Data Protection & Privacy

Privacy Policy

Our commitment to safeguarding your proprietary data, knowledge security, and customer privacy

Last updated: August 18, 2026Version 1.0Official Legal Document

Strict Guarantee: Zero AI Training on Customer Data

Your documents, knowledge bases, and customer conversation logs are 100% isolated with bank-grade encryption and are never used to train or refine public foundation models.

1. Introduction & Privacy Commitment

O My Syria is deeply dedicated to maintaining the trust and privacy of our business customers and their end-users. This Privacy Policy details the types of information we collect, how it is processed, and the robust security measures enforced to protect it.

2. Information We Collect

We collect only the minimum data required to deliver reliable service: (1) Account Information: email address, full name, business details, and contact numbers; (2) Knowledge Base Data: documents, guides, and policies uploaded by the customer; (3) Interaction Data: questions, answers, and feedback collected via widgets and APIs; (4) Technical Telemetry: IP addresses, browser types, and security audit logs.

3. Purpose of Processing

Data is processed strictly for: (a) Document extraction, vector embedding, and accurate grounded answer synthesis; (b) Workspace access management and secure authentication via OTP and Google OAuth; (c) Providing analytics, inbox management, and audit trails; (d) Platform security monitoring, rate limiting, and subscription billing.

4. Zero Foundation Model Training Guarantee

O My Syria strictly ensures that proprietary customer knowledge, uploaded files, and conversation logs are never used to train or fine-tune public large language models (LLMs). The retrieval pipeline functions in real time and retains zero persistent training state in third-party model providers.

5. Multi-Tenant Architectural Security & Encryption

We enforce strict defense-in-depth security: TLS 1.3 encryption in transit, AES-256 encryption at rest for object storage, database Row-Level Security (RLS) across all PostgreSQL tables, and isolated pgvector embeddings partitioned per organization and project.

6. Cookies & Session Management

We only use essential, functional cookies for secure session authentication (configured with HttpOnly, SameSite=Lax, Secure flags, and CSRF tokens) and local storage for theme (dark/light mode) and language preferences. We do not use third-party advertising or tracking cookies.

7. User Rights, Data Portability & Right to Erasure

Customers maintain complete sovereignty over their data, including the right to inspect, edit, download uploaded documents, export conversation records, and execute permanent hard deletions of projects and organizations via OTP-protected dashboard controls.

8. Sub-processors & Infrastructure Partners

We partner only with vetted cloud infrastructure and enterprise AI providers bound by strict Data Processing Agreements (DPAs) meeting international data security and privacy standards.

9. Contact & Data Protection Officer

For any inquiries or data protection requests, please contact our privacy team at [email protected] or write to us at Hamou Software Co., Damascus, Syrian Arab Republic.

Back to Home