OMNITRIX Logo
Home About Partners Contact Get a Quote
⚡ CMS
Home Company GDPR Compliance
EU Regulation (EU) 2016/679 & Global Privacy Compliance

General Data Protection Regulation (GDPR) Compliance

OMNITRIX is dedicated to institutional data privacy, sovereign cloud isolation, and uncompromising protection of enterprise data subject rights across the European Union, United Kingdom, and international operations.

100%
GDPR Aligned
ISO 27701
Privacy Verified
72 Hours
Breach SLA
Standard DPA
Ready to Sign
§

1. Executive Overview & Data Protection Principles

Adherence to Article 5(1) & Article 5(2) of Regulation (EU) 2016/679

At OMNITRIX (Omnitrix Next Generation IT Solutions Pvt. Ltd.), data privacy is an architectural imperative embedded into our multi-cloud designs, enterprise bare-metal GPU clusters, cyber SOC operations, and customer engagement platforms. We strictly adhere to the seven foundational GDPR principles governing lawful processing:

01. Lawfulness, Fairness & Transparency

Processing only occurs with valid lawful justification, complete transparency, and clear notice to individuals.

02. Purpose Limitation

Data is collected solely for specified, explicit, and legitimate enterprise IT service delivery purposes.

03. Data Minimisation

Only data strictly necessary for fulfilling technical and contractual scopes is collected and stored.

04. Accuracy & Verification

Processes exist to keep personal records up-to-date and rectify inaccuracies without undue delay.

05. Storage Limitation

Personal data is retained only for as long as required by contractual fulfillment and regulatory mandates.

06. Integrity & Confidentiality

Protected using enterprise-grade AES-256 encryption at rest, TLS 1.3 in transit, and Zero-Trust access.

Role A

OMNITRIX as a Data Controller

When you interact with our website, request quotes, consult with our solutions architects, or register corporate accounts, OMNITRIX acts as the Data Controller.

  • Corporate procurement contact details (Name, Work Email, Phone, Title)
  • Billing, GST invoicing, and corporate payment records
  • Website telemetry, technical error logs, and cookie preferences
Governed by OMNITRIX Privacy Notice Article 4(7) →
Role B

OMNITRIX as a Data Processor

When we provide Managed Cloud, Dedicated GPU Supercomputing, SOC/NOC Monitoring, or Disaster Recovery, our enterprise clients are the Controllers and OMNITRIX acts as the Data Processor.

  • Processing strictly in accordance with client documented instructions
  • Comprehensive Data Processing Addendum (DPA) executed with Standard Clauses
  • Zero secondary usage: Client data is never used for training third-party public AI models
Enterprise DPA Execution Available Article 28 →
Chapter III Guarantees

Data Subject Rights & Request Procedures

Under the GDPR, individuals residing in the European Economic Area (EEA), the UK, and aligned jurisdictions possess explicit, enforceable rights regarding their personal data. OMNITRIX guarantees a maximum 30-day fulfillment SLA for all verified requests:

Right to Access Art. 15

You can request confirmation of whether we process your data and receive a full, human-readable export of all records.

Right to Rectification Art. 16

You may update, correct, or complete any inaccurate or obsolete personal details stored within our systems.

Right to Erasure Art. 17

Also known as the 'Right to be Forgotten', you may request immediate purging of data no longer required for statutory purposes.

Right to Restriction Art. 18

Request that we pause processing while data accuracy or legal legitimacy is verified.

Right to Data Portability Art. 20

Receive your personal records in a structured, commonly used, and machine-readable format (JSON or CSV).

Right to Object Art. 21

Object at any time to the processing of personal data for direct marketing, profiling, or legitimate interest grounds.

Need to file a formal Data Subject Access Request (DSAR)?

Email our Data Protection Officer directly at dpo@omnitrix.in or use the submission portal below.

Submit DSAR Online →
Article 32 Compliance

Technical & Organizational Measures (TOMs)

OMNITRIX implements state-of-the-art cybersecurity defenses certified under ISO/IEC 27001, ISO/IEC 27701, and CMMI Level 5 methodologies:

🔒 End-to-End Cryptography

Data is secured using AES-256 encryption at rest across SAN/NAS storage arrays, SSD pools, and backups. All data in transit utilizes TLS 1.3 with Perfect Forward Secrecy (PFS).

🛡️ Zero-Trust Network Access & IAM

Strict Role-Based Access Control (RBAC), hardware token Multi-Factor Authentication (MFA), and Just-In-Time (JIT) privileged access management ensure zero unauthorized lateral movement.

