Omesta
How it worksAd creationReviewsPricingCase studies
Log inGet started
How it worksAd creationReviewsPricingCase studiesLog inGet started
GDPR

European Privacy Information

GDPR is a legal framework, not a certification earned by publishing a policy.

Last updated · September 19, 2026
PrivacyTermsCookiesGDPRData Deletion

On this page

01

When GDPR can apply

Omesta Systems LLC is a US business currently serving US customers. The EU General Data Protection Regulation can nevertheless apply to relevant activities involving an EU establishment, offering goods or services to individuals in the EU, or monitoring their behavior there. UK requirements must be assessed separately. A customer’s US address alone does not determine where its visitors or attendees are located.

We do not represent that Omesta is GDPR-certified or that publishing this page establishes compliance. Read our Privacy Policy for current data categories, recipients and controls, and the European Commission’s applicability guidance.

02

Roles and processing agreements

Omesta generally determines the purposes of account, billing, support and service-security processing. For customer-directed end-customer records, the business or organizer generally determines the purposes and Omesta processes on its behalf. Actual responsibilities depend on the activity and cannot be changed simply by naming a role in a policy.

We do not currently offer an approved standard Data Processing Addendum (DPA) through account settings. Contact support@omestasystems.com before connecting data that requires one. An Article 28 processing agreement, required provider contracts and any necessary transfer safeguards must be separately reviewed and established before the relevant processing. These pages are not a signed DPA or Standard Contractual Clauses.

03

European privacy rights

Where GDPR applies, rights can include access, correction, erasure, restriction, portability, objection and withdrawal of consent, subject to legal conditions. You can complain to the competent supervisory authority. See the EEA authority directory or the UK Information Commissioner.

Send requests to support@omestasystems.com. You do not need an Omesta account. Identify the business or event involved; do not send passwords or unnecessary sensitive documents. Where we act for a customer, we may coordinate with it after proportionate verification.

The usual GDPR response period is one month from receipt. A permitted extension can add two further months for complexity or number of requests, with reasons communicated within the initial month. Rights are not replaced by a dashboard button or made dependent on whether a complete self-service export exists.

04

Consent and sensitive context

A valid basis is required for each relevant purpose. Consent, where required, must be obtained before the processing and be capable of withdrawal. Account authorization, first-party cookies and hashed contact details do not remove that requirement.

Optional Omesta website analytics is disabled by default; when enabled, it requires an affirmative Cookie settings choice and honors Global Privacy Control ahead of saved approval. The separate customer tracking script does not default to strict opt-in and reads a saved marketing choice before that browser signal. Webhook registration and attendance transfers have separate behavior. See tracking controls and advertising transfers. These limitations must be addressed for a deployment requiring opt-in or other controls; describing them does not cure them.

Health or religious context can arise from event attendance, URLs or connected records. Assess special-category restrictions, profiling, necessity and platform rules before processing or transferring this information. Do not assume an ordinary newsletter or event registration provides permission for advertising audiences.

05

Transfers, retention and safeguards

Cloud and connected-platform processing may occur in the US and other countries. We do not promise EU-only hosting, an available EU deployment or signed transfer safeguards that have not been established. Applicable international-transfer rules require a valid mechanism and any additional measures needed for the particular transfer.

Retention and erasure must also satisfy the applicable purposes, law and agreements. Disconnecting is not complete erasure, and a reporting window is not a deletion schedule. Earlier commitments remain relevant. See retention and deletion requests.

Contact us to assess a proposed European deployment, including processor contracts, transfer assessments, consent, rights handling, incident-response duties and whether a representative, data protection officer or impact assessment is required. This page does not claim those arrangements already exist.

The new dashboard does not change that readiness assessment. AI chat, creative inputs and outputs, team or managed-service access, profiling, and any new production provider must be included in the processing inventory, contractual review, retention and deletion testing, and any necessary impact or transfer assessment before covered processing begins. A plan comparison or credit purchase is not consent from the people described in uploaded material.

06

Contact

Omesta Systems LLC, 5830 E 2nd St, Ste 7000 #33555, Casper, WY 82609, United States. Email support@omestasystems.com. Nothing here removes a right or obligation under applicable law or an existing agreement.

Need something else?

Reach our team at support@omestasystems.com. We respond within one business day.

Product

  • How it works
  • Ad creation
  • Pricing
  • Reviews
  • Integrations

Solutions

  • Local businesses
  • E-commerce
  • Marketing agencies
  • Growth teams
  • Multi-brand

Resources

  • Blog
  • Case studies
  • Compare
  • Glossary
  • Help center
  • Changelog

Company

  • About
  • Careers
  • Partners
  • Press
  • Security
  • Contact
  • Privacy
  • Terms
  • Refund policy
  • Data disclosure
  • System status

© 2026 Omesta Systems.