OmegaOS
Enterprise privacy

Subprocessors

Core and conditional providers that may process customer or service data when the relevant Omega capability is used.

Status
Published provider register
Owner
Omega Privacy, Security, and Procurement
Effective
July 21, 2026
Last updated
July 21, 2026
Internal review posture

Published following operator-authorized Omega privacy, security, claims, and operational review. External counsel review is not recorded.

External counsel posture
No external approval claimed

Subprocessors is published as current informational posture, not legal advice, certification, or a contractual commitment. External counsel approval is not recorded.

How to read this register

A provider processes data only when its service is part of the customer's configuration, a public-site function is invoked, or Omega uses it for platform operations. Provider regions and data categories vary by account and feature. The executed agreement and provider configuration control.

Vercel

Purpose: public-site and application hosting, delivery, serverless execution, and operational logs. Typical data: request metadata, public content, deployment data, and service logs. Posture: core web infrastructure.

Supabase

Purpose: managed PostgreSQL, authentication, storage, and related platform services. Typical data: accounts, application records, Customer Content, metadata, and logs. Posture: core application data infrastructure.

Amazon Web Services

Purpose: object storage, queues, key and secret custody, and supporting cloud infrastructure. Typical data: files, job payloads, configuration secrets, encrypted service data, and logs. Posture: core or feature-dependent infrastructure.

Stripe

Purpose: checkout, payment processing, invoicing, subscriptions, tax-support data, and fraud prevention. Typical data: customer contact, transaction, payment method token, invoice, and risk metadata. Posture: active when commercial or billing functions are used.

NVIDIA

Purpose: AI, model, voice, or inference services selected for an enabled workflow. Typical data: prompts, instructions, media, generated output, technical metadata, and usage records. Posture: conditional by feature and route.

Identity and connector providers

Google, GitHub, LinkedIn, Meta, and other connector or identity providers may process authentication, profile, content, or integration data when a user enables the corresponding connection. Their own terms and privacy practices also apply.

Additional model providers

OpenAI, Anthropic, local models, or other model providers may be selected for specific workflows where enabled. Data categories and retention depend on the selected provider, account, endpoint, and contract. Omega does not represent that every provider is active for every customer.

Professional and support providers

Omega may use professional advisers, communications, support, security, and business-operations providers under confidentiality and purpose limitations. Providers that process Customer Personal Data as subprocessors are added to the applicable register or agreement.

Changes and objections

Omega may add, replace, or remove providers as services evolve. Contract customers receive notice and an opportunity to object where the executed DPA requires it. Questions or objections can be sent to privacy@omeganeural.com.

Related policies

Read this page with the related policy, trust, and service information that applies to your use of Omega.

Contact Omega