes required to provision headless architectures, connect third-party enterprise services (AWS, Google Cloud, Meta CAPI), or manage DNS configurations.
- Financial Ledger Data: Payment verification timestamps, Master Services Agreement (MSA) invoicing history, and subscription tier metadata. Critical Note: Raw credit card numbers and sensitive banking credentials are never stored on Omeiro's internal servers. All transactions are routed directly through PCI-DSS Level 1 certified payment gateways (e.g., Stripe, Authorize.net).
B. Technical Telemetry & Automated Threat Detection
When interacting with our agency platform or client portals, our edge-network servers automatically log non-personally identifiable technical telemetry to ensure platform security and detect DDoS or unauthorized access attempts. This includes IP addresses, deep browser user-agent strings, operating system environment specs, referring URL nodes, and exact microsecond session timestamps.
2. Enterprise Compliance: HIPAA, SOC2, GDPR & CCPA
Omeiro does not operate on shared, vulnerable infrastructure. We design our ecosystems specifically for enterprises operating under severe regulatory scrutiny.
HIPAA Compliance & BAAs
For our medical and dental partners, we architect infrastructure strictly adhering to the Health Insurance Portability and Accountability Act. We execute formal Business Associate Agreements (BAAs), encrypt Protected Health Information (PHI) at rest and in transit, and deploy isolated cloud VPCs.
SOC 2 Type II Readiness
Our internal agency operations, data access logs, and deployment pipelines are engineered to meet the American Institute of CPAs (AICPA) SOC 2 standards for security, availability, processing integrity, and extreme confidentiality.
GDPR & CCPA Frameworks
We are fully compliant with the European Union's General Data Protection Regulation and the California Consumer Privacy Act. We respect the right to be forgotten, mandate active consent for tracking, and appoint internal Data Protection Officers (DPOs).
PCI-DSS Level 1 Routing
Whether configuring an e-commerce headless Shopify store for a client, or processing our own agency invoices, all transactional payment data is tokenized and routed directly through PCI-DSS Level 1 processors.
3. Non-Disclosure Agreements (NDAs) & Intellectual Property
Traditional agencies hold client assets hostage. Omeiro views intellectual property as the sole asset of the client.
Formal NDA Execution Policy
Before our architects review a single line of your proprietary source code, database schemas, or marketing strategy, Omeiro is prepared to execute mutual or unilateral Non-Disclosure Agreements (NDAs). We utilize zero-knowledge architecture approaches when auditing enterprise environments.
Upon project completion, our Master Services Agreement (MSA) guarantees a 100% Legal Intellectual Property Transfer. You own all GitHub repositories, Figma design tokens, raw video project files, and backend cloud infrastructure keys.
4. Infrastructure & Security Architecture
We process collected data exclusively for legitimate operational purposes using hardened environments:
- Encryption at Rest and in Transit: All client databases are encrypted at rest using AES-256 block-level encryption. All network transmissions are secured via TLS 1.3 cryptographic protocols, thwarting man-in-the-middle interception.
- Isolated VPC Deployments: For enterprise clients, we deploy web applications within dedicated Virtual Private Clouds (VPCs) on AWS or Google Cloud, ensuring your data processes in a sterile, isolated environment away from noisy or compromised neighbors.
- Role-Based Access Control (RBAC): Omeiro operates on a Principle of Least Privilege (PoLP). Our engineers and designers are granted access strictly to the micro-environments necessary for their specific sprint tasks, utilizing Mandatory Multi-Factor Authentication (MFA).
5. Sub-processors & Vendor Sharing
We absolutely do not sell, rent, or trade your personal or corporate data to data brokers. Information is shared strictly under these tightly controlled scenarios:
- Authorized Vendor Provisioning: When we configure third-party enterprise tools on your behalf (e.g., establishing a Hostinger Cloud server, purchasing Adobe licenses, or connecting Meta CAPI APIs), the minimal necessary metadata is transmitted via secure API to generate your authorized keys.
- Audited Sub-processors: We utilize top-tier infrastructure providers (like AWS for hosting, or Stripe for payments) who are bound by strict Data Processing Agreements (DPAs) that legally obligate them to uphold our security standards.
- Legal Compliance: We will disclose data only if compelled by a valid, legally binding court order or subpoena from a recognized legal jurisdiction.
6. Data Retention & Cryptographic Erasure
Omeiro does not hoard dead data. We retain personal data, codebase backups, and project media only for the active duration of our Master Services Agreement (MSA) or to fulfill ongoing 24/7 Agency Support requirements.
Upon contract termination, or at the explicit written request of the client, all non-essential data is subjected to Cryptographic Erasure. This process overwrites the encryption keys associated with your data blocks, rendering the underlying information mathematically unrecoverable, fulfilling strict GDPR erasure mandates.
7. Incident & Breach Response Protocol
In the highly unlikely event of a security anomaly or infrastructure breach affecting client data, Omeiro has a documented Incident Response Plan. Our protocol mandates that affected clients are notified within 72 hours of threat verification. This notification will include the nature of the breach, the specific data vectors compromised, and the immediate mitigation engineering being deployed to neutralize the threat.
8. Your Data Privacy Rights
Depending on your geographic jurisdiction (such as the EU or California), you are legally entitled to extreme control over your personal records:
- Right of Access (DSAR): You may request a complete exported copy of the personal data profiles we maintain regarding your account.
- Right of Rectification: You may demand immediate correction of inaccurate or incomplete corporate or personal information.
- Right to Erasure ("Right to be Forgotten"): You may request the total cryptographic deletion of your records, assuming it does not conflict with active contractual obligations or anti-money laundering (AML) laws.
- Right to Object & Restrict: You may formally object to specific data processing activities, particularly regarding automated marketing or telemetry tracking.
To exercise any of these rights, or to initiate a Data Subject Access Request (DSAR), please contact our compliance engineering team directly.
Secure your digital infrastructure.
Partner with an agency that treats your intellectual property and data compliance as seriously as you do. Request an NDA and initiate your architecture audit today.