24x7 SOC Telemetry & SIEM

Real-time threat monitoring powered by Fortinet and Sophos EDR/XDR with automated anomaly detection, immediate isolation protocols, and audited audit log retention.

💾 Air-Gapped & Immutable Disaster Recovery

Veeam and Acronis enterprise backup pipelines with write-once-read-many (WORM) storage, ensuring business continuity and rapid recovery against ransomware without data loss.

📋 Third-Party VAPT & Independent Auditing

Bi-annual independent Vulnerability Assessment and Penetration Testing (VAPT) alongside certified annual surveillance audits for ISO 27001, ISO 20000, and ISO 9001.

👥 Continuous Employee Privacy Training

Mandatory annual privacy training and background security verification for all engineering staff, systems administrators, and solutions architects handling customer workloads.

Cross-Border Data Transfers (Chapter V)

For enterprise clients whose data traverses international borders, OMNITRIX guarantees strict transfer mechanisms:

EU Standard Contractual Clauses (SCCs)

We incorporate the European Commission's approved SCCs (Implementing Decision 2021/914) directly into our Master Services Agreement.

Transfer Impact Assessments (TIAs)

Every cross-border route undergoes comprehensive risk assessment evaluating local statutory surveillance laws and encryption safeguards.

EU Sovereign Residency Options

Clients can designate primary data hosting exclusively in EU regions (Frankfurt, Dublin, Amsterdam) with strict geo-fencing.

Sub-processors & Vendor Due Diligence

OMNITRIX partners exclusively with global Tier-1 technology OEMs who demonstrate certified GDPR, SOC 2, and ISO 27001 compliance:

NVIDIA Cloud & DGX AI Clusters SOC 2 / ISO 27001
Amazon Web Services (AWS) EMEA GDPR Art. 28 DPA
Microsoft Azure Europe EU Boundary Aligned
Fortinet & Sophos Cyber Security Zero-Trust Audited

Clients are notified at least 30 days prior to onboarding any new infrastructural sub-processor with right-to-object mechanisms.

Articles 33 & 34 Protocols

Data Breach Notification & 72-Hour Response SLA

In the improbable event of a security incident leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data:

  • Immediate containment and forensic root-cause analysis by Tier-3 CERT architects.
  • Formal notification to supervisory authorities within 72 hours of awareness.
  • Prompt direct notification to affected client controllers detailing mitigation steps and remediation.
🚨 Emergency Incident Reporting: Security and privacy escalations are routed directly to our 24x7 Computer Security Incident Response Team (CSIRT): security@omnitrix.in
Direct DPO Intake Portal

Submit a Privacy or GDPR Request

Connect directly with our Data Protection Officer for DSAR requests, DPA execution, or regulatory compliance reviews.

Common Inquiries

Frequently Asked GDPR Questions

Clear answers to enterprise legal, procurement, and data compliance queries.

Yes. OMNITRIX provides a pre-approved, enterprise-grade Data Processing Addendum (DPA) incorporating the latest 2021 EU Standard Contractual Clauses (SCCs) and UK IDTA. We also accommodate custom customer DPAs for enterprise-tier engagements.
Yes. For European enterprise deployments, OMNITRIX provisions bare-metal GPU nodes, virtual machines, and object storage strictly in Tier-3/Tier-4 ISO 27001 facilities located in Frankfurt (Germany), Dublin (Ireland), Amsterdam (Netherlands), or Paris (France), guaranteeing zero cross-border replication unless explicitly requested.
Strictly NO. OMNITRIX maintains a zero-retention, non-training policy for all client inference workloads, fine-tuning datasets, and proprietary telemetry. Your private weights, vector databases, and enterprise prompts remain exclusively under your contractual ownership and encryption keys.
Our data protection framework is dual-aligned to satisfy both EU GDPR and India's DPDP Act 2023. This includes notice-and-consent mechanisms in multiple recognized languages, local data fiduciary protocols, grievance redressal officer appointments, and rapid breach response procedures.

Official Data Protection Office

OMNITRIX Enterprise Legal & Regulatory Affairs Division

OMNITRIX Towers, Tech Park Boulevard, Electronic City Phase 1, Bangalore, Karnataka 560100, India

DPO Email: dpo@omnitrix.in CSIRT Response: security@omnitrix.in Phone: +91 80 4123 4567
🤖 ✓