Privacy policy
Which data we keep about you, why, for how long, and what you can decide about it.
Last updated: 18 September 2026
Who processes your data
- The data controller is Ōmata Insurance, Justitiestraat 30, 2018 Antwerp, hello@omata.be.
- For any privacy question, you can write to the e-mail address above.
What data, and why
- What you type and send in the chat: the conversation itself, and the files you attach. We use these to understand your question, to handle it, and to help you faster afterwards — the context of a conversation is exactly what saves you explaining it a second time.
- Who looks at it: at Ōmata, that is today a staff member following up on your question. So that a reply can be written, the text of the conversation goes to the provider of the language model behind the assistant, listed below under "Who we share data with"; the files you send do not go there.
- What does not happen today: we do not record the conversation. It sits in the memory of your own screen and is gone on a reload; what you email us stays in our mailbox. As soon as we do store conversations, that will be in an environment set up for it, with a retention period that will be stated below.
- On what legal basis: we handle your request in order to prepare or perform the contract with you (Article 6(1)(b) GDPR). Sending a newsletter is a different purpose on a different basis, and the two are not mixed. The legal basis for the data of prospects (those who are not yet clients) has not yet been determined.
- Not for anything else: if a new purpose is added, it will be stated here first, and we will ask your consent where consent is the basis. A purpose that is not stated here is a purpose for which we do not use your data. Nothing comes from other sources today: Ōmata starts without existing client data.
Automated processing
- An AI assistant conducts the conversation. That is also stated literally: the chat window states "You are talking to an AI assistant", so this is never unclear.
- No policy is ever concluded without confirmation from an insurance expert. A decision is therefore never taken in a fully automated way (article 22 therefore does not apply today); should that ever change, the right to human intervention and to an explanation would still apply.
- The AI intake today asks questions to clarify your situation; it does not recommend any policy over another.
Who we share data with
- The insurers a request ends up with.
- The suppliers that process data on our behalf: hosting, e-mail, WhatsApp, the provider of the language model behind the assistant. Each of them should have a data processing agreement; that list can only be complete once every supplier has been chosen.
- Microsoft, for the visitor statistics (Microsoft Clarity) on the four public pages of the site — not on "My file", and not in the chat window: that is expressly masked, so that no word from a conversation ends up in a session recording. Clarity only loads after your consent via the consent bar, and Microsoft does not act on our behalf there but as its own controller, partly on servers in the United States, on the basis of its certification under the EU-US Data Privacy Framework. What exactly Clarity places, and what Microsoft does with it, is set out in the Cookie policy.
- We store your data within the European Economic Area. Where Ōmata uses a processor that handles data outside it, that happens only on a valid transfer basis; for Microsoft Clarity, that basis is stated above.
How long, and what rights
- How long we keep things. The GDPR sets no fixed period: data may not be kept longer than is necessary for the purpose (Article 5(1)(e)). Where Belgian law imposes a period, we follow it; where no statutory period applies, we keep it short.
- A conversation or request that does not lead to a policy: 1 year after your last contact with us.
- A client file, including what we recorded about your demands and needs: 10 years after the end of the contract. That is the limitation period for a contractual claim, and it covers the shorter periods under insurance law (3 years for a claim under the policy, 5 years for the claim of an injured third party).
- Data that receives extra protection, such as health data in the event of a claim: no longer than the file they were needed for, and after that only for as long as the limitation period of that file runs.
- Invoices and other accounting records: 7 years, and 10 years where the VAT retention duty or the anti-money-laundering law requires it.
- Cookies and measurement data: the period is stated per cookie in the Cookie policy.
- Your rights: access, correction, erasure, restriction, portability, objection, and withdrawing consent where that is the basis.
- How to exercise these rights: via hello@omata.be. You can also file a complaint with the Data Protection Authority, Drukpersstraat 35, 1000 Brussels.
- For Microsoft Clarity specifically, a distinction applies between two parts. For the Ōmata part — whether Clarity is active on this site, and the two cookies placed by Ōmata itself (see the Cookie policy) — you exercise your rights with Ōmata, in the same way as above. For the Microsoft part — what Microsoft does with the data after receiving it, as its own data controller — you turn to Microsoft itself, via the rights described in Microsoft's own Privacy Statement